Somewhat related to this ongoing Mozilla plugin saga, are there any infamous stories I should look up that involve huge mistakes leading to unfixable clients? Ie. Imagine bricking your customer's devices with an irreversible buggy update. In Mozilla's case they were able to deploy a hotfix for many, and an update for others. But I imagine there's got to be some great stories about completely bricking countless device…
It's one of my favorite interview questions. I only know the answer because it happened to us once with 5M users on the affected version before it was discovered. It's a very good question to see how people react in a mostly hopeless situation. The only candidate out of 100s to logically get to the solution (or essentially it) was one of the best engineesr I've hired and worked with. "So you and your team just releas…
Tor Browser disabled NoScript, but can't update
31–40 of 125 posts
Re: Tor Browser disabled NoScript, but can't update
#32Conspiracy theory time: Mozilla received a National Security Letter, or equivalent, requiring them to all this cert to expire in an effort to weaken Tor.
Re: Tor Browser disabled NoScript, but can't update
#33Re: Tor Browser disabled NoScript, but can't update
#34I don't buy for 5 minutes that Tor Browser is secure regardless of configuration. TAILS maybe but Tor Browser you may as well let an FBI agent into your house. A few years back the government starts busting all these dark web sites/users and will pull out of court cases rather then explain how. Gee I wonder.
You don't need to "buy" this idea - we're talking about free and open source software. If you passionately believe it's insecure, you would do everyone a great service by explicitly pointing out how it is so in the source code, rather than peddle FUD.
Re: Tor Browser disabled NoScript, but can't update
#35I can't improve upon this comment: "Hey Mozilla - this is why people said that forcing addons to be signed with no way to disable was a bad idea. You didn't even make it a year without screwing it up. Who could have seen this coming? Oh wait, pretty much everyone who argued against this policy."
It's a dumb comment. There was a ton of malware being distributed as add-ons that came packaged with other installers. This solved that issue.
Re: Tor Browser disabled NoScript, but can't update
#36Every single one of my Firefox extensions stopped working with an error message that says "could not be verified for use in Firefox and has been disabled" re-downloading doesn't work either. I'm assuming it's happening to everyone?
Re: Tor Browser disabled NoScript, but can't update
#37This whole thing is also yet another reason to use something like Tails or Whonix which are much safer to use with JS enabled.
Re: Tor Browser disabled NoScript, but can't update
#38Somewhat related to this ongoing Mozilla plugin saga, are there any infamous stories I should look up that involve huge mistakes leading to unfixable clients? Ie. Imagine bricking your customer's devices with an irreversible buggy update. In Mozilla's case they were able to deploy a hotfix for many, and an update for others. But I imagine there's got to be some great stories about completely bricking countless device…
It's one of my favorite interview questions. I only know the answer because it happened to us once with 5M users on the affected version before it was discovered. It's a very good question to see how people react in a mostly hopeless situation. The only candidate out of 100s to logically get to the solution (or essentially it) was one of the best engineesr I've hired and worked with. "So you and your team just releas…
Most applications have some data that comes from a remote server, whether it's on the home screen, any kind of announcements screen, server-sourced error messages, etc.
I would use that to communicate an update is available, with a handy link.
Re: Tor Browser disabled NoScript, but can't update
#39If Mozilla hadn't locked down Firefox so much, the fix could have been as simple as going into about:config and flipping a switch to allow unsigned plugins.
Ordinary users would have 5 levels of toolbars!!! Installed by anti-virus apps, etc.
Locking down can back fire, but think not that this wasn't done in the interest of most users.
Re: Tor Browser disabled NoScript, but can't update
#40> remotely disable Tor anonymity protections [!]
Maybe a 'certificate is expiring soon' warning on the browser side?
Users would know and Mozilla would be forced to keep certs valid.