Live data from Hacker News

Technical Details on the Recent Firefox Add-On Outage

hacks.mozilla.org

251–260 of 279 posts

Re: Technical Details on the Recent Firefox Add-On Outage

#251

Earlier quoted context omitted.

In the case of apt-get, there's a release process with signed packages and open source code that the distributions adhere to, publicly visible oversight etc. End users specifically make the choice, either to run the upgrade process themselves, or set up automated upgrades on the understanding of what processes things have gone through, and the ability to verify. The Studies mechanism occurs silently, running private…

The Studies mechanism is clear, public and fully transparent. You can see what they've done. You can see what they plan to do. It's all out in the open. At the end of the day the question is whether you can trust Mozilla. I trust them more than most entities, including many that push changes through apt-get.

Yes, Studies, that mechanism so open that end users didn't know about it until they found they were participating in some random Augmented Reality marketing collaboration with a TV show.

I would love to see a link to the code related to various Studies. So far I've not been able to find any. All you seem to get told is the name of any studies you're in, and only if you go over to about:studies and go looking.

This is not to say I don't trust Mozilla. I do. I trust them far more than I do Google / Chrome. It's hard not to see Studies as a privacy nightmare, though, and the level of power it has is disturbing.

Re: Technical Details on the Recent Firefox Add-On Outage

#252

Earlier quoted context omitted.

Normal update channels usually ask me (or let me set it so that they have to ask me) if I want to apply the update and I make sure to at least read the changelog if not skim through the source. In addition to that I trust the Debian team much more than I trust the Mozilla team. The studies in contrast are both for anti-user things such as telemetry and the mr robot thing, are inconvenient to disable, are not transpar…

I love it. You read the changelog and what, you reject the update for some trivial thing you don't like and stay on that previous version forever? Seriously, look at how studies operates. If you're using firefox, go to about:studies and see for yourself.

No, I reject the update for non-trivial issues which I feel that violate my privacy or could pose some other serious threat and move to some other browser as soon as possible.

> look at how studies operates

It works on the background and without asking you anything. Is that correct?

> If you're using firefox, go to about:studies and see for yourself.

It says "You have not participated in any studies." - probably because I have them disabled.

Re: Technical Details on the Recent Firefox Add-On Outage

#253
post #11

Looks like a good read. I haven't finished reading it yet, but there's something I still don't get ... Windows and macOS both have a signing infrastructure for apps. The rules of that infrastructure dictate only that apps must have been signed by a valid certificate at the time they were signed. That way old app downloads don't need to be periodically re-signed just to account for expiring certificates. I can downloa…

One small note on your mention of MacOS, and I don't know if this has been fixed. A couple of years ago, the certificates expired on some versions of the OS installer, like El Capitan and could no longer be verified. While there's the simple workaround of changing the clock, it did give me pause when trying to get an old Mac upgraded to the latest supported operating system.

Re: Technical Details on the Recent Firefox Add-On Outage

#254

My point of view as a long-time Firefox user that cares about privacy but also knows we live in an imperfect world: It obviously sucks that this happened but I think they handled it very well. The bug was fixed so quickly that I wouldn't even have realized it had happened if it hadn't been for the thread here on HN. My extensions hadn't even been disabled yet by the time the patch came out. And pushing out the hotfix…

They were able to push out a fix so fast because they repurposed the "sure, do some studies on my usage" to enable arbitrary changes to the browser that are under the control of the marketing team. And a lot of people were "opted in", thinking they had opted out.

That is 100% not reassuring. Remember Looking Glass?

https://news.ycombinator.com/item?id=15956325

Well, the marketing team has the power to tweak how ads are handled, silently, with no update action from the user.

Out of the frying pan, into the fire.

Re: Technical Details on the Recent Firefox Add-On Outage

#255

My point of view as a long-time Firefox user that cares about privacy but also knows we live in an imperfect world: It obviously sucks that this happened but I think they handled it very well. The bug was fixed so quickly that I wouldn't even have realized it had happened if it hadn't been for the thread here on HN. My extensions hadn't even been disabled yet by the time the patch came out. And pushing out the hotfix…

To contrast, I noticed my extensions were disabled first thing in the morning, and if I had not seen the thread(s) on HN I would have spent maybe a few hours trying to fix.

Re: Technical Details on the Recent Firefox Add-On Outage

#256

My point of view as a long-time Firefox user that cares about privacy but also knows we live in an imperfect world: It obviously sucks that this happened but I think they handled it very well. The bug was fixed so quickly that I wouldn't even have realized it had happened if it hadn't been for the thread here on HN. My extensions hadn't even been disabled yet by the time the patch came out. And pushing out the hotfix…

> The bug was fixed so quickly that I wouldn't even have realized it had happened if it hadn't been for the thread here on HN Maybe this is a timezone thing, but I was in East Asia, and I had to deal with the internet for close to 36 hrs (android) with no ublock. It was almost enough to look for a new browser (but browsers with adblock on Android are few and far between - so instead I just didn't use the internet as…

You should give Brave a shot. Seriously, every time I open Chrome on my phone on accident, I'm horrified at what the internet has become..

Re: Technical Details on the Recent Firefox Add-On Outage

#257
post #232
post #217

Earlier quoted context omitted.

The idea here may be to invalidate certain add-ons after they have been released in the wild by revoking the certificates used to sign them.

Only one certificate was used for all add-ons, its expiration disabled all signed. No “certain add-ons” it was “all.”

Per the article, there is a separate "end-entity" certificate for each add-on. They were all signed by the same "intermediate" CA, however.

Re: Technical Details on the Recent Firefox Add-On Outage

#258
post #82

If anyone's wondering if this answers the Actual Question of why the cert was allowed to expired, don't waste your time, it doesn't. I guess implicitly that's a "social detail"?

The post-mortem hasn't happened yet. ekr's post is a preliminary description of what happened, everything he felt confident saying in advance of the post-mortem and so necessarily heavy on technical details but light on process details.

Yes I saw that, I just wish he had mentioned this at the top of the post (which currently reads " I wanted to walk through the details of what happened, why, and how we repaired it.") instead of near the bottom.

Re: Technical Details on the Recent Firefox Add-On Outage

#259

Earlier quoted context omitted.

Just to be clear: supported version or not, this sucks, and I hope we'll have a fix for you. I wanted to point out this wasn't remotely broken, however. Even if you had no internet connection, your addons would have stopped working when the certificate expired. (Disclosure: I work for Mozilla)

Hey sciurus, I just wanted to chime in way down deep in this comment chain because my thought only makes sense in the context of your comment right here. I think there may be a special mode of operation of Firefox that may need to be considered here. You said, "Even if you had no internet connection, your addons would have stopped working when the certificate expired." This seems like an unfortunate design flaw to me…

> I think it is a reasonable expectation that the marooned Firefox should continue to run indefinitely without failure.

I personally agree this is a worthwhile goal. The blog post talks about "tracking the status of everything in Firefox that is a potential time bomb and making sure that we don’t find ourselves in a situation where one goes off unexpectedly." I expect once that is done we'll be positioned to evaluate if and how we could support this.

(Disclosure: I work for Mozilla)

Re: Technical Details on the Recent Firefox Add-On Outage

#260
post #256

Earlier quoted context omitted.

> The bug was fixed so quickly that I wouldn't even have realized it had happened if it hadn't been for the thread here on HN Maybe this is a timezone thing, but I was in East Asia, and I had to deal with the internet for close to 36 hrs (android) with no ublock. It was almost enough to look for a new browser (but browsers with adblock on Android are few and far between - so instead I just didn't use the internet as…

You should give Brave a shot. Seriously, every time I open Chrome on my phone on accident, I'm horrified at what the internet has become..

Why? I use firefox+uBlock on my phone, and don't have chrome installed on any devices.
Post reply on HN