Live data from Hacker News

Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

ghacks.net

31–37 of 37 posts

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#31
post #17

Earlier quoted context omitted.

> Decade-old versions of TLS are flat-out bad for users. TLS 1.0 is from 1999! no, bad standards are flat-out bad for users. lots of text files being written in ascii, for example, and 'ASCII is from 1963!'

Time to get on the ball and upgrade to Latin-1.

You mean latin-9 hopefully. The one with the euro sign.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#33

Earlier quoted context omitted.

Time to get on the ball and upgrade to Latin-1.

You mean latin-9 hopefully. The one with the euro sign.

That may be too difficult. These things take time.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#34
post #11
post #6

>"The preference change will be remotely applied to Firefox 74" No thanks. How do they do this, and how do I stop people from being able to remotely "manage" my Firefox install?

While I agree with the pragmatic choice of keeping older TLS enabled a while longer, I am very much at unease of Firefox remote updates and management (pushing code fixes as studies etc), disrespecting preferences in local configs and proliferation of services and multitude of background service connections. Mozilla, please, I want a browser that I , as a "power user" can manage. Not an idiot-proof remotely managed o…

> Mozilla, please, I want a browser that I, as a "power user" can manage. Not an idiot-proof remotely managed on-prem SaaS.

Then you need to accept that Firefox will linger at a very low number of users and many of those users will be left with insecure browsers because they fail to update them properly. Maybe that's a fine thing, but that's the world you need to accept if Firefox is explicitly targeting power users.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#35
post #11

Earlier quoted context omitted.

While I agree with the pragmatic choice of keeping older TLS enabled a while longer, I am very much at unease of Firefox remote updates and management (pushing code fixes as studies etc), disrespecting preferences in local configs and proliferation of services and multitude of background service connections. Mozilla, please, I want a browser that I , as a "power user" can manage. Not an idiot-proof remotely managed o…

> Mozilla, please, I want a browser that I, as a "power user" can manage. Not an idiot-proof remotely managed on-prem SaaS. Then you need to accept that Firefox will linger at a very low number of users and many of those users will be left with insecure browsers because they fail to update them properly. Maybe that's a fine thing, but that's the world you need to accept if Firefox is explicitly targeting power users.

It's not either or. They could make it easy do disable all various background activity, document users prefs and respect provided settings (perhaps with different branding), accept targeted donations etc.

Firefox is already providing automatic updates. Would it be so bad to release a point version (do they even to that anymore) instead of a remote preference change?

Still, it's not exclusive - they could do both, while providing a clear power user mode, where you may need to update, because they don't do such shenanigans.

It's not an idle offer - I'm offering 1k€ to properly document user prefs and not second guess their setting (could be a compile time switch, possibly with altered branding, but on a supported/LTS versions). Anyone want to set up a gofund me or something?

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#36
post #32

I have Firefox 74.0 with studies disabled and yet TLS 1.0 and 1.1 are enabled. I don't understand how Mozilla turned them on if I had studied disabled since the Mr. Robot incident.

I was also curious. It appears they used Normandy. From the Mozilla website: "Normandy Pref Rollout is a feature that allows Mozilla to change the default value of a preference for a targeted set of users, without deploying an update to Firefox. This document focuses on the use of Pref Rollout as a mechanism to enable feature flagging in Firefox."

And I see a new Firefox about:config preference: app.normandy.startupRolloutPrefs.security.tls.version.min

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#37
post #36
post #32

I have Firefox 74.0 with studies disabled and yet TLS 1.0 and 1.1 are enabled. I don't understand how Mozilla turned them on if I had studied disabled since the Mr. Robot incident.

I was also curious. It appears they used Normandy. From the Mozilla website: "Normandy Pref Rollout is a feature that allows Mozilla to change the default value of a preference for a targeted set of users, without deploying an update to Firefox. This document focuses on the use of Pref Rollout as a mechanism to enable feature flagging in Firefox." And I see a new Firefox about:config preference: app.normandy.startupR…

Thanks for the pointer. I've set 'app.normandy.enabled' to false, hopefully that is the last way someone can change something on my computer without my knowledge.
Post reply on HN