Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

111–120 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#113

Earlier quoted context omitted.

> They'd better have the best post mortum ever, possibly with someone being fired. Arguably these two goals are incompatible. :)

People are generally not inclined to be truthful about their mistakes if they expect to be punished for them. Its how problems keep getting covered up until they become catastrophes.

I guess it depends on if it was an honest mistake or gross negligence. I don’t think people should be fired for mistakes. I also don’t think everyone should be trusted with important tasks.

Re: All extensions disabled due to expiration of intermediate signing cert

#116
post #45

First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla. They'd better have the best post mortum ever, possibly with someone being fired.

Why does someone need to be fired? Does some blood spilled really make it better? Have some compassion.

Why does someone need to be fired?

That might seem rather extreme, but the fact that this situation was even possible was a consequence of a series of bad decisions over an extended period of time about the required behaviour of new versions of Firefox, combined with technical failures that betray fundamental weaknesses in the whole system design. Whoever was ultimately responsible for those failings demonstrably isn't competent to run something of this importance and should probably either implement immediate and dramatic changes to the relevant policies and technical details or consider their position. Anything less is surely going to damage trust, which is something Firefox can ill afford when it's already in danger of being reduced to a niche product rather than a mainstream browser.

Re: All extensions disabled due to expiration of intermediate signing cert

#117
post #44

This is why users need to be in control of their own computers. Why can't I tell my copy of Firefox to ignore the certificate? Why can't I sign my own extensions? Mistakes happen, it's okay. But users should be empowered to work around them.

It is possible, according to another post by bitbang [1]: > Temporary work around till the cert gets fixed: set "xpinstall.signatures.required" to false https://news.ycombinator.com/item?id=19823879

Gratzi!

Re: All extensions disabled due to expiration of intermediate signing cert

#118
post #70

Earlier quoted context omitted.

I'm generally not a fan of firing people for making mistakes. This one is so monumental it may require it though. This breaks most FF installations.

You didn't answer my question. What does firing achieve? You fire a person who learnt their lesson and will never make the mistake again? And then hire someone new? Or you fire the scapegoat because of a broken system that allowed one person to make a mistake?

If this mistake was due to incompetence then the person should be fired. Incompetence shouldn't be tolerated.

But we're outsiders looking in and don't know what's going on at this point. That's why I used the qualifier "possibly." It's quite possibly it wasn't incompetence.

Re: All extensions disabled due to expiration of intermediate signing cert

#120

First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla. They'd better have the best post mortum ever, possibly with someone being fired.

A mistake of this magnitude cannot be the fault of an individual, because if it was, then the organization lacked adequate safeguards. What I'd like to see is a post-mortem, followed by an explanation of how they'll prevent the mistake from being made again in future.

I hope you're correct.
Post reply on HN