Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

121–130 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#121
post #25

Earlier quoted context omitted.

ACME / Let's Encrypt go in the direction of making expiry happen so often that renewal gets automated, rather than a being a rare manual process that can be forgotten about. Not sure that's viable for a signing certificate like this, but that's the way to solve it for the web PKI.

It’s funny to me that people talk about this limitation as if it were some kind of virtue.

Short-term certs _are_ a virtue. Not only do you not have a manual event rare enough for people to forget how to do it, you also don't have to worry about which 15 services someone granted a 10 year wildcard cert to early in the company's history.

Re: All extensions disabled due to expiration of intermediate signing cert

#122

Earlier quoted context omitted.

protecting 99.999% of the users It is horribly paternalistic to advocate for keeping users ignorant, unlearning, and --- dare I say it --- easily manipulated. I will refrain from mentioning again that infamous Franklin quote. I am frankly very fucking pissed off by this authoritarian walled-garden trend, and vehemently oppose anyone who helps this industry put the nooses around the necks of others as well as their ow…

I’ve been in software development and operations for 25 years. I still don’t want to have to understand everything I ever touch, even if I could.

>I still don’t want to have to understand everything I ever touch

If you don't understand it, don't touch it. The default settings should work for most users. There can even be a warning against touching without understanding, like with Firefox's about:config. The offensive thing is preventing users from touching even if they do understand.

Re: All extensions disabled due to expiration of intermediate signing cert

#123
post #12

I’ll still keep using Firefox since I recognize the importance of browser diversity and the hazards of a Chrome monoculture (that and vertical tabs), but, yikes. Still, this type of oversight seems all too common even in large companies. I remember several cases from Fortune 500 companies in the past few years alone. What would be a good way to automate checking for them? Has anyone developed a tool designed specific…

That's a great question. I've never seen a bulletproof solution for organizational tasks that need to be done yearly. If someone's in charge... and both they and their manager happen to leave in the same year... and whatever system they had in place to remember (probably their personal calendars) is gone... and the manager's manager has 1,000 other things to remember... ...how does an organization ensure the task sti…

There should be a separation between the things that need to get done and the people that do them. As in, tasks should be created first and then assigned.

Re: All extensions disabled due to expiration of intermediate signing cert

#124

Earlier quoted context omitted.

> Why can't I tell my copy of Firefox to ignore the certificate? Why can't I sign my own extensions? The issue is that if you leave any sort of lever that reduces security, it will be abused by bad actors. This is why browsers are having ever decreasing ways to bypass security and have full access. It is annoying, but at the end of the day, protecting 99.999% of the users trumps what us power users want.

Consider the recent news stories about the Boeing 737 Max. Boeing added an automatic system to an airplane, and then didn't give users (the pilots) a way to disable that system. This worked out great while the automatic system is working properly. When the system broke, well, we all know what happened. If we're going to assume that software is right and the user is wrong 100% of the time, then the software needs to a…

You mean the 737Max?

Re: All extensions disabled due to expiration of intermediate signing cert

#125
post #45

Earlier quoted context omitted.

Why does someone need to be fired? Does some blood spilled really make it better? Have some compassion.

I'm generally not a fan of firing people for making mistakes. This one is so monumental it may require it though. This breaks most FF installations.

Couldn’t disagree more. Do you want to fix the conditions that led to the problem? Or do you view a post mortem as a punitive process?

Re: All extensions disabled due to expiration of intermediate signing cert

#126
post #25
post #12

I’ll still keep using Firefox since I recognize the importance of browser diversity and the hazards of a Chrome monoculture (that and vertical tabs), but, yikes. Still, this type of oversight seems all too common even in large companies. I remember several cases from Fortune 500 companies in the past few years alone. What would be a good way to automate checking for them? Has anyone developed a tool designed specific…

ACME / Let's Encrypt go in the direction of making expiry happen so often that renewal gets automated, rather than a being a rare manual process that can be forgotten about. Not sure that's viable for a signing certificate like this, but that's the way to solve it for the web PKI.

See also: GPS vs GLONASS time encoding. GPS rolls over every 19 years, so devices, cars and even Boeing aircraft saw their GPS-based clocks turn back to 1999 last month. Meanwhile, GLONASS epochs are only four years long, so every device that uses it as a time reference is built to handle rollover.

Re: All extensions disabled due to expiration of intermediate signing cert

#127

Earlier quoted context omitted.

Consider the recent news stories about the Boeing 737 Max. Boeing added an automatic system to an airplane, and then didn't give users (the pilots) a way to disable that system. This worked out great while the automatic system is working properly. When the system broke, well, we all know what happened. If we're going to assume that software is right and the user is wrong 100% of the time, then the software needs to a…

You mean the 737Max?

Yes, that was stupid. Edit now, thank you.
Post reply on HN