Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

21–30 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#21

This is a goddamned disaster. I'm just thankful that I use an offline password manager, but even still ... I like FF, don't get me wrong, but this is going to absolutely fucking destroy user trust in Mozilla. This kind of incompetence, on a browser scale , is breathtaking.

>This is a goddamned disaster. I'm just thankful that I use an offline password manager I'm not sure this cert is used with the PW manager?

I think MrEldritch is referring not to Firefox's built-in password manager, but third-party password managers such as Bitwarden, KeePass, and LastPass. Those rely on add-ons for browser integration.

Re: All extensions disabled due to expiration of intermediate signing cert

#22
post #12

I’ll still keep using Firefox since I recognize the importance of browser diversity and the hazards of a Chrome monoculture (that and vertical tabs), but, yikes. Still, this type of oversight seems all too common even in large companies. I remember several cases from Fortune 500 companies in the past few years alone. What would be a good way to automate checking for them? Has anyone developed a tool designed specific…

Let's not forget multiple mobile networks across Europe went down on the same day last year because Ericsson(?) let a cert expire on some internal management system that had not been updated. SSL cert renewal is one of the great unsolved problems in computer science

edit: not Europe, just UK and Japan apparently: https://www.zdnet.com/article/ericsson-expired-certificate-c...

Re: All extensions disabled due to expiration of intermediate signing cert

#23
First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla.

They'd better have the best post mortum ever, possibly with someone being fired.

Re: All extensions disabled due to expiration of intermediate signing cert

#24

First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla. They'd better have the best post mortum ever, possibly with someone being fired.

> They'd better have the best post mortum ever, possibly with someone being fired.

Arguably these two goals are incompatible. :)

Re: All extensions disabled due to expiration of intermediate signing cert

#25
post #12

I’ll still keep using Firefox since I recognize the importance of browser diversity and the hazards of a Chrome monoculture (that and vertical tabs), but, yikes. Still, this type of oversight seems all too common even in large companies. I remember several cases from Fortune 500 companies in the past few years alone. What would be a good way to automate checking for them? Has anyone developed a tool designed specific…

ACME / Let's Encrypt go in the direction of making expiry happen so often that renewal gets automated, rather than a being a rare manual process that can be forgotten about.

Not sure that's viable for a signing certificate like this, but that's the way to solve it for the web PKI.

Re: All extensions disabled due to expiration of intermediate signing cert

#27
post #10
post #5

Active discussion here: https://news.ycombinator.com/item?id=19823465

Even though that's active and has more votes, it's ranked very low (#39 as of right now, and this post is now #1 on the site). I think HN penalizes non-link posts (or people are flagging it because they think it's just someone asking for tech support).

Looks like you're right. I saw the other discussion first and it still has more comments for now, but this one is ranked higher. Perhaps the threads could be merged or something.

Re: All extensions disabled due to expiration of intermediate signing cert

#29

This is a goddamned disaster. I'm just thankful that I use an offline password manager, but even still ... I like FF, don't get me wrong, but this is going to absolutely fucking destroy user trust in Mozilla. This kind of incompetence, on a browser scale , is breathtaking.

Still beats using Chrome.
Post reply on HN