Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

261–270 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#261

Earlier quoted context omitted.

> Those still would have their certificates checked on installation. How? These extensions were not being installed through the normal mechanism. The malicious extension installer will just set the flag that says "this extension has been verified". > And honestly, I think it is security theater to attempt to defend against attackers on the same or higher privilege level. I understand that, and Mozilla does too: "By b…

But that's the point. Either the installer does something malicious or it doesn't. If it does you lost the game. If it doesn't then a simple check is sufficient. Everything else is security theater which makes life worse for everyone. Also, they could still run the verification and prompt the user instead of just forcing the decision.

I don't think that's necessarily true. After all, the policy is effective against undesirable-but-not-malicious extensions. Before signature verification I had extensions installed in Firefox that I didn't install; today I don't. [1]

And the clearly malicious action of modifying Firefox to disable signature verification can and should be flagged by anti-malware software, which runs at a higher privilege level.

[1] Putting aside for the moment the fact that most users now have no extensions installed due to the certificate expiration issue. No Firefox user, myself included, is happy about that.

Re: Update Regarding Add-Ons in Firefox

#262

I'm shocked and suprised to find out that mozilla is using EXPIRING certificates for this. It requires them to continuously take action to prevent all addons from breaking, which will eventually fail (like it did). Firefox has a pretty robust update system and everyone is used to frequent updates. Why don't they instead have a revocation system built into updates? That way they would have to take action to disable ma…

You are right. It doesn't make any sense to use certificates for this kind of stuff.

If an extension turns out to be malicious, you simply deactivate it in the store, and then proactively deactivate the existing installs. This is how Chrome is doing it.

But having a certificate does offer Mozilla the feeling of absolute control, which seems to be of primary importance for them nowadays.

This is probably the reason release and beta users are not even allowed to deactivate signing in the about:config settings.

Re: Update Regarding Add-Ons in Firefox

#263

Earlier quoted context omitted.

So that's pretty unfair. 1) They state they are working on a fix for normal, release channel users who don't want to run studies 2) they tell you to temporarily run studies to get the fix within up to 6 six hours (could be faster; set expectation) 3) You can explicitly install nightly or 66.4 before it's pushed if you want a fix now Yes, it's unfortunate, I'd expect them to meet it head on, push a tested fix in a tim…

Not saying that their current actions are wrong , just that the optics of it are terrible for them. There was a chain of bad decisions that led them here though: 1) thinking it's ok to disable software after its installed (using cert expiration -- I'm ok if the cert was revoked but that's a totally different discussion), 2) Taking more control of people's local software than many people are comfortable with, especial…

Being a former ops guy the items you list resonate with me. On the one hand I do feel for the developers and hope they come up with a fix soon. On the other side, this is frustrating and there were some bad decisions made that a typical ops person would have pointed out and been ignored. The ignoring of ops guys until something breaks is something that has been consistent in my experience. Anyway for the sake of having an alternative to Chrome I hope they fix this yesterday.

Re: Update Regarding Add-Ons in Firefox

#264

Earlier quoted context omitted.

Hiding behind ToS is ridiculous. Nobody reads them and a moral company should never assume that because its in the ToS they actually have informed consent.

TOS agreements should be illegal in the US, especially those that try to circumvent our 'Freedoms of Speech'.

[flagged]

Re: Update Regarding Add-Ons in Firefox

#265

Earlier quoted context omitted.

I agree with you, it was more important to do the work than to signal. However, I bet it’s likely they have procedures and policies for work that first involve signaling like for example the priority level. I’d be willing to bet lots of things surrounding this issue weren’t handled in a by the book manner. So if you are always going to wing it, why have a book (or a public priority level system) at all?

First, because priority is for things like major feature work, so that engineers can find the bugs that are useful to work on. In this case, everyone in the team responsible was already spending 100% of their time addressing the issue. Second, because we care about solving problems, not being bureaucrats.

Really? Because being the bottleneck (i.e. single point of failure) responsible for approving all addons is exactly what bureaucrats would want to do ;-)

The non-bureaucratic thing to do, as has been pointed out many times of course, would be to give users the power to override the cert signing check as an advanced option.

Re: Update Regarding Add-Ons in Firefox

#266

Earlier quoted context omitted.

As I understand it, you agree to the terms of Studies as part of the ToS agreed to on installation. You can disable it later. And--while it was a ridiculous mistake--they didn't make any "unauthorized changes" to your computer. They just let a certificate expire and your computer, running the same code it always had, stopped trusting it.

Hiding behind ToS is ridiculous. Nobody reads them and a moral company should never assume that because its in the ToS they actually have informed consent.

At what point is it your responsibility to verify that something you're using is keeping it's end of the bargain? Ceding all responsibility doesn't seem like the answer either. While forced arbitration and other crappy things in contracts suck, a company protecting itself against explicitly stupid or bad behavior seems reasonable. While it's reasonable to expect a consumer to understand hot coffee is hot, its unreasonable to say that a customer who has purchased coffee that gives them second degree burns had reasonable understanding of the risks. I think the only real solution would be putting customers through plain English video presentations of what rights are present or excluded for every piece of software. This would be terribly inconvenient, however it would make sure people only installed software they trusted and actually needed.

Re: Update Regarding Add-Ons in Firefox

#267
Mozilla decided to make signing mandatory, then screwed up and now they're trying to fix it by making use of a feature that basically allows them to remotely execute code on all their users silently?

I checked Mozilla's main site again, and it still has this ironic statement in its description tag (it's been there for many years):

https://www.mozilla.org/en-US/firefox/new/

Firefox is created by a global non- profit dedicated to putting individuals in control online.

...I guess it's more dedicated to putting Mozilla in control now. Something about this whole incident brings up a point that just feels very wrong to me --- it's not a Google or Microsoft, but the fact that Mozilla also seems to have this large amount of control over its users is unsettling.

Re: Update Regarding Add-Ons in Firefox

#268
post #219

Earlier quoted context omitted.

So you think Mozilla is enjoying this right now? And that this is going to help the perception and market share of Firefox? Hypothetically, lets say they took the opposite approach, and only checked the certificate date on installation. What would have happened? There would have been a brief period of time where people couldn't install extensions, it would have been fixed in a few hours, and this story would probably…

Not only that, but now people are evaluating other decisions that Mozilla has made separately from this in an unfavorable light (Studies and Normandy, specifically). Sounds like a good thing. Probably sounds like a good thing to some of the engineers at Mozilla. The computing industry loses out on this too: we're all better off for chrome having a viable open source competitor. I want a free competitor, not an open s…

I do agree; although, it would have been nice for this discussion to come up without things breaking like this.

Re: Update Regarding Add-Ons in Firefox

#269

This one will be emotional as this destroyed some of my today's work. F you Mozilla. I lost all my tabs opened in other containers. The containers don't work too, so I cannot reopen them. This bug has been known for 3 years, and you did nothing to fix it. You get so much money, and what you do is basically provide a pathetic software (thunderbird) and a nice browser (which you just stopped from working) and you show…

Hey, just FYI, there are some good solutions in this thread to get your problem fixed ASAP.

This one should work. https://news.ycombinator.com/item?id=19827302

Re: Update Regarding Add-Ons in Firefox

#270

Earlier quoted context omitted.

But that's the point. Either the installer does something malicious or it doesn't. If it does you lost the game. If it doesn't then a simple check is sufficient. Everything else is security theater which makes life worse for everyone. Also, they could still run the verification and prompt the user instead of just forcing the decision.

I don't think that's necessarily true. After all, the policy is effective against undesirable-but-not-malicious extensions. Before signature verification I had extensions installed in Firefox that I didn't install; today I don't. [1] And the clearly malicious action of modifying Firefox to disable signature verification can and should be flagged by anti-malware software, which runs at a higher privilege level. [1] Pu…

I consider these to be mental acrobatics to find a position to justify wresting away any control from the user. It is not mozilla's responsibility to attempt to protect the user from the very slim line of "effectively malicious but still somehow principled" malware, picking a near-by line of verifying once would be far less problematic.

If the user does not want that crap on their machine they should remove the origin instead. We would not have the current situation if mozilla did not assume responsibility and control for problems outside their domain.

At least they could have made this opt-in by asking the user if they want an extra locked down version of firefox that might disable their addons if they are deemed malicious. Then the user could have made an informed choice.

Post reply on HN