Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

281–290 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#281

On Android I get this: >We rolled out a hotfix that re-enables affected add-ons. The fix will be automatically applied in the background within the next few hours. For more details, please check out the update at https://support.mozilla.org/en-US/kb/add-ons-failing-install... Which is like "we did something we shouldn't have causing unauthorised changes to your computer, so we're going to make unauthorised changes to…

It's worth reading the comments on the original HN article about Firefox extension signing becoming mandatory. Some of them are eerily prescient:

https://news.ycombinator.com/item?id=10038999

Re: Update Regarding Add-Ons in Firefox

#282
post #67

I have a bunch of privacy-enhancing addons installed, which have now all been disabled. If I hadn't read HN this morning, I wouldn't even have known why. Until now, I had no idea that it was even possible to remotely disable my addons. And now Mozilla are saying that the "fix" is to allow them to install & run "studies" on my machine? What are they smoking? I'm having a hard time trusting a company that randomly & re…

> And now Mozilla are saying that the "fix" is to allow them to install & run "studies" on my machine? What are they smoking? Can you elaborate what's your concern with "studies"? By installing Firefox that updates automatically, the user is already giving control of the software and letting Mozilla decide what's the best. How is modifying software logic using studies different than modifying logic by updating the bi…

Studies are installed and their data sent to Mozilla without my knowledge or consent. Updates are installed with my consent. Pretty big difference.

Re: Update Regarding Add-Ons in Firefox

#283

I know Firefox isn't being malicious, but ugh, this seems like the worst possible PR move for this, optics wise. "Hey so uh, we accidentally broke your browser, so you need to opt-in to becoming a guinney pig. But don't worry! You probably were already opted in anyway and just didn't realize it! Also it might take six hours to work."

They only point out the opt-in instructions for the few people that voluntarily opt out of Shield studies and wish to get the fix sooner.

Most Firefox users have that checkbox enabled by default, and so most Firefox users received the fix within 0-6 hours of the blog post's publication.

HN readers often take special care to prevent Mozilla from updating Firefox, but that in no way represents the wider population of either all addons users or all Firefox users.

Re: Update Regarding Add-Ons in Firefox

#284

I know Firefox isn't being malicious, but ugh, this seems like the worst possible PR move for this, optics wise. "Hey so uh, we accidentally broke your browser, so you need to opt-in to becoming a guinney pig. But don't worry! You probably were already opted in anyway and just didn't realize it! Also it might take six hours to work."

On Debian the distributed ESR has that option greyed out anyways. Maybe we’ll have to wait for maintainers to push an update?

I am sure an update will be pushed quickly. I'm waiting too, as a testing user.

You can fix this temporarily via setting "xpinstall.signatures.required" to false. Toggle it back to true once update is released and you install it.

Meanwhile I'm hijacking this comment that is to the upper parts of the tree to state this: the way the community treats Mozilla and Firefox is horribly, inexplicably, unacceptably unfair.

This is nothing compared to innumerable other fuckups in software history, and even recent ones like goto fail, heartbleed, or Chrome logging you into Sync w/o notice.

This is a mistake, an easily recoverable one, and is not intentional or malicious. Firefox is developed in the out and open, all the processes are public. And people, with an absurd entitlement and malice, go as far as to call things backdoors or malware. Meanwhile the alternative actually is a backdoor ridden malware.

Please don't be this ungrateful.

Re: Update Regarding Add-Ons in Firefox

#285

This one will be emotional as this destroyed some of my today's work. F you Mozilla. I lost all my tabs opened in other containers. The containers don't work too, so I cannot reopen them. This bug has been known for 3 years, and you did nothing to fix it. You get so much money, and what you do is basically provide a pathetic software (thunderbird) and a nice browser (which you just stopped from working) and you show…

Every browser I used has managed to lose my open tabs, chrome did it most frequently and with no obvious way to restore them. Hurts every time, but the only actual answer you will not be happy to hear is you shouldn't depend on browser saving your current open tabs, that's just asking for trouble.

Re: Update Regarding Add-Ons in Firefox

#286
post #93

Earlier quoted context omitted.

If you can disable all my addons by having a certificate expire, you can effectively remotely disable all my addons. And that's exactly what happened. The fact that this was (presumably?) not intentional is irrelevant. The switch may not be an actual switch, but it's there nevertheless. And it shouldn't be.

So you are saying there should be no way for an installed addon to fail an integrity check?

Non sequitur. An installed addon could be signed with a certificate. Mozilla can push out a revocation for that certificate if it deems it appropriate. The revocation can pop up a modal telling users it wants to disable the addon. The user can click 'Disable addon' or 'Ignore (dangerous)'.

This doesn't need to be done through a dead man's switch (expiring certificate) that someone will forget to renew.

Re: Update Regarding Add-Ons in Firefox

#287

Earlier quoted context omitted.

Keep guessing.

He has moved to Lynx.

CVE-2016-9179 was published about Lynx in November 2016. Lynx took more than 5 minutes to release an update, with the fix included [1] in 2.8.9dev.11 not reaching a production release until July 2018 — almost two years after the CVE was published.

With a response time like that, I don't see how Lynx will satisfy their "5 minute fix" need any more than Firefox did.

[1] https://lynx.invisible-island.net/current/CHANGES

Re: Update Regarding Add-Ons in Firefox

#288
post #18

Instead of enabling studies just click on this link. It installs that specific "study" (hotfix) without installing anything else. https://storage.googleapis.com/moz-fx-normandy-prod-addons/e...

Please, don't tell people to do this. This way computers get infected. People should know that clicking in a random link posted by an anonymous guy on a forum page is one of the worst things they can ever do.

I addressed above (will probably stay above, it's the top reply) about why I felt safe clicking this link myself and think others should too.

You're right that in general training them to listen to anonymous forum posts is less than ideal, but all in all I'd rather they have a working browser. As a side benefit they get to see posts like this that rightly point out you shouldn't trust strangers on the internet too much.

Re: Update Regarding Add-Ons in Firefox

#289

Earlier quoted context omitted.

> And now Mozilla are saying that the "fix" is to allow them to install & run "studies" on my machine? What are they smoking? Can you elaborate what's your concern with "studies"? By installing Firefox that updates automatically, the user is already giving control of the software and letting Mozilla decide what's the best. How is modifying software logic using studies different than modifying logic by updating the bi…

Studies are installed and their data sent to Mozilla without my knowledge or consent. Updates are installed with my consent. Pretty big difference.

Oh, I did not know that. Are you sure that enabling studies also means that user's data is sent to Mozilla without consent? Are you sure about this?

I'm asking because there I can imagine that there is a benefit for Mozilla to develop a feature that enables studies without sending data. It could be used to fix a broken feature or a broken logic (as in the case of expired certificates here). So, I'm not convinced that enabling studies always means that your data gets uploaded without the consent. Can you point me to privacy whitepaper / source code to backup that statement?

Re: Update Regarding Add-Ons in Firefox

#290

Earlier quoted context omitted.

> I can boot up almost any 20 year old piece of Windows software and it'll work fine, it might not make sense in the current world but it won't go "2019? Fuck off!" Is that really true? Would it connect to 802.11m WiFi router? Would you consider it secure enough to open your banking website on it? The bar is not just booting up the machine. The bar is whether the machine is usable (secure).

> Would it connect to 802.11m WiFi router? Sure. It's using OS networking APIs. Or running in a virtual machine. > Would you consider it secure enough to open your banking website on it? If I'm running 20 year old software, it's probably to interact with a legacy system. There are still businesses that run on like 486's with Windows 3.1. This is more common than you think! > The bar is whether the machine is usable (…

> The bar is whatever I WANT it to be, it's my machine, and it's pretentious of a software developer to assume they know what I'm using the software for and what my best interests are. For all they know I'm using the software in a museum, 20 years from now, about this era of computing.

I think that's a reasonable point of view. However, for such users, it's best not to use software that's largely developed for masses who just expect the software to work. It might be best to just checkout the source code, and build your own binary. Sorry for being rude :(

Post reply on HN