Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

341–350 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#341

Can we take a moment and consider the side effects? This is a once in a lifetime chance for Google & Co. to get a glimpse of all those sly fuckers hiding behind adblockers. This effectively uncloaked a very specific subset of Internet users and exposed them to the very companies that they've been actively trying to avoid. Not just those who avoid Chrome, but those who take extra steps to explicitly evade the tracking…

FWIW I think it's pretty easy to test if someone is using an adblocker anyway. (I see sites do the "It looks like you're using an adblocker" thing all the time). I don't know if there's any realistic way to entirely hide that.

Re: Update Regarding Add-Ons in Firefox

#342

IMHO it seems problematic, that they can remotely push code changes, including replacement of trusted certificate, and bypass package managers. I don't expect software to (significantly?) change during runtime, outside of what was packaged, signed, distributed and installed as part of apt/yum/pacman/etc. I understand (not that I like or agree with) that some apps are just embedded web browsers, and load everything ex…

If you didn't have browsers auto updating no-one would update them manually, meaning bad news for web developers wanting to take advantage of newer features.

> meaning bad news for web developers wanting to take advantage of newer features.

I think you spelled “mass compromise of unsuspecting users due to unpatched security holes” wrong.

Like it or not, browsers as the primary networked application that people use are the prime target to exploit users. They connect to unknown endpoints of questionable trustworthiness (unlike most other networked apps) and execute code loaded from there. They also handle people’s secrets such as credentials to Homebanking. We maybe shouldn’t be at that point, but here we are and browser vendors need to handle that responsibility. Quick auto updates are crucial for that. Expert users might dislike them, but let’s face it, we’re not the majority.

Re: Update Regarding Add-Ons in Firefox

#343
post #149

Earlier quoted context omitted.

Bezos and his strategy to name the company something starting with A so it always comes first finally pays off.

Now I understand why Google renamed itself Alphabet. One step ahead, literally.

Have you been able to restore your search providers? Really a kick in the nuts, this one..

Re: Update Regarding Add-Ons in Firefox

#344
post #48

Earlier quoted context omitted.

Hold up there. Before people start clicking and installing random add-on links, how about linking to something official (either from a FF dev, or in a soure repository) that references this URL?

This is true. However it is signed by moz and looking at the source it seems safe enough (the cert is legit). It's just a normal wrapper with the following code added: // first inject the new cert try { let intermediate = "MIIHLTCCBRWgAwIBAgIDEAAIMA0GCSqGSIb3DQEBDAUAMH0xCzAJBgNVBAYTAlVTMRwwGgYDVQQKExNNb3ppbGxhIENvcnBvcmF0aW9uMS8wLQYDVQQLEyZNb3ppbGxhIEFNTyBQcm9kdWN0aW9uIFNpZ25pbmcgU2VydmljZTEfMB0GA1UEAxMWcm9vdC1jYS1wc…

Why can't they just release that certificate for everyone to install on all affected non-recent and derivative builds (like Tor Browser)? Or is the internal certificate storage different from the one that is configurable in settings? Then tell us straight away what file to change, and the community (everyone likes to mention so much) comes up with the ways to patch it much faster than you think.

Re: Update Regarding Add-Ons in Firefox

#345

IMHO it seems problematic, that they can remotely push code changes, including replacement of trusted certificate, and bypass package managers. I don't expect software to (significantly?) change during runtime, outside of what was packaged, signed, distributed and installed as part of apt/yum/pacman/etc. I understand (not that I like or agree with) that some apps are just embedded web browsers, and load everything ex…

If you didn't have browsers auto updating no-one would update them manually, meaning bad news for web developers wanting to take advantage of newer features.

Good news for users is sometimes bad news for developers. Anyway, too often these "newer features" are just new ways to exploit people or shiny add-ons without much societal value.

Re: Update Regarding Add-Ons in Firefox

#346
post #284

Earlier quoted context omitted.

On Debian the distributed ESR has that option greyed out anyways. Maybe we’ll have to wait for maintainers to push an update?

I am sure an update will be pushed quickly. I'm waiting too, as a testing user. You can fix this temporarily via setting "xpinstall.signatures.required" to false. Toggle it back to true once update is released and you install it. Meanwhile I'm hijacking this comment that is to the upper parts of the tree to state this: the way the community treats Mozilla and Firefox is horribly, inexplicably, unacceptably unfair. Th…

> This is a mistake, an easily recoverable one, and is not intentional or malicious.

While I agree with most of your comment, you're downplaying the severity here, especially since, IIUC, this situation also affected the Tor browser, disabling NoScript. If regimes like China were on the ball, and succeeded in escalating the remote code execution vulnerability into into deanonimization, this debacle may end up having a death toll attached to it.

Re: Update Regarding Add-Ons in Firefox

#347

On Android I get this: >We rolled out a hotfix that re-enables affected add-ons. The fix will be automatically applied in the background within the next few hours. For more details, please check out the update at https://support.mozilla.org/en-US/kb/add-ons-failing-install... Which is like "we did something we shouldn't have causing unauthorised changes to your computer, so we're going to make unauthorised changes to…

> My understanding is that this is literally illegal in the UK.

What about this is against UK law?

Re: Update Regarding Add-Ons in Firefox

#348
From a UX point of view I don’t know why tools don’t have these two features:

1. “Warning, a critical method for verifying authenticity is set to expire in X days. Please visit to update now.”

2. “A critical verification certificate has expired; while you should immediately go to to obtain an update, you may defer authentication for up to 5 more days.”

...or in other words, why can’t tools cut us some slack on either side of a deadline? Security for most things is not going to fall apart just by giving people a little room to deal with issues on their own schedule.

Re: Update Regarding Add-Ons in Firefox

#349

From a UX point of view I don’t know why tools don’t have these two features: 1. “Warning, a critical method for verifying authenticity is set to expire in X days. Please visit to update now.” 2. “A critical verification certificate has expired; while you should immediately go to to obtain an update, you may defer authentication for up to 5 more days.” ...or in other words, why can’t tools cut us some slack on either…

That would be assuming this would ever happen, which clearly Mozilla didn’t expect, wrongly. It’s a shame, but eh! Mistakes were made. Precautions will hopefully be made.

Re: Update Regarding Add-Ons in Firefox

#350

Earlier quoted context omitted.

I just switched my browser. Bye bye Firefox.

I'm curious, do you switch at every fuck up? Then it's only a matter of time until you come back to Firefox, or maybe you'll end up making your own web browser?

And operating system, and smartphone, and processor, and video card.
Post reply on HN