Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

431–440 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#431
post #420

Earlier quoted context omitted.

It seems like your objection to the Normandy system is that the UX surrounding it includes the word “Studies”. I am grateful they chose in this instance to prioritize repairing addons worldwide over the confusion that word has caused you and potentially others. I assume, having seen this and other such comments delivered with outrage rather than thankfulness today, that they will re-evaluate the UX surrounding the No…

It's not about designation, it's about control. If Mozilla really cares about trust, they shouldn't mix their update delivery system, which should care for timely security-related material, with general telemetry, data-gathering, and experiments. I use FF because I care about principles. Otherwise I might as well just let myself be exploited by Google, MS, Apple and friends.

Ah, you object to Normandy’s design in some manner. That’s being hashed out in today’s Normandy thread, and if you haven’t already read that link you’ll definitely want to:

https://news.ycombinator.com/item?id=19825830

(While of course you’re welcome to continue pursuing your issues with it here, your opinions will receive more views there.)

Re: Update Regarding Add-Ons in Firefox

#432
post #373

I wonder if there is someone out there in the middle of the ocean with a browser extension based communication and navagation system which is dead in the water? It sounds to me that the real headline here is that every copy of firefox out there was timebombed and we only noticed because someone forgot to elongate the fuse.

The browser itself continued working fine. Are you aware of any life-depending extension? Leaving this particular issue aside, your hypothetical "browser extension for people in the middle of the ocean" was doomed from its inception if it was designed to run as a browser extension (though it opens the door for an interesting discussion about similar scenarios that are happenning, like pilots relying on ipads)

> your hypothetical "browser extension for people in the middle of the ocean" was doomed from its inception if it was designed to run as a browser extension

Why? You haven't backed up that statement at all. Especially before they killed XUL it was easy to make a non-doomed app that runs as a browser extension, and it's still plenty possible.

No (non-demo) program should brick itself if it can't connect home.

Re: Update Regarding Add-Ons in Firefox

#433
post #48

Earlier quoted context omitted.

This is true. However it is signed by moz and looking at the source it seems safe enough (the cert is legit). It's just a normal wrapper with the following code added: // first inject the new cert try { let intermediate = "MIIHLTCCBRWgAwIBAgIDEAAIMA0GCSqGSIb3DQEBDAUAMH0xCzAJBgNVBAYTAlVTMRwwGgYDVQQKExNNb3ppbGxhIENvcnBvcmF0aW9uMS8wLQYDVQQLEyZNb3ppbGxhIEFNTyBQcm9kdWN0aW9uIFNpZ25pbmcgU2VydmljZTEfMB0GA1UEAxMWcm9vdC1jYS1wc…

Thanks to this script, I think I just managed to apply the patch to an old Firefox 56 install, whereas the .xpi had no effect.

There are other people here who I think would really appreciate details if you still have them.

Re: Update Regarding Add-Ons in Firefox

#434
post #41

Earlier quoted context omitted.

So, I just got this url from this HN comment: https://news.ycombinator.com/item?id=19825921 I'm not clear if they rehosted the XPI or if that's the original mozilla url. I'm not too worried about it either. The only reason anyone is clicking on this fine link is because firefox only lets you install addons signed by Mozilla. And since the typical signing process gives addons signed by the broken intermediary we can b…

>I'm not too worried about it either. The only reason anyone is clicking on this fine link is because firefox only lets you install addons signed by Mozilla. unzip *.xpi nano META-INF/manifest.mf gives me Manifest-Version: 1.0 Name: background.js Digest-Algorithms: MD5 SHA1 MD5-Digest: pcBRGwbuhPz06VrGWmAitQ== SHA1-Digest: szDd6YcB3bpF+NusZhEHhmMDi5U= Name: content.js Digest-Algorithms: MD5 SHA1 MD5-Digest: CGOATrflE…

What's your point?

There might be a very difficult preimage attack on MD5.

There's no evidence of a preimage attack on SHA1.

There is absolutely no way you're doing both at once.

Re: Update Regarding Add-Ons in Firefox

#435

Earlier quoted context omitted.

So that's pretty unfair. 1) They state they are working on a fix for normal, release channel users who don't want to run studies 2) they tell you to temporarily run studies to get the fix within up to 6 six hours (could be faster; set expectation) 3) You can explicitly install nightly or 66.4 before it's pushed if you want a fix now Yes, it's unfortunate, I'd expect them to meet it head on, push a tested fix in a tim…

Not saying that their current actions are wrong , just that the optics of it are terrible for them. There was a chain of bad decisions that led them here though: 1) thinking it's ok to disable software after its installed (using cert expiration -- I'm ok if the cert was revoked but that's a totally different discussion), 2) Taking more control of people's local software than many people are comfortable with, especial…

As an alternative perspective, I'm totally fine with FF disabling the extensions when the cert went invalid, and I'm also happy that it auto-updated itself to fix the issue. To me the optics are pretty good: a mistake happened and they were able to recover pretty fast, and my browser wasn't exploited by bad actors in the meantime.

Re: Update Regarding Add-Ons in Firefox

#436

Earlier quoted context omitted.

Hiding behind ToS is ridiculous. Nobody reads them and a moral company should never assume that because its in the ToS they actually have informed consent.

At what point is it your responsibility to verify that something you're using is keeping it's end of the bargain? Ceding all responsibility doesn't seem like the answer either. While forced arbitration and other crappy things in contracts suck, a company protecting itself against explicitly stupid or bad behavior seems reasonable. While it's reasonable to expect a consumer to understand hot coffee is hot, its unreaso…

> Ceding all responsibility doesn't seem like the answer either.

Whether I cede my responsibility or not does not excuse a company from acting morally or not. You can't act immorally and say its okay because your users have given informed consent, when you know for a fact that they don't. Studies show that it would take over a year for an average user to read all the EULAs that they agree to in a year. It is literally impossible for an average user to read all the agreements they "agree" to in the average case of a computer user.

> I think the only real solution...

I'm not sure that this problem needs a solution exactly. The status quo is fairly reasonable, companies are expected to act morally and when they don't they get called out in social media and people move on to other companies. The primary threat to this model working is when overly pedantic people on HN and other sites excuse companies actions by saying things like "Well actually you _did_ agree to it by the EULA, so you shouldn't be suprised that they took your first born child, next time pay more attention to what you agree to!"

Re: Update Regarding Add-Ons in Firefox

#437
post #385

Earlier quoted context omitted.

I hate that attitude from entitled users so much. If you don't want security, you're welcome to have a malware-ridden system, but don't think that this means all users should have to put up with malware-ridden systems.

Say what now? Users are entitled for being in control of their own systems? Are you crazy?

It's just the IBM mainframe priesthood reasserting its dominance, lurching from the tomb of computing history to save us all from ourselves. Nothing to see here.

Re: Update Regarding Add-Ons in Firefox

#438

I asked this in the other thread but I guess there's too many comments there: Is there a project for Firefox that is analogous to Chromium for Chrome? I need a Firefox build with all the Mozilla shit ripped out. I don't trust the org that decided their certificate expiration was more important than giving users the choice to run what they want.

Librefox isn't exactly what you described, but it's close. It's a set of configs that disable a bunch of telemetry and other unauthorized mothership connectivity and settings pushing. https://github.com/intika/Librefox However, Librefox is only Firefox with some configuration changes. It is not a whole new build, and it wouldn't have protected you from this problem since the problematic addon cert checking is still t…

> Note that this would have happened even if the browser never communicated back home - this problem was triggered via an unwitting time bomb of sorts, not because Mozilla actively took an action that inadvertently broke something.

I was never worried about Mozilla's telemetry. I happily enabled all feedback/telemetry options because I genuinely wanted them to fix any problems. I understand that this problem is not caused due to phoning home.

The decision process that led them to make it impossible to load an extension without it being signed by them is problematic. It means that I don't trust them with all my debugging data. I don't know what other time bombs are hiding inside the code.

What would happen if Mozilla ceased to exist tomorrow? Will existing firefox installs get bricked after some time? Even big bad Microsoft allows you to install unsigned hardware drivers if you dismiss the scary warning.

Re: Update Regarding Add-Ons in Firefox

#439

Very curious how the decision to use the Studies program happened. Why not just roll the version early and include the fix in the new version - isn't Firefox an evergreen browser now? Maybe there is extra bureaucracy to roll a new version, or the hotfixers didn't have permission to do it. Either of which I can understand, being that they made the fix late on a Friday night - so huge kudos to those who worked hard to…

Doing a full release takes a lot longer, so they presumably decided to use a faster method where possible. https://hacks.mozilla.org/2018/03/shipping-a-security-update...

Re: Update Regarding Add-Ons in Firefox

#440

Earlier quoted context omitted.

Not saying that their current actions are wrong , just that the optics of it are terrible for them. There was a chain of bad decisions that led them here though: 1) thinking it's ok to disable software after its installed (using cert expiration -- I'm ok if the cert was revoked but that's a totally different discussion), 2) Taking more control of people's local software than many people are comfortable with, especial…

As an alternative perspective, I'm totally fine with FF disabling the extensions when the cert went invalid, and I'm also happy that it auto-updated itself to fix the issue. To me the optics are pretty good: a mistake happened and they were able to recover pretty fast, and my browser wasn't exploited by bad actors in the meantime.

> a mistake happened and they were able to recover pretty fast, and my browser wasn't exploited by bad actors in the meantime.

To me adding a new plugin signing cert through a side loaded plugin is pretty much the definition of exploited.

All this tells me is that their plugin signing solution is utterly worthless.

The only way this should have been fixed was through official update channels.

Post reply on HN