I wonder if there is someone out there in the middle of the ocean with a browser extension based communication and navagation system which is dead in the water? It sounds to me that the real headline here is that every copy of firefox out there was timebombed and we only noticed because someone forgot to elongate the fuse.
The browser itself continued working fine. Are you aware of any life-depending extension? Leaving this particular issue aside, your hypothetical "browser extension for people in the middle of the ocean" was doomed from its inception if it was designed to run as a browser extension (though it opens the door for an interesting discussion about similar scenarios that are happenning, like pilots relying on ipads)
Update Regarding Add-Ons in Firefox
501–504 of 504 posts
Re: Update Regarding Add-Ons in Firefox
#502Re: Update Regarding Add-Ons in Firefox
#503I wonder if there is someone out there in the middle of the ocean with a browser extension based communication and navagation system which is dead in the water? It sounds to me that the real headline here is that every copy of firefox out there was timebombed and we only noticed because someone forgot to elongate the fuse.
The browser itself continued working fine. Are you aware of any life-depending extension? Leaving this particular issue aside, your hypothetical "browser extension for people in the middle of the ocean" was doomed from its inception if it was designed to run as a browser extension (though it opens the door for an interesting discussion about similar scenarios that are happenning, like pilots relying on ipads)
I don't personally know of any obviously life critical application done this way, mostly because I try to stay as far away from that sort of insanity.
If you don't think it's at least a plausible thing that could eventually happen you haven't been paying attention.
I personally got stuck stranded because of signals stupid built in timebombing when I was relying on a device with no untrusted third party ability to shove silent software updates for communication.
Re: Update Regarding Add-Ons in Firefox
#504Earlier quoted context omitted.
Clearly, downstream distributors need to create a patch which causes their distributes Firefox builds to only check certificates on add-on installation (and to check revocations too, sure): it should never be possible for a browser to fail into an unsafe configuration.
Cert expiration is the only safe revocation. You cannot rely on revocation lists in many settings. Access to them might be maliciously blocked or, if locally kept, tampered with. The list could for example be replaced with an older one, which would circumvent signing the list unless the signature contains an expiration date and then you’re back to “oh, list expired, how do we fail?” You cannot rely on check at extens…
And I most definitely don’t want my browser to fail into an unsafe configuration.