Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

501–504 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#501
post #373

I wonder if there is someone out there in the middle of the ocean with a browser extension based communication and navagation system which is dead in the water? It sounds to me that the real headline here is that every copy of firefox out there was timebombed and we only noticed because someone forgot to elongate the fuse.

The browser itself continued working fine. Are you aware of any life-depending extension? Leaving this particular issue aside, your hypothetical "browser extension for people in the middle of the ocean" was doomed from its inception if it was designed to run as a browser extension (though it opens the door for an interesting discussion about similar scenarios that are happenning, like pilots relying on ipads)

No but what about people who use password managers, that were locked out of not being able to access bank accounts, credit cards, and reddit.

Re: Update Regarding Add-Ons in Firefox

#502
Well, I'm about to make a lot of people happy with this info. I was researching this today as I'm using FF 56.0.2 and found the solution on this discussion thread. Leave it to an end user to do the job the professionals either failed or refused to due. It worked for me on 3 different machines. Go to this link and follow the instructions detailed:

http://bit.ly/2DUiOLN

Re: Update Regarding Add-Ons in Firefox

#503
post #373

I wonder if there is someone out there in the middle of the ocean with a browser extension based communication and navagation system which is dead in the water? It sounds to me that the real headline here is that every copy of firefox out there was timebombed and we only noticed because someone forgot to elongate the fuse.

The browser itself continued working fine. Are you aware of any life-depending extension? Leaving this particular issue aside, your hypothetical "browser extension for people in the middle of the ocean" was doomed from its inception if it was designed to run as a browser extension (though it opens the door for an interesting discussion about similar scenarios that are happenning, like pilots relying on ipads)

There are _many_ applications that exist as browser extensions, including critical communications applications.

I don't personally know of any obviously life critical application done this way, mostly because I try to stay as far away from that sort of insanity.

If you don't think it's at least a plausible thing that could eventually happen you haven't been paying attention.

I personally got stuck stranded because of signals stupid built in timebombing when I was relying on a device with no untrusted third party ability to shove silent software updates for communication.

Re: Update Regarding Add-Ons in Firefox

#504
post #87

Earlier quoted context omitted.

Clearly, downstream distributors need to create a patch which causes their distributes Firefox builds to only check certificates on add-on installation (and to check revocations too, sure): it should never be possible for a browser to fail into an unsafe configuration.

Cert expiration is the only safe revocation. You cannot rely on revocation lists in many settings. Access to them might be maliciously blocked or, if locally kept, tampered with. The list could for example be replaced with an older one, which would circumvent signing the list unless the signature contains an expiration date and then you’re back to “oh, list expired, how do we fail?” You cannot rely on check at extens…

Well, frankly, I don’t really want a revocation list, and I don’t really want signed extensions in the first place. It’s my browser, and it’s not Mozilla’s business to decide what I install on my browser.

And I most definitely don’t want my browser to fail into an unsafe configuration.

Post reply on HN