Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

511–520 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#511

They have acknowledged the defect and are working on a fix. While this is a severe impact, I am still with Firefox. The are enough alternative browsers to tide over the problem for now. The fact that alternatives exist is the reason why we should support projects like Firefox.

>I am still with Firefox that's kinda the problem. there's plenty of reasons to be "with" firefox still, but you shouldn't need reasons other than it's the best browser. when it starts requiring loyalty to be a user, that's a big problem.

For me, it is the best browser. Yes, this is a big fuck up, but it's not like this has caused me material harm. It's easy for me to switch over to Chrome until this is fixed, and I doubt the same mistake will be repeated in Mozilla.

I expect perfection from plane and car manufacturers, and I pay for that. My browser, I can live with an occasional hiccup.

Re: All extensions disabled due to expiration of intermediate signing cert

#512
post #66
post #12

I’ll still keep using Firefox since I recognize the importance of browser diversity and the hazards of a Chrome monoculture (that and vertical tabs), but, yikes. Still, this type of oversight seems all too common even in large companies. I remember several cases from Fortune 500 companies in the past few years alone. What would be a good way to automate checking for them? Has anyone developed a tool designed specific…

> Still, this type of oversight seems all too common even in large companies. (...) Has anyone developed a tool designed specifically to avoid certificate expiry disasters? LetsEncrypt renewal is supposed to be automated. [1] I know of a company that hosted blogs for thousands of customers. They used LetsEncrypt, but the CTO considered automatic renewals a possible security risk, so they did it manually. Problem is,…

Then the automatic update process stops for some reason and your certificate expires...

At the end of the day, someone needs to verify that new certificates gets acquired and installed before the old ones expire. Automation makes acquiring them less tedious, but not much for making sure someone pays attention.

Re: All extensions disabled due to expiration of intermediate signing cert

#513

I have disabled signature checks in Firefox because otherwise it is impossible to install a private extension without uploading the source code to Mozilla. This is how you allow unsigned extensions in Firefox on Arch Linux, the same files can be edited on Windows and macOS, restart the browser after changes: sudo tee /usr/lib/firefox/defaults/pref/config-prefs.js &>/dev/null /dev/null This method also works for the s…

It's very good that it's possible, but it's literally the worst solution for most people.

Re: All extensions disabled due to expiration of intermediate signing cert

#514
post #320

Mozilla doesn't seem to have communicated the issue well. I could imagine a lot of unsavvy users have tried some wild things in an attempt to fix the problem, and maybe made a mess in the process. Doesn't Mozilla have a mechanism for blasting out a message to all Firefox browsers? Also I have a Firefox account, why haven't I been inboxed about this? Otherwise I'm not bothered. I won't be switching as long as this get…

> Doesn't Mozilla have a mechanism for blasting out a message to all Firefox browsers? The cynical side of me says that it must not have this feature because if it did I'd have seen someone complaining about the browser "phoning home" or "forcing Mozilla's opinions into my eyeballs".

They have. How do you think they pushed that Mr. Robot add extension?

Re: All extensions disabled due to expiration of intermediate signing cert

#515

I have disabled signature checks in Firefox because otherwise it is impossible to install a private extension without uploading the source code to Mozilla. This is how you allow unsigned extensions in Firefox on Arch Linux, the same files can be edited on Windows and macOS, restart the browser after changes: sudo tee /usr/lib/firefox/defaults/pref/config-prefs.js &>/dev/null /dev/null This method also works for the s…

I feel like this should be a checkbox in settings, considering the spirit of Firefox.

Re: All extensions disabled due to expiration of intermediate signing cert

#516

Earlier quoted context omitted.

Firefox 66.0.3 here, and this has been the case also for me, i.e. everything is still working. After looking around for a while in bewilderment, I think that what's going is that they have remotely used the "studies" feature of Firefox to temporarily work around the problem. Indeed, I see in about:studies, hotfix-reset-xpi-verification-timestamp-1548973•Complete This study sets app.update.lastUpdateTime.xpi-signature…

Perhaps that's what Mozilla Add-ons was referring to when they tweeted: https://twitter.com/mozamo/status/1124569680662777856 > We deployed a fix to users who hadn't had their add-ons disabled to make sure they saved that way. You're in that group. :)

Of course, that fix only got to people who didn't disable the "studies" feature after Mozilla abused it to deploy a Mr Robot ad to all their users. Also, enabling it seems to require also agreeing to send telemetry information to Mozilla, so all the privacy-concious people who use extensions to protect their privacy will likely have it disabled as well.

Re: All extensions disabled due to expiration of intermediate signing cert

#517

There have been major organizational problems at Mozilla for a long time that precipitated this. Many of us saw something like this coming, saw gaps and unclear responsibilities, reported these gaps and confusions up the chain, and were reprimanded and financially penalized for asking the tough questions. The questions were never answered, and we all quit, were fired, or lost motivation as a result. This is a tech pr…

Oh man, remember that thing where firefox just randomly installed that LookingGlass Mr. Robot thing (end of 2017 I think..)?

This was their second chance already...

Re: All extensions disabled due to expiration of intermediate signing cert

#518
post #368

Earlier quoted context omitted.

The developer edition has its own user profile.

And I told the developer edition to use my regular profile because that's the one that has all my settings and add-ons and I didn't realize the risk was there. Guess at this point all I can really do is hope and cross the bridge when I get there.

If you’re on Mac, you should be able to recover the old profile with time machine. Or if you are on windows and have another backup setup.

Re: All extensions disabled due to expiration of intermediate signing cert

#519

There's a workaround that involves going to about:config and setting xpinstall.signatures.required to false. However, if you're running the Stable or Beta version, it will only work under Linux. On Windows and MacOS you'll need to download Nightly or the Developer Edition. To fix this on MacOS I did the following: 1. Downloaded and installed Firefox Nightly 2. Ran /Applications/Firefox\ Nightly.app/Contents/MacOS/fir…

The following workaround works on regular editions: https://www.reddit.com/r/firefox/comments/bkhzjy/temp_fix_fo...

Origin here... https://news.ycombinator.com/item?id=19824410

Re: All extensions disabled due to expiration of intermediate signing cert

#520
Update: We have rolled out a partial fix for this issue. We generated a new intermediate certificate with the same name/key but an updated validity window and pushed it out to users via Normandy (this should be most users). Users who have Normandy on should see their add-ons start working over the next few hours. We are continuing to work on packaging up the new certificate for users who have Normandy disabled.
Post reply on HN