Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

751–760 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#751
post #717

I don't get why an expiring cert disables the extensions. Shouldn't the browser be checking the cert expiry date against the date the extension was installed, not against current time? As long as there's no way to manipulate the extension installation date that would be fine, wouldn't it? edit: or even why the browser is checking this at run-time. As long as it checked the cert when the extension was installed, isn't…

If Mozilla somehow lost control of one of these signing certs (as in: it got stolen) they would put in on a revocation list. If certificates don't get re-checked, all installations between "cert got stolen" and "noticed that the cert got stolen" would keep installed & running.

Re: All extensions disabled due to expiration of intermediate signing cert

#752
post #604

Update: We have rolled out a partial fix for this issue. We generated a new intermediate certificate with the same name/key but an updated validity window and pushed it out to users via Normandy (this should be most users). Users who have Normandy on should see their add-ons start working over the next few hours. We are continuing to work on packaging up the new certificate for users who have Normandy disabled.

I've been through all of Firefox `about:config` a few times in the past, fixing preferences to, e.g., try to disable umpteen different services that leak info or create potential vulnerabilities gratuitously, but this is the first I recall hearing of Normandy. Apparently I missed `app.normandy.enabled`, because I think I would've remembered a name with connotations of a bloody massive surprise attack. Incidentally, `…

[deleted]

Re: All extensions disabled due to expiration of intermediate signing cert

#753
post #749
post #698

Earlier quoted context omitted.

Automatic updates aren't a security hole. They are a security enhancement

Unless the entity that pushes the updates become malicious, then they're a security hole.

How do you audit Firefox updates? Because if the answer is “I don’t”, Mozilla already controls the most important piece of userspace code on your computer. And if the answer is “I don’t install them”, then everyone with a few grand to spare already controls the most important piece of userspace code on your computer.

Re: All extensions disabled due to expiration of intermediate signing cert

#754
post #743

another month, another browser vendor that does something inconceivably bone-headed in "the service of users." first it was deprecating ALSA for pulseaudio, then it was pocket, then tiles and their suggestions, then that weird video/voice chat thing, and then running "studies" as if my use of the browser was some tacit acceptance of my position as a guinea pig of the internet. Today every extension I use to make the…

This appears to be a mistake. It's clearly bad that things can break this way. But this happened because a certificate expired. Mozilla didn't have to require signatures and certificates for extensions. They did so because they want to protect users. Protecting users with signature schemes, increase complexity and, thus, the risk of debacles like this.

People take their privacy seriously. Our addons were disabled. I was browsing for a few minutes until I saw ads and didn't realize what was going on. Unacceptable that the default to an expiring signature is to disable them completely.

Re: All extensions disabled due to expiration of intermediate signing cert

#755
post #604

Earlier quoted context omitted.

I've been through all of Firefox `about:config` a few times in the past, fixing preferences to, e.g., try to disable umpteen different services that leak info or create potential vulnerabilities gratuitously, but this is the first I recall hearing of Normandy. Apparently I missed `app.normandy.enabled`, because I think I would've remembered a name with connotations of a bloody massive surprise attack. Incidentally, `…

I too use Debian's Firefox ESR. I noticed the "Allow Firefox to install and run studies" option in Privacy & Security Preferences a long time ago. It was unchecked and greyed out (i.e., unclickable), and a label below it says "Data reporting is disabled for this build configuration", so I gave it no further thought. This morning I woke up and launched Firefox, noticed this headline, and then noticed my extensions wer…

On Windows I have the "Allow Firefox to install and run studies" option disabled and yet in about:config Normandy was still enabled. I haven't received the fix. Could be that Firefox simply hasn't checked for it, or it could be that there's more than that about:config setting that determine whether Normandy is run.

Weird.

Re: All extensions disabled due to expiration of intermediate signing cert

#756
post #656

Earlier quoted context omitted.

app.normandy.enabled That is not what I meant by a UI knob, and I sure hope you knew that. By UI knob I mean something easily discoverable and self-explanatory. Rooting around a gated (with a mighty strong warning, I should add) config section for something called "normandy" is not intuitive, and it's not self-explanatory. And I sure hope that by disclosed to users I did not mean some Hitchhiker's Guide-esque disclai…

I'm sorry to break it to you, but a fuckton is not actually part of the metric system...

Well, it should be, but that's an entirely different discussion.

Re: All extensions disabled due to expiration of intermediate signing cert

#757
post #704

Earlier quoted context omitted.

Hey, if you just click on that storage.googleapis.com link it installs the hotfix directly without having to enable normandy ;)

Just tried on Android. Hooray!

Clicking the URL was the only way I was able to get the hotfix on Firefox mobile for Android

Re: All extensions disabled due to expiration of intermediate signing cert

#758
Certificates have been in common use online for maybe two decades now, if not more. This is a common failure mode and it keeps happening. Is there some fix so we don’t have to keep dealing with spontaneous failures due to expirations? Or are we doomed to suffer with this until the end of time?

Re: All extensions disabled due to expiration of intermediate signing cert

#759

Earlier quoted context omitted.

I have spent ~10 years using Firefox daily, tweaking the config and getting the addons set up the way I want. I was a professional web developer for most of those years. This is the first I have heard of Firefox changing my config settings invisibly in the background. This is obscene. Who on earth thought this was a good idea? The security ramifications are limitless. I understand all too well that most companies hav…

The way that Firefox needs 5-10 privacy extensions to be usable isn't just inconvenient when the certs fail, but you also have to trust all these strangers and their extension code. I've been using brave because of that: all of that is baked in so my only extension is my password manager

Exactly the same here, Brave + a password manager after 25y of Firefox/Netscape/Mosaic.

Re: All extensions disabled due to expiration of intermediate signing cert

#760
post #592

Earlier quoted context omitted.

I read at https://discourse.mozilla.org/t/certificate-issue-causing-ad... >12:50 p.m. UTC / 03:50 a.m. PDT: We rolled-out a fix for release, beta and nightly users. The fix will be automatically applied in the background within the next few hours, you don’t need to take active steps. >In order to be able to provide this fix on short notice, we are using the Studies system. You can check if you have studies enabled by…

JSON response from the `normandy` API here: https://xor.cat/assets/other/random/2019-05-04/normandy_sign... hotfix-update-xpi-signing-intermediate-bug-1548973: https://storage.googleapis.com/moz-fx-normandy-prod-addons/e... From the looks, it installs the above plugin, and changes `app.update.lastUpdateTime.xpi-signature-verification` to `1556945257` I can't get it to work in ESR 60 though. Getting file not found on…

So not only does this 'normandy' thing exist, but it goes to a google server? So much for using Firefox to keep google out of my life. :(
Post reply on HN