Update Regarding Add-Ons in Firefox
blog.mozilla.org
blog.mozilla.org
And now Mozilla are saying that the "fix" is to allow them to install & run "studies" on my machine? What are they smoking? I'm having a hard time trusting a company that randomly & remotely disabled all my addons, regardless of the cause.
I do think that the UX should ideally be a bit more graceful; one of my add-ons is Multi-account Containers and its being disabled suddenly caused the window I was actively browsing in to just close, among other side effects.
But that kind of UX polish for what should be an exceptional case is obviously not going to be super-high priority, unfortunately.
You cannot rely on check at extension install. That would assume that all malicious extensions are installed via FF proper. Oracles crapware bundling in the Java installer taught us that’s now how things go. You cannot remember the trust flag when an extension is installed via FF as a crapware installer could just set the trust flag, too. After all, that storage would be accessible, too. You cannot sign or encrypt that trust storage as the key material would have to be kept locally and would be accessible to the crapware installer.
You use a browser that has remote update capability, which allows them to install and run new software on your machine all the time. There is a whole separate section of the Preferences that says "Privacy" in large print that has a section that clearly identifies the Studies feature and lets you turn it off. And you use a browser that lets you install privacy-enhancing add-ons in the first place, and in fact which invented the whole concept of add-ons. When the browser discovered that it couldn't verify the add-on integrity with a valid cert, it did what it's supposed to do, it disabled them to protect you from someone backdooring these add-ons.
Someone at Mozilla fucked up, and they're trying in good faith to fix it. I don't know what else people are expecting them to do, putting on sackcloth and ashes won't resolve the problem.
Here's a metaphor: Let's say you let someone seemingly trustworthy watch your kid. (In this metaphor you have a kid). And they let your kid get a broken arm through gross negligence (let's say they passed out drinking beer), and then someone said "well, obviously, you should have never trusted that person, after all, they can do anything with your kid while you're gone, so why are you outraged?" You probably would still be pretty outraged right? You would certainly question your decision to trust them, but at the end of the day you have to trust someone, you'd be a complete shut-in if you could never hire a baby-sitter.
Which is impossible unless you're either running Linux or running Nightly or Developer Edition. That setting is willfully ignored in normal Mac/Windows/Android builds most people are on.
"A certificate chain has expired, do you want to disable all add-ons?"
How hard is that?
The add-ons were signed by a certificate with an expiration date, which means that the add-ons are trusted until that certificate expires, not that they're trusted in perpetuity. It's not a hidden dead-mans hand; expiry is and has always been part of the process.
I think it's arguable that it shouldn't be part of the process, and having things like 20-year expiry satisfies the letter of the spec while being even worse than no expiry, but it's not a hidden dead-man's hand. It's how it was designed to work, and isn't considered optional.
If you think that’s trivial, I challenge you to go build it. It might seem warranted in hindsight, but thinking about all failure cases ahead of time is hard. If it weren’t, we’d not have bugs.
Is that really true? Would it connect to 802.11m WiFi router? Would you consider it secure enough to open your banking website on it? The bar is not just booting up the machine. The bar is whether the machine is usable (secure).
Can you elaborate what's your concern with "studies"? By installing Firefox that updates automatically, the user is already giving control of the software and letting Mozilla decide what's the best. How is modifying software logic using studies different than modifying logic by updating the binary?
I'm asking because there I can imagine that there is a benefit for Mozilla to develop a feature that enables studies without sending data. It could be used to fix a broken feature or a broken logic (as in the case of expired certificates here). So, I'm not convinced that enabling studies always means that your data gets uploaded without the consent. Can you point me to privacy whitepaper / source code to backup that statement?
Eorum est humanum.
There was a similar issue[0] a few years ago that was only caught a month in advance.
Even better would be to set things up to only do a verify on install instead on every startup.
That would defeat the purpose of verification: "Add-on signing in Firefox helps protect against browser hijackers and other malware by making it harder for them to be installed." [1]
And it's not just malware that was doing that. Microsoft force-installed the ".NET Framework Assistant" into Firefox on Windows, and you had to edit the registry to remove it. [2] If I recall correctly, AVG and Logitech were also among the list of offenders.
[1] https://support.mozilla.org/en-US/kb/add-on-signing-in-firef... [2] https://support.microsoft.com/en-us/help/963707/how-to-remov...
And honestly, I think it is security theater to attempt to defend against attackers on the same or higher privilege level. If microsoft wants to force something down your throat on windows then there's not much you can do.
The problem is that mozilla turns the failures of others into their own problem and then they try to fix it themselves. That scope and responsibility creep leads us to the fallout we're seeing now.
How? These extensions were not being installed through the normal mechanism. The malicious extension installer will just set the flag that says "this extension has been verified".
> And honestly, I think it is security theater to attempt to defend against attackers on the same or higher privilege level.
I understand that, and Mozilla does too: "By baking the signing requirement into the executable these programs will either have to submit to our review process or take the blatant malware step of replacing or altering Firefox." [1]
[1] https://blog.mozilla.org/addons/2015/04/15/the-case-for-exte...
Edit: Let me amend my question - why is it necessary for the certificates to expire? If a plugin is signed by Mozilla, why wouldn't it be trusted once it gets old?
I asked essentially that question earlier, and received some good answers explaining why [1].
Briefly, if something is signed by an expired certificate, whether or not you can trust the signature depends on whether or not the signing took place while the certificate was not expired.
If all you have is the thing and the signature from the code signer, you can't tell for sure when it was signed. If a bad guy has obtained an old signing certificate and its keys, that bad guy can generate new signatures that claim to have been signed while the certificate was valid.
Some code signing systems, such as the one in Windows (and I think the one Apple uses) also use another certificate, from a timestamp service, to prevent this. The way a timestamp service works is you send them a hash of a document, and they generate a certificate signed by them that essentially says "We were shown this hash on this particular date/time".
When you include the timestamp certificate with the signature from the code signer, then when you come across code that was signed by an expired certificate but purports to have been signed while the certificate was still valid, you can check the timestamp certificate to see if that is true. If it is, you can still consider the code signing to be valid.
Forgetting to renew a signing certificate is still bad even if you do this, but not as bad. If Microsoft or Apple forget, it doesn't stop existing applications from working, so end users aren't immediately impacted. It does stop developers from shipping updates or new applications, so still would be a big deal. I could see a bad guy noticing that a company always updates expiring certificates one month in advance, say, and then noticing that a certificate is expiring in just a week, infer that the certificate renewal has slipped through the cracks and is going to expire, and time the use of a critical zero day exploit to fall in the window when updates are broken by the expired certificate.
If it's not a malicious extension, verifying the signature doesen't prevent a forced install.
I don't expect software to (significantly?) change during runtime, outside of what was packaged, signed, distributed and installed as part of apt/yum/pacman/etc.
I understand (not that I like or agree with) that some apps are just embedded web browsers, and load everything externally, and that Firefox extensions are in the end just some JS/CSS/HTML loaded outside of system's package manager. However, extensions have limited API they can interact with, and you need to allow permissions for each extension. Having Mozilla owned extension, that can modify core functionality, seems a bit scary.
I think you spelled “mass compromise of unsuspecting users due to unpatched security holes” wrong.
Like it or not, browsers as the primary networked application that people use are the prime target to exploit users. They connect to unknown endpoints of questionable trustworthiness (unlike most other networked apps) and execute code loaded from there. They also handle people’s secrets such as credentials to Homebanking. We maybe shouldn’t be at that point, but here we are and browser vendors need to handle that responsibility. Quick auto updates are crucial for that. Expert users might dislike them, but let’s face it, we’re not the majority.
I don't think anyone is really against quick security-related fixes being delivered with a degree of automation. What most power users dislike is mixing these updates with other ones (typically for commercial reasons).
It sounds to me that the real headline here is that every copy of firefox out there was timebombed and we only noticed because someone forgot to elongate the fuse.
IMO this seems like just plain bad design. The Firefox addon certificate should never have had an expiry date. If they ever needed to revoke it, they could distribute an updated version of the browser with the previous intermediate explicitly marked as revoked.
xpinstall.signatures.required
Works on Fennec version of Firefox.
Also IceCat version of Firefox wasn't affected AFAIK.
Why? You haven't backed up that statement at all. Especially before they killed XUL it was easy to make a non-doomed app that runs as a browser extension, and it's still plenty possible.
No (non-demo) program should brick itself if it can't connect home.
I don't personally know of any obviously life critical application done this way, mostly because I try to stay as far away from that sort of insanity.
If you don't think it's at least a plausible thing that could eventually happen you haven't been paying attention.
I personally got stuck stranded because of signals stupid built in timebombing when I was relying on a device with no untrusted third party ability to shove silent software updates for communication.
If you visit the Mozilla homepage, there is nothing to acknowledge the problem (at least at the time of writing this message). Let's try the Support page. Where is it? Scroll down to the bottom of the lengthy Mozilla homepage to the page footer to find the link. (How many visitors will make it to the bottom?)
When you click through to the Support page, an easy-to-miss banner in tiny text appears at the top of the page that mentions the problem - screenshot here: https://imgur.com/a/TAHZSWa
Additionally, when the add-ons are disabled, Firefox misleading says: "These extensions do not meet current Firefox standards so they have been deactivated". This is probably a generic message but it's also an example when a generic message is misleading.
Finally, poorly-named settings like "Normandy" and "studies" that give no hint of their meaning only adds to the confusion.
I love Firefox. It's my daily driver. It will continue to be. But this is a huge fuck-up and they're probably going to pay big in usership because of it.
Also why it took 6 hrs to assign P1 to the bug
I would assume the delay in assigning P1 is really just a result of assigning P1 not being as high priority as fixing the damn problem.
Because people were staying up until the wee hours of the morning working on fixing it instead of toggling priorities in Bugzilla. This was treated as a five-alarm fire.
Saying "we were too busy fixing to communicate" is actually a really bad sign, because it's not just about what you are communicating to the outside world, but also, for example, about making sure people that need to be brought in are getting consistent information.
However, I bet it’s likely they have procedures and policies for work that first involve signaling like for example the priority level.
I’d be willing to bet lots of things surrounding this issue weren’t handled in a by the book manner. So if you are always going to wing it, why have a book (or a public priority level system) at all?
I don't think it bothers me personally but it's funny you said that. Presumably you mean a "'no-alarm fire' because who has time to set off an alarm when there's a fire to fight"?!
Random user: What the fuck is a tree and why is the priority of this not higher yet?
I understand why an add-on update or new installation would be prevented from succeeding by a certificate expiration. But why would a certificate expiration prevent an already-installed from running? Any already-installed add-ons were previously validated at installation time and should (IMO) run as-is. It seems unnecessary to continuously check the status of an add-on's certificate if it has not been changed. Am I missing something?
[1] GitHub mirror to not stress their infra: https://github.com/mozilla/gecko-dev/commit/1d1260c7615f1d9a...
Yes, it's unfortunate, I'd expect them to meet it head on, push a tested fix in a timely matter, admit a mistake was made, explain publicly how/why and apply learning moving forward. Beyond that, what's your expectation?
There was a chain of bad decisions that led them here though: 1) thinking it's ok to disable software after its installed (using cert expiration -- I'm ok if the cert was revoked but that's a totally different discussion), 2) Taking more control of people's local software than many people are comfortable with, especially considering that their main market is tech savvy people that tend to be more sensitive to this than most 3) Making some of these things opt-out rather than opt-in, giving the perception that they may value data collection and control more than their users privacy.
Here, the mechanism that kicked in was the protection against add-ons that could have been signed with stolen credentials, which would make them clearly malicious.
Of course, it turns out that the problem was an expired cert, so a bug/human error. But generally speaking, I think that 1 is good.
Is that so, though? Firefox is still being used by millions of users, and I doubt those are only the tech savvy internet users.
(Then again, this mostly applies to Firefox users using add-ons, which probably has a higher share of technical users.)
CAs can delete certificates from their revocation lists after expiration, which means that you can't tell the difference between a certificate that was never revoked but merely expired and a revoked-and-then-expired certificate.
I still prefer Firefox over all the other browsers, and will continue to use it, but the project has lost a lot of trust and goodwill over this.
The optics are indeed awful, and this was fully preventable. Firefox fucked up, full stop.
Based on the timing of initial tweets and blog posts on this fiasco, I'm pretty sure I was in the first 10%, if not first 1%, of people who experienced this. And I was in a plane at 36,000 feet trying to work on a cross country (U.S.) flight when suddenly about 130 tabs in 7 windows disappeared. Really, REALLY bad. Panic, frustration, confusion...
I was more than 50% sure that all was not lost forever, that it was some "glitch" (Extensions all showed the same bloody red status), but I was tweaked. I work in security (embedded systems, not computers/IT) so I have a very good understanding of certificates, TLS, PKI, etc. There are many ways things can get out of whack if the people in charge screw up.
Regardless, this is embarrassing, dare I say shameful (pretty much almost up there with "Ooooppsss... we just lost our domain - it expired and no one thought to renew it)
Come on, guys, get it together. Have a procedure, document it, practice it, stay in front of it.
EDIT: after installing the fixed XPI, I have to sadly report that all data has gone. All my carefully-managed containerized life was wiped clean. Heads should roll.
Complete shambles. And the worst thing is, I suspect it's all a plot to have more people opt-in to the shitty telemetry. Otherwise, why not push an update through the usual channels? Had it been a security-related fix, would have they used "studies"? I bet not.
Given that it has happened, I expect them to provision a new certificate and push a fixed version within an hour or two to all release channels.
What I would emphatically ‘not’ expect, is a hack that might take up to 6 hours to be applied.
Most Firefox users have that checkbox enabled by default, and so most Firefox users received the fix within 0-6 hours of the blog post's publication.
HN readers often take special care to prevent Mozilla from updating Firefox, but that in no way represents the wider population of either all addons users or all Firefox users.
You can fix this temporarily via setting "xpinstall.signatures.required" to false. Toggle it back to true once update is released and you install it.
Meanwhile I'm hijacking this comment that is to the upper parts of the tree to state this: the way the community treats Mozilla and Firefox is horribly, inexplicably, unacceptably unfair.
This is nothing compared to innumerable other fuckups in software history, and even recent ones like goto fail, heartbleed, or Chrome logging you into Sync w/o notice.
This is a mistake, an easily recoverable one, and is not intentional or malicious. Firefox is developed in the out and open, all the processes are public. And people, with an absurd entitlement and malice, go as far as to call things backdoors or malware. Meanwhile the alternative actually is a backdoor ridden malware.
Please don't be this ungrateful.
While I agree with most of your comment, you're downplaying the severity here, especially since, IIUC, this situation also affected the Tor browser, disabling NoScript. If regimes like China were on the ball, and succeeded in escalating the remote code execution vulnerability into into deanonimization, this debacle may end up having a death toll attached to it.
Usually, this mechanism is explained as being helpful to ensure a rollout of an experimental update can be rolled back if it's failing. That's not so much a concern in this case, I think. But this mechanism has another effect: it works as a solution to the thundering-herd problem. Every browser updating at once is bad, not just for Mozilla's servers, but for every piece of Internet infrastructure that those browsers (and their arbitrary set of addons) talk to when they update/restart. Within the time budget you have for running a rolling update, you ideally want as few machines updating concurrently as possible, just because you don't want to generate mysterious correlated traffic bursts that make NOCs paranoid.
You go a bit in, wait to see if the canary, then go further.
HN has this problem too.
“I (name the individual accountable) will give you an update at 12:00 PT (name a time) as an update to this post (name the communication channel) with the current status and latest information on this issue (don’t promise time to resolution, just time to info).”
Simple, clear, concrete, and unambiguous. I had hoped that Firefox had better communication procedures in the event of global-impact P1 issues.
Also...my default search engine is now Amazon.com?? WTF is going on.
EDIT: Also my only search engine. Heck of a job Mozilla.
https://wiki.archlinux.org/index.php/Firefox#Firefox_disable...
AFAIK, this will enable all the disabled add-ons until the next check, which is in 24 hours. This will be hopefully enough time for Mozilla to release a stable channel update, instead of the "Studies hack".
At least for me, fiddling with the Studies settings had no effect; the about:studies page remained empty regardless of what I did. I've also seen multiple reports from people who got the Studies hack working that the fix actually failed to address the issue properly.
Could we have for example a publicly verifiable ledger that can be used to verify a cert chain with not only a defined workflow to answer if a cert is still trusted but also a requirement for the workflow to be fully implemented? Seems quite doable, vs sort of hacks of auto-renew which are hit and miss depending on the CA.
In other words, when do we fix the sport rather than the players here?
What did (seem to) help was setting app.normandy.run_interval_seconds to a small value (21). At least just a couple of seconds after I did, all my addons came back.
Edit: plugins -> addons
Out of curiosity, how did you know that? What does this actually do?
I stumbled upon this myself earlier
The feeling of no control over my web browser was why I left Chrome in the first place.
>We rolled out a hotfix that re-enables affected add-ons. The fix will be automatically applied in the background within the next few hours. For more details, please check out the update at https://support.mozilla.org/en-US/kb/add-ons-failing-install...
Which is like "we did something we shouldn't have causing unauthorised changes to your computer, so we're going to make unauthorised changes to fix it".
Quite telling is that this is supposed to protect us from other developers. On the add-on screen "Enable" is greyed out, there's no "Enable even though Mozilla doesn't like it".
The UX is just like the "fuck you this computer isn't yours it belongs to Microsoft and we'll do what we like with it" that I thought I'd left in the past decades ago.
It's not your computer Mozilla, you fucked it up, you don't get to mess around with it without asking the owner.
My understanding is that this is literally illegal in the UK.
Mozilla barely had any trust left to burn IMO but they sure went all out.
But for Firefox? My expectations for browsers in general aren't anywhere high enough to warrant raised eyebrows even in the face of monumental fuckups like the one were seeing today. Specially because users tried to warn that this could happen and Mozilla stubbornly said NO: https://news.ycombinator.com/item?id=10038999
What about this is against UK law?
This is a once in a lifetime chance for Google & Co. to get a glimpse of all those sly fuckers hiding behind adblockers.
This effectively uncloaked a very specific subset of Internet users and exposed them to the very companies that they've been actively trying to avoid. Not just those who avoid Chrome, but those who take extra steps to explicitly evade the tracking.
Surely Mozilla, the privacy advocate, must understand the impact of this fuck up, and yet the offered "fix" doesn't even mention a one-click .xpi install, but rather asks to enable a mechanism that, if left enabled, will grant unnecessary control to Mozilla over people installs.
This ain't right.
I guess because I watched anime videos?
Perhaps leave yourself a note to change it back once an update ships : )
Sure they can, they can just send back a resource request. It could even be for like an image with a query string attached with it, it doesn't have to be an ajax request necessarily.
So I wasn't exactly left unaware that Bad Stuff had happened. I could - and did - shut the thing down, apply a fix, and be back up running normally within a few minutes.
My particular brand of fix: https://wiki.archlinux.org/index.php/Firefox#Firefox_disable...
it does really feel like "the great upscertificate expiration foul play"
> There are a number of work-arounds being discussed in the community. These are not recommended as they may conflict with fixes we are deploying...
Let's give them a little time to get this fixed..
I checked Mozilla's main site again, and it still has this ironic statement in its description tag (it's been there for many years):
https://www.mozilla.org/en-US/firefox/new/
Firefox is created by a global non- profit dedicated to putting individuals in control online.
...I guess it's more dedicated to putting Mozilla in control now. Something about this whole incident brings up a point that just feels very wrong to me --- it's not a Google or Microsoft, but the fact that Mozilla also seems to have this large amount of control over its users is unsettling.
In the meantime I'm enjoying trying out Vivaldi[1] - really reminds me of opera 3/4, that I loved.
Especially when you could switch to the unbranded/nightly firefox builds, disable addon signature checking and continue using the only independent FOSS browser remaining.
Anyway, used to be Firefox had a lot more going for it than being open source. Now that's really the only thing left I can think of.
https://storage.googleapis.com/moz-fx-normandy-prod-addons/e...
https://news.ycombinator.com/item?id=19825921
I'm not clear if they rehosted the XPI or if that's the original mozilla url.
I'm not too worried about it either. The only reason anyone is clicking on this fine link is because firefox only lets you install addons signed by Mozilla. And since the typical signing process gives addons signed by the broken intermediary we can be pretty confident that this wasn't just signed by mozilla, but is the original study.
In general caution about installing software from random links is definitely a good idea though.
Edit: Looks to me like it's an original mozilla url (judging by github comments on mozilla/normandy - I haven't found an official source saying it is official due to lack of continuing to search: https://github.com/mozilla/normandy/pull/1697)
// first inject the new cert
try {
let intermediate = "MIIHLTCCBRWgAwIBAgIDEAAIMA0GCSqGSIb3DQEBDAUAMH0xCzAJBgNVBAYTAlVTMRwwGgYDVQQKExNNb3ppbGxhIENvcnBvcmF0aW9uMS8wLQYDVQQLEyZNb3ppbGxhIEFNTyBQcm9kdWN0aW9uIFNpZ25pbmcgU2VydmljZTEfMB0GA1UEAxMWcm9vdC1jYS1wcm9kdWN0aW9uLWFtbzAeFw0xNTA0MDQwMDAwMDBaFw0yNTA0MDQwMDAwMDBaMIGnMQswCQYDVQQGEwJVUzEcMBoGA1UEChMTTW96aWxsYSBDb3Jwb3JhdGlvbjEvMC0GA1UECxMmTW96aWxsYSBBTU8gUHJvZHVjdGlvbiBTaWduaW5nIFNlcnZpY2UxJjAkBgNVBAMTHXNpZ25pbmdjYTEuYWRkb25zLm1vemlsbGEub3JnMSEwHwYJKoZIhvcNAQkBFhJmb3hzZWNAbW96aWxsYS5jb20wggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQC/qluiiI+wO6qGA4vH7cHvWvXpdju9JnvbwnrbYmxhtUpfS68LbdjGGtv7RP6F1XhHT4MU3v4GuMulH0E4Wfalm8evsb3tBJRMJPICJX5UCLi6VJ6J2vipXSWBf8xbcOB+PY5Kk6L+EZiWaepiM23CdaZjNOJCAB6wFHlGe+zUk87whpLa7GrtrHjTb8u9TSS+mwjhvgfP8ILZrWhzb5H/ybgmD7jYaJGIDY/WDmq1gVe03fShxD09Ml1P7H38o5kbFLnbbqpqC6n8SfUI31MiJAXAN2e6rAOM8EmocAY0EC5KUooXKRsYvHzhwwHkwIbbe6QpTUlIqvw1MPlQPs7Zu/MBnVmyGTSqJxtYoklr0MaEXnJNY3g3FDf1R0Opp2/BEY9Vh3Fc9Pq6qWIhGoMyWdueoSYa+GURqDbsuYnk7ZkysxK+yRoFJu4x3TUBmMKM14jQKLgxvuIzWVn6qg6cw7ye/DYNufc+DSPSTSakSsWJ9IPxiAU7xJ+GCMzaZ10Y3VGOybGLuPxDlSd6KALAoMcl9ghB2mvfB0N3wv6uWnbKuxihq/qDps+FjliNvr7C66mIVH+9rkyHIy6GgIUlwr7E88Qqw+SQeNeph6NIY85PL4p0Y8KivKP4J928tpp18wLuHNbIG+YaUk5WUDZ6/2621pi19UZQ8iiHxN/XKQIDAQABo4IBiTCCAYUwDAYDVR0TBAUwAwEB/zAOBgNVHQ8BAf8EBAMCAQYwFgYDVR0lAQH/BAwwCgYIKwYBBQUHAwMwHQYDVR0OBBYEFBY++xz/DCuT+JsV1y2jwuZ4YdztMIGoBgNVHSMEgaAwgZ2AFLO86lh0q+FueCqyq5wjHqhjLJe3oYGBpH8wfTELMAkGA1UEBhMCVVMxHDAaBgNVBAoTE01vemlsbGEgQ29ycG9yYXRpb24xLzAtBgNVBAsTJk1vemlsbGEgQU1PIFByb2R1Y3Rpb24gU2lnbmluZyBTZXJ2aWNlMR8wHQYDVQQDExZyb290LWNhLXByb2R1Y3Rpb24tYW1vggEBMDMGCWCGSAGG+EIBBAQmFiRodHRwOi8vYWRkb25zLm1vemlsbGEub3JnL2NhL2NybC5wZW0wTgYDVR0eBEcwRaFDMCCCHi5jb250ZW50LXNpZ25hdHVyZS5tb3ppbGxhLm9yZzAfgh1jb250ZW50LXNpZ25hdHVyZS5tb3ppbGxhLm9yZzANBgkqhkiG9w0BAQwFAAOCAgEAX1PNli/zErw3tK3S9Bv803RV4tHkrMa5xztxzlWja0VAUJKEQx7f1yM8vmcQJ9g5RE8WFc43IePwzbAoum5F4BTM7tqM//+e476F1YUgB7SnkDTVpBOnV5vRLz1Si4iJ/U0HUvMUvNJEweXvKg/DNbXuCreSvTEAawmRIxqNYoaigQD8x4hCzGcVtIi5Xk2aMCJW2K/6JqkN50pnLBNkPx6FeiYMJCP8z0FIz3fv53FHgu3oeDhi2u3VdONjK3aaFWTlKNiGeDU0/lr0suWfQLsNyphTMbYKyTqQYHxXYJno9PuNi7e1903PvM47fKB5bFmSLyzB1hB1YIVLj0/YqD4nz3lADDB91gMBB7vR2h5bRjFqLOxuOutNNcNRnv7UPqtVCtLF2jVb4/AmdJU78jpfDs+BgY/t2bnGBVFBuwqS2Kult/2kth4YMrL5DrURIM8oXWVQRBKxzr843yDmHo8+2rqxLnZcmWoe8yQ41srZ4IB+V3w2TIAd4gxZAB0Xa6KfnR4D8RgE5sgmgQoK7Y/hdvd9Ahu0WEZI8Eg+mDeCeojWcyjF+dt6c2oERiTmFTIFUoojEjJwLyIqHKt+eApEYpF7imaWcumFN1jR+iUjE4ZSUoVxGtZ/Jdnkf8VVQMhiBA+i7r5PsfrHq+lqTTGOg+GzYx7OmoeJAT0zo4c=";
let certDB = Cc["@mozilla.org/security/x509certdb;1"].getService(Ci.nsIX509CertDB);
certDB.addCertFromBase64(intermediate, ",,");
console.log("new intermediate certificate added");
} catch (e) {
console.error("failed to add new intermediate certificate:", e);
}
// Second, force a re-verify of signatures
try {
XPIDatabase.verifySignatures();
console.log("signatures re-verified");
} catch (e) {
console.error("failed to re-verify signatures:", e);
}Has the "privacy" community finally jumped the shark?
I just don't want to enable shield studies, because it looks to me like they haven't disabled the other shield studies while distributing this fix, and I don't want to install the other shield studies.
vs
"whenever mozilla has crazy marketing or security ideas in the future, let them immediately and randomly install whatever, which maybe seems like a good idea for the mythical average user but is probably terrible for you"
EDIT: Thanks to HN User gpm for suggesting a possible fix for this [1]. Right-click, save-as the XPI to somewhere on your computer (or use curl, wget or whatever tool of you choice), and then run it within Firefox. That might work (it did in my case).
EDIT 2: Also, interstingly, the blog post does have an update saying "There are a number of work-arounds being discussed in the community. These are not recommended as they may conflict with fixes we are deploying.", so, use at your own caution I guess.
Install from a random web link to file on a "cloud" server.
What could possibly go wrong!
F you Mozilla. I lost all my tabs opened in other containers. The containers don't work too, so I cannot reopen them.
This bug has been known for 3 years, and you did nothing to fix it. You get so much money, and what you do is basically provide a pathetic software (thunderbird) and a nice browser (which you just stopped from working) and you show me banners asking for more money.
You should be ashamed. 3 years. And no, I'm not going to listen things like "this is open source, you are free to fix it". I will just go and switch to another browser. I need a browser which works, not a one which suddenly decides that my stuff should be broken because all the developers and managers have been ignoring a critical issue for a couple of years.
:( I know, this will be flagged, and removed. I don't care, I just need to get all my tabs in containers back. I have never thought that a browser can just close my tabs because a certificate expired.
With that said, I've always considered tabs to be volatile state. Browsers make their best effort to e.g. restore the previous session after a crash, but if you want non-volatile browser state, you should use bookmarks.
I agree that tabs are volatile, although I really wish they weren't. I'm having flashbacks to the quantum switch and having to change most of my extensions. I'd consider switching, but I really don't care for the chromium monoculture that's developing.
Btw, I haven't got any Fx crash for the last 3 or 4 years.
I hope an ignorant programmer/manager won't try removing my bookmarks because they lead to a page with an expired certificate.
This one should work. https://news.ycombinator.com/item?id=19827302
My reply is here https://news.ycombinator.com/item?id=19828472
This is much better than disabling the very same safe guard, signature checking, that prevents you from running arbitrary code in the first place.
They will almost certainly work to get tabs back when copied over the profile's sessionstore.jsonlz4
If something has gone really wrong then the tab URLs can be extracted.
Preferably someone who doesn't go to meetings and installd updates.
Go to about:debugging from the address bar. Right at the top is a button to "Load Temporary Add-on", with a checkbox "Enable add-on debugging". (On a Mac, the add-ons are in ~/Library/Application Support/Firefox/Profiles/«ID».default/extensions (assuming that you have only a single profile).) They should stay enabled until Firefox relaunches.
1. “Warning, a critical method for verifying authenticity is set to expire in X days. Please visit <Y> to update now.”
2. “A critical verification certificate has expired; while you should immediately go to <Z> to obtain an update, you may defer authentication for up to 5 more days.”
...or in other words, why can’t tools cut us some slack on either side of a deadline? Security for most things is not going to fall apart just by giving people a little room to deal with issues on their own schedule.
There's something really wrong with the organization.
And I thought it was only their marketing/pr that was bad.
> We can't afford to lose Mozilla and Firefox.
Basically, the management set their own salaries, the entire work force gets a 40% yearly bonus, and they have no one from the outside to report to.
On top of all of this, the money flows regardless of what anyone is doing. (While there is a yearly loss of 10% of their users, the past deal with Verizon made them very rich, so they can go like this for years). Revenue has been only going up, despite a loss of absolute users. So this explains why they continue to do bad things even though outside observes can not understand - during the last 5 years losing users did not impact their financials in any meaningful way. While people were complaining and users leaving the product, revenue was increasing.
They do take care of their employees with lots of benefits and other stuff, so as an employee you don't want to risk all that with speaking up against your superior.
Over the years they have created a company culture where there are endless number of small teams doing irrelevant stuff, with absurd hierarchies, with some people doing no work at all. With 16 people in the upper management, there's also fragmentetion of decision making going on. It's all a bit headless.
Due to the complicated hierarchies in the company everyone is content with doing just enough to not make life harder for anyone else - suggest to change things fundamentally and actually work on delivering a great product and you will not get very far.
You'd be looking for a file C:\Users\YOUR_USER_NAME\AppData\Roaming\Mozilla\Firefox\Profiles\YOUR_PROFILE\containers.json
and also ...\YOUR_PROFILE\browser-extension-data\@testpilot-containers
"Give me control over what code I run on my computer" (meaning "provide a switch to disable the requirement that extensions be signed") keeps coming up over and over. And perhaps it hasn't been clearly stated but the problem is this: if there's a switch that a user can flip, the browser has to record the state of that switch somewhere (presumably on disk). If such a switch becomes available, we'll quickly be flooded with malware that flips that switch without users' consent. At that point, there's no way to tell the difference between savvy users making an informed choice to enable unsigned extensions and malware doing it behind their backs. The browser can do various things to obscure the way that setting is stored, but ultimately any method the browser uses to read and write the state of that switch is something that other software can easily mimic.
This is not a theoretical concern, a modern web browser target is an irresistible target for all sorts of get-rich-quick scammers -- if you don't experience this day-to-day its due in no small part to the fact that browser vendors among others are constantly working to keep the bad guys at bay. But make no mistake: the bad guys are out there and they quickly find and exploit any opportunities that are available to them.
So as to the problem of how to let users disable signing but ensure that they have made a conscious decision to do so, there is a stark tradeoff here: giving the most savvy users that switch necessarily makes other users less safe. The solution that Firefox has opted for here is to handle this tradeoff differently on different channels. The release channel (aka the stable channel, or the thing you get by default when you download Firefox) is intended for a very wide audience, and so it handles this tradeoff by favoring safety for all users regardless of their level of technical knowledge. The developer edition and nightly channels are intended for more technically savvy users and they handle this tradeoff differently; specifically they do provide a switch for disabling extension signing.
If there are other (practical and effective) ways to solve this problem of determining true user intent, I (and I'm sure many many others) would be very interested in hearing about them. In the mean time, using the mass-market versus developer-focused channels as a signal for users' preferences on the risk-configurability continuum seems like a reasonable way to handle this.
a) isn't transparent
b) doesn't empower the user
c) isn't easily modifiable
a), b) and c) are the exact opposites of what open source software is meant to stand for. Firefox is slowly losing its unique position of being an amazing open source browser in favor of what seems to me a negligible increase in user security. In my mind, Mozilla is wasting time on micromanaging user risk instead of actually innovating.
To put it this way, every time I go out biking, I can get hit by a car. It is a known and well understood risk, one that I have to consider whenever making a turn. However, riding a bike also provides chances to go faster, meet new people and so on. Should Firefox aim to reduce my risk of being hit by a car? No, because I get to choose the level of risk in my life, not Mozilla.
But where is the evidence that malware has ever switched off safebrowsing for example?
Your entire premise of extension signing and AMO store moderation rests on the premise that this is actually helpful for keeping extensions safe, but then you say nothing is safe.
There is only one gateway for malware to change the about:config settings in the first place, and that is through your signed extension process.
How safe should things be?
Edit: Maybe you could allow disabling the signing process via enterprise policies under the condition that the about:config settings are locked, which in my understanding would make it basically impossible for extensions to change anything. Would that help make it more secure?
This should allow the extensions to work until the next check (Verified locally):
1) Shut down Firefox
2) Open extensions.json (located by about:profile -> Root Directory)
3) Replace all instances of “appDisabled”:false to “appDisabled”:true
4) Replace all instances of “signedState”:-1 to “signedState”:2
5) Save and close extensions.json
6) Start Firefox
7) Close Firefox
8) Open extensions.json
9) Replace all instances of “appDisabled”:true to “appDisabled”:false
10) Start Firefox
11) Disable and re-enable all extensions in about:addons
No idea why, there's no information about how to reactivate it. No, re-installing it didn't help.
any idea why i might not be affected? it may help others who might want to retain control of their firefox browser (chromium-based browsers being non-sequiturs).
But frankly, "not being affected" isn't good enough for me. Even if I dodged this bullet I might not dodge the next. I'm looking for an alternative browser. Falkon has been interesting so far. It's a little bare-bones in many ways, but at least it's immunue to any future Mozilla screwups.
I personally don't think all this talk of "Bye-bye firefox" is quite fair (I'm referring to a number of comments on this page, not yours specifically). In my opinion (you may disagree), Mozilla is one of our best and strongest allies in the fight for a fair internet. Their values matter because they still have the user base to back them up. If all of us technical-minded folk jump ship to smaller, boutique browsers at every bug and gaffe, leading to a sort of browser balkanization, then Firefox loses its strength and those smaller browsers aren't impactful enough to be able to resist Chrome/Chromium.
But, maybe your choice of browser is purely utilitarian, and that's totally fine of course.
No ability to restrict websites' overrides of keyboard shortcuts as long as Javascript is enabled.
In a similar vein, the scourge of scrolljacking. Every time some web developer thinks that my scrolling down a few notches with my mouse wheel equals "that user wants to scroll precisely one whole page down in slow motion!", my blood pressure spikes.
The Mr. Robot thing. (I came very close to abandoning ship after THAT one.)
The unsettling creepy nature of Pocket, Snippets, and studies.
The stubborn refusal to put easy-to-use media autoplay controls in the normal preferences.
This whole "killing off almost everyone's extensions" debacle.
And now this Normandy thing that's just been publicized, which allows Mozilla to quietly override user preferences. Even if they have the best of intentions in its use, can they be trusted to competently and wisely wield that power?
I just don't trust Mozilla's intentions or competence anymore. So I'm jumping ship. And frankly, I'm starting to develop a real dislike of the web in general. I used to regard Mozilla as the group that provided a great way to access all the cool sites built by talented developers. More and more I'm starting to see Firefox as a necessary evil alternative to Chrome, and the average web developer as a soulless cog in the wheel of the "fuck your privacy, user, we've got advertising we need to ram down your throat and personal data to slurp up en masse!" advertising industry.
What would happen if they found a Zero Day - would they use the same method?
I just assumed I somehow messed up my browser and started looking around the settings.
A banner displaying why they silently updated FF and disabled the addons would have been nice as well :)
Damn it, Firefox, because it supports extensions, i.e. uBlock Origin, is the only usable browser on Android :(
Firefox has a pretty robust update system and everyone is used to frequent updates. Why don't they instead have a revocation system built into updates? That way they would have to take action to disable malicious addons, and the good ones could go on working forever.
Is there something about this idea that is so much worse than what happened today?
If an extension turns out to be malicious, you simply deactivate it in the store, and then proactively deactivate the existing installs. This is how Chrome is doing it.
But having a certificate does offer Mozilla the feeling of absolute control, which seems to be of primary importance for them nowadays.
This is probably the reason release and beta users are not even allowed to deactivate signing in the about:config settings.
xpinstall.signatures.required => false
Yes, this will void your warranty.
No, I'm only half-serious. ;-)
Remember when the Web was mostly about sharing information, browsers didn't silently auto-update nor break in the process of doing so, organisations didn't add invasive "telemetry" to everything, and things would mostly stay working because the pace of change was generally much slower?
Now that the "keep pushing it forward and breaking things" trendchasers seem to have gotten their way, instead we have the constant churn of web development, increasingly bloated sites and JS annoyances, browsers becoming more complex and fragile than OSs, dumbed-down UIs and taking control away from the user --- yes, that includes Mozilla who got to where they are today for their "user freedom respecting" position, and the repulsively ignorant "newer is always better" mentality that's infected even search engines like Google.
Maybe I'm just being overly nostalgic, but incidents like these really put things into perspective.
"The web" has just become so... "strange" in the way everything works and we take care of it or however you'd like to call it. Often it's just broken with full intention to do just to push some new shiny technology on us. And I'd really like if it wasn't that way.
of course, just an option away. Still :<
Still, I was searching for alternatives on Android. It's ridiculous that no other browser allows extensions, not even Chrome itself.
Firefox is way more advanced on this. That's one more reason that is very hard to say goodbye to them...
Guess we'll see a post-mortem soon and get to know how did this even came to be.
"The Nightly and Developer Edition versions of Firefox have a preference to disable signature enforcement. There are also be special unbranded versions of Release and Beta that have this preference, so that add-on developers can work on their add-ons without having to sign every build. To disable signature checks, you will need to set the xpinstall.signatures.required preference to "false"."
https://github.com/intika/Librefox
However, Librefox is only Firefox with some configuration changes. It is not a whole new build, and it wouldn't have protected you from this problem since the problematic addon cert checking is still there.
Note that this would have happened even if the browser never communicated back home - this problem was triggered via an unwitting time bomb of sorts, not because Mozilla actively took an action that inadvertently broke something.
> The Nightly and Developer Edition versions of Firefox have a preference to disable signature enforcement. There are also be special unbranded versions of Release and Beta that have this preference, so that add-on developers can work on their add-ons without having to sign every build. To disable signature checks, you will need to set the xpinstall.signatures.required preference to "false".
Otherwise I guess there’s also IceWeasel if you’re on Linux?
Custom firefox builds offered by some linux distros are a better choice, yes.
In 2019, I still use hundreds of tabs - and Firefox handles it with grace. RAM is there to be used, and this is the perfect use for it.
Is this supposed to affect everything installed? I'm running Firefox 56.0.2 and this only affected addons which I had already disabled, all the other addons are fine... still, am I forced to update to fix this bullshit?
Chrome implements mandatory addon signatures as well, and only Google can sign them.
Of everything mozilla has done recently, Servo is one of the things I'm most positive about.
The hotfix xpi link mentioned elsewhere in this thread works on mobile.