So don’t use this unless you don’t mind it breaking randomly whenever there’s an update.
So don’t use this unless you don’t mind it breaking randomly whenever there’s an update.
Also, I echo the other people saying that the typeface you chose for the website is very difficult to read.
This probably falls in the same boat. :)
i.e. I don't think that the authors of this tool wanted to have developers be forced to use the latest version of their tool.
It's probably that they didn't think about it when they wrote the code, but now they know and hopefully this gets fixed in the next release?
There are some bugs that are just hard to find until they're out there.
Mozilla bricked SSL certificates that are mandatory for everything, including Browser Extensions.
There is a flag for about:config to unbrick it. Problem is though, that this lasts less than a second because of the remote settings service running in a loop. If you block that services domain with a host firewall (like opensnitch), Firefox will do an endless for loop using 100% CPU load trying to request the shavar and other services domains.
So, effectively, you cannot run an old Firefox version, and especially not a version that uses the old bundled mozilla certificate (which is all provided download variants).
That's what the previous commenter was (likely) referring to.
Font are ugly but it loaded HN just fine.
> Firefox 53 from 2017
not the same. I was talking about post-quantum Firefox releases, which added the mentioned dependencies on Mozilla's SSL certificate.
(The grandparent's comment was also about post-quantum, obviously)
Snakeoil certificates in Enterprise licensing might disagree with this statement, which in my opinion is pretty identical to Mozilla's approach to have control over "who is allowed to use when" of their software.
It's also not a few specific releases over time, it's all releases after Browser Extension signatures were introduced as being mandatory, which made the rest of the Browser rely heavily on their certificate management servers.
I'm not saying it's malicious intent, what I am saying is that this could've been implemented in a much better manner, which wouldn't rely on a centralized certificate signing service.