7 ms·
There's a workaround that involves going to about:config and setting xpinstall.signatures.required to false. However, if you're running the Stable or Beta vers
by weavejester 7y ago
There's a workaround that involves going to about:config and setting xpinstall.signatures.required to false.
However, if you're running the Stable or Beta version, it will only work under Linux. On Windows and MacOS you'll need to download Nightly or the Developer Edition.
To fix this on MacOS I did the following:
1. Downloaded and installed Firefox Nightly
2. Ran /Applications/Firefox\ Nightly.app/Contents/MacOS/firefox-bin --profilemanager
3. Changed the profile to "default" so my normal Firefox profile would be used
4. Started up Firefox Nightly, opened about:config, then set xpinstall.signatures.required to false
Not sure if it's a good idea to use my default profile in Nightly. It might be a wiser idea to copy it instead.
- mirimir 7y agoThank you! Saved me tons of ultimately pointless thrashing.
- phyzome 7y agoThis worked for me on Firefox 60.6.1esr on Debian 9 Linux—changing the setting instantly restored my addons.
- deleted 7y ago[deleted]
- strainer 7y agoGotta love the Linux release team for not disabling this ability.
- hodgesrm 7y agoAnd Linux desktop for being pretty usable. :)
- jacob019 7y agoWorks on android too.
- nonbirithm 7y agoDoesn't work for me. Using Arch Linux. I was already on Nightly when this happened.
- c0nducktr 7y agoWhat timezone are you in? I'm in UTC-4 (Detroit), and haven't seen any problems so far. (Also running Nightly on Arch Linux - I haven't made any previous changes to the addon signing either)
- nonbirithm 7y agoTo clarify, by 'not working' I meant none of the addons with signing issues are re-enabled after changing xpinstall.signatures.required. I might have wrongly assumed this would happen. However, I tried installing a new addon I had never installed before and that works, but reinstalling one that I had previously installed still doesn't, even after uninstalling it (uBlock Origin). My timezone is America/Los_Angeles. EDIT: Sorry, I'm dumb. I actually have two versions of FF installed and I chose the one that wasn't Nightly.
- classichasclass 7y agoThis also works if you build from source, even if you build off mozilla-release. (Just tried it.)
- floatingatoll 7y agoUpgrading your profile from Release to Nightly, which occurs automatically when you open it with Nightly, is a one-way irreversible step. This could prevent your profile from being used with Release without crashes, or lose profile data such as bookmarks or saved passwords when later used with Release, depending on what work is underway in Nightly and if it happens to be backwards-compatible. Be sure to backup your profile if you choose to switch channels. Note: I am told that Developer channel uses a separate profile, but there are instructions below showing people how to override that, at which point this warning becomes relevant once again.
- andreareina 7y agoOof. Would you happen to know if it's the same with the developer edition as well?
- pygy_ 7y agoThe developer edition has its own user profile.
- floatingatoll 7y agoThat’s a good point. However, some of the instructions below specifically tell people how to force any channel onto using the existing Release profile. I’ll update my post.
- andreareina 7y agoAnd I told the developer edition to use my regular profile because that's the one that has all my settings and add-ons and I didn't realize the risk was there. Guess at this point all I can really do is hope and cross the bridge when I get there.
- obituary_latte 7y agoIf you’re on Mac, you should be able to recover the old profile with time machine. Or if you are on windows and have another backup setup.
- PhantomGremlin 7y agoOn Windows and MacOS you'll need to download Nightly or the Developer Edition. The workaround also works if you're running Firefox Extended Support Release on MacOS. Thankfully. For me missing extensions aren't just an inconvenience. I simply don't browse with JS on. Firefox is dead to me without NoScript.
- glindhol 7y agoSame is true for ESR on Windows.
- hum6ug 7y agoThis does not work with Firefox 66.0.3 in Arch Linux ...
- deleted 7y ago[deleted]
- gonhidi 7y agoIt is probably safer to use an unbranded build with the same version as the currently installed Firefox (take note that it will not update). Page with links to the latest release builds: https://wiki.mozilla.org/Add-ons/Extension_Signing https://wiki.mozilla.org/Add-ons/Extension_Signing
- captainmuon 7y agoThe following workaround works on regular editions: https://www.reddit.com/r/firefox/comments/bkhzjy/temp_fix_for_the_armagaddon_20_for_regular/ https://www.reddit.com/r/firefox/comments/bkhzjy/temp_fix_fo...
- bitcuration 7y agoOrigin here... https://news.ycombinator.com/item?id=19824410 https://news.ycombinator.com/item?id=19824410
- SilasX 7y agoFirefox stopped respecting the signature-required setting in the mainline version in 2016. I know because I got burned by it and made a Hitler parody. https://youtube.com/watch?v=taGARf8K5J8 https://youtube.com/watch?v=taGARf8K5J8 And frankly, this an extra absurdity on top of that. If you’re going to require signatures for all extensions, regardless of user preference, shouldn’t you be keeping an eye on the signing process?
- chappi42 7y agoWhy does Mozilla do this? Same with removing the option to not update. Why not let users choose (in the case of update maybe with an about config setting)?
- the8472 7y agoBecause (stable) users are dumb, are easily manipulated and can't be trusted. Thus the mothership has to be in control for the greater good. They also argue that enduser computers are already effectively "compromised" from a mozilla perspective because adware runs installers with admin privs and thus could insert things into the program folders. Thus anything the user can do adware could do too and therefore they can't give them any choice. They put it in nicer words though. To their credit, you can opt out but only if you switch to dev edition, nightly or custom builds, which either is a one-way road since downgrades corrupt profiles or tedious because you don't receive auto-updates. But what they should really have done is allowing additional signing roots. Even secure boot does that.
- SilasX 7y agoI get the ostensible justification, but attacking this way requires the user to dig into the obscure dev settings and load an xpi from outside the browser[1]. Is there even one case of a user compromised that way? [1] or at least they could have allowed that as a compromise
- the8472 7y ago