8 ms·
So that's pretty unfair. 1) They state they are working on a fix for normal, release channel users who don't want to run studies 2) they tell you to temporarily
by usecontainers 7y ago
So that's pretty unfair.
1) They state they are working on a fix for normal, release channel users who don't want to run studies
2) they tell you to temporarily run studies to get the fix within up to 6 six hours (could be faster; set expectation)
3) You can explicitly install nightly or 66.4 before it's pushed if you want a fix now
Yes, it's unfortunate, I'd expect them to meet it head on, push a tested fix in a timely matter, admit a mistake was made, explain publicly how/why and apply learning moving forward. Beyond that, what's your expectation?
- Aeolun 7y agoMy expectation is that something like this doesn’t happen in the first place. Given that it has happened, I expect them to provision a new certificate and push a fixed version within an hour or two to all release channels. What I would emphatically ‘not’ expect, is a hack that might take up to 6 hours to be applied.
- overgard 7y agoNot saying that their current actions are wrong, just that the optics of it are terrible for them. There was a chain of bad decisions that led them here though: 1) thinking it's ok to disable software after its installed (using cert expiration -- I'm ok if the cert was revoked but that's a totally different discussion), 2) Taking more control of people's local software than many people are comfortable with, especially considering that their main market is tech savvy people that tend to be more sensitive to this than most 3) Making some of these things opt-out rather than opt-in, giving the perception that they may value data collection and control more than their users privacy.
- Vinnl 7y ago> their main market is tech savvy people that tend to be more sensitive to this than most Is that so, though? Firefox is still being used by millions of users, and I doubt those are only the tech savvy internet users. (Then again, this mostly applies to Firefox users using add-ons, which probably has a higher share of technical users.)
- yawaramin 7y agoOne of their biggest 'selling points' is that they protect your privacy. It's really, really off brand for them to be distributing a critical bugfix through a telemetry collection channel.
- DoctorOetker 7y agoit does feel like the normalization of deviance it's also entirely predictable that a non-negligable fraction of users -after enabling studies and verifying everything works again- will ... simply go on with their lives and forget about disabling studies... I also don't understand why the certificate graph is not exposed through a user interface, so that the user can add and remove certificates, or enable and disable certificates at their own discretion. This should have been obvious when the certified add-ons were introduced. Then all they would have to do is host the certificate file on their own domain and everyone could follow the simple steps in the GUI to replace the expired certificate...
- overgard 7y agoI might be wrong, I don't have data, but, as far as I can tell most users either use the installed browser or chrome (or whatever their tech savvy friends/relatives install for them).
- mmsimanga 7y agoBeing a former ops guy the items you list resonate with me. On the one hand I do feel for the developers and hope they come up with a fix soon. On the other side, this is frustrating and there were some bad decisions made that a typical ops person would have pointed out and been ignored. The ignoring of ops guys until something breaks is something that has been consistent in my experience. Anyway for the sake of having an alternative to Chrome I hope they fix this yesterday.
- Yoric 7y agoFor what it's worth, the (initial) mechanism for disabling add-ons (your 1) has been present since before Firefox 1.0. It was designed to quickly deactivate any malicious add-on as soon as it was detected, before it had a chance to do too much damage. In my books, that's a good thing. Here, the mechanism that kicked in was the protection against add-ons that could have been signed with stolen credentials, which would make them clearly malicious. Of course, it turns out that the problem was an expired cert, so a bug/human error. But generally speaking, I think that 1 is good.
- zaat 7y ago> It was designed to quickly deactivate any malicious add-on as soon as it was detected, before it had a chance to do too much damage. In my books, that's a good thing. I hate this attitude from security people so much. If for the sake of fighting malicious code you are crippling the software usability or my user experience, you are the malicious code.
- lilyball 7y agoI hate that attitude from entitled users so much. If you don't want security, you're welcome to have a malware-ridden system, but don't think that this means all users should have to put up with malware-ridden systems.
- zaat 7y agoI wish that was true, but in fact I have no way to disable this and similiar amazing security entrenchments. The monthly device bricking windows updates, for instance. If I can't do anything with my hardened computer, I don't care if is eaten alive by malware, it is useless anyways. At work, as the guy who have to fight on behalf of the sysadmins and the users dozens of clueless security advisors who are hardening everything according to security best-practices written by similarily clueless experts, I'm seriously astonished by the common backward thinking. If you are blocking access to all users pdf files, for an instance, you are the malware, you are causing disturbance to the business operation and annoying everyone.
- httpsterio 7y agoWhat does optics mean in this context?
- overgard 7y agoPublic perception. For instance, one of the first comments on their post is this: > Why not just post a link to the fix that can be installed WITHOUT enabling Studies? This sounds like a clever plan to get more people to share their data via Studies… I definitely don't agree with that guy, and I doubt that's a majority opinion, but asking people to use a workaround that benefits them (Mozilla) after they broke things for a lot of people is bad publicity for sure. For what it's worth I think Mozilla is doing the right thing here, just it's not going to make them look great.
- jcranmer 7y ago> using cert expiration -- I'm ok if the cert was revoked but that's a totally different discussion CAs can delete certificates from their revocation lists after expiration, which means that you can't tell the difference between a certificate that was never revoked but merely expired and a revoked-and-then-expired certificate.
- trashface 7y agoAs an alternative perspective, I'm totally fine with FF disabling the extensions when the cert went invalid, and I'm also happy that it auto-updated itself to fix the issue. To me the optics are pretty good: a mistake happened and they were able to recover pretty fast, and my browser wasn't exploited by bad actors in the meantime.
- lugg 7y ago> a mistake happened and they were able to recover pretty fast, and my browser wasn't exploited by bad actors in the meantime. To me adding a new plugin signing cert through a side loaded plugin is pretty much the definition of exploited. All this tells me is that their plugin signing solution is utterly worthless. The only way this should have been fixed was through official update channels.
- tinus_hn 7y agoThe worst part is taking control because they think they know better than the user, and then messing up like this.
- gatherhunterer 7y agoIt is too late to listen to reason. Many commenters have spent their Saturday morning pushing a narrative that appeals to emotion.
- isoskeles 7y agoI just switched my browser. Bye bye Firefox.
- tilolebo 7y agoI'm curious, do you switch at every fuck up? Then it's only a matter of time until you come back to Firefox, or maybe you'll end up making your own web browser?
- isoskeles 7y agoNo, just this one because it took me more than 5 minutes to not find a working fix, and this was such a massive fuck-up that I don't feel like sticking around. I appreciate the condescension of both your comment and the person I initially replied to, but I honestly see your comments as saying, in more words, "Fuck the user." And that's fine, but why don't you just say it? Go ahead and type it, I want you to type what you really think about the users who are so dumb and fickle that they can't handle something so trivial as not being able to use their precious stupid add-ons like HTTPS Everywhere and uBlock.
- MeltySmelty 7y agokys faggot
- mruts 7y agoAnd operating system, and smartphone, and processor, and video card.
- isoskeles 7y ago
- MichaelBravo 7y agoHow do you get these studies or beta version?
- rosser 7y agoI'm not sure I care how unfair the characterization is. I heavily use container tabs — ahem, 'usecontainers — and all of my open container tabs disappeared at once, with no indication of why or what to do about it, when this happened. I lost an absurd amount of work and state because of that. I only knew what caused it by inference, because I'd just previously read The Fine Article (which, btw, gave no indication that losing state like that was something I should expect, merely, "No active steps need to be taken to make add-ons work again"...) I still prefer Firefox over all the other browsers, and will continue to use it, but the project has lost a lot of trust and goodwill over this. The optics are indeed awful, and this was fully preventable. Firefox fucked up, full stop.
- thr0w__4w4y 7y agoThis is pretty much exactly my thought as well. Based on the timing of initial tweets and blog posts on this fiasco, I'm pretty sure I was in the first 10%, if not first 1%, of people who experienced this. And I was in a plane at 36,000 feet trying to work on a cross country (U.S.) flight when suddenly about 130 tabs in 7 windows disappeared. Really, REALLY bad. Panic, frustration, confusion... I was more than 50% sure that all was not lost forever, that it was some "glitch" (Extensions all showed the same bloody red status), but I was tweaked. I work in security (embedded systems, not computers/IT) so I have a very good understanding of certificates, TLS, PKI, etc. There are many ways things can get out of whack if the people in charge screw up. Regardless, this is embarrassing, dare I say shameful (pretty much almost up there with "Ooooppsss... we just lost our domain - it expired and no one thought to renew it) Come on, guys, get it together. Have a procedure, document it, practice it, stay in front of it.
- toyg 7y ago> I lost an absurd amount of work and state EDIT: after installing the fixed XPI, I have to sadly report that all data has gone. All my carefully-managed containerized life was wiped clean. Heads should roll. Complete shambles. And the worst thing is, I suspect it's all a plot to have more people opt-in to the shitty telemetry. Otherwise, why not push an update through the usual channels? Had it been a security-related fix, would have they used "studies"? I bet not.