Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #208122 > unrolled thread

Can't install addons for firefox

Started byRoss Boylan <rossboylan@stanfordalumni.org>
First post2019-05-04 18:30 +0200
Last post2019-05-07 14:10 +0200
Articles 20 on this page of 26 — 18 participants

Back to article view | Back to linux.debian.user


Contents

  Can't install addons for firefox Ross Boylan <rossboylan@stanfordalumni.org> - 2019-05-04 18:30 +0200
    Re: Can't install addons for firefox Jonas Smedegaard <jonas@jones.dk> - 2019-05-04 18:40 +0200
      Re: Can't install addons for firefox Erwan David <erwan@rail.eu.org> - 2019-05-04 19:00 +0200
        Re: Can't install addons for firefox Ross Boylan <rossboylan@stanfordalumni.org> - 2019-05-04 20:00 +0200
          Re: Can't install addons for firefox Ross Boylan <rossboylan@stanfordalumni.org> - 2019-05-04 23:40 +0200
            Re: Can't install addons for firefox Peter Ehlert <peter@sdi-baja.com> - 2019-05-05 02:30 +0200
            Re: Can't install addons for firefox Zenaan Harkness <zenaan@freedbms.net> - 2019-05-05 03:00 +0200
      Re: Can't install addons for firefox Curt <curty@free.fr> - 2019-05-04 19:00 +0200
      Re: Can't install addons for firefox Ben Caradoc-Davies <ben@transient.nz> - 2019-05-05 02:40 +0200
        Re: Can't install addons for firefox Dave Sherohman <dave@sherohman.org> - 2019-05-05 12:00 +0200
          Re: Can't install addons for firefox Ben Caradoc-Davies <ben@transient.nz> - 2019-05-06 00:20 +0200
        Re: Can't install addons for firefox Ben Caradoc-Davies <ben@transient.nz> - 2019-05-06 22:50 +0200
    Re: Can't install addons for firefox Cindy Sue Causey <butterflybytes@gmail.com> - 2019-05-04 18:40 +0200
    Re: Can't install addons for firefox "Trevor D. Manning" <trevor.monique@bigpond.com> - 2019-05-04 19:00 +0200
    Re: Can't install addons for firefox Dan Ritter <dsr@randomstring.org> - 2019-05-06 01:40 +0200
      Re: Can't install addons for firefox Carl Fink <carlf@panix.com> - 2019-05-06 03:30 +0200
      Re: Can't install addons for firefox Dave Sherohman <dave@sherohman.org> - 2019-05-06 09:10 +0200
        Re: Can't install addons for firefox Lee <ler762@gmail.com> - 2019-05-06 19:40 +0200
          Re: Can't install addons for firefox Reco <recoverym4n@enotuniq.net> - 2019-05-06 20:10 +0200
            Re: Can't install addons for firefox Lee <ler762@gmail.com> - 2019-05-06 20:20 +0200
              Re: Can't install addons for firefox Reco <recoverym4n@enotuniq.net> - 2019-05-06 22:20 +0200
    Re: Can't install addons for firefox Peter Ehlert <peter@sdi-baja.com> - 2019-05-06 23:10 +0200
      Re: Can't install addons for firefox David <bouncingcats@gmail.com> - 2019-05-07 02:00 +0200
    Re: Can't install addons for firefox Siard <shiems146@kpnplanet.nl> - 2019-05-07 12:30 +0200
      Re: Can't install addons for firefox Joe <joe@jretrading.com> - 2019-05-07 13:50 +0200
        Re: Can't install addons for firefox Greg Wooledge <wooledg@eeg.ccf.org> - 2019-05-07 14:10 +0200

Page 1 of 2  [1] 2  Next page →


#208122 — Can't install addons for firefox

FromRoss Boylan <rossboylan@stanfordalumni.org>
Date2019-05-04 18:30 +0200
SubjectCan't install addons for firefox
Message-ID<xU5HY-5YI-3@gated-at.bofh.it>
Running firefox-esr on buster I don't seem to be able to install
addons.  I tried selenium IDE and katalon.  Has Debian blocked the
installation of addons?  I don't see indications of that in the docs
or the net.

Likewise, I know selenium (and maybe katalon) have had compatibility
issues with some versions of FF, but the page from which I installed
the addons (which was via the addon manager in FF) doesn't mention
anything.

And, if FF selectively blocks addons for which a Debian package is
available, that doesn't seem to apply since there are no such
packages.  There are some selenium packages, but not as a FF
extension.

Any ideas?

Thanks,
Ross

DIAGNOSTICS

The FF console log shows
Events to handle the installation initialized. BigInteger.js:27
[GA: ON] sendEvent {"hitType":"event","eventCategory":"AMO Addon
Installs Download Failed","eventAction":"addon","eventLabel":"Katalon
Recorder"} BigInteger.js:27
Error: install failed

The first log entries are warnings:
Content Security Policy: Directive ‘child-src’ has been deprecated.
Please use directive ‘worker-src’ to control workers, or directive
‘frame-src’ to control frames respectively.
Content Security Policy: Couldn’t process unknown directive ‘prefetch-src’

Then there are a bunch of errors like
Content Security Policy: The page’s settings blocked the loading of a
resource at self (“style-src”). Source: width:119%.
katalon-automation-record

[toc] | [next] | [standalone]


#208124

FromJonas Smedegaard <jonas@jones.dk>
Date2019-05-04 18:40 +0200
Message-ID<xU5RE-61S-5@gated-at.bofh.it>
In reply to#208122

[Multipart message — attachments visible in raw view] — view raw

Quoting Ross Boylan (2019-05-04 18:27:26)
> Running firefox-esr on buster I don't seem to be able to install
> addons.  I tried selenium IDE and katalon.  Has Debian blocked the
> installation of addons?  I don't see indications of that in the docs
> or the net.
> 
> Likewise, I know selenium (and maybe katalon) have had compatibility
> issues with some versions of FF, but the page from which I installed
> the addons (which was via the addon manager in FF) doesn't mention
> anything.
> 
> And, if FF selectively blocks addons for which a Debian package is
> available, that doesn't seem to apply since there are no such
> packages.  There are some selenium packages, but not as a FF
> extension.

It is an error in Mozilla infrastructure upstream - they have fixed it 
by abusing a backdoor in Firefox to update a certificate, but Debian 
has that backdoor disabled by default.

https://blog.mozilla.org/addons/2019/05/04/update-regarding-add-ons-in-firefox/


 - Jonas

-- 
 * Jonas Smedegaard - idealist & Internet-arkitekt
 * Tlf.: +45 40843136  Website: http://dr.jones.dk/

 [x] quote me freely  [ ] ask before reusing  [ ] keep private

[toc] | [prev] | [next] | [standalone]


#208127

FromErwan David <erwan@rail.eu.org>
Date2019-05-04 19:00 +0200
Message-ID<xU6aZ-68K-1@gated-at.bofh.it>
In reply to#208124
Le 04/05/2019 à 18:50, Curt a écrit :
> On 2019-05-04, Jonas Smedegaard <jonas@jones.dk> wrote:
>> It is an error in Mozilla infrastructure upstream - they have fixed it
>> by abusing a backdoor in Firefox to update a certificate, but Debian
>> has that backdoor disabled by default.
>>
>> https://blog.mozilla.org/addons/2019/05/04/update-regarding-add-ons-in-fire
>> fox/
> Note that the fix does not apply to Firefox ESR (which the OP is using). 
>

There are other possibilities at 
https://www.ghacks.net/2019/05/04/your-firefox-extensions-are-all-disabled-thats-a-bug

Hope one of them will work for OP

[toc] | [prev] | [next] | [standalone]


#208131

FromRoss Boylan <rossboylan@stanfordalumni.org>
Date2019-05-04 20:00 +0200
Message-ID<xU773-6I1-5@gated-at.bofh.it>
In reply to#208127
Thanks Cindy, Jonas, Curt, Trevor and Erwan for all the good info.  I
wish my internet searches were as effective as yours!

I noticed a few days ago that I started having problems accessing a
lot of sites through https* (might have been on Windows at the time,
either FF or FF ESR).  The errors always reported that the site policy
required using https and that the site's certificate was no good
because it expired in the 1970s!  This struck me as more likely a
browser problem than a site problem, but I haven't dug into it.  I
wonder if it's related.

Back to my original problem: if it's just triggered by an expired
mozilla certificate, I would expect fixing the certificate to be the
start and end of the fix, not all these code updates they've been
pushing.   But if FF is misreading expiration dates, as my https
problems suggest, that would require code.

It sounds as if the easiest options are 1) disabling security for
addons or 2) switching to current (non-ESR) FF and enabling "run
studies" 3) wait.
I think I'll try 3 since I have other stuff to work on and prefer to
keep security tight.

Ross

*Problems only arose with some indirection, which is one reason I
didn't follow up.  For example, I'd be browsing forums and could
navigate around and read messages fine.  But if I right-clicked on a
link to see a related posting in a new tab, I'd get the security
error.

[toc] | [prev] | [next] | [standalone]


#208162

FromRoss Boylan <rossboylan@stanfordalumni.org>
Date2019-05-04 23:40 +0200
Message-ID<xUaxY-qn-3@gated-at.bofh.it>
In reply to#208131
Just wanted to draw people's attention to a couple of things:

"There are a number of work-arounds being discussed in the community.
These are not recommended as they may conflict with fixes we are
deploying. We’ll let you know when further updates are available that
we recommend, and appreciate your patience. (May 4, 15:01 EST)"
>From the updates on the bottom of
https://blog.mozilla.org/addons/2019/05/04/update-regarding-add-ons-in-firefox/

Second, that blog entry will supposedly be updated as things unfold,
so it may be at least a semi-authoritative way to track what's going
on.

[toc] | [prev] | [next] | [standalone]


#208165

FromPeter Ehlert <peter@sdi-baja.com>
Date2019-05-05 02:30 +0200
Message-ID<xUdct-23l-3@gated-at.bofh.it>
In reply to#208162
I have been just waiting for Mozilla. A few moments ago I saw this:
https://www.dedoimedo.com/computers/firefox-addons-disabled-bug.html
simple and logical work-around... just remember to check back and re-enable.

Peter running ESR on Buster Mate

On 5/4/19 2:34 PM, Ross Boylan wrote:
> Just wanted to draw people's attention to a couple of things:
>
> "There are a number of work-arounds being discussed in the community.
> These are not recommended as they may conflict with fixes we are
> deploying. We’ll let you know when further updates are available that
> we recommend, and appreciate your patience. (May 4, 15:01 EST)"
> >From the updates on the bottom of
> https://blog.mozilla.org/addons/2019/05/04/update-regarding-add-ons-in-firefox/
>
> Second, that blog entry will supposedly be updated as things unfold,
> so it may be at least a semi-authoritative way to track what's going
> on.
>
>
>

[toc] | [prev] | [next] | [standalone]


#208167

FromZenaan Harkness <zenaan@freedbms.net>
Date2019-05-05 03:00 +0200
Message-ID<xUdFv-2cW-1@gated-at.bofh.it>
In reply to#208162
On Sat, May 04, 2019 at 02:34:16PM -0700, Ross Boylan wrote:
> Just wanted to draw people's attention to a couple of things:
> 
> "There are a number of work-arounds being discussed in the community.
> These are not recommended as they may conflict with fixes we are
> deploying. We’ll let you know when further updates are available that
> we recommend, and appreciate your patience. (May 4, 15:01 EST)"
> >>From the updates on the bottom of
> https://blog.mozilla.org/addons/2019/05/04/update-regarding-add-ons-in-firefox/
> 
> Second, that blog entry will supposedly be updated as things unfold,
> so it may be at least a semi-authoritative way to track what's going
> on.


This worked for one extremely humble (wink wink) user:
https://forums.informaction.com/viewtopic.php?p=100053#p100053

in particula, temporarily disabling xpinstall.signatures.required :

 1) Open about:config
 2) Toggle the value of xpinstall.signatures.required so it becomes false.
 3) Restart the browser.

This epitome of submission did not need step 3).

I suggest writing one's elf a little note to try re-enabling this in
a day or two.

Good luck ;)

[toc] | [prev] | [next] | [standalone]


#208129

FromCurt <curty@free.fr>
Date2019-05-04 19:00 +0200
Message-ID<xU6aZ-68K-3@gated-at.bofh.it>
In reply to#208124
On 2019-05-04, Jonas Smedegaard <jonas@jones.dk> wrote:
>
> It is an error in Mozilla infrastructure upstream - they have fixed it
> by abusing a backdoor in Firefox to update a certificate, but Debian
> has that backdoor disabled by default.
>
> https://blog.mozilla.org/addons/2019/05/04/update-regarding-add-ons-in-fire
> fox/

Note that the fix does not apply to Firefox ESR (which the OP is using). 

-- 
The boys at first were very polite about my medals and asked me what I had done
to get them. I showed them the papers, which were written in very beautiful
language and full of fratellanza and abnegazione, but which really said, with
the adjectives removed, that I had been given the medals because I was 
an American. - "Another Country"

[toc] | [prev] | [next] | [standalone]


#208166

FromBen Caradoc-Davies <ben@transient.nz>
Date2019-05-05 02:40 +0200
Message-ID<xUdm9-26o-3@gated-at.bofh.it>
In reply to#208124
Setting about:config / xpinstall.signatures.required to false fixed 
extensions for me for firefox 66.0.1-1 amd64 on Debian sid and for 
Firefox 66.0.2 on Android. I needed to restart Firefox on Debian.

Kind regards,

-- 
Ben Caradoc-Davies <ben@transient.nz>
Director
Transient Software Limited <https://transient.nz/>
New Zealand

[toc] | [prev] | [next] | [standalone]


#208185

FromDave Sherohman <dave@sherohman.org>
Date2019-05-05 12:00 +0200
Message-ID<xUm65-7jV-1@gated-at.bofh.it>
In reply to#208166
On Sun, May 05, 2019 at 10:52:56AM +1200, Ben Caradoc-Davies wrote:
> Setting about:config / xpinstall.signatures.required to false fixed
> extensions for me for firefox 66.0.1-1 amd64 on Debian sid and for Firefox
> 66.0.2 on Android. I needed to restart Firefox on Debian.

When I tried that yesterday, it allowed extensions to be reinstalled
(yes, I was one of those who tried to fix this problem by uninstalling
and reinstalling my extensions), but not all plugins actually worked in
this state.  Most notably, NoScript displayed no icon on the toolbar
(just a blank space with a tooltip) and did not appear to actually do
anything.  Its settings were also inaccessible, both through the
(missing) popup menu and via the list of installed add-ons (in which
case I got a blank grey page with an endless "loading" spinner
animation).

Based on this, it appears that xpinstall.signatures.required may be no
more than a partial solution.  (Although it's also possible that
something may have been broken in the uninstall/reinstall process.)

-- 
Dave Sherohman

[toc] | [prev] | [next] | [standalone]


#208239

FromBen Caradoc-Davies <ben@transient.nz>
Date2019-05-06 00:20 +0200
Message-ID<xUxEd-6hR-3@gated-at.bofh.it>
In reply to#208185
On 05/05/2019 21:30, Dave Sherohman wrote:
> On Sun, May 05, 2019 at 10:52:56AM +1200, Ben Caradoc-Davies wrote:
>> Setting about:config / xpinstall.signatures.required to false fixed
>> extensions for me for firefox 66.0.1-1 amd64 on Debian sid and for Firefox
>> 66.0.2 on Android. I needed to restart Firefox on Debian.
> When I tried that yesterday, it allowed extensions to be reinstalled
> (yes, I was one of those who tried to fix this problem by uninstalling
> and reinstalling my extensions), but not all plugins actually worked in
> this state.  Most notably, NoScript displayed no icon on the toolbar
> (just a blank space with a tooltip) and did not appear to actually do
> anything.  Its settings were also inaccessible, both through the
> (missing) popup menu and via the list of installed add-ons (in which
> case I got a blank grey page with an endless "loading" spinner
> animation).
> Based on this, it appears that xpinstall.signatures.required may be no
> more than a partial solution.  (Although it's also possible that
> something may have been broken in the uninstall/reinstall process.)

My prexisting NoScript installation works correctly after setting 
xpinstall.signatures.required to false, including Add On preferences 
page and toolbar icon. I did not uninstall/reinstall.

Kind regards,

-- 
Ben Caradoc-Davies <ben@transient.nz>
Director
Transient Software Limited <https://transient.nz/>
New Zealand

[toc] | [prev] | [next] | [standalone]


#208325

FromBen Caradoc-Davies <ben@transient.nz>
Date2019-05-06 22:50 +0200
Message-ID<xUSIG-2AO-5@gated-at.bofh.it>
In reply to#208166
On 05/05/2019 10:52, Ben Caradoc-Davies wrote:
> Setting about:config / xpinstall.signatures.required to false fixed 
> extensions for me for firefox 66.0.1-1 amd64 on Debian sid and for 
> Firefox 66.0.2 on Android. I needed to restart Firefox on Debian.

Seems fixed in firefox 66.0.4-1 on Debian sid and firefox 66.0.4 on 
Android: extensions continue to work after restoring the default 
about:config xpinstall.signatures.required setting (true).

Kind regards,

-- 
Ben Caradoc-Davies <ben@transient.nz>
Director
Transient Software Limited <https://transient.nz/>
New Zealand

[toc] | [prev] | [next] | [standalone]


#208125

FromCindy Sue Causey <butterflybytes@gmail.com>
Date2019-05-04 18:40 +0200
Message-ID<xU5RE-61S-13@gated-at.bofh.it>
In reply to#208122
On 5/4/19, Ross Boylan <rossboylan@stanfordalumni.org> wrote:
> Running firefox-esr on buster I don't seem to be able to install
> addons.  I tried selenium IDE and katalon.  Has Debian blocked the
> installation of addons?  I don't see indications of that in the docs
> or the net.
>
> Likewise, I know selenium (and maybe katalon) have had compatibility
> issues with some versions of FF, but the page from which I installed
> the addons (which was via the addon manager in FF) doesn't mention
> anything.
>
> And, if FF selectively blocks addons for which a Debian package is
> available, that doesn't seem to apply since there are no such
> packages.  There are some selenium packages, but not as a FF
> extension.
>
> Any ideas?


How about... extremely EMBARRASSINGLY expired certificate(s)? Just
read this about 5 minutes ago:

https://www.osnews.com/story/129944/due-to-expired-certificate-all-firefox-extensions-disabled/

Does anyone know if that might affect things in this manner?

Cindy :)
-- 
Cindy-Sue Causey
Talking Rock, Pickens County, Georgia, USA

* runs with birdseed *

[toc] | [prev] | [next] | [standalone]


#208128

From"Trevor D. Manning" <trevor.monique@bigpond.com>
Date2019-05-04 19:00 +0200
Message-ID<xU6b0-68K-5@gated-at.bofh.it>
In reply to#208122
* Ross Boylan (rossboylan@stanfordalumni.org) wrote:
> Running firefox-esr on buster I don't seem to be able to install
> addons.  I tried selenium IDE and katalon.  Has Debian blocked the
> installation of addons?  I don't see indications of that in the docs
> or the net.

https://github.com/mozilla/addons/issues/978

https://blog.mozilla.org/addons/2019/05/04/update-regarding-add-ons-in-firefox/

It appears to be a recent bug.

Bestest,

-- 
Trevor D. Manning

BOFH Excuse #232:

Ionization from the air-conditioning

[toc] | [prev] | [next] | [standalone]


#208243

FromDan Ritter <dsr@randomstring.org>
Date2019-05-06 01:40 +0200
Message-ID<xUyTD-6XD-5@gated-at.bofh.it>
In reply to#208122
Ross Boylan wrote: 
> Running firefox-esr on buster I don't seem to be able to install
> addons.  I tried selenium IDE and katalon.  Has Debian blocked the
> installation of addons?  I don't see indications of that in the docs
> or the net.
> 

No, Mozilla really screwed up. Every Firefox user has this
problem.

Try installing

https://storage.googleapis.com/moz-fx-normandy-prod-addons/extensions/hotfix-update-xpi-intermediate%40mozilla.com-1.0.2-signed.xpi

And your problems should go away immediately. Upgrade your
browser later on.

-dsr-

[toc] | [prev] | [next] | [standalone]


#208248

FromCarl Fink <carlf@panix.com>
Date2019-05-06 03:30 +0200
Message-ID<xUAC5-8bl-1@gated-at.bofh.it>
In reply to#208243
Being impatient and easily annoyed, I just installed Waterfox,
which works fine. Yes, I know about the theoretical security issues.

-- 
Carl Fink                           nitpicking@nitpicking.com

Read my blog at blog.nitpicking.com.  Reviews!  Observations!

[toc] | [prev] | [next] | [standalone]


#208254

FromDave Sherohman <dave@sherohman.org>
Date2019-05-06 09:10 +0200
Message-ID<xUFV8-3fB-3@gated-at.bofh.it>
In reply to#208243
On Sun, May 05, 2019 at 07:29:55PM -0400, Dan Ritter wrote:
> No, Mozilla really screwed up.

Understatement of the month, if not the year.  And yet, on the Mozilla
blog, all the comments are "oh, you're so awesome for working on a
weekend to fix this!", completely ignoring that there wouldn't have been
a problem to "heroically" work all weekend to solve if they'd just done
things right (staying on top of cert expirations, not trying to funnel
everything through a single point of failure, etc.) in the first place.

> Try installing
> 
> https://storage.googleapis.com/moz-fx-normandy-prod-addons/extensions/hotfix-update-xpi-intermediate%40mozilla.com-1.0.2-signed.xpi
> 
> And your problems should go away immediately.

Thanks!  The Mozilla blog just says to get the updated version, no
mention of how to install the updated cert directly.

I did still need to uninstall/reinstall my add-ons before they started
working again (I assume it would have eventually revalidated them on its
own, but I didn't have the patience to wait for that) but everything
appears normal again after doing that.  And all my settings appear to
have survived across the uninstall/reinstall cycle, even!

-- 
Dave Sherohman

[toc] | [prev] | [next] | [standalone]


#208304

FromLee <ler762@gmail.com>
Date2019-05-06 19:40 +0200
Message-ID<xUPKN-MT-5@gated-at.bofh.it>
In reply to#208254
On 5/6/19, Dave Sherohman <dave@sherohman.org> wrote:
> On Sun, May 05, 2019 at 07:29:55PM -0400, Dan Ritter wrote:
>>
>> No, Mozilla really screwed up.
>
> Understatement of the month, if not the year.  And yet, on the Mozilla
> blog, all the comments are "oh, you're so awesome for working on a
> weekend to fix this!", completely ignoring that there wouldn't have been
> a problem to "heroically" work all weekend to solve if they'd just done
> things right (staying on top of cert expirations, not trying to funnel
> everything through a single point of failure, etc.) in the first place.

Is it just me, or does anyone else see the real screw up as mozilla
not allowing users to override their decisions -- in this case, about
an addon being "safe"?

I like that mozilla can disable addons they find out are doing 'bad'
things (whatever 'bad' means).  I also like the fail safe aspect where
if they can't verify an addon it defaults to 'bad'.  What I don't
like, and what I think turned a minor issue into a very visible and
embarrassing problem, is not being able to over-ride their decision.

Lee

[toc] | [prev] | [next] | [standalone]


#208308

FromReco <recoverym4n@enotuniq.net>
Date2019-05-06 20:10 +0200
Message-ID<xUQdQ-1dq-1@gated-at.bofh.it>
In reply to#208304
	Hi.

On Mon, May 06, 2019 at 01:35:48PM -0400, Lee wrote:
> On 5/6/19, Dave Sherohman <dave@sherohman.org> wrote:
> > On Sun, May 05, 2019 at 07:29:55PM -0400, Dan Ritter wrote:
> >>
> >> No, Mozilla really screwed up.
> >
> > Understatement of the month, if not the year.  And yet, on the Mozilla
> > blog, all the comments are "oh, you're so awesome for working on a
> > weekend to fix this!", completely ignoring that there wouldn't have been
> > a problem to "heroically" work all weekend to solve if they'd just done
> > things right (staying on top of cert expirations, not trying to funnel
> > everything through a single point of failure, etc.) in the first place.
> 
> Is it just me, or does anyone else see the real screw up as mozilla
> not allowing users to override their decisions -- in this case, about
> an addon being "safe"?

xpinstall.signatures.required = false

They do allow it … for now.

Reco

[toc] | [prev] | [next] | [standalone]


#208313

FromLee <ler762@gmail.com>
Date2019-05-06 20:20 +0200
Message-ID<xUQnw-1gF-7@gated-at.bofh.it>
In reply to#208308
On 5/6/19, Reco <recoverym4n@enotuniq.net> wrote:
> 	Hi.
>
> On Mon, May 06, 2019 at 01:35:48PM -0400, Lee wrote:
>> On 5/6/19, Dave Sherohman <dave@sherohman.org> wrote:
>> > On Sun, May 05, 2019 at 07:29:55PM -0400, Dan Ritter wrote:
>> >>
>> >> No, Mozilla really screwed up.
>> >
>> > Understatement of the month, if not the year.  And yet, on the Mozilla
>> > blog, all the comments are "oh, you're so awesome for working on a
>> > weekend to fix this!", completely ignoring that there wouldn't have
>> > been
>> > a problem to "heroically" work all weekend to solve if they'd just done
>> > things right (staying on top of cert expirations, not trying to funnel
>> > everything through a single point of failure, etc.) in the first place.
>>
>> Is it just me, or does anyone else see the real screw up as mozilla
>> not allowing users to override their decisions -- in this case, about
>> an addon being "safe"?
>
> xpinstall.signatures.required = false
>
> They do allow it … for now.

Only for the ESR, developer and nightly versions of firefox.
  https://support.mozilla.org/en-US/kb/add-on-signing-in-firefox
Firefox Extended Support Release (ESR), Firefox Developer Edition and
Nightly versions of Firefox will allow you to override the setting to
enforce the extension signing requirement, by changing the preference
xpinstall.signatures.required to false in the Firefox Configuration
Editor (about:config page).

Lee

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web