All Firefox add-ons disabled due to Mozilla certificate expiration

Mozilla warned about the emergence of mass issues extensions for Firefox. All users of the browser found their extensions blocked due to the expiration of the certificate used for generating digital signatures. Additionally, it has been noted that installing new extensions from the official catalog AMO (addons.mozilla.org).

There is currently no solution to the situation found, Mozilla developers are considering possible options for fixing the issue and have only issued a general confirmation of the situation. It is mentioned that extensions became inactive after 0:00 (UTC) on May 4. The certificate was supposed to be updated a week ago, but for some reason, this did not happen and this fact went unnoticed. Now, a few minutes after launching the browser, a warning appears about the deactivation of extensions due to problems with the digital signature, and extensions disappear from the list. The digital signature is checked once a day or after launching the browser, so long-running instances of Firefox may not disable extensions immediately.

All Firefox add-ons disabled due to Mozilla certificate expiration

As a workaround to restore access to extensions, Linux users can disable digital signature verification by setting the variable "xpinstall.signatures.required" to "false" in about:config. This method works for stable and beta releases only on Linux and Android; for Windows and macOS, such manipulation is only possible in night builds and the Developer Edition. Alternatively, you can change the system clock to a time before the certificate's expiration, which will restore the ability to install extensions from the AMO catalog, but the already set deactivation tag is not removed.

It should be noted that mandatory verification of Firefox extensions via digital signatures was implemented in April 2016. According to Mozilla, the digital signature verification allows blocking the distribution of malicious and spyware extensions. Some extension developers disagree With this position, it is believed that the mandatory verification mechanism using digital signatures only creates difficulties for developers and increases the time to deliver corrective releases to users, without affecting security. There are many trivial and obvious methods to bypass the automated extension verification system, allowing the unnoticed injection of malicious code, for example, by generating an operation on the fly by concatenating several strings and subsequently executing the resulting string with eval. Mozilla's stance boils down to the fact that most authors of malicious extensions are lazy and will not resort to such techniques to conceal malicious activity.

Note: Mozilla developers informed on the start of testing a fix, which, if successfully validated, will soon be made available to users (the decision to implement the proposed fix has not yet been made). Until the fix is applied, the generation of digital signatures for new extensions is disabled.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster