Full corrective releases have been published. and , which includes fixes for replacement and recovery of disabled add-ons. However, several unresolved side effects have been noted:
- Some add-ons, such as Epubreader, in about:addons after the certificate is updated or remain in an unsupported state. This issue affects add-ons without an identifier in the manifest.json file, which were removed in case of a digital signature verification error. Such add-ons to be reinstalled (data will be restored as it remains in the profile directory);
- data and settings loss in add-ons using the (Containers), such as in Multi-Account Containers and Facebook Container add-ons. Users need to reconfigure add-on data from scratch in about:addons;
- should reinstall them from addons.mozilla.org. ;
- to default values. The user needs to set the homepage and search engine again.
For older versions (Firefox 56.0.2 and earlier), which do not include
normandy solved the problem by extracting the certificate from the XPI file certificate should be saved as a pem file and imported through the dialog "Options/Privacy & Security/Certificates/View Certificates/Authorities/Import." You should save it in a pem file and import this file through the dialog "Options/Privacy & Security/Certificates/View Certificates/Authorities/Import."
Additionally, it is worth noting the issue of Tor Browser's dependency on Mozilla's infrastructure. Let’s remember that Tor Browser users face a problem with the certificate. the included add-on NoScript, which provides an additional layer of protection. To restore it, simply set the option xpinstall.signatures.required = false in about:config, but it raises concerns about the reliance of installed Tor Browser instances on a third party, whose actions can disable additional layers of anonymity.
Source: opennet.ru
