How does Add-on signing increase security when everyone will be turning it off to get existing add-ons to continue working when they update?
I have several issues with the introduction of mandatory add-on signing. Given that it is INEVITABLE that there will be many useful / important add-ons that are not signed (eg Kaspersky security, iCloud, IKEA 3-D viewer) users are being forced to either - not update FF / revert to earlier version* - turn off add-on checking, which afik can NOT be done selectively but can only be done globally, for all add-ons - stop using FF
So how does this improve security exactly?
And, could someone please tell me how to roll back the update - windows restore point?
All Replies (4)
https://support.mozilla.org/en-US/kb/add-on-signing-in-firefox
https://wiki.mozilla.org/Firefox/AddOns/Status/Updates#Exec_Summary “Currently targeting Signing with no pref to turn off in Firefox 47”
FredMcD said
“Currently targeting Signing with no pref to turn off in Firefox 47”
Moving that from Firefox 44 to Firefox 47 - might be a wise decision considering the slow rate of conformance thus far.
richard, Not advisable to "roll back" a Firefox version via a Windows restore point. Better off using the xpinstall.signatures.required pref to disable that feature or re-install Firefox 42. https://support.mozilla.org/en-US/kb/install-older-version-of-firefox
the-edmeister said
Moving that from Firefox 44 to Firefox 47 - might be a wise decision
Some risk, yes. But many fine, useful add-ons are still not signed.
i find this quite interesting. I'm a user not a dev, in case that wasnt obvious!
i havent yet seen an explanation of why there cannot be an add-on specific override, versus global which is obviously a vulnerability.
Are there any stats as to the % of users with add-ins that have turned signing off?
For something as major as this should there not have been an organised program to educate users?
it is beyond ironic that the main reason I have had to turn this off is my internet Security suite!
Thanks for the advice on how to roll back the update. I guess im actually not sure which is better, roll back to 42 or stay on 43 with add-on signing turned off