I have walked in the spirit world. I have opened my third nostril. I have boosted my own toots.

  • 0 Posts
  • 10 Comments
Joined 1 year ago
cake
Cake day: November 3rd, 2023

help-circle


  • Telemetry can be turned off without modifying the code. I don’t know about the legality of it, maybe in the case of Firefox the other things they do are also at most build options rather than code changes. But generally distros are allowed to make changes to the packages they distribute, that is how free software works.




  • That would depend on the parameters of “possible” but it has no bearing on the topic at hand. It seems likely that you ask due to mistaking the idea of not requiring everything to be periodically re-signed by Mozilla in order to keep running for the unrelated idea of not checking the signature at all.

    P.S. Okay that may be slightly wrong but I mean it’s not as if two-years-old keys are automatically compromised just because they’re that old. If there’s reason to believe they’re at risk, let them be revoked for cause.



  • Signing certs should be expected to expire. Already-installed browser extensions signed by them should not, when the user doesn’t want them to.

    Doing it the right way would prevent, for one thing, any possible repeat of the problem they had a couple years ago when they simply forgot to renew the cert and one day everyone’s browsers unexpectedly stopped working with no way to fix them short of making a new build. The debate was had then, you can go back and read what was said. A thorough review was promised. Presumably Mozilla came came to the wrong conclusion and decided it would be best not to publicise it much.