
Update: Mozilla has released version 66.0.4, which includes the fix for the expired certificate and disabled addons. You can use the automatic update feature of Firefox or download it here. This article has been updated to reflect this.
Mozilla Firefox 66.0.4 has been released to the Stable channel and contains a fix for the expired intermediate signing certificate that caused everyone's addons to be disabled on Friday.
On Friday, Mozilla allowed an intermediate certificate to expire that is used to sign Firefox addons. As Firefox requires addons to be signed by a valid certificate, once the certificate expired, users suddenly found all of their Firefox addons disabled.
As a temporary fix, Mozilla issued an extension through their Normandy Study system that installed a new intermediate signing certificate. Once the hotfix was installed, addons would automatically be enabled again.
In order to use this system you need to enable the Study system. Doing so, though, provides telemetry back to Mozilla regarding how you use Firefox and some consider this a privacy risk.

Even with the studies enabled, some users, including myself, report not receiving the hotfix.
Version 66.0.4 fixes expired certificate without studies
Mozilla has now released Firefox 66.0.4, which includes a new intermediate signing certificate that is not expired and will force signature reverification.
Three release candidates of Firefox 66.0.4 were created over the past 2 days to fix this bug, with the first one being pulled as it did not properly resolve the addon problems. The third release candidate was the last candidate build before Mozilla released it to the public.

Mozilla has updated their release notes for 66.0.4 to contain the following fix as part of the list of changes.
Repaired certificate chain to re-enable web extensions that had been disabled

Users should expect to see Mozilla Firefox 66.0.4 being pushed through autoupdate as we speak.
Original story H/T Techdows.com
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Get the whitepaper



Comments
ddeerrff - 7 years ago
...and what about those of us using older releases of FF?
Bullwinkle-J-Moose - 7 years ago
and what (if any) is the potential for spreading malware from the lack of ad blockers or script blockers or....
other blockers, especially on older versions?
and...
Can you list examples or predict how bad it "could" be on a scale of 1 - 10
1 = As safe as you'll ever be
10 = This is the end.....Run for the hills!
TanyaC - 7 years ago
"...and what about those of us using older releases of FF?"
Or on ESR releases?
buddy215 - 7 years ago
QUOTE: In order to use this system you need to enable the Study system. Doing so, though, provides telemetry back to Mozilla regarding how you use Firefox and some consider this a privacy risk. END QUOTE
Just to remind....you can disable Study after your extensions reappear. That is what I did earlier this morning. I'm one of those who think the less telemetry is sent from my computer and the less programs, browsers, etc. call home the better.
xmris - 7 years ago
mozilla crackheads
Zitch - 7 years ago
Mozilla RULES Chrome won't let you go into ABOUT:CONFIG and make about 20 changes like I did.....Linux sucks, command line BS, Apple is vulnerable, Windows 10 Pro is THE BEST operating system, and Mozilla is simply the best browser. So many people using Google don't have a clue......
Zitch - 7 years ago
You can UNCHECK "Firefox Data collection and use" as I am sure a lot of you already have.Directly above that you will see"Permissions". The LAST option (which is UNCHECKED by default says: "Prevent accessibility services from accessing your browser" Leave that UNCHECKED while you download your favorite addons, Then put a checkmark on it to prevent accessibility. Forget all of this "Studies" stuff. I don't think it's needed. Older versions of FF I don't know, maybe you want to try updating, unless you are using some other system than Windows.
Zitch - 7 years ago
It works been doing it this way for over a year.
forum11 - 7 years ago
What about FF for Android? I don't currently see an update for it.
RosyBear - 7 years ago
That version was published also for Android stable version. Downloaded as soon as I read the news, and everything is working as expected now.
Take a look on Play Store.
Zitch - 7 years ago
I am not one who does everything on my phone. If you read some other sites and forums you will see how the bad guys are targeting shoppers and bill payers who do all their transactions on a cell phone. This WILL leave you vulnerable to hacks. Get off of the phone, set up a hardened version of Windows and a hardened version of Mozilla for all of your online purchases and bill pay. I have been doing this for a long time. Years ago. the bad guys went after desktop users.(They still do) NOW, however, they are going after cell phones. cause they know people are addicted to them. You are much safer shopping and bill paying if you set up a hardened desktop and ONLY use it for buy and pay purposes.Windows 10 incorporates the remnants of Microsoft EMET, and their antivirus is much much better now. It is as good as a paid app. Spend a little time looking around, the info is out there.....Zitch
Zitch - 7 years ago
AND....ALWAYS (This is MEGA important) Run your Windows on a STANDARD user account. Never web surf as an administrator. Easy to change log into Control Panel. This is the single most important thing to do in Windows. I am offering this advice for those who read this site, who may not be an advanced user. You can thank me later....Zitch
Bullwinkle-J-Moose - 7 years ago
I run Window XP-SP2 without ANY MS security updates on an ADMIN account "ONLINE"
Never had a problem and never will...
You see, Windows security professionals see what the real problem is and you don't!
Zitch - 7 years ago
Dude....you know better.....right?.....I have a spotless Dell laptop/Windows 7 Pro.....It sits on a shelf. Don't use it. Get on a website like Amazon, or Ebay, (I really like Ebay), get you a good Dell or Lenovo laptop running Windows 10 Pro. 200 bucks will get you a good one.I cannot fathom why there are people who stick with XP/Vista/7/8 you are just asking for trouble...
Bullwinkle-J-Moose - 7 years ago
Relax, it's perfectly safe!
I never use it for passwords or sensitive information, it's more of a research tool for malware study
It is a Read Only, write protected install of XP (using Driveshield) so any malware is wiped as soon as I reboot
Java scripts, Net Framework, Adobe Reader, Flash and all other major security problems have been eliminated
Everything, including All Microsoft components are blocked from Internet access except for the browser and many other security tweaks were used
It has never been successfully hit with any persistent threat in the past 5 years and has not had a Blue screen of Death in more than 10 years
I was using it online during the wannacry outbreak and it has never been successfully hit with extortionware of any type
The system is a separate drive and no other drives are ever connected while online
If anyone can successfully wreck my XP box, I will be VERY impressed!
No worries here!
ADMIN ACCOUNTS RULE!
Zitch - 7 years ago
IMPRESSIVE.....lol....good job. My very first PC was a Windows XP, that dam thing used to blue screen often, of course, back in those days, that was par for the course.I started studying WHY this happened, learned a lot. Have been a regular reader on this site, Wilders, Security Week, etc. I agree that you can isolate an XP box so as to be invulnerable to hacks, exploits, etc. BUT, you can ALSO set up a 10 pro with minimal telemetry, a bullet proof browser, (AKA Mozilla/with DNS over HTTPs, other settings in ABOUT:CONFIG (referrer header, media peer connections, web gl, punycode, to name a few- I use about 20 different adjustments), then you can alter adapter option for internet connectivety, Like secure dns servers, this gives you the advantage of exploit updates from Windows, and if you feel the need you can install a proxy or VPN. Now, I'm gonna say that doing this gives you a system that is just as safe, and not more risky than Linux, Apple, or Android.....care to disagree? I know from reading your reply where you mentioned Shadow Defender that you are no way a novice. Beginners have never heard of Shadow Defender, or Virtual machines, etc.Hey- thanks for the talk, HAVE A GREAT DAY ! .......Zitch
Zitch - 7 years ago
PS....I also toggle Javascript, and I have removed Flash from all of the machines I work on.I don't have a need at this time for virtual machines, but can if I decide to.
NickAu - 7 years ago
Seems Ubuntu kept Firefox at 66.0.3. I just ran sudo apt-get update && sudo apt-get upgrade all my plug ins work.
https://www.bleepstatic.com/fhost/uploads/6/183-workspace-1_009.png