ThreatLocker

Firefox 66.0.4 Released With Fix for Disabled Addons

  • May 5, 2019
  • 12:36 PM
  • 18

Firefox 66.0.4

Update: Mozilla has released version 66.0.4, which includes the fix for the expired certificate and disabled addons. You can use the automatic update feature of Firefox or download it here. This article has been updated to reflect this.

Mozilla Firefox 66.0.4 has been released to the Stable channel and contains a fix for the expired intermediate signing certificate that caused everyone's addons to be disabled on Friday.

On Friday, Mozilla allowed an intermediate certificate to expire that is used to sign Firefox addons. As Firefox requires addons to be signed by a valid certificate, once the certificate expired, users suddenly found all of their Firefox addons disabled.

image

As a temporary fix, Mozilla issued an extension through their Normandy Study system that installed a new intermediate signing certificate. Once the hotfix was installed, addons would automatically be enabled again.

In order to use this system you need to enable the Study system. Doing so, though, provides telemetry back to Mozilla regarding how you use Firefox and some consider this a privacy risk.

Studies Enabled

Even with the studies enabled, some users, including myself, report not receiving the hotfix.

Version 66.0.4 fixes expired certificate without studies

Mozilla has now released Firefox 66.0.4, which includes a new intermediate signing certificate that is not expired and will force signature reverification.

Three release candidates of Firefox 66.0.4 were created over the past 2 days to fix this bug, with the first one being pulled as it did not properly resolve the addon problems.  The third release candidate was the last candidate build before Mozilla released it to the public.

Firefox 66.0.4 Release Candidate 3
Firefox 66.0.4 Release Candidate 3

Mozilla has updated their release notes for 66.0.4 to contain the following fix as part of the list of changes.

Repaired certificate chain to re-enable web extensions that had been disabled
Release Notes
Prepped Firefox 66.0.4 Release Notes

Users should expect to see Mozilla Firefox 66.0.4 being pushed through autoupdate as we speak.

Original story H/T Techdows.com

article image

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper
Lawrence Abrams
Lawrence Abrams is the owner and Editor in Chief of BleepingComputer.com. Lawrence's area of expertise includes Windows, malware removal, and computer forensics. Lawrence Abrams is a co-author of the Winternals Defragmentation, Recovery, and Administration Field Guide and the technical editor for Rootkits for Dummies.

Comments

  • ddeerrff Photo
    ddeerrff - 7 years ago

    ...and what about those of us using older releases of FF?

  • Bullwinkle-J-Moose Photo
    Bullwinkle-J-Moose - 7 years ago

    and what (if any) is the potential for spreading malware from the lack of ad blockers or script blockers or....

    other blockers, especially on older versions?

    and...
    Can you list examples or predict how bad it "could" be on a scale of 1 - 10
    1 = As safe as you'll ever be
    10 = This is the end.....Run for the hills!

  • TanyaC Photo
    TanyaC - 7 years ago

    "...and what about those of us using older releases of FF?"

    Or on ESR releases?

  • buddy215 Photo
    buddy215 - 7 years ago

    QUOTE: In order to use this system you need to enable the Study system. Doing so, though, provides telemetry back to Mozilla regarding how you use Firefox and some consider this a privacy risk. END QUOTE
    Just to remind....you can disable Study after your extensions reappear. That is what I did earlier this morning. I'm one of those who think the less telemetry is sent from my computer and the less programs, browsers, etc. call home the better.

  • xmris Photo
    xmris - 7 years ago

    mozilla crackheads

  • Zitch Photo
    Zitch - 7 years ago

    Mozilla RULES Chrome won't let you go into ABOUT:CONFIG and make about 20 changes like I did.....Linux sucks, command line BS, Apple is vulnerable, Windows 10 Pro is THE BEST operating system, and Mozilla is simply the best browser. So many people using Google don't have a clue......

  • Zitch Photo
    Zitch - 7 years ago

    You can UNCHECK "Firefox Data collection and use" as I am sure a lot of you already have.Directly above that you will see"Permissions". The LAST option (which is UNCHECKED by default says: "Prevent accessibility services from accessing your browser" Leave that UNCHECKED while you download your favorite addons, Then put a checkmark on it to prevent accessibility. Forget all of this "Studies" stuff. I don't think it's needed. Older versions of FF I don't know, maybe you want to try updating, unless you are using some other system than Windows.

  • Zitch Photo
    Zitch - 7 years ago

    It works been doing it this way for over a year.

  • forum11 Photo
    forum11 - 7 years ago

    What about FF for Android? I don't currently see an update for it.

  • RosyBear Photo
    RosyBear - 7 years ago

    That version was published also for Android stable version. Downloaded as soon as I read the news, and everything is working as expected now.
    Take a look on Play Store.

  • Zitch Photo
    Zitch - 7 years ago

    I am not one who does everything on my phone. If you read some other sites and forums you will see how the bad guys are targeting shoppers and bill payers who do all their transactions on a cell phone. This WILL leave you vulnerable to hacks. Get off of the phone, set up a hardened version of Windows and a hardened version of Mozilla for all of your online purchases and bill pay. I have been doing this for a long time. Years ago. the bad guys went after desktop users.(They still do) NOW, however, they are going after cell phones. cause they know people are addicted to them. You are much safer shopping and bill paying if you set up a hardened desktop and ONLY use it for buy and pay purposes.Windows 10 incorporates the remnants of Microsoft EMET, and their antivirus is much much better now. It is as good as a paid app. Spend a little time looking around, the info is out there.....Zitch

  • Zitch Photo
    Zitch - 7 years ago

    AND....ALWAYS (This is MEGA important) Run your Windows on a STANDARD user account. Never web surf as an administrator. Easy to change log into Control Panel. This is the single most important thing to do in Windows. I am offering this advice for those who read this site, who may not be an advanced user. You can thank me later....Zitch

  • Bullwinkle-J-Moose Photo
    Bullwinkle-J-Moose - 7 years ago

    I run Window XP-SP2 without ANY MS security updates on an ADMIN account "ONLINE"

    Never had a problem and never will...

    You see, Windows security professionals see what the real problem is and you don't!

  • Zitch Photo
    Zitch - 7 years ago

    Dude....you know better.....right?.....I have a spotless Dell laptop/Windows 7 Pro.....It sits on a shelf. Don't use it. Get on a website like Amazon, or Ebay, (I really like Ebay), get you a good Dell or Lenovo laptop running Windows 10 Pro. 200 bucks will get you a good one.I cannot fathom why there are people who stick with XP/Vista/7/8 you are just asking for trouble...

  • Bullwinkle-J-Moose Photo
    Bullwinkle-J-Moose - 7 years ago

    Relax, it's perfectly safe!

    I never use it for passwords or sensitive information, it's more of a research tool for malware study

    It is a Read Only, write protected install of XP (using Driveshield) so any malware is wiped as soon as I reboot

    Java scripts, Net Framework, Adobe Reader, Flash and all other major security problems have been eliminated

    Everything, including All Microsoft components are blocked from Internet access except for the browser and many other security tweaks were used

    It has never been successfully hit with any persistent threat in the past 5 years and has not had a Blue screen of Death in more than 10 years

    I was using it online during the wannacry outbreak and it has never been successfully hit with extortionware of any type

    The system is a separate drive and no other drives are ever connected while online

    If anyone can successfully wreck my XP box, I will be VERY impressed!

    No worries here!

    ADMIN ACCOUNTS RULE!

  • Zitch Photo
    Zitch - 7 years ago

    IMPRESSIVE.....lol....good job. My very first PC was a Windows XP, that dam thing used to blue screen often, of course, back in those days, that was par for the course.I started studying WHY this happened, learned a lot. Have been a regular reader on this site, Wilders, Security Week, etc. I agree that you can isolate an XP box so as to be invulnerable to hacks, exploits, etc. BUT, you can ALSO set up a 10 pro with minimal telemetry, a bullet proof browser, (AKA Mozilla/with DNS over HTTPs, other settings in ABOUT:CONFIG (referrer header, media peer connections, web gl, punycode, to name a few- I use about 20 different adjustments), then you can alter adapter option for internet connectivety, Like secure dns servers, this gives you the advantage of exploit updates from Windows, and if you feel the need you can install a proxy or VPN. Now, I'm gonna say that doing this gives you a system that is just as safe, and not more risky than Linux, Apple, or Android.....care to disagree? I know from reading your reply where you mentioned Shadow Defender that you are no way a novice. Beginners have never heard of Shadow Defender, or Virtual machines, etc.Hey- thanks for the talk, HAVE A GREAT DAY ! .......Zitch

  • Zitch Photo
    Zitch - 7 years ago

    PS....I also toggle Javascript, and I have removed Flash from all of the machines I work on.I don't have a need at this time for virtual machines, but can if I decide to.

  • NickAu Photo
    NickAu - 7 years ago

    Seems Ubuntu kept Firefox at 66.0.3. I just ran sudo apt-get update && sudo apt-get upgrade all my plug ins work.
    https://www.bleepstatic.com/fhost/uploads/6/183-workspace-1_009.png

Post a Comment Community Rules
You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

Login

Reporter

Help us understand the problem. What is going on with this comment?

Read our posting guidelinese to learn what content is prohibited.

SUBMIT