pwshub.com

Mozilla advises Firefox users to update if they want their browser add-ons to keep working

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

In context: Root certificates are an essential element for modern browser security. They protect users by verifying signed web pages, extensions, and other types of content. However, developers must update root certificates constantly; otherwise, the root of the trust chain breaks, and everything goes down the drain.

Mozilla is reminding Firefox users that a necessary root certificate expires soon and that older browser versions could become a security and usability nightmare in a few months. Starting March 14, 2025, Firefox versions older than 128 (ESR 115.13) containing the expired certificate will likely cause "significant" issues with add-ons, content signing, and streaming of DRM-protected media.

Failing to update Firefox before next March means losing features relying on remote functionality. Many installed add-ons will become disabled, and other systems that require content verification could also break. The issue affects Firefox editions for Android and Windows operating systems, including Windows, macOS, and Linux. Those with iPhone or iPad versions of Firefox should be okay.

Mozilla's FAQs explain that a root certificate authenticates browser content as trusted. When a certificate expires, Firefox cannot verify content anymore. The newest versions of Firefox and other Mozilla software using the same root-of-trust model include a new root certificate that will prevent the expiration issue in March 2025.

Mozilla is likely trying to prevent the chaos experienced by Firefox users in 2019 when an expired certificate suddenly borked many instances of the open-source browser. Today's Firefox market share is much lower than five years ago, but we're still talking about millions of users potentially becoming vulnerable to the expiration issue.

Some add-on developers have expressed concern over how Mozilla is managing the problem. One developer said Firefox should clearly state what could happen on all the affected platforms. Otherwise, disgruntled users could direct their complaints directly to add-on programmers. One-star review bombing campaigns after the certificate expires could also be part of the deal.

Mozilla advises users to update to Firefox 128 on each device with the browser installed, which is the best practice to avoid this and other issues. The latest release always provides significant performance improvements and important security fixes. Mozilla released Firefox 128 and ESR 115.13 on July 9, 2024, so there have been minor incremental updates since then. The most current version is Firefox 131.0.3.

Source: techspot.com

Related stories
1 week ago - And why the backlash to Meta AI, LinkedIn and PayPal’s new advertising business is a healthy thing.
1 month ago - According to the official Firefox release calendar, the extended support release version of the Firefox web browser will continue to receive updates through at least March 4, 2025. Firefox 115 ESR was originally expected to end support...
1 month ago - Tracking alternative is less invasive than other methods, but is opt out by default Privacy activist group noyb has filed a complaint against Mozilla over a "Privacy Preserving Attribution" feature that was quietly enabled in the Firefox...
1 week ago - Firefixed: It's maintenance time for low-complexity, high-impact security flaw It's patch time for Firefox fans as Mozilla issues a security advisory for a critical code execution vulnerability in the browser.…
1 week ago - Firefox 131.0.2 includes a security fix for a vulnerability actively exploited in the wild, where attackers can achieve code execution by exploiting a use-after-free flaw in animation timelines.Read Entire Article
Other stories
23 minutes ago - For the first time in decades, the Federal Aviation Administration recognized a new category of aircraft, an electric vehicle that can take off and land vertically.
47 minutes ago - Everybody needs more widgets in their life, right? Vivaldi has updated its eponymous browser – it now has a refreshed user interface and a dashboard packed with widgets.…
58 minutes ago - Week 8 of the NFL season kicks off tonight in Los Angeles with the Rams hosting the Minnesota Vikings.
58 minutes ago - The sooner you open a high-yield savings account, the more interest you stand to earn.
58 minutes ago - It's a confusing time to start repaying your student loans. Here's what you need to know.