Changes between Initial Version and Version 1 of Ticket #20146, comment 6


Ignore:
Timestamp:
Sep 16, 2016, 10:43:34 PM (3 years ago)
Author:
flyryan
Comment:

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #20146, comment 6

    initial v1  
    1 Hey guys. Just wanted to throw Mozilla's statement in here. They are enabling HPKP to addons.mozilla.org which will inherently fix the problem. They could do this right now and fix all of Firefox but I don't know if that's their plan or if they are waiting until Tuesday.
     1Hey everyone. Just wanted to throw Mozilla's statement in here. They are enabling HPKP to addons.mozilla.org which will inherently fix the problem. They could do this right now and fix all of Firefox but I don't know if that's their plan or if they are waiting until Tuesday.
    22
    33> We investigated this and a fix will be issued in the next Firefox release on Tuesday, September 20. We had fixed an issue with the broken automation on the Developer Edition on September 4, but a certificate pinning had expired for users of our Release and Extended Support Release versions. We will be turning on HPKP on the addons.mozilla.org server itself so that users will remain protected once they have visited the site even if the built-in pins expire. We will be changing our internal processes so built-in certificate pins do not expire prematurely in future releases.