Pin *.firefox.com to mozilla services whitelisted roots in Firefox
Categories
(Cloud Services :: Security, enhancement)
Tracking
(firefox64 fixed)
| Tracking | Status | |
|---|---|---|
| firefox64 | --- | fixed |
People
(Reporter: jvehent, Assigned: ajvb)
References
(Depends on 1 open bug)
Details
(Whiteboard: [secops:2021])
Attachments
(2 files)
| Reporter | ||
Updated•7 years ago
|
Comment 1•7 years ago
|
||
| Reporter | ||
Comment 2•7 years ago
|
||
| Reporter | ||
Comment 3•7 years ago
|
||
Comment 4•7 years ago
|
||
Comment 5•7 years ago
|
||
Comment 6•7 years ago
|
||
| Reporter | ||
Comment 7•7 years ago
|
||
| Reporter | ||
Comment 8•7 years ago
|
||
Comment 9•7 years ago
|
||
Comment 10•7 years ago
|
||
| Reporter | ||
Comment 11•7 years ago
|
||
Comment 12•7 years ago
|
||
Comment 13•7 years ago
|
||
Updated•7 years ago
|
Comment 14•7 years ago
|
||
| bugherder | ||
| Reporter | ||
Comment 15•7 years ago
|
||
Comment 16•7 years ago
|
||
| Reporter | ||
Comment 18•7 years ago
|
||
| Reporter | ||
Comment 19•7 years ago
|
||
Comment 20•7 years ago
|
||
| Reporter | ||
Comment 21•7 years ago
|
||
| Reporter | ||
Comment 22•7 years ago
|
||
According to [1], the probe is pre-release only, so we're not getting any telemetry for the release channel. Dana, is this something you'd like to change?
Meanwhile, looking at the last 30 days for nightly 66 and dev edition 65, I count:
- 18,756 (6 + 18,750) entries in bucket 30 (failures)
- 749,480 (215,400 + 534,080) entries in bucket 31 (successes)
That's a failure rate of 2.5%, concentrated on dev edition 65 on windows 10. The data there is actually worse, with 18,750 failures and 338,770 successes, or a failure rate of 5.5%. This is too high up to enable enforcement, and we need more data to figure out what is happening here.
Comment 23•7 years ago
|
||
(In reply to Julien Vehent [:ulfr] from comment #22)
According to [1], the probe is pre-release only, so we're not getting any telemetry for the release channel. Dana, is this something you'd like to change?
Yeah, that might be a good idea.
Meanwhile, looking at the last 30 days for nightly 66 and dev edition 65, I count:
- 18,756 (6 + 18,750) entries in bucket 30 (failures)
- 749,480 (215,400 + 534,080) entries in bucket 31 (successes)
That's a failure rate of 2.5%, concentrated on dev edition 65 on windows 10. The data there is actually worse, with 18,750 failures and 338,770 successes, or a failure rate of 5.5%. This is too high up to enable enforcement, and we need more data to figure out what is happening here.
That seems quite high. Some ideas:
- it could be that a significant portion of those users have changed their pinning settings from "allow mitm" (the default) to "strict" (particularly since these are pre-release/dev users) (maybe we should only gather telemetry if the pref is set to the default?) (these users would also have to be behind some intercepting device/software)
- small measurements/populations could be throwing this off. In beta 65, I'm seeing 13K failures vs. 1.4M successes (which I guess is still about 1%, and is higher than the other test sites we're measuring for)
- maybe we have some forgotten
foo.firefox.comdomain that doesn't use the right CA - maybe someone is intercepting traffic to
firefox.comwith a cert from a publicly-trusted CA (I think this is unlikely)
| Reporter | ||
Comment 24•7 years ago
|
||
I'm also concerned about the small size of the sample. Enabling the probe in release seems important before we can take this any further. Should that be a separate bug?
| Reporter | ||
Updated•7 years ago
|
| Assignee | ||
Updated•5 years ago
|
| Assignee | ||
Updated•4 years ago
|
Description
•