> installing the STUDIES "hotfix" from Mozilla by hand on each one is not > feasible.
Not to mention, this requires that other features of Firefox's 'phone home' framework are turned on, which 'studies' uses. For example, in the GUI, the 'studies' option is under: "Allow Firefox to send technical and interaction data to Mozilla" So to get their current fix? One must submit to privacy violations, and allow Firefox to phone home (even more than it still does). Conspiracy nuts might say, that this entire debacle was designed to get people to turn 'studies' and 'data reporting' on... even if only to get a temporary snapshot of users, before they turn it back off.... But of course, losing 20% of their userbase over a weekend, doesn't seem like a logical reason for the above.. so, probably not. I am hoping that Debian realises the level of severity here, and does issue a fix whenever Mozilla gets around to simply fixing the cert issue.