Mozilla reinstates support for SHA-1 certificates temporarily after some Firefox users experienced problems accessing HTTPS sites
Firefox ban on SHA-1 dropped after many locked out of HTTPS sites — Mozilla reinstates support for the vulnerable SHA-1 crypto on a temporary basis until …
Context & Ripple Effects
Mozilla's rollback is the predicted cost of the SHA-1 sunset arriving on schedule. Weeks earlier, Facebook warned that the SHA-1 sunset would block millions from the encrypted web, and ZDNet's October reporting flagged that the SHA-2 transition would lock out tens of millions of older-browser and device users. Firefox enforced the deadline anyway — and enough real users hit broken HTTPS access that Mozilla blinked, restoring SHA-1 support as a temporary valve.
First-order effects
- Firefox users stranded by the ban regain access to HTTPS sites still serving SHA-1 certificates, while site operators who missed the migration deadline get an unplanned grace period instead of emergency reissuance.
Second-order effects
- Certificate authorities now face two conflicting pressures at once — browsers demanding fast SHA-2 migration but punishing them when deprecation breaks users — and the extended SHA-1 window creates exactly the kind of loose oversight that surfaced months later when Mozilla accused WoSign of back-dating SHA-1 certificates to dodge the cutoff.
Third-order effects
- The episode cements browsers, not certificate authorities, as the enforcing layer of web PKI: deadlines are set unilaterally, then patched with temporary exemptions when they break too many users — a pattern that recurs in later coordination like the 398-day certificate-lifespan cap Apple introduced and Chrome and Firefox copied.
The trend: Web encryption standards are converging on browser-enforced deprecation timelines with rollback valves, trading cryptographic hygiene for continuity of access whenever legacy devices are caught mid-migration.