Turns out an unrelated 3rd party can suddenly remotely disable Tor anonymity protections at their whim, and possibly endanger TBB users (or deliberately help in deanonymizing them).
remotely disable Tor anonymity protections [!]
Maybe a 'certificate is expiring soon' warning on the browser side?
Users would know and Mozilla would be forced to keep certs valid.