Live data from Hacker News

Firefox 42 will not allow unsigned extensions

wiki.mozilla.org

161–170 of 315 posts

Re: Firefox 42 will not allow unsigned extensions

#161

Does anyone know if the maintainers of Pale Moon or Waterfox intend to keep the extension signing requirement on their builds?

I very much doubt Pale Moon will, based on their reaction to previous restrictions and removals of features. I know that it would be hypocritical if they did.

Waterfox... I don't know.

Re: Firefox 42 will not allow unsigned extensions

#162
post #143

You know, there was something beautiful about users being able to pick up a tutorial and extend their browsers, if they wanted. There was something very empowering about being able to write extensions even in a corporate environment. I've written Firefox extensions for personal and business use, and Mozilla are preventing that from every happening again. Why? Cui bono? I'll mention, again, that they completely broke…

Didn't Chrome take this same approach? I suspect that if multiple major browser vendors are pursuing it, it's probably to address some issue. It's not like Mozilla just thought, "let's limit people more, that will make them happy." This doesn't make it the right approach, but it does make it understandable.

So I suspect it's to the benefit of the "average user" if that's what you are asking.

I'm going to step outside of HN for a minute and say that in my work I work with people who rely on the Internet, but have no concept, and I mean none, how it works. They do not understand that when they create a Yahoo email account that no one can help them when they forget their password. They do not understand that if you type "yaho com" that you are not going to get anywhere (until auto search came along, that is). I've come to realize that Internet safety is not a simple set of rules, it's a complex understanding of the whole ecosystem that can't be readily taught in the time I have with these users (and never taught to some). I can't explain why I click on links in some emails and not others, so I just say "don't click on links". I can't explain why you shouldn't use the same password everywhere to someone who needs to reset their password literally every time they log on, so I just tell them to use the one their friend or child has written down for them. It's terrible, but I get it when vendors draw a line in the sand and say "this is to protect those users."

That said, as a user who does understand, there's an element of frustration. Hopefully they bury an override option somewhere, or maybe just add it to their ESR but I doubt I would ever use it.

Re: Firefox 42 will not allow unsigned extensions

#163
post #145

Earlier quoted context omitted.

https://wiki.mozilla.org/Electrolysis/Firefox "Goals There are number of things we believe the e10s project will give us: ... 2. Improved performance, especially on multi-core machines. 3. Better memory core stats." That seems to directly contradict your concerns. However, these are stated goals and may not align with practical reality. I'd be surprised if, when these are numbers 2 and 3 on their list of priorities,…

See https://news.ycombinator.com/item?id=9558745 (and actually the rest of that submission also) Now, mind you, that was nearly 3 months ago. But the concerns there are still very relevant.

Those 3 months can make a world of difference. I'd like to see it in action before I decide whether it is a good or a bad thing.

Also, I'd be very surprised if the numbers in this little test are more than anecdotal. Performance will depend heavily on the kind of content you're viewing and I'd wager that the IPC calls make up a very small minority of the runtime profile for a tab process. Also, not everything is so performance-critical. For instance, if response to a mouse click went from 1 to 7 milliseconds, would anybody notice it? If everything in the browser just slowed down by a factor of 2, would Mozilla really ship it?

Re: Firefox 42 will not allow unsigned extensions

#164
post #132

Earlier quoted context omitted.

> I use several small add-ons I wrote myself. Why should I have to get Mozilla's approval before I can install my own damn add-ons? Mozilla has to balance the needs of several hundred million users, who are being attacked by malware every day, with the needs of people who write their own add-ons. Is it really that difficult to see it from that perspective? And it's not like you have no options now. You can either use…

They've always catered to the hacker perspective, too. Why take out the about:config flag? How about letting me trust my own certificate, instead of just AMO's? What about running AMO alternatives?

Did you not read the blog post? You can use the dev edition or the special release and beta version that don't have this limitation. Nobody is forcing you to live with this limitation. If this was done as an about:config flag it could easily be changed by an add-on too.

Re: Firefox 42 will not allow unsigned extensions

#165
Mozilla used to be the best place in the world for extension developers -- it was natural to have your best extension on Firefox because you could release early and often. Active developers made the platform.

When Chrome came along they decided to go in a different direction entirely slowly making it more and more painful to accomplish what used to be easy in the name of security. The review process went from automatic if you were trusted to weeks and then months and then more than a quarter year. They started demanding source code. It became scary to release to addons.mozilla.org because you never knew how long it would be before your next release would be approved.

Mozilla needs to realize they're hastening their own demise - Chrome now offers better features than when Mozilla was the leader including releasing to a percentage of users and faster nearly invisible to the user updates. They should go back to their roots and embrace developers again.

Re: Firefox 42 will not allow unsigned extensions

#166
post #164

Earlier quoted context omitted.

They've always catered to the hacker perspective, too. Why take out the about:config flag? How about letting me trust my own certificate, instead of just AMO's? What about running AMO alternatives?

Did you not read the blog post? You can use the dev edition or the special release and beta version that don't have this limitation. Nobody is forcing you to live with this limitation. If this was done as an about:config flag it could easily be changed by an add-on too.

I did read the blog post. It says I have to use a less stable (beta) or less customizable (dev edition) version of Firefox to avoid this burden.

Re: Firefox 42 will not allow unsigned extensions

#167
post #106

Earlier quoted context omitted.

Mozilla have been doing odd things in recent years, almost like they are transitioning into an authoritarian movement. Want to use unsanctioned extensions? No, go away. Want to use non-secure HTTP? Sure, but we will take away your features. Want to work for them but have unapproved views? Fired. All this is from viewing them as an outsider, so you never know, but something is different.

"Unapproved views"? Would you oppose firing someone for openly expressing white supremacy?

For expressing it while not on the job, no, they should not be fired.

Re: Firefox 42 will not allow unsigned extensions

#168

Isnt chrome already like this? I spent 45 minutes trying to find a way to install a non extension store extension this weekend and gave up after being blocked repeatedly.

It's actually incredibly simple, just rename the .crx to a .zip and load it as an unpacked extension.

https://developer.chrome.com/extensions/getstarted#unpacked

Re: Firefox 42 will not allow unsigned extensions

#170
post #112

Earlier quoted context omitted.

I don't see what would prevent folks from switching to a fork if that happened.

Sure. It will be a fork that falls behind master without funding or support. Get enough momentum and push it far enough and Chromium and Firefox will stop being OSS altogether.

This is indistinguishable from the conspiracy theories people used to circulate about a magic carburetor design which got 85MPG and was killed by Detroit automakers for unknown reasons.

Just look at the chain of unsupported assertions which have to all come true for this to make any sense: Mozilla will prevent you from installing ad-blockers, and that this will bother enough users to matter but somehow that won't lead to enough volunteered developer time to maintain even an almost unmodified “fork” which changes only a build flag (or a signing key)?

Or that somehow if that proved popular enough to attract a large number of users they'd react not by reconsidering such policies but instead push everyone over to Edge/WebKit? Microsoft and Apple are not primarily advertising companies and at least Apple is marketing actively on the idea of respecting your privacy – it's hard to imagine anyone working at a browser vendor not realizing that such a move is simply going to push users to switch.

Post reply on HN