Live data from Hacker News

Firefox 42 will not allow unsigned extensions

wiki.mozilla.org

221–230 of 315 posts

Re: Firefox 42 will not allow unsigned extensions

#221

Earlier quoted context omitted.

> - Can't run my own version of AMO You can, AMO is open source: https://github.com/mozilla/olympia Run your own instance and make your own builds of Firefox that point to it and you're good.

>make your own builds of Firefox Yeah, let me just get all of the potential users of my AMO alternative to compile a custom version of Firefox for it

If you want to run a custom AMO I'm assuming you're in a corporate environment or something like that where you can control what browser gets installed on people's machines.

https://addons.mozilla.org is an integral part of Firefox, if you set it up with an alternative you're effectively making your own fork.

Re: Firefox 42 will not allow unsigned extensions

#222

Earlier quoted context omitted.

>make your own builds of Firefox Yeah, let me just get all of the potential users of my AMO alternative to compile a custom version of Firefox for it

If you want to run a custom AMO I'm assuming you're in a corporate environment or something like that where you can control what browser gets installed on people's machines. https://addons.mozilla.org is an integral part of Firefox, if you set it up with an alternative you're effectively making your own fork.

It's not an integral part of Firefox, though. You can install add-ons without it by just clicking a link on any page that leads to an XPI, same as how AMO behaves.

And no, I'm not in a corporate environment. I'm talking about decentralization.

Re: Firefox 42 will not allow unsigned extensions

#223
This is going to be an annoying change me since I use the 1Password extension which isn't signed as far as I know. So, it's likely I'll switch over to Chrome (which I've had performance issues with in the past) or Pale Moon. Seriously, it's my browser. It's fine if you want to make users white list extensions but to completely block unsigned extensions is a bit over zealous. Unless Mozilla makes the signing process automatic (since it seems some extensions on addons.mozilla.org can go months before being updated to the current version) I don't see this working out at all.

Re: Firefox 42 will not allow unsigned extensions

#224
post #220

Earlier quoted context omitted.

WTF people. So much hate for Mozilla these days, this appear pitchfork group. Lets review what the article says: addons needed to be signed. The process is automated. It takes only seconds. It prevents some malware from spreading. You can still host your addon wherever you want. This is just an extra step that can actually improve security. It requires more effort by the part of the developer but it also helps preven…

What is the rationale behind removing the configuration switch, though? Is there supposed to be some contingent of users who are not sufficiently tech-savvy to be trusted with choosing their own add-ons, but sufficiently tech-savvy to go and edit something in about:config, which really needs to be protected from their own stupidity? This sort of "mother knows best" approach is something I would expect from Apple, not…

Chrome tried that "configuration switch" before, and what happened was malware would find and flip that switch as one of the first things it did once installed.

Then it would work like it used to (installing bullshit extensions, wrecking the browser overall, and being damn near impossible to remove)

Re: Firefox 42 will not allow unsigned extensions

#225

Mozilla's hypocrisy is astounding: https://blog.mozilla.org/security/2013/01/29/putting-users-i... "Users should have the choice of what software and plugins run on their machine." https://blog.mozilla.org/theden/2014/12/15/introducing-a-sma... "Firefox is dedicated to putting users in control of their online experience" More recently: https://blog.mozilla.org/blog/2015/06/02/firefox-puts-you-in... "Firefox Puts You…

WTF people. So much hate for Mozilla these days, this appear pitchfork group. Lets review what the article says: addons needed to be signed. The process is automated. It takes only seconds. It prevents some malware from spreading. You can still host your addon wherever you want. This is just an extra step that can actually improve security. It requires more effort by the part of the developer but it also helps preven…

Mozilla will certainly continue to sign my piracy-enabling add-on that is perfectly legal in many jurisdictions worldwide, even after an US court ordered them not to sign it explicitly?

I also heard mozilla got an NSL for my "Ed Snowden for president, Find out more on wikileaks" add-on, or rather, I didn't because NSL.

Then again, I hear a brought coalition of human rights, LGBT and feminist groups lobbying mozilla not to sign my "Find nearest public stoning near you - Saudi Arabia Editon" add-on any more, effectively blacklisting it worldwide. But mozilla will keep to their promise not to blacklist my stuff and my regular users can still use my add-on, right? The creator of Javascript and mozilla CEO Brendan Eich will make sure of it... Oh wait...

Speaking of which, what about my "mozilla - not protecting Brendan from harm was shit" add-on, is that compliant with the mozilla trademark policy that I need to abide by per https://developer.mozilla.org/en-US/Add-ons/Add-on_guideline... ?

Yes, those examples are a bit contrived, but actually not that much over the top. Also, please note that I do not necessarily condone these things ;)

My point being: Security through tech-enforce policy is nice and has a lot of upsides as you say, I agree, but it also may have downsides you aren't even aware of.

Re: Firefox 42 will not allow unsigned extensions

#226
post #47

It's little more than a year ago that Brendan Eich was ousted from Mozilla by an ugly orchestrated cabal. When I read Mitchell Baker's vapid blog post [1] on the decision, filled with polite backstabbing and politically correct buzzwordery I understood that Mozilla has been taken over by politicians and that its decline is just a matter of time. [1] https://blog.mozilla.org/blog/2014/04/03/brendan-eich-steps-...

I have been looking at https://input.mozilla.org/ now and then for a long time, and I am still astounded at how it's typically around 90% unhappy, 10% happy. I know that some Mozilla supporters will justify that huge difference by saying, "but unhappy people will always complain and happy people won't say anything", but I don't think that's necessarily the case. Here we have Mozilla's own stats saying that a lot of t…

Input is not an approval rating, not even close. That is what Heartbeat is for.

Mozilla Heartbeat is constantly asking for ratings from a random sample of Firefox users.

The Heartbeat rating for Firefox Desktop is currently about 4.3/5- or 86%.

P.s. Despite the amount of negative feedback in Input, the portion of feedback which is positive is about twice what it was in May.

Re: Firefox 42 will not allow unsigned extensions

#228
post #66

Earlier quoted context omitted.

Wise words, kragen. With the excuse "you need english because" a new form of imperialism is on the making. And what is worse, is that this attitude is often self-imposed.

I think your are mixing “English, the lingua franca”, with “English, the language spoken in the US”. Why would using the lingua franca that everyone agrees on be imperialism?

Because there is no such a thing like “English, the lingua franca”; changing the name do not change the content.

We should stop self-deluding ourselves in believing that English exits in a geopolitical void. English is the language of the anglosphere, and speaking English is a huge favor to those economies, and that comes with a sense of cultural inferiority as well, in many peoples.

Re: Firefox 42 will not allow unsigned extensions

#229
post #11

It's the "no override" part that concerns me. I created and maintain an extension that is used by visually-impaired people around the world (it has been translated by volunteers into Dutch and Chinese, for example). Occasionally a Firefox update breaks this extension. OK, fine, that's the cost of doing business. Of course, the automated compatibility report that Firefox creates is utterly useless; it almost never cat…

Hi, Mozilla developer here, speaking for only myself. I'm not sure why we don't make this clearer on the wiki page, but I think the reason there's no override is that any malware installation routine would simply activate it and continue on its merry way. (Disclaimer: I didn't work on this feature and am going by recollection and my own logic.)

We see many copies of Firefox infested with rogue add-ons the user didn't ask for or isn't even aware of. Sometimes these add-ons even ship with big-name software, with no opt out or with the opt out squirreled away in some dark corner. Typically, they do one or more of the following: (1) spy on the user, (2) add affiliate codes for money, (3) cause performance problems and crashes.

The network is a pretty hostile place these days. It's no longer 14-year-olds playing around for fun; there are moneyed interests in the game. And the sorts of people who don't frequent HN are pretty much helpless and clueless in the perpetual tug of war between various companies and mafias. As a "user agent", we have the opportunity defend users who lack the sophistication to root around and remove invasive software they didn't ask for.

Of course, if you're reading this, you're in a different category. You have a better idea which software to trust, and you know how to scour your machine if something gets past you. That's why nightlies and the Developer Edition let you do whatever you want: you aren't the ones who need hard-coded protections to shield you from pref-twiddling installers.

I hope that provides some needed context. Safe surfing, all!

Re: Firefox 42 will not allow unsigned extensions

#230

Mozilla's hypocrisy is astounding: https://blog.mozilla.org/security/2013/01/29/putting-users-i... "Users should have the choice of what software and plugins run on their machine." https://blog.mozilla.org/theden/2014/12/15/introducing-a-sma... "Firefox is dedicated to putting users in control of their online experience" More recently: https://blog.mozilla.org/blog/2015/06/02/firefox-puts-you-in... "Firefox Puts You…

WTF people. So much hate for Mozilla these days, this appear pitchfork group. Lets review what the article says: addons needed to be signed. The process is automated. It takes only seconds. It prevents some malware from spreading. You can still host your addon wherever you want. This is just an extra step that can actually improve security. It requires more effort by the part of the developer but it also helps preven…

Why is everybody supposed to love the Mozilla Corporation? Just because you do?
Post reply on HN