Live data from Hacker News

Firefox 42 will not allow unsigned extensions

wiki.mozilla.org

271–280 of 315 posts

Re: Firefox 42 will not allow unsigned extensions

#271

Earlier quoted context omitted.

You're being pretty grim. Hello is fucking awesome, and while I don't use Pocket it isn't the end of the world. Firefox isn't Lynx, but even as a Unix guy I enjoy and appreciate it. I also appreciate that they're trying to be more attractive to the masses, which is societally beneficial.

As you do, I have a lot of programs and extensions installed on my machine. How about you install them all on yours? Come on! Don't be grim! They are fucking awesome and if you don't use them it's not like it is the end of the world :^)

It's funny, one of the other top comments here is about how many features Firefox is removing. Vital, core stuff, like setting being able to set custom user agents for specific domains...

I think the real reason many people are angry is that their demographic isn't catered to. I'm part of that demographic, and it does annoy me sometimes. However, unlike Debian/systemd, I find the tradeoff definitely worthwhile.

Re: Firefox 42 will not allow unsigned extensions

#272
post #218

Earlier quoted context omitted.

You can sign the addons and distribute it on other channels. If you want to have it on AMO then it takes a while to review. The process is done by volunteers

This is one of the things which is frustrating about Mozilla. I love that they stand for open protocols, free software and user privacy, but I don't love what they prioritize. Reviewing extensions is critical to their user-experience. If this really doesn't have an team of paid staffers, that's unfortunate.

It has paid staff and volunteers. More volunteers than paid staff IIRC. Reviewing stuff correctly takes time :-( sorry.

This can be mitigated by having more volunteers (or paid staff (or both)) to help though.

Re: Firefox 42 will not allow unsigned extensions

#275
post #154

I hope Firefox 41 is really good because it's the last one I'll be using.

What do you consider the better alternative? (serious question)

I think at this moment it's fair to say that switching to Pale Moon is the next obvious step for power-users in need of fiddling with their browser as they please.

Re: Firefox 42 will not allow unsigned extensions

#276
post #30

This is deeply disappointing. Two details: the extensions need to be signed by Mozilla , and only US English speakers will be allowed to disable this requirement. The point of free software is that users, individually and collectively, are free to modify it as they wish, without requiring approval from third parties. (And of course to use, copy, and redistribute.) This is a sharp turn away from the free-software etho…

> The point of free software is that users, individually and collectively, are free to modify it as they wish, without requiring approval from third parties. You've been on HN for over six and a half years. Surely you can't be this jaded or obtuse? That freedom is absolutely, unequivocally preserved: The entire source to Firefox is available under OSI-approved libre licenses. APIs change, but the freedom of the softw…

I'm not jaded, and as to whether I'm obtuse, I have to let the other commenters judge.

I agree that, yes, in theory, you legally have that freedom. But if Mozilla thought users were practically able to exercise that freedom, there would be no way for them to impose a change like this; all the users would switch to a fork. In practice, maintaining a fork of a major active software project is a huge amount of work and easily to do poorly (think of the Debian OpenSSL hole), and nearly all the people qualified to do it work at Mozilla or are burned out. And Mozilla, if they want to make it harder to maintain a fork, has a wide variety of strategies at their disposal.

(In case it matters, I'm typing this comment in Iceweasel!)

As a side note, it seems to me rather in poor taste to attack my intelligence in the first line of your comment, and suggests that you think your arguments won't stand on their own merits.

Re: Firefox 42 will not allow unsigned extensions

#277
post #228

Earlier quoted context omitted.

Because there is no such a thing like “English, the lingua franca”; changing the name do not change the content. We should stop self-deluding ourselves in believing that English exits in a geopolitical void. English is the language of the anglosphere, and speaking English is a huge favor to those economies, and that comes with a sense of cultural inferiority as well, in many peoples.

There is a such thing as "English, the lingua franca" no matter how much one tries to will it away. Aviation is a curious industry. English is commonly spoke between flight crews and ground stations world wide (with few but notable exceptions). Circumstances where the English meaning of a word wasn't well understood by the flight crew or the wrong words were spoken have, on occasion, lead to disaster--Avianca Flight…

It sounds like you're saying that using English as the lingua franca of aviation puts at risk the lives of flight crews for whom English is not a native language, as well as their passengers. This seems like a good example of how English-as-lingua-franca gives special worldwide advantages to native English speakers.

Re: Firefox 42 will not allow unsigned extensions

#278

Earlier quoted context omitted.

> There are FOUR VERSIONS OF FIREFOX WITH A SWITCH TO DISABLE THIS While that may be true, requiring that you run a non-standard version of Firefox to be able to use "random" extensions will probably have a chilling effect on the Firefox extension ecosystem. That, and it reeks of Chromeism.

you will be able to run "random" extension if the developer care enough about it and about the new security procedures to sign it. After all, it takes only couple seconds for the signing to work. The versions I quoted are not non-standard. They are all versions of Firefox being worked on and with all the relevant teams. All those versions eventually become Firefox Stable and after that becomes outdated and a new rele…

They are non-standard in the sense that 99% of Firefox users are not using them.

Re: Firefox 42 will not allow unsigned extensions

#279
post #241

Earlier quoted context omitted.

Hi, Mozilla developer here, speaking for only myself. I'm not sure why we don't make this clearer on the wiki page, but I think the reason there's no override is that any malware installation routine would simply activate it and continue on its merry way. (Disclaimer: I didn't work on this feature and am going by recollection and my own logic.) We see many copies of Firefox infested with rogue add-ons the user didn't…

> We see many copies of Firefox infested with rogue add-ons the user didn't ask for or isn't even aware of. GoogleUpdate? why Firefox could not remove these extension itself? I needed to remove some files from the harddisk --I doubt john.doe will be able to remove such evils Please excuse the rant tone, these things make me feel my intimacy raped

Mozilla does this from time to time for really egregious cases [1]. There is a high cost to staging the block. If the author is known there is a delay to try to get the author to ship a fix [2]. If it is unknown then the block can proceed rather quickly but the cost of changing the extension to avoid the block is usually cheap [3].

[1] https://addons.mozilla.org/en-US/firefox/blocked/ [2] https://bugzilla.mozilla.org/show_bug.cgi?id=527135 [3] https://bugzilla.mozilla.org/show_bug.cgi?id=937405

You can still use Dev Edition or Nightly with an about:config pref set.

Re: Firefox 42 will not allow unsigned extensions

#280
post #276

Earlier quoted context omitted.

> The point of free software is that users, individually and collectively, are free to modify it as they wish, without requiring approval from third parties. You've been on HN for over six and a half years. Surely you can't be this jaded or obtuse? That freedom is absolutely, unequivocally preserved: The entire source to Firefox is available under OSI-approved libre licenses. APIs change, but the freedom of the softw…

I'm not jaded, and as to whether I'm obtuse, I have to let the other commenters judge. I agree that, yes, in theory , you legally have that freedom. But if Mozilla thought users were practically able to exercise that freedom, there would be no way for them to impose a change like this; all the users would switch to a fork. In practice, maintaining a fork of a major active software project is a huge amount of work and…

I apologize for the disparagement; I was miffed at your statement that "only US English speakers will be allowed to disable this requirement," which completely misrepresents the situation, followed by doubt about Firefox's status as F/OSS. Instead of ascribing that to malice, I should have assumed good intent and that the communications from our end were unclear.

As to the English issue, we have absolutely no intent to restrict the signature opt-out to English speakers.

Much like with our Nightly builds, the unbranded copies of Firefox will only be pre-compiled with en-US strings. Additional locales can be added at any time through https://addons.mozilla.org/firefox/language-tools/.

For users that want to disable verification without installing a language pack, the Developer Edition and ESR builds will always allow for opting out and will continue to be released will a full complement of pre-compiled locales.

As a Debian user, I'd like to draw a parallel between these measures and the default requirement for GPG signatures on packages installed by apt, which has been the case since version 0.6 in 2003. These signatures are tools to ensure integrity and provenance, not to restrict your freedoms. Much like with the secure apt initiative, it's entirely possible for users to opt out of these protections after jumping through minimally invasive hoops.

Post reply on HN