Live data from Hacker News

Mozilla Firefox Add-On Signing Update

blog.mozilla.org

1–10 of 68 posts

Re: Mozilla Firefox Add-On Signing Update

#2
Can somebody please explain to me the purpose of this change. I read the blog post explaining the decision[0]. The crux of the argument was

>many tens of millions of users have non-hosted add-ons that were installed without their informed consent"

Why go thermonuclear and require add-on signing for everyone? Why not just make the add-on installation screen a little bit scarier. And if the concern is to make sure that people are installing what they think they're installing (i.e not something served by a man in the middle), then maybe just require that add-ons be downloaded from a site with HTTPS.

I just really don't see the point in this extreme choice.

[0] https://blog.mozilla.org/addons/2015/04/15/the-case-for-exte...

Re: Mozilla Firefox Add-On Signing Update

#3
post #2

Can somebody please explain to me the purpose of this change. I read the blog post explaining the decision[0]. The crux of the argument was >many tens of millions of users have non-hosted add-ons that were installed without their informed consent" Why go thermonuclear and require add-on signing for everyone? Why not just make the add-on installation screen a little bit scarier. And if the concern is to make sure that…

people become 'blind' to scary screens. see: windows UAC dialogs.

i wish they would clearly indicate what problem it is that they're solving.

---

edit: after reading the post you linked, it's clear they're fighting against software installers that 'conveniently' install firefox addons.

for example you download skype, and it 'helpfully' installs an addon for firefox.

---

their solutions might solve the problem, but I think it goes too far.

Is it possible to require the user to approve and addons before they are active on the user's firefox install? even if they came from a 3rd party source?

Re: Mozilla Firefox Add-On Signing Update

#4
TLDR: People complained so we're back-pedaling.

There are good technical reasons for requiring signed add-ons. Well, maybe not so much "good" but necessary because of other bad things in Firefox that prevent a less extreme requirement from being implemented.

But the signing requirement isn't what upsets anyone. It's that add-ons must be signed _only by Mozilla_. The whole mess could have been avoided from the start by saying that add-ons must be signed by a trusted certificate but the end-user gets to choose what certificates are trusted.

Re: Mozilla Firefox Add-On Signing Update

#5

TLDR: People complained so we're back-pedaling. There are good technical reasons for requiring signed add-ons. Well, maybe not so much "good" but necessary because of other bad things in Firefox that prevent a less extreme requirement from being implemented. But the signing requirement isn't what upsets anyone. It's that add-ons must be signed _only by Mozilla_. The whole mess could have been avoided from the start b…

I don't think that would work very well. After all, the list of certificates would have to be a preference, so crapware could just stick its own certificate into the preferences file before installing its addon. Of course, baking the requirement into the binary isn't perfect either, since the crapware can just patch or replace it if it has sufficient access rights, but I'd say it 'feels' drastic in a way changing preferences doesn't (which matters if the crapware is trying to be semi-legitimate), and it requires somewhat more work to come up with a suitable binary and keep it up to date.

Re: Mozilla Firefox Add-On Signing Update

#6
post #2

Can somebody please explain to me the purpose of this change. I read the blog post explaining the decision[0]. The crux of the argument was >many tens of millions of users have non-hosted add-ons that were installed without their informed consent" Why go thermonuclear and require add-on signing for everyone? Why not just make the add-on installation screen a little bit scarier. And if the concern is to make sure that…

because they're being installed OUT of the browser. It's not about being scarier. It's about drawing a line in the ground and saying "fuck you, we're not loading you into memory without a guarantee that you are legit and the user added you intentionally."

Re: Mozilla Firefox Add-On Signing Update

#7
post #2

Can somebody please explain to me the purpose of this change. I read the blog post explaining the decision[0]. The crux of the argument was >many tens of millions of users have non-hosted add-ons that were installed without their informed consent" Why go thermonuclear and require add-on signing for everyone? Why not just make the add-on installation screen a little bit scarier. And if the concern is to make sure that…

people become 'blind' to scary screens. see: windows UAC dialogs. i wish they would clearly indicate what problem it is that they're solving. --- edit: after reading the post you linked, it's clear they're fighting against software installers that 'conveniently' install firefox addons. for example you download skype, and it 'helpfully' installs an addon for firefox. --- their solutions might solve the problem, but I…

Android does it best - you can install non-play-store stuff, but you have to go into a scary menu and fiddle with settings. Better than an are you sure popup.

Re: Mozilla Firefox Add-On Signing Update

#8

TLDR: People complained so we're back-pedaling. There are good technical reasons for requiring signed add-ons. Well, maybe not so much "good" but necessary because of other bad things in Firefox that prevent a less extreme requirement from being implemented. But the signing requirement isn't what upsets anyone. It's that add-ons must be signed _only by Mozilla_. The whole mess could have been avoided from the start b…

> good technical reasons

For forcing signed add-ons? Maybe. Mayyybe.

For removing the ability to opt-out of this requirement via the preference? What's the good technical reason?

Re: Mozilla Firefox Add-On Signing Update

#10
post #9

I honest-to-goodness don't understand. Why not just let the preference remain forever?

For the same reason Facebook puts a big loud warning in the developer console. People will follow any instructions they're given. "Press ctrl+shift+I and paste this in the box and you'll get a free puppy" "Put this in your address bar and your crush will be revealed" "Go to about:config and double click this thing, and then click this link and we'll show you nearby singles that want to hook up"

Firefox add-ons essentially have full, unrestricted access to your computer. Locking this down good and well is pretty important.

Post reply on HN