Live data from Hacker News

Mozilla pulls Bypass Paywalls from Firefox add-ons store

github.com

251–260 of 288 posts

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#251

Earlier quoted context omitted.

How do you do this without leaking your code to mozilla?

"Leaking your code to mozilla"? What do you think they are going to do with it?

Doesn't matter. When developing an internal company tool, it can become a blocker due to policy or legal reasons.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#252

Earlier quoted context omitted.

The idea is to protect users, not hurt them in any way. Anyone can sign and run their own add-ons, or offer those add-ons for others to use. The only thing being restricted now is who can distribute their addons via addons.mozilla.org, which seems more than fair.

I can download an arbitrary exe file and run it with a few clicks. It can do anything, install rootkit in my BIOS and of course completely replace Firefox.exe or anything else. What's the reasoning to forbid me to download and run addon? I can already shot myself, very easily. Additional protection does not do any good, only harms users.

People don't seem to understand how dangerous browser add-ons are. Protecting people from eg. malicious add-ons emptying their bank accounts is probably one of the reasons for restricting add-ons.

However, restricting add-on installations to a community-moderated app store model is not a secure enough way to do it. It's hard to prove that it helps at all, but it sure is annoying.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#253

Earlier quoted context omitted.

> that volunteers review the addons I don't think that makes it better. In fact, it's worse. Why is Mozilla Corporation, a company with gross revenue of $562 million, delegating an important security role to unpaid and apparently unaccountable volunteers?

Thats not how it works. To become an addon reviewer there is a process and it is not like all the reviewers are the same. Again please, don't treat volunteers who are donating their time and effort as unaccountable or as if they don't know security, they are accountable and there is also a staff team working on there. There are a ton of volunteers who are very good with security. Whatever happened between this addon…

I don't understand what point you are trying to make. First you agree with the OP that the reviews being done by volunteers who can makes mistakes somehow makes Mozilla less culpable, then you jump in to say that these volunteers are just as accountable, technically capable and security wise as an employee would be.

You only seem interested in letting Mozilla off the hook rather than acknowledging the systemic issues that gave rise to this situation.

> Also treating Mozilla as a company is not really the ideal mindset. Mozilla is at best a NGO, a foundation, who owns a company for legal reasons, who is also a community, who builds a ton of stuff.

Except the Mozilla Corporation is the entity that develops Firefox and is a company. That company may be wholey owned by a non-profit, but it is still a company.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#254

Earlier quoted context omitted.

How do you do this without leaking your code to mozilla?

Out of curiosity, under what circumstances would you consider distributing an extension bundle to be leaking its code? Unless I'm misunderstanding, isn't this the same file you'll be distributing to your users? At first bluff it seems similar to worrying about leaking your website's frontend (I've got news for you...).

off-topic: the phrase is, "at first blush"

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#255
post #219

Earlier quoted context omitted.

Those seem like two entirely unrelated issues

I don't know the whole story, but I'm inferring that the signing change affected the ability for people to sideload plugins.

That had nothing to do with the move to WebExtensions and the associated compatibility issues though...

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#256
post #245

Earlier quoted context omitted.

Distinction without a difference, IMO. Mozilla has chosen to require this level of curation on Firefox against all complaints in the name of "safety", so they can also take the heat when their process results in an outcome like this. Their browser, their addon site, their decision, their fault.

The idea that AMO shouldn't be curated is baffling. Browser extensions are the biggest malware vector since email attachments named `importantstuff.txt.exe`. The title saying that Mozilla "pulled" this extension is not merely incorrect, it is blatant misinformation.

>The idea that AMO shouldn't be curated is baffling. Browser extensions are the biggest malware vector since email attachments named `importantstuff.txt.exe`.

This is a strawman, the GP did not say AMO shouldn't be curated. [Edit: added missing "n't"]

> The title saying that Mozilla "pulled" this extension is not merely incorrect, it is blatant misinformation.

Mozilla selected, manages and empowers the reviewer who made this decisions. Since organizations are not people, delegating authority like this is the only way that organizations can ever do anything. Therefor to claim that Mozilla did not do this is spurious at best.

Now, Mozilla can disown the decision by saying the reviewer did not follow the appropriate process in making the decision. If that claim is shown to be true, only then would the title possibly be incorrect or misleading. Until then, Mozilla is as culpable for the authorized actions of its agents.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#257
post #216

Earlier quoted context omitted.

I'm currently developing a browser extension, and was a bit shocked that I couldn't just load it on Firefox like on Chromium. It seems like such a basic thing, maybe that's because I'm a dev and expect that they will cater to development, but it was one of the first usability things where I preferred Chrome. I ditched iPhone for Android for similar reasons, and it seems that one thing Google does really well is make…

You can load it like on Chromium. Go to about:debugging#addons, click the "Load temporary Addons" button and select your manifest.json file.

Aaah, thank you! That will help tremendously. The third-party resources I was looking at neglected that point.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#258
post #34

Earlier quoted context omitted.

Good idea, but they are not tech companies, so they likely lack the ability to do so. They'd best gain the ability, then, or fade into irrelevance and die. And honestly, we're talking about serving a few images from their own webserver. It's not rocket science.

Technically, serving few images is not a problem. The question arises, what images to serve. Someone has to sell advertisement, find clients, persuade them to advertise with the given site, etc. That's something they are getting with ad networks for free.

> That's something they are getting with ad networks for free.

Its also not a new problem. Newspapers have always had to have their own add sales department or outsource add sales.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#259
post #70

Lots of heat in this thread... So, Addons are mostly reviewed by volunteers. Sometimes people make mistakes. The best course of action is to try to reach out for the AMO team on IRC or their mailing list. - Addons forum is at https://discourse.mozilla.org/c/add-ons - All contact info for AMO dev stuff is at: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons#Con... - Developer Hub for addons is at: https://addo…

Is it just me or there’s a lot of these ‘hot’ threads on GitHub lately? I don’t mean the issue at hand—validity is beside the point—but the fact is that these issues unravel on GitHub on a very predictable cadence, and Github Issues is fairly ill equipped to deal with making sense of this. So everyone just shouts at thin ether at the top of their lungs, hoping to attract some attention and answers, then it becomes an arms race.

That’s a design problem - if the voting system made things become more visible, then likely fewer people would feel the need to shout. That has its own drawbacks, though.

It’s a hard problem building anything remotely social. I don’t think they realised what they were putting themselves into when they were building Issues.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#260
post #2

I don't want to subscribe, I also don't want to see ads or be tracked. I wish there was a universal micropayments way of paying for what I read.

Google has the ability to get us halfway there, if not more.

The previous version of google contributor was almost a solution.

But it used a bad payment allocation algorithm, it never guaranteed adsense ads would be blocked, and the new version is just a way to subscribe to a handful of sites.

But they also run youtube red, which has the model they need. They just need to copy their own idea.

Post reply on HN