Earlier quoted context omitted.
> Those still would have their certificates checked on installation. How? These extensions were not being installed through the normal mechanism. The malicious extension installer will just set the flag that says "this extension has been verified". > And honestly, I think it is security theater to attempt to defend against attackers on the same or higher privilege level. I understand that, and Mozilla does too: "By b…
But that's the point. Either the installer does something malicious or it doesn't. If it does you lost the game. If it doesn't then a simple check is sufficient. Everything else is security theater which makes life worse for everyone. Also, they could still run the verification and prompt the user instead of just forcing the decision.
And the clearly malicious action of modifying Firefox to disable signature verification can and should be flagged by anti-malware software, which runs at a higher privilege level.
[1] Putting aside for the moment the fact that most users now have no extensions installed due to the certificate expiration issue. No Firefox user, myself included, is happy about that.