Live data from Hacker News

Google and Mozilla are failing to support browser extension developers

armin.dev

91–100 of 195 posts

Re: Google and Mozilla are failing to support browser extension developers

#91
post #25

Earlier quoted context omitted.

> BUT - extensions are also often the cause of a slow and frustrating Firefox experience I doubt that this is true. Some extensions like Adblockers even make browsing faster.

I reset Firefox recently on an ancient Linux laptop and before I got uBlock origin set back up the browser was nearly unusable. I had taken for granted how much it was doing. If I ever get out of this deep financial hole I am sending gorhill a large donation (if he accepts, I recall in the past he wasn't taking any). One of the most, if not THE most useful QOL add-ons in my view.

The list maintainers deserve a lot of the credit too, the blocklists probably takes a lot of time to keep up to date.

Re: Google and Mozilla are failing to support browser extension developers

#92
post #89
post #50

Earlier quoted context omitted.

As an extension developer who recently got one of these offers, your analysis is a good verbalization of my gut feeling on the matter. I turned it down, of course. While users may feel bad about extension developers not being compensated, I feel like the larger story here is that: - Companies are buying extensions for nefarious purposes, which presents a huge security risk. - Evidently, app stores are sufficiently ba…

> Evidently, app stores are sufficiently bad at detecting this that it remains profitable. What percent of extensions connect/download from the internet? That could be an easy way to identify a much smaller group of vulnerable extensions. Make extensions request permission to connect, then you can see the smaller group and watch any new extensions that request the permission. Connections could also be domain restrict…

The relevant extensions here (adblockers like uBlock vs. uBlock Origin, the author's extensions like adding a search-by-image button and removing +1s from GitHub) all have the ability to modify the web page that they're running on. If you have that ability, you therefore have the indirect ability to perform network access as that web page. Blocking the extension's own network access won't identify malicious behavior, and blocking indirect network access will get in the way of productive extensions.

Yes, you can imagine a way where extensions provide some declarative input to the browser saying how to block certain elements, and don't have any connection to the web page. That's more or less what iOS ad blockers do, as well as Chrome's new proposed ad blocker approach, and extension authors generally dislike it. And that only helps you remove elements, not add them - things like night mode extensions generally want to add either elements or at least CSS to the browser, and if you have that much access, you can definitely add ads or inject referral links into shopping sites.

Re: Google and Mozilla are failing to support browser extension developers

#93
post #52

Earlier quoted context omitted.

That's an interesting thought. It's almost like Chrome and Firefox have been in a "browser cold war" for years now, trying to outdo each other's version numbers, trying to entice users with greener grass rather than the stronger "attacks" of the IE-Firefox "browser wars" of the past, and one side trying to imitate the other. Chrome realized that if it jumped ahead in version number, it could gain a huge PR advantage,…

Chrome realized that if it jumped ahead in version number, it could gain a huge PR advantage, and then Firefox was forced to follow that pattern or appear outdated. Personal anecdote, but of all the non-technical people I know (which I define as those who may barely know what a browser is, and only use the computer for browsing a tiny fraction of the Internet), none of them like the constant change, especially when i…

Certainly isn't me. I'm still salty about Firefox 2 removing the "close current tab" button and putting an X on every tab instead. It was nice having that muscle memory instead of having to hunt down whichever tab you're currently focused on.

Re: Google and Mozilla are failing to support browser extension developers

#94
post #62
post #55

Earlier quoted context omitted.

Yes, agree - detecting extensions that have changed hands into someone who wants to "monetize" it and preventing those updates from getting to users definitely seems like a thing that the browser manufacturers should be doing (even if - and perhaps especially if - it lowers the apparent market value of extensions) and that the onus is on browser manufacturers / extension store operators to do so.

I'm not sure how one would automatically detect such a thing as a browser extension changing hands. If you require signing extensions to make a release, there's nothing stopping a developer from selling their keys. And even without changing hands, the threat to users remains the same if the company just goes from "we'll give you $10k for your extension" to "we'll give you $10k to link this library into your extension…

As others mentioned, I'm primarily interested in noticing the extension gaining malicious code, such as often occurs in the wake of a transfer, not noticing the transfer itself. (Which would also capture the case of extension not actually changing hands but nonetheless shipping malicious code - including both your example as well as a targeted attack on an ethical developer.)

Also I think it's reasonable for browsers to require complete auditable source (even if there's some obfuscation happening before it gets to users), which would probably have a deterrent effect on weakly-ethical developers - it's harder to ship code you can plainly see is malicious than to just sell the extension and wipe your hands of it. (There are enough stories of founders who care about their companies selling startups to acquirers that don't that I think there is something in human nature that makes it easier to hand off your creation to someone who will do bad things with it than to do the same bad things yourself.)

Re: Google and Mozilla are failing to support browser extension developers

#95
post #13

On the one hand, this seems like a real missed opportunity by Mozilla. As Chrome reigns in extensions that conflict with Google's business model, this is a reason to use Firefox. BUT - extensions are also often the cause of a slow and frustrating Firefox experience, which then leads folks to talk about how Chrome is better-performing/faster (I've been guilty of this myself in the past). Mozilla needs to make sure Fir…

Which browser extension is responsible for making Firefox slow as a slug when deleting large numbers history entries? I've not checked the source, but my guess is firefox stores the history in a SQLite db and when you select 500 history items then delete them, it's doing 500 DELETEs, maybe even without a proper index. It's seriously slow. There seems to be a lot of low hanging fruit in Firefox, but not being employed…

I think it’s not 500 deletes, but it’s certainly not great. There is definitely an index. If you can repro this, you should file a bug for it, I’ve noticed it being slow too, but couldn’t repro it recently. If you file a bug for this, you can CC me (tcsc at mozilla dot com).

Re: Google and Mozilla are failing to support browser extension developers

#96
post #79
post #44

> It is a regular occurrence to hear about open source developers selling their browser extensions, only for their users to be exploited later on by the new owners. ... We are witnessing the failure of browser vendors to recognize the value of our labor and the important role it plays in a healthy browser ecosystem. So this is an interesting philosophical question - the market value of the extension is the value of "…

The value of an extension is whatever someone is willing to pay for it. The value of someone's ethics also has a price. It is a different price for everyone. It's silly to go into details about ethics, because maybe I donate half of the unethical income to buy mosquito nets and now I've traded saving lives with inconveniencing users or some other such very personal calculation/rationalization. You can browbeat develo…

This doesn't respond to my argument: if your users knew that your sense of ethics is that attacking their private browsing data to buy mosquito nets is justified, they wouldn't be your users. (That small subset of your users that thinks mosquito nets are a good use of money would either donate directly and ignore your extension, or voluntarily participate in a scheme to turn ad views into mosquito nets such that you gain no additional mosquito nets by selling.) So whether or not you are willing to sell, in a market with perfect information, the value of your extension would be close to zero.

Therefore the only way that your extension has value is if you are intentionally withholding information from users about your willingness to sell. Which, even without getting into the ethics of deceiving your users, is at odds with the generally-accepted sense of the word "value" in economics. If a company is withholding information about it doing poorly and has a higher stock price than it would if it didn't, you generally say the company is "overvalued," that people are erring in attributing that value to it, not that it increased its actual value.

Re: Google and Mozilla are failing to support browser extension developers

#97

Chrome and Google not caring or supporting these kind of things I get but Firefox's recent efforts seem to be either gross negligence or targeted moved to destroy their addon ecosystem. I thought Firefox was going to get better with their redesign but it seems like it just resulted in lost functionality. Their misguided quest to get more market share has been a completely failure and pushed anyone who valued their cu…

I think there’s a certain degree to which needing to implement spectre mitigations (e.g. site isolation) threw a wrench into some of the plans for improving the baseline of the extension apis.

disclosure: I work at mozilla, but not on this.

Re: Google and Mozilla are failing to support browser extension developers

#98
Despite having a smaller extension ecosystem, Apple seems to have the right idea: Safari extensions (and soon even system extensions) are discovered and delivered via the App Store like any other app, and their developers can charge for them like any other app.

Re: Google and Mozilla are failing to support browser extension developers

#99

Earlier quoted context omitted.

It would not be about detecting the change of hands but about detecting the (malicious) monetization. Depending on the type of extension this might still be hard to do, but I could well imagine heuristics triggering a manual check from the extension store providers.

With many extensions having hundreds of thousands of lines of minified code, a manual check is unlikely to find anything nefarious if it's been well hidden.

IMO, extension authors should not be allowed to submit minified code alone to the extension stores for review. (Options include having standard minifiers that the extension stores run themselves, allowing extension authors to provide a .travis.yml or something where the sources to the build pipeline are themselves auditable, etc.) I can see an argument for withholding source from end users for things like paid extensions or clients to proprietary services (to be clear, I wouldn't agree with such arguments but I can see them), but I don't see the argument for withholding source from the browser manufacturers themselves.

Put another way, if the browser manufacturers run an extension store, they are (or ought to, at least) endorse the extensions in that store as reasonable to install. I don't see how they can do that without source. I think they could sort of make that endorsement without proactive auditing if they can remove extensions they discover are malicious, but if they can't even human-audit the source in response to a report of problems, I don't think there's any way they can responsibly offer extensions to their users.

Post reply on HN