Live data from Hacker News

Mozilla pulls Bypass Paywalls from Firefox add-ons store

github.com

161–170 of 288 posts

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#161
post #67
post #33

> Release and Beta versions of Firefox do not allow unsigned extensions to be installed I'm really disappointed at Mozilla regarding this. I recently wanted to do some Firefox customization for my own private use (not even an extension, I just wanted to have some visual indication of which Firefox windows belong to which profile). I was surprised to find out that even just a header .png in a theme can't be loaded loc…

IIRC you can install unsigned extensions in the dev and nightly as well as unbranded versions of firefox (usually the last option means compiling it yourself). Mozilla is, to some extend understandably, concerned with the image of Firefox and patrolling what Addons are available in the store is part of that. Apple does the very same thing.

Requiring people to use a buggy beta (this is what betas are!) is not acceptable. I warned about this constantly before they jumped the shark in version 37 and was always downvoted here and ignored at Moz. Well, here's what you get. Another Apple product beholden to corporate power instead of for the user.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#162
I 'm going to have to defend Mozilla here. There is this very perverse idea here that everything should be free, but that's only because you are used to using VC-funded services with an expiration (acquisition) date. This seems to be endemic thinking in SV but the rest of the world has to make their own paycheck.

Maybe mozilla should think of experimenting with some micropayment service though. They are ideally positioned for that.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#163
post #159
post #149

Earlier quoted context omitted.

As in the sibling, thread, no, you can't disable the signature check, not in the regular, mainline FF download. Even if you enable it in about::config! This was a change introduced in ~August 2016, to ignore your preferences on that setting. (As you note in the sibling thread, you can get it in a special development version, but that still contradicts your claim that you can toggle something to allow it.)

You can toggle a compile option to allow unsigned addons. I've mentioned this repeatedly and I'm unsure how you didn't notice that.

And I've explained that you can't expect the average newbie coder to navigate the recompilation process; I'm unsure why you blithely dismiss people who aren't as capable as you.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#164
post #31

Earlier quoted context omitted.

yes!!! people don't realize that volunteers review the addons and that sometimes they make mistakes. They start acting as if Mozilla sent an internal memo to kill something when it is usually not the case.

> that volunteers review the addons I don't think that makes it better. In fact, it's worse. Why is Mozilla Corporation, a company with gross revenue of $562 million, delegating an important security role to unpaid and apparently unaccountable volunteers?

Thats not how it works. To become an addon reviewer there is a process and it is not like all the reviewers are the same. Again please, don't treat volunteers who are donating their time and effort as unaccountable or as if they don't know security, they are accountable and there is also a staff team working on there. There are a ton of volunteers who are very good with security. Whatever happened between this addon author and the review this is kinda private to them.

I really dislike when people assume that because you're a volunteer that you're unaccountable or less capable technically or security wise than an employee. That is simply not true.

There are volunteers in all places at Mozilla and personally, I think this is great. Also treating Mozilla as a company is not really the ideal mindset. Mozilla is at best a NGO, a foundation, who owns a company for legal reasons, who is also a community, who builds a ton of stuff. It is quite a complex entity to be summarized as "a company should handle this different".

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#165

Earlier quoted context omitted.

> Isn't this exactly the kind of user-hostile behavior open source is supposed to prevent? What part of behavior is user-hostile?

Preventing the user from installing whatever they choose, for starters.

> for starters.

It is not only for starter but for the whole platform ecosystem. It is not even user-hostile. It is just to prevent "Nah forget Firefox add-on market, just install this file" fragmentation. Firefox add-on platform is already much smaller than Google chrome (of course). I wouldn't be happy if the market got even smaller because of the fragmentation.

And Firefox already allows us to install whatever we want in dev/nightly version, for hackers. So I don't see any problems here.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#166

Earlier quoted context omitted.

How do you do this without leaking your code to mozilla?

Out of curiosity, under what circumstances would you consider distributing an extension bundle to be leaking its code? Unless I'm misunderstanding, isn't this the same file you'll be distributing to your users? At first bluff it seems similar to worrying about leaking your website's frontend (I've got news for you...).

It could be a private extension developed by a company internally, and only distributed to internal users.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#167

Earlier quoted context omitted.

That is a totally different issue. One thing is reviewing what's on your store. The other is restricting people to only installing what's on their store. One is happening on their property. The other is happening on the user's property. They also want to exert control over the latter, which is causing these problems.

It's the difference between on the one hand some spyware or adware shoving an addon in the right location in the Firefox profile directory and either accepting any dialogs to confirm you want to side-load or social engineering the user into accepting them, and on the other the same spyware having to actually patch the firefox binary or exploit it to get the same behavior, since the binary has verification baked in. I…

I am aware of mozilla's given rationale (and I disagree with the implementation), I was just pointing out that patrolling an addon store is orthogonal.

And the decision to not even let users add additional signing root keys is yet another axis on the decision space that was totally neglected.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#168
post #71

Earlier quoted context omitted.

Did you try reaching out for the team in IRC or the mailing list?

As a process, that is a flat out awful one.

Thats not the process, that is just a way to reach out for a team as apparently they've been unable to communicate with them. If you think about it it is great that you can actually use some channel to talk to people involved in a product you use. That is not that common.

There is a process, it is through the AMO developer hub page for their addon. What I've been saying here is about ways to contact the team if they want to talk to them directly. From the Addon admin page, from the "review history" page, they have a form to message their review team. Usually, if something happen and by any reason your addon is rejects, you can use that form to escalate and find out why it happened. There is also an email address for escalating this stuff which I am assuming they've emailed already.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#169
post #159
post #149

Earlier quoted context omitted.

As in the sibling, thread, no, you can't disable the signature check, not in the regular, mainline FF download. Even if you enable it in about::config! This was a change introduced in ~August 2016, to ignore your preferences on that setting. (As you note in the sibling thread, you can get it in a special development version, but that still contradicts your claim that you can toggle something to allow it.)

You can toggle a compile option to allow unsigned addons. I've mentioned this repeatedly and I'm unsure how you didn't notice that.

Then you don't get security updates. That's forcing users to make uncomfortable tradeoffs.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#170
post #159

Earlier quoted context omitted.

You can toggle a compile option to allow unsigned addons. I've mentioned this repeatedly and I'm unsure how you didn't notice that.

Then you don't get security updates. That's forcing users to make uncomfortable tradeoffs.

The developer edition allows you to use unsigned addons, that has security updates.

You can't live in the modern world and expect all choices to be handed down without consequences and tradeoffs.

Post reply on HN