> Release and Beta versions of Firefox do not allow unsigned extensions to be installed I'm really disappointed at Mozilla regarding this. I recently wanted to do some Firefox customization for my own private use (not even an extension, I just wanted to have some visual indication of which Firefox windows belong to which profile). I was surprised to find out that even just a header .png in a theme can't be loaded loc…
IIRC you can install unsigned extensions in the dev and nightly as well as unbranded versions of firefox (usually the last option means compiling it yourself). Mozilla is, to some extend understandably, concerned with the image of Firefox and patrolling what Addons are available in the store is part of that. Apple does the very same thing.
Mozilla pulls Bypass Paywalls from Firefox add-ons store
161–170 of 288 posts
Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store
#162Maybe mozilla should think of experimenting with some micropayment service though. They are ideally positioned for that.
Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store
#163Earlier quoted context omitted.
As in the sibling, thread, no, you can't disable the signature check, not in the regular, mainline FF download. Even if you enable it in about::config! This was a change introduced in ~August 2016, to ignore your preferences on that setting. (As you note in the sibling thread, you can get it in a special development version, but that still contradicts your claim that you can toggle something to allow it.)
You can toggle a compile option to allow unsigned addons. I've mentioned this repeatedly and I'm unsure how you didn't notice that.
Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store
#164Earlier quoted context omitted.
yes!!! people don't realize that volunteers review the addons and that sometimes they make mistakes. They start acting as if Mozilla sent an internal memo to kill something when it is usually not the case.
> that volunteers review the addons I don't think that makes it better. In fact, it's worse. Why is Mozilla Corporation, a company with gross revenue of $562 million, delegating an important security role to unpaid and apparently unaccountable volunteers?
I really dislike when people assume that because you're a volunteer that you're unaccountable or less capable technically or security wise than an employee. That is simply not true.
There are volunteers in all places at Mozilla and personally, I think this is great. Also treating Mozilla as a company is not really the ideal mindset. Mozilla is at best a NGO, a foundation, who owns a company for legal reasons, who is also a community, who builds a ton of stuff. It is quite a complex entity to be summarized as "a company should handle this different".
Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store
#165Earlier quoted context omitted.
> Isn't this exactly the kind of user-hostile behavior open source is supposed to prevent? What part of behavior is user-hostile?
Preventing the user from installing whatever they choose, for starters.
It is not only for starter but for the whole platform ecosystem. It is not even user-hostile. It is just to prevent "Nah forget Firefox add-on market, just install this file" fragmentation. Firefox add-on platform is already much smaller than Google chrome (of course). I wouldn't be happy if the market got even smaller because of the fragmentation.
And Firefox already allows us to install whatever we want in dev/nightly version, for hackers. So I don't see any problems here.
Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store
#166Earlier quoted context omitted.
How do you do this without leaking your code to mozilla?
Out of curiosity, under what circumstances would you consider distributing an extension bundle to be leaking its code? Unless I'm misunderstanding, isn't this the same file you'll be distributing to your users? At first bluff it seems similar to worrying about leaking your website's frontend (I've got news for you...).
Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store
#167Earlier quoted context omitted.
That is a totally different issue. One thing is reviewing what's on your store. The other is restricting people to only installing what's on their store. One is happening on their property. The other is happening on the user's property. They also want to exert control over the latter, which is causing these problems.
It's the difference between on the one hand some spyware or adware shoving an addon in the right location in the Firefox profile directory and either accepting any dialogs to confirm you want to side-load or social engineering the user into accepting them, and on the other the same spyware having to actually patch the firefox binary or exploit it to get the same behavior, since the binary has verification baked in. I…
And the decision to not even let users add additional signing root keys is yet another axis on the decision space that was totally neglected.
Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store
#168Earlier quoted context omitted.
Did you try reaching out for the team in IRC or the mailing list?
As a process, that is a flat out awful one.
There is a process, it is through the AMO developer hub page for their addon. What I've been saying here is about ways to contact the team if they want to talk to them directly. From the Addon admin page, from the "review history" page, they have a form to message their review team. Usually, if something happen and by any reason your addon is rejects, you can use that form to escalate and find out why it happened. There is also an email address for escalating this stuff which I am assuming they've emailed already.
Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store
#169Earlier quoted context omitted.
As in the sibling, thread, no, you can't disable the signature check, not in the regular, mainline FF download. Even if you enable it in about::config! This was a change introduced in ~August 2016, to ignore your preferences on that setting. (As you note in the sibling thread, you can get it in a special development version, but that still contradicts your claim that you can toggle something to allow it.)
You can toggle a compile option to allow unsigned addons. I've mentioned this repeatedly and I'm unsure how you didn't notice that.
Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store
#170Earlier quoted context omitted.
You can toggle a compile option to allow unsigned addons. I've mentioned this repeatedly and I'm unsure how you didn't notice that.
Then you don't get security updates. That's forcing users to make uncomfortable tradeoffs.
You can't live in the modern world and expect all choices to be handed down without consequences and tradeoffs.