Live data from Hacker News

Mozilla pulls Bypass Paywalls from Firefox add-ons store

github.com

171–180 of 288 posts

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#171
post #70

Lots of heat in this thread... So, Addons are mostly reviewed by volunteers. Sometimes people make mistakes. The best course of action is to try to reach out for the AMO team on IRC or their mailing list. - Addons forum is at https://discourse.mozilla.org/c/add-ons - All contact info for AMO dev stuff is at: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons#Con... - Developer Hub for addons is at: https://addo…

SOP: Downplay.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#172
post #170

Earlier quoted context omitted.

Then you don't get security updates. That's forcing users to make uncomfortable tradeoffs.

The developer edition allows you to use unsigned addons, that has security updates. You can't live in the modern world and expect all choices to be handed down without consequences and tradeoffs.

Right, we can't. Unless we're promising to give users control over their machines and there are trivial ways to accommodate this means of giving them control.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#173
post #163
post #159

Earlier quoted context omitted.

You can toggle a compile option to allow unsigned addons. I've mentioned this repeatedly and I'm unsure how you didn't notice that.

And I've explained that you can't expect the average newbie coder to navigate the recompilation process; I'm unsure why you blithely dismiss people who aren't as capable as you.

I don't because I also mention the developer edition and nightly, which allows unsigned addons and has regular updates.

I'm not dismissing people who aren't as capable as me either, I've mentioned alternative approaches and I'm getting tired of having to repeat "there is the dev and nightly edition" to the same 5 people over and over again.

Mozilla is making tradeoffs in protecting the average user and giving the power users a little bit less freedom unless they use an edition of firefox intended for power users and developers. Simple as that.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#174
post #170

Earlier quoted context omitted.

Then you don't get security updates. That's forcing users to make uncomfortable tradeoffs.

The developer edition allows you to use unsigned addons, that has security updates. You can't live in the modern world and expect all choices to be handed down without consequences and tradeoffs.

They could add a way to add signing keys to the stables. This gives you security updates and user freedom without significant downsides because the user would still be in charge of signing.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#175
post #172
post #170

Earlier quoted context omitted.

The developer edition allows you to use unsigned addons, that has security updates. You can't live in the modern world and expect all choices to be handed down without consequences and tradeoffs.

Right, we can't. Unless we're promising to give users control over their machines and there are trivial ways to accommodate this means of giving them control.

Users will abuse the ability to control their own machines. Given full administrative privilege on their machine, it takes, by my experience, about a month until the machine either has various pieces of malware installed or their malware has malware installed.

The average user cannot be trusted with full control of their machine and it's fairly reasonable to say that power users need to take the extra steps to, for example, install a power user edition of firefox.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#176
post #170

Earlier quoted context omitted.

The developer edition allows you to use unsigned addons, that has security updates. You can't live in the modern world and expect all choices to be handed down without consequences and tradeoffs.

They could add a way to add signing keys to the stables. This gives you security updates and user freedom without significant downsides because the user would still be in charge of signing.

That would allow any third party software running on your computer to add malicious plugins to the browser (which has happened in the past and is in part why it requires Moz' signature now).

Most users, ie, the average user plus a significant amount, don't really care that they can't install random addons from outside the addon store.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#177
post #93
post #70

Lots of heat in this thread... So, Addons are mostly reviewed by volunteers. Sometimes people make mistakes. The best course of action is to try to reach out for the AMO team on IRC or their mailing list. - Addons forum is at https://discourse.mozilla.org/c/add-ons - All contact info for AMO dev stuff is at: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons#Con... - Developer Hub for addons is at: https://addo…

My experience with firefox add-on reviewers has been hit or miss - One of the most frustrating things is that reviews often happen long after your add-on has been published. I'd rather have a longer waiting time, but once an add-on is published then it means it's been approved. From the developer point of view it means that it's very hard to communicate on releases, because you never know when your addon is going to…

This was the old model and it put a lot of pressure on the volunteer add-on reviewers and their were times where the delays stretched out to several months.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#178
post #10

Earlier quoted context omitted.

I've recently been experimenting with creating an extension, and the automated signing was literally one of the first things I did when I followed the Hello World tutorial. It's very easy to obtain an .xpi that you can distribute to your users yourself.

How do you do this without leaking your code to mozilla?

"Leaking your code to mozilla"? What do you think they are going to do with it?

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#179

This would not be an issue at all if Firefox had not jumped the shark in version 37 by implementing anti-user features like requiring Mozilla approval (signed) to run add-ons.

The idea is to protect users, not hurt them in any way. Anyone can sign and run their own add-ons, or offer those add-ons for others to use. The only thing being restricted now is who can distribute their addons via addons.mozilla.org, which seems more than fair.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#180
post #175
post #172

Earlier quoted context omitted.

Right, we can't. Unless we're promising to give users control over their machines and there are trivial ways to accommodate this means of giving them control.

Users will abuse the ability to control their own machines. Given full administrative privilege on their machine, it takes, by my experience, about a month until the machine either has various pieces of malware installed or their malware has malware installed. The average user cannot be trusted with full control of their machine and it's fairly reasonable to say that power users need to take the extra steps to, for e…

I'm not asking for full administrative privilege.

I'm asking for: "If the user goes into a deep part of the obscure developer options and bypasses the warnings about unsigned addons, and then uses a non-obvious but documented process for side-loading, something virus peddlers can't really walk users through, then Firefox should honor that while explicitly displaying the list of unsigned addons the users added."

>I'm not dismissing people who aren't as capable as me either, I've mentioned alternative approaches and I'm getting tired of having to repeat "there is the dev and nightly edition" to the same 5 people over and over again.

And I and others have explained how those involve unacceptable tradeoffs and run directly contrary to "give users back control over their machines" ethos, though not, of course, to your extremely limited version of the ethos.

Post reply on HN