Live data from Hacker News

Mozilla pulls Bypass Paywalls from Firefox add-ons store

github.com

181–190 of 288 posts

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#181

Earlier quoted context omitted.

It's the difference between on the one hand some spyware or adware shoving an addon in the right location in the Firefox profile directory and either accepting any dialogs to confirm you want to side-load or social engineering the user into accepting them, and on the other the same spyware having to actually patch the firefox binary or exploit it to get the same behavior, since the binary has verification baked in. I…

I am aware of mozilla's given rationale (and I disagree with the implementation), I was just pointing out that patrolling an addon store is orthogonal. And the decision to not even let users add additional signing root keys is yet another axis on the decision space that was totally neglected.

That would go a long way to solving the problem once and for all. It would be nice if Mozilla would provide the ability to install private signing keys to the browser.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#182
post #93

Earlier quoted context omitted.

My experience with firefox add-on reviewers has been hit or miss - One of the most frustrating things is that reviews often happen long after your add-on has been published. I'd rather have a longer waiting time, but once an add-on is published then it means it's been approved. From the developer point of view it means that it's very hard to communicate on releases, because you never know when your addon is going to…

This was the old model and it put a lot of pressure on the volunteer add-on reviewers and their were times where the delays stretched out to several months.

It's not like Mozilla has no funds. Why not hire a couple of people for the reviews?

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#183
post #180
post #175

Earlier quoted context omitted.

Users will abuse the ability to control their own machines. Given full administrative privilege on their machine, it takes, by my experience, about a month until the machine either has various pieces of malware installed or their malware has malware installed. The average user cannot be trusted with full control of their machine and it's fairly reasonable to say that power users need to take the extra steps to, for e…

I'm not asking for full administrative privilege. I'm asking for: "If the user goes into a deep part of the obscure developer options and bypasses the warnings about unsigned addons, and then uses a non-obvious but documented process for side-loading, something virus peddlers can't really walk users through, then Firefox should honor that while explicitly displaying the list of unsigned addons the users added." >I'm…

>"If the user goes into a deep part of the obscure developer options and bypasses the warnings about unsigned addons, and then uses a non-obvious but documented process for side-loading, something virus peddlers can't really walk users through, then Firefox should honor that while explicitly displaying the list of unsigned addons the users added."

Any such process would have to be difficult for external programs. As it stands, the best way to get verification of such a setting is through the built in binary verification that firefox does, which require that any application needs to reverse engineer and patch the binary to install it's own addons.

Your process requires editing the about:config values, which is possible for an external application and installing an addon, which copies it into a specific folder and is also possible for an external application. We know this is possible because this is what other applications did to install their shitty toolbars.

>And I and others have explained how those involve unacceptable tradeoffs and run directly contrary to "give users back control over their machines" ethos, though not, of course, to your extremely limited version of the ethos.

It seems to me that further discussion is unnecessary considering you continue to ignore significant portions of my comments.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#184
post #67
post #33

> Release and Beta versions of Firefox do not allow unsigned extensions to be installed I'm really disappointed at Mozilla regarding this. I recently wanted to do some Firefox customization for my own private use (not even an extension, I just wanted to have some visual indication of which Firefox windows belong to which profile). I was surprised to find out that even just a header .png in a theme can't be loaded loc…

IIRC you can install unsigned extensions in the dev and nightly as well as unbranded versions of firefox (usually the last option means compiling it yourself). Mozilla is, to some extend understandably, concerned with the image of Firefox and patrolling what Addons are available in the store is part of that. Apple does the very same thing.

> Apple does the very same thing.

As my dear old mom used to say, 'if everyone else were jumping off a bridge, would you?' The fact that Apple constrain their users doesn't justify Mozilla doing the same.

My browser belongs to me, not to Mozilla and not to anyone else: I should be able to load any extension into it that I wish to, just as I should be able to load any program onto my phone or install any root cert in my operating system.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#185
post #176

Earlier quoted context omitted.

They could add a way to add signing keys to the stables. This gives you security updates and user freedom without significant downsides because the user would still be in charge of signing.

That would allow any third party software running on your computer to add malicious plugins to the browser (which has happened in the past and is in part why it requires Moz' signature now). Most users, ie, the average user plus a significant amount, don't really care that they can't install random addons from outside the addon store.

What would prevent malicious software running on the computer from installing a malicious version of Mozilla? What's their attack model?

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#186

Earlier quoted context omitted.

Preventing the user from installing whatever they choose, for starters.

> for starters. It is not only for starter but for the whole platform ecosystem. It is not even user-hostile. It is just to prevent "Nah forget Firefox add-on market, just install this file" fragmentation. Firefox add-on platform is already much smaller than Google chrome (of course). I wouldn't be happy if the market got even smaller because of the fragmentation. And Firefox already allows us to install whatever we…

What? There is no requirement to offer your add-on on AMO.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#187
post #184
post #67

Earlier quoted context omitted.

IIRC you can install unsigned extensions in the dev and nightly as well as unbranded versions of firefox (usually the last option means compiling it yourself). Mozilla is, to some extend understandably, concerned with the image of Firefox and patrolling what Addons are available in the store is part of that. Apple does the very same thing.

> Apple does the very same thing. As my dear old mom used to say, 'if everyone else were jumping off a bridge, would you?' The fact that Apple constrain their users doesn't justify Mozilla doing the same. My browser belongs to me, not to Mozilla and not to anyone else: I should be able to load any extension into it that I wish to, just as I should be able to load any program onto my phone or install any root cert in…

"if everyone goes off and gets vaccinated, would you?"

Apple constraints their users for certain reasons which they believe are good for the user (with some negative side effects that Apple also likes). Mozilla likely has a similar motive; doing good for their users.

It doesn't mean every user will be happy with that, the average user will however be better off. The non-average user can then install the developer or nightly edition of firefox or even compile it themselves too get unsigned addongs if they so choose. Choosing the branded release branch of firefox means that Mozilla wants to keep you safe to some extend. This means not allowing third parties to install arbitrary addons into your browser, for example. Users rarely know what they want or if they do, they go about it in destructive ways.

Install the developer edition and you get your "I want to be able to load any extension".

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#188

Earlier quoted context omitted.

> Apple does the very same thing. I understand that Apple does everything in its power to make the life of developers miserable (such as requiring a Mac to be used for iOS development), but Mozilla were supposed to be the good guys on the web.

Can we be friends? As a Dev, Apple has been my biggest obstacle for a mainstream app. I'm not sure if HN has lots of Apple fans, or Apple marketing patrols HN, but these comments are describing real problems but are constantly downvoted. EDIT: We have been found. These Apple accounts don't even respond to legitimate points.

Please stop breaking the guidelines:

> Please don't impute astroturfing or shillage. That degrades discussion and is usually mistaken. If you're worried about it, email us and we'll look at the data.

https://news.ycombinator.com/newsguidelines.html

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#189

Earlier quoted context omitted.

It's the difference between on the one hand some spyware or adware shoving an addon in the right location in the Firefox profile directory and either accepting any dialogs to confirm you want to side-load or social engineering the user into accepting them, and on the other the same spyware having to actually patch the firefox binary or exploit it to get the same behavior, since the binary has verification baked in. I…

I am aware of mozilla's given rationale (and I disagree with the implementation), I was just pointing out that patrolling an addon store is orthogonal. And the decision to not even let users add additional signing root keys is yet another axis on the decision space that was totally neglected.

The problem is that it's essentially just another dialog or control to be scripted or socially engineered around. You can make it more onerous because it's basically a one-time action that's not something most users will do, but to what degree is adding a signing key before install different that a dialog asking you if you really want to install this third party extension?

Until you have different access levels and can both restrict users/programs from running at the base level required to do this, and condition users to recognize when increased access is being requested, I don't see this problem going away. Windows UAC is basically what we're talking about, and it still took years to users to understand it and not just always allow it (if that's even true!), and that's a system shared over all of windows.

I think the only sane way to accomplish this that worked for users and didn't cause enterprise admins to totally shun Firefox would be to piggy back on Windows' certificate store and register certificate for Firefox use only (I assume this is possible, I'm pretty sure you can do this for app-to-app communication such as MSSQL encrypted connections), but then you have to make sure you also handle the mechanisms to do the same in Linux and OS X, and now we're seeing it's a much more complex undertaking.

Protecting users from their own stupidity is a tough and mostly unsolved problem. Punting and eating their own resources to provide the safest solution they can, even if it's annoying for a more technically literate subset of users, is a solution I can understand and respect, even if it's problematic for me, because it's putting safety and security the majority of users over a simple solution that would be worse overall.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#190
post #185
post #176

Earlier quoted context omitted.

That would allow any third party software running on your computer to add malicious plugins to the browser (which has happened in the past and is in part why it requires Moz' signature now). Most users, ie, the average user plus a significant amount, don't really care that they can't install random addons from outside the addon store.

What would prevent malicious software running on the computer from installing a malicious version of Mozilla? What's their attack model?

The attack model is largely that fairly normal software wants to install adware on the computer. The software isn't direct malware but will attempt to install and activate addons, redirect the users homepage and search engine as well as setting various other options on the user behalf that are ultimatively harmful to the user experience in Firefox.

Mozilla wants their branded Firefox to be something the user can trust and that means controlling what code with elevated privileges (ie, Addons) can run in the browser.

edit: It should be mentioned that in response to the first question; Firefox performs some binary verification and won't run or attempt to repair if it detects tampering.

Post reply on HN