Live data from Hacker News

Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

nakedsecurity.sophos.com

21–30 of 104 posts

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#21
The problem here is not the signing.

It is a perfectly valid reasoning: Addons can be like malware, and that is something Mozilla should protect its users from. Reviewing and then signing extensions is an ok way to do that. But the focus here is not the signing, it is the reviewing.

The problem is not the reviewing either. That may take time and is unpleasant, but it offers something good in return. The problem is the "we will do it this way and make it not configurable". There is no need for that. Users don't change defaults, it would be perfectly valid to go the android route: Disallow the installation of unreviewed addons by default, but add an option in the settings to override this behaviour for users who know what they are doing.

That way, you still protect users in general, and you don't anger the other users who want to install addons from github or whatever. It was completely unnecessary to make it this controversial by forcing it on all users, by taking freedom away.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#22

Well thats a totally click-bait and misleading title. The essence of a walled garden is that it's hard to get in, and if you're not let in then you lose out. Mozilla only require signing by them or by someone else, which given the proliferation of malware is hard to see as a bad thing, especially given the privileged access granted to addons. If you're too stubborn to let Mozilla sign it AND too lazy to do it yoursel…

Some people will see walled garden as one with few gates and a sentry controlling who can enter, e.g. Ios app store is not very difficult to enter in as a million apps have entered, but if apple does not agree, you cannot publish the app.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#23
post #5

"That makes it vaguely more egalitarian than a complex and bureaucratic mechanism that tends to favour bigger, more established software makers, who themselves have the staff and bureaucracy to match." This is FUD. Even Apple's App Store doesn't require huge amount of bureaucracy let alone what they seem to be talking about.

I think this refers to the apple practice of having vague rules and arbitrarily classify apps one way or another with no reliable explanation reaching the outside. So not bureaucratic in a literal sense, but rather in the sense of an opaque apparently rule-driven organization that produces incomprehensible decisions.

Sometimes apps containing things like pictures of old paintings with nude ladies are fine, sometimes not.

Often updates to something published will get stuck because some rule is supposedly being broken by the update, but of course the original, accepted, app contained the exact same thing.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#24
post #2

With each passing day, Mozilla tries harder and harder to get me to stop using their browser. If not for Chrome being the only viable alternative, they would have long since succeeded. Wreck the address bar algorithm? Ugh. Move the tabs on top? Ugh. Force me to keep download history? Ugh. Bury all the configuration options (like JS features) into about:config? Ugh. Turn the UI into a poor Chrome imitation? Ugh. Turn…

It's too bad to see that your comment is getting downvoted. I think it hits on some important issues.

From what I can tell, Mozilla's own Firefox feedback stats support what you're saying.

https://input.mozilla.org/en-US/?product=Firefox

It's currently showing 77% of the reports about Firefox as being 'sad', while only 23% are 'happy'. It gets even worse if Firefox OS and Firefox for Android are included, too. In that case, 86% of the reports are 'sad', and only 14% are 'happy'.

I expect disappointed users to be more likely to say something, but that's still an awfully large difference between the proportion of users who are 'happy' and those who are 'sad'. When I used Firefox for Android, I'm pretty sure it sometimes prompted me to give feedback, so it's not like only disappointed users looking to complain are being sampled.

I don't know how things work at Mozilla, but at any other software product company I've ever worked at, feedback results so out of whack would've raised a lot of eyebrows, and gotten a lot of attention. Much effort would have been put toward finding out what's wrong, and what can be done to fix it, especially if the results were consistently bad for weeks or months on end.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#25
post #21

The problem here is not the signing. It is a perfectly valid reasoning: Addons can be like malware, and that is something Mozilla should protect its users from. Reviewing and then signing extensions is an ok way to do that. But the focus here is not the signing, it is the reviewing. The problem is not the reviewing either. That may take time and is unpleasant, but it offers something good in return. The problem is th…

true but if Malware.exe ships with an addon, it could tweak Firefox user profile to allow the addon install

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#26
post #21

The problem here is not the signing. It is a perfectly valid reasoning: Addons can be like malware, and that is something Mozilla should protect its users from. Reviewing and then signing extensions is an ok way to do that. But the focus here is not the signing, it is the reviewing. The problem is not the reviewing either. That may take time and is unpleasant, but it offers something good in return. The problem is th…

Actually, the point of this change is that there is no opt out. The main target of this change is to prevent grayware from silently sideloading bad add-ons onto users' systems. Up to this point, such grayware could hide behind the argument that some user action implied consent to the add-on installation. With this new change, that is no longer possible. It is almost as easy for such grayware to silently modify the Firefox binary directly, so from a security standpoint this change does not really contribute much. However, such modification to the Firefox binary (or a similar action) is much more obviously malware than side loading an extension is. So Mozilla is trying to gain leverage against bad actors who are trying to pose as legitimate actors. The problem with an opt-out is that grayware could silently activate the opt-out and claim that such an action was implied by the installation of the grayware.

That said, Mozilla has also said that they will release an unbranded version of Firefox that does not include the add-on signing restriction but is otherwise identical. Hopefully, that "identical" promise holds true and users who do not want to deal with the signing restriction can use this unbranded version.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#27
post #25
post #21

The problem here is not the signing. It is a perfectly valid reasoning: Addons can be like malware, and that is something Mozilla should protect its users from. Reviewing and then signing extensions is an ok way to do that. But the focus here is not the signing, it is the reviewing. The problem is not the reviewing either. That may take time and is unpleasant, but it offers something good in return. The problem is th…

true but if Malware.exe ships with an addon, it could tweak Firefox user profile to allow the addon install

You argument is basically: "if a user installs the virus, the virus will make sure that the user will install the virus". Nonsense.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#28
post #25
post #21

The problem here is not the signing. It is a perfectly valid reasoning: Addons can be like malware, and that is something Mozilla should protect its users from. Reviewing and then signing extensions is an ok way to do that. But the focus here is not the signing, it is the reviewing. The problem is not the reviewing either. That may take time and is unpleasant, but it offers something good in return. The problem is th…

true but if Malware.exe ships with an addon, it could tweak Firefox user profile to allow the addon install

It could also patch firefox.exe to allow it. Or, just run in the background in its own process because malware.exe is already running. Once you have malicious binaries running on the user's computer all bets are off.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#29
post #25
post #21

The problem here is not the signing. It is a perfectly valid reasoning: Addons can be like malware, and that is something Mozilla should protect its users from. Reviewing and then signing extensions is an ok way to do that. But the focus here is not the signing, it is the reviewing. The problem is not the reviewing either. That may take time and is unpleasant, but it offers something good in return. The problem is th…

true but if Malware.exe ships with an addon, it could tweak Firefox user profile to allow the addon install

Malware.exe doesn't need Firefox to do its dirty work.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#30
post #25
post #21

The problem here is not the signing. It is a perfectly valid reasoning: Addons can be like malware, and that is something Mozilla should protect its users from. Reviewing and then signing extensions is an ok way to do that. But the focus here is not the signing, it is the reviewing. The problem is not the reviewing either. That may take time and is unpleasant, but it offers something good in return. The problem is th…

true but if Malware.exe ships with an addon, it could tweak Firefox user profile to allow the addon install

[deleted]
Post reply on HN