Live data from Hacker News

Firefox 42 will not allow unsigned extensions

wiki.mozilla.org

231–240 of 315 posts

Re: Firefox 42 will not allow unsigned extensions

#231
post #220

Earlier quoted context omitted.

WTF people. So much hate for Mozilla these days, this appear pitchfork group. Lets review what the article says: addons needed to be signed. The process is automated. It takes only seconds. It prevents some malware from spreading. You can still host your addon wherever you want. This is just an extra step that can actually improve security. It requires more effort by the part of the developer but it also helps preven…

What is the rationale behind removing the configuration switch, though? Is there supposed to be some contingent of users who are not sufficiently tech-savvy to be trusted with choosing their own add-ons, but sufficiently tech-savvy to go and edit something in about:config, which really needs to be protected from their own stupidity? This sort of "mother knows best" approach is something I would expect from Apple, not…

[deleted]

Re: Firefox 42 will not allow unsigned extensions

#232

Earlier quoted context omitted.

Dev Edition is not less customizable... its just Firefox with a new theme and more bleeding edge dev tools which you should be using to develop addons anyway.

The theme is the problem I'm referring to.

The cool thing about themes is that you can change them. Developer Edition just comes with a different default theme.

Re: Firefox 42 will not allow unsigned extensions

#233
post #4

It's important to note that the Developers Editions (and the Nightlys) will have a setting for disabling the requirement. The assumption being that developers need to test as they develop. And are a more informed user.

Did they say why beta wouldn't have this setting? If anything beta is closer to release and developer would target that. Developer edition is still nightly if I'm not correct?

Generally, beta is supposed to be almost completely identical to the release version, to ensure that what gets shipped to release users is tested. This particular pref seems harmless, but you never know.

Developer edition is what used to be known as "Aurora", which is in between Beta and Nightly.

Re: Firefox 42 will not allow unsigned extensions

#234
Firefox disabled HTTPS Everywhere with no warning to me whatsoever. I use Dev Edition. I always just assumed it would always work, but apparently I can't rely on that anymore. Wasn't Mozilla pushing for non-encrypted HTTP to be deprecated? They should wait for that to happen before disabling HTTPS Everywhere.

Re: Firefox 42 will not allow unsigned extensions

#235

Mozilla's hypocrisy is astounding: https://blog.mozilla.org/security/2013/01/29/putting-users-i... "Users should have the choice of what software and plugins run on their machine." https://blog.mozilla.org/theden/2014/12/15/introducing-a-sma... "Firefox is dedicated to putting users in control of their online experience" More recently: https://blog.mozilla.org/blog/2015/06/02/firefox-puts-you-in... "Firefox Puts You…

Firefox users see through this feel-good marketing nonsense from Mozilla. They've seen Firefox's UI change for the worse in so many ways, even in the face of wide opposition. They've seen unwanted bloat, like Hello and Pocket, forced upon them, again in the face of wide opposition. They've seen their requests for bug fixes and performance improvements go unheeded, sometimes for years. The easy use of extensions has b…

I don't remember Firefox being well over 30%. The highest I've seen them had been 27%.

That said I can see how users don't like Mozilla's attitude. I've actually noticed it as far back as Firefox 3.5. I know users didn't like the changes post Firefox 2.0. It's too bad Firefox wasn't componentized enough to separate UI from the layout engine and JavaScript engine.

I myself like Australis but I'm also someone who's loved Chrome from the beginning. That said I think it was a mistake to turn Firefox into Chrome. They should've released Australis as a separate browser like they did with Firefox in the Mozilla Internet Suite days. That way they wouldn't have alienated so many users and their core user base would've been secure while they experiment with big user facing changes.

These days I'm more disappointed in what they didn't add to the browser like built-in ad-blocking and tracker blocking. I understand they have this view that the web needs ads but that doesn't mean it needs third-party ad networks. Just like popups they degrade the user's experience. More importantly they also compromise the security and privacy of the user. Clearly they are a practice that should be fought against. That they haven't tells me they are no longer an advocate of the user but the site owners.

Re: Firefox 42 will not allow unsigned extensions

#236

This is going to be an annoying change me since I use the 1Password extension which isn't signed as far as I know. So, it's likely I'll switch over to Chrome (which I've had performance issues with in the past) or Pale Moon. Seriously, it's my browser. It's fine if you want to make users white list extensions but to completely block unsigned extensions is a bit over zealous. Unless Mozilla makes the signing process a…

Hi. I'm Eva and I work for AgileBits, the makers of 1Password.

I wanted to reassure you that we are working with Mozilla on getting our Firefox extension signed. That will allow you to continue using Firefox as your default browser while still using the 1Password browser extension.

Re: Firefox 42 will not allow unsigned extensions

#237
post #47

It's little more than a year ago that Brendan Eich was ousted from Mozilla by an ugly orchestrated cabal. When I read Mitchell Baker's vapid blog post [1] on the decision, filled with polite backstabbing and politically correct buzzwordery I understood that Mozilla has been taken over by politicians and that its decline is just a matter of time. [1] https://blog.mozilla.org/blog/2014/04/03/brendan-eich-steps-...

I have been looking at https://input.mozilla.org/ now and then for a long time, and I am still astounded at how it's typically around 90% unhappy, 10% happy. I know that some Mozilla supporters will justify that huge difference by saying, "but unhappy people will always complain and happy people won't say anything", but I don't think that's necessarily the case. Here we have Mozilla's own stats saying that a lot of t…

"I have been looking at https://input.mozilla.org/ now and then for a long time, and I am still astounded at how it's typically around 90% unhappy, 10% happy."

I've been reading Mozilla's bug system for 17 years and the bug numbers keep going up. That can't be a good sign.

Re: Firefox 42 will not allow unsigned extensions

#238

I recently made an update my own Firefox extension, called Tab Grenade. It took them 4 months to review. 4 months. And that's for a (very) minor update. Because of that, I was definitely considering to start releasing it on my own, instead of through Mozilla's add-on website. It looks like I will be able to do that, but I'll have to use the signed extension process. I'll believe this system works when I see it. After…

Addons get signed by an automated process that is independent from the public store review.

Re: Firefox 42 will not allow unsigned extensions

#239
post #11

It's the "no override" part that concerns me. I created and maintain an extension that is used by visually-impaired people around the world (it has been translated by volunteers into Dutch and Chinese, for example). Occasionally a Firefox update breaks this extension. OK, fine, that's the cost of doing business. Of course, the automated compatibility report that Firefox creates is utterly useless; it almost never cat…

Hi, Mozilla developer here, speaking for only myself. I'm not sure why we don't make this clearer on the wiki page, but I think the reason there's no override is that any malware installation routine would simply activate it and continue on its merry way. (Disclaimer: I didn't work on this feature and am going by recollection and my own logic.) We see many copies of Firefox infested with rogue add-ons the user didn't…

It's been a few months already, and Mozilla is still 'undecided' on what will happen to Enterprise add-ons.

The only two options you are giving us are: 1) Either remain on 'ESR' branch, which is always outdated, OR, 2) Reveal private Enterprise source code to you to get it signed (it might even be illegal for employees to do that).

Both of them could be unacceptable to many organizations.

Re: Firefox 42 will not allow unsigned extensions

#240
post #219

Earlier quoted context omitted.

Yes. The Firefox viewer sits on top of the JavaScript sandbox, which is the same sandbox that has to withstand attacks from pretty much everything on the internet and has been very hardened over the years (same for other browsers). Ironically it had a vulnerability last week, but that's ONE and that's why it got so much attention. Adobe Reader and similar have had hundreds.

Allowing people to implement viewers for file types that run in the sandbox as plugins seems like a good idea then. Not that I mind that a PDF-viewer is already built in, but firefox can't support all file types.

A plugin API separate from the Web APIs is itself a large source of complexity and bloat.
Post reply on HN