Live data from Hacker News

Gorhill pulls uBlock Origin Lite from Firefox store

neowin.net

351–360 of 442 posts

Re: Gorhill pulls uBlock Origin Lite from Firefox store

#351
post #134

Earlier quoted context omitted.

I can’t fault gorhill for not wanting to play the “give large rich organization infinite second chances” game. Sometimes enough is enough even if you think you’d act differently in his shoes. > Mozilla apologized No they didn’t. Now I’m not here to play apology police or anything. But that’s just a perfunctory customer service voice statement which happened to include the word “apologize”. And that’s fine. Nobody exp…

What could the email have said that would have made you believe they had apologised? If the literal string “we apologize” isn’t it, what is?

Why does it matter if they apologize? Are there brownie points that make a rote ineffectual interaction somehow better if that check box can be checked?

> What could the email have said

If the goal is finding the right magic incantation for apology, then answer to your question is “nothing”. If it’s not, then the answer is “almost anything”.

Re: Gorhill pulls uBlock Origin Lite from Firefox store

#352
post #216

It seems to me that any platform with a review gateway should treat failing a review erroneously as a critical failure. In fact it does literally constitute denial-of-service. When a failure like this occurs, it needs more than an apology, it should have an incident report to show that the failure was understood and steps were taken to prevent future failures.

From a security standpoint the opposite is true: false negatives are to be avoided at all costs, even when that posture increases false positives. There’s always a trade-off.

Or there isn't and such level of competence just increases the chances of both types of negatives: there is no good reason to think that people who can't see the obvious in cases like this one will catch hidden vulnerabilities

Re: Gorhill pulls uBlock Origin Lite from Firefox store

#353
post #7

Because no one ever have taken over and compromised high profile extensions? Chrome battles with it a lot, see eg. https://news.ycombinator.com/item?id=36146278 I find Mozilla's process to be quite reassuring, but would be good to have alternative "addon stores" that also have a review process

What's reassuring about the lack of basic competence? Why would you think such people/processes will help catch the types of issues mentioned in the Chrome link?

Re: Gorhill pulls uBlock Origin Lite from Firefox store

#354
post #251

Earlier quoted context omitted.

Every time I hear about the review processes for browser extensions I'm shocked that the it involves humans having to read your README and manually plumb together the build process. Sometimes I hear that reviewers are even reusing VMs when doing reviews, or even not using VMs at all. I'd have expected the review form to have a textbox where you paste your git link and a well-documented automated pipeline that stands…

Browser extensions really seem like they're slowly failing and just not supported. Kinda like PWAs. I want to write a chat program, but it has to work on phones, and the DevEx for native phone frameworks compared to desktop apps looks like hell, and PWAs seem to be barely supported. It's easier than ever to make a CLI or desktop app, but phones seem like the worst of all Microsoft dev history - Learn these arcane lif…

Someone will come up with a solution that is utterly ingenious. Like the ability to install a plugin without third party intervention with a single click.

Re: Gorhill pulls uBlock Origin Lite from Firefox store

#355
post #134

Earlier quoted context omitted.

What could the email have said that would have made you believe they had apologised? If the literal string “we apologize” isn’t it, what is?

Why does it matter if they apologize? Are there brownie points that make a rote ineffectual interaction somehow better if that check box can be checked? > What could the email have said If the goal is finding the right magic incantation for apology, then answer to your question is “nothing”. If it’s not, then the answer is “almost anything”.

An apology is an admission of wrongdoing and shows remorse for one’s actions. It means the perpetrator is committing to improving themselves and not make the same mistake. You can’t change a mistake in the past, but you can promise to do better in the feature.

So yes, apologies matters. It is baffling, and honestly worrying, that this has to be explained.

It is important to realise the people steering the apology are not the same ones that caused the offence. The organisation is the same, but you can’t control what every single individual does.

Re: Gorhill pulls uBlock Origin Lite from Firefox store

#356

I manage a medium-sized browser extension at work. We also offer(ed) it on Firefox. But I have spent the past year struggling to get back into Mozilla store after a manual review. As far as I can tell, there are maybe two reviewers that are based in Europe (Romania?). The turn around time is long when I am in the US, and it has been rife with this same kind of "simple mistake" that takes 2 weeks to resolve. "You need…

Similar boat. I release an extension with about 1 million installs across Chrome/Firefox/Edge for work. Firefox (despite being the smallest usage) is utterly insane with regards to process. They demand a reproducible build, but then can't do things like install the right version of yarn (no - npm install -g yarn is not correct, our readme says it in bold like 5 times and provides the exact correct command to install…

They should switch to an fdroid like model that does public builds on cloud infra.

Re: Gorhill pulls uBlock Origin Lite from Firefox store

#357
post #355

Earlier quoted context omitted.

Why does it matter if they apologize? Are there brownie points that make a rote ineffectual interaction somehow better if that check box can be checked? > What could the email have said If the goal is finding the right magic incantation for apology, then answer to your question is “nothing”. If it’s not, then the answer is “almost anything”.

An apology is an admission of wrongdoing and shows remorse for one’s actions. It means the perpetrator is committing to improving themselves and not make the same mistake. You can’t change a mistake in the past, but you can promise to do better in the feature. So yes, apologies matters. It is baffling, and honestly worrying, that this has to be explained. It is important to realise the people steering the apology are…

> It is baffling, and honestly worrying, that this has to be explained.

Hey man, you’re the one that seems to be of the impression that the person sending form letter extension review responses is in a position in Mozilla to be able to do any of the shit you just said apologizes represent.

I asked what’s it matter if they tick the apology box because they can’t actually apologize.

I just don’t get why, in my previous post, I was supposed to pretend like the person who wrote that “we apologize” statement even intended to apologize.

—-

And in the odd chance the person who sent that email is in that position (or it’s a personal apology limited to their own reviewing failures) they need to use their words and distinguish themselves from a prefunctory customer service script. Rote apologies are not apologies, they’re simply someone saying what they believe are the right polite words for a situation.

Re: Gorhill pulls uBlock Origin Lite from Firefox store

#358

Earlier quoted context omitted.

Indian dialect is derived from the colonial English. So, lot of words and usage can be found in British English.

I don't think that most of Brits are "doing the needful". Indian English has plenty of expressions that are exclusive to India.

Pretty sure "why did you redeem it?!" is a British English slang from the victorian era :)

Re: Gorhill pulls uBlock Origin Lite from Firefox store

#359
post #265

Earlier quoted context omitted.

> That anyone dumber than such a reviewer cannot sneak malicious extensions in. Although people smarter than such a reviewer are free to? What kind of standard is that? > Which, sadly, is probably a non-trivial number of submissions. Then they're not, as an organization, actually capable of doing what they're promising here. There are more ways to get this wrong than to get it right, and borrowing the Google strategy…

> What kind of standard is that? That's the standard of all currated stores. We can argue about whether Mozilla's reviewer skillset is too low, but there's always going to be someone smarter than a reviewer, when reviewing is a cost center that companies want to spend the minimum amount of money on.

It could be $0, volunteer labor. I doubt it’s a paid position.

Re: Gorhill pulls uBlock Origin Lite from Firefox store

#360
post #288

Earlier quoted context omitted.

I looked at this just a few months as I have a few extensions with some very me-specific stuff that I don't really need/want to distribute – it's just not going to be useful for anyone except me. I couldn't find a good way to permanently install an unsigned or self-signed extension. You can temporarily add unsigned extensions in about:debugging, but those are lost on restarts, which is pretty annoying. I used this fo…

> So my solution now is to just create "unlisted" extensions and sign them with the web-ext CLI. It works and it's not entirely horrible, but it's a lot more hassle than I'd like. Wait. web-ext allows the signing of arbitrary extensions without review? Wouldn't that defeat the purpose Mozilla is sacrificing technical users for? While I didn't come across web-ext, I also tried my hand at working around firefox's limit…

> web-ext allows the signing of arbitrary extensions without review? Wouldn't that defeat the purpose Mozilla is sacrificing technical users for?

It takes about ten minutes to sign, and only seems like it uses automatic checks. I do get an email that "any extension may be reviewed by a human at any time".

I don't know if it matters that it's unlisted, or that they're all very simple extensions with very limited permissions. I'm not an expert on any of this and I've never published a public extension; I just have a few for my own use. But it does seem that they apply some heuristic to determine what is worth reviewing and what isn't.

> To this day, I still don't understand the "significant" threat that Mozilla sees (and other browser vendors apparently don't) that warrants such heavy-handed Apple-esque control over their users' ability to control their browser.

There are support scammers and such that will phone you with "hi, we are from Microsoft support to help you. You need to go to h4xx0r.ru to install an extension to protect your computer".

There are other ways of doing this of course, but an extension is a simple abd easy way.

I don't really know how to best solve this. I agree with your dislike of the current heavy-handed approach without escape hatch. But I also think the concerns are real, and you're being a bit too dismissive about that.

Post reply on HN