I think Firefox needs to stop this add-on signing and review madness. The web is OPEN. It's not a walled-garden Apple App Store. Yes, extensions run arbitrary JavaScript code. So does any webpage you go to, and nobody from Mozilla reviewed all that JavaScript either. How are extensions any different? Chrome is doing just fine without all this non-sense process and policy.
Extensions have dramatically more access to powerful APIs to affect the browser. They can be used to perform a great variety of annoying, intrusive or downright malicious actions which a website is incapable of. Of course they have much more stringent policy. Chrome implements mandatory addon signatures as well, and only Google can sign them.
Update Regarding Add-Ons in Firefox
471–480 of 504 posts
Re: Update Regarding Add-Ons in Firefox
#472Earlier quoted context omitted.
It's just another database collecting unknown information about me ("anonymized" in some way that may be reversible), stored for an unknown length of time, and enabled by default. Just ask. Plenty of people will beta test software for a $20 gift certificate, or even for free, but they should be given a choice.
Mozilla does ask.
Studies _must_ be opt-out given the amount of users Mozilla says the fix covers, and they're basically a form of telemetry, in their intended use anyway.
Re: Update Regarding Add-Ons in Firefox
#473(disclosure: I am a Mozilla employee but not commenting in any official capacity) "Give me control over what code I run on my computer" (meaning "provide a switch to disable the requirement that extensions be signed") keeps coming up over and over. And perhaps it hasn't been clearly stated but the problem is this: if there's a switch that a user can flip, the browser has to record the state of that switch somewhere (…
But where is the evidence that malware has ever switched off safebrowsing for example?
Your entire premise of extension signing and AMO store moderation rests on the premise that this is actually helpful for keeping extensions safe, but then you say nothing is safe.
There is only one gateway for malware to change the about:config settings in the first place, and that is through your signed extension process.
How safe should things be?
Edit: Maybe you could allow disabling the signing process via enterprise policies under the condition that the about:config settings are locked, which in my understanding would make it basically impossible for extensions to change anything. Would that help make it more secure?
Re: Update Regarding Add-Ons in Firefox
#474Earlier quoted context omitted.
> Quick auto updates are crucial for that. Expert users might dislike them I don't think anyone is really against quick security-related fixes being delivered with a degree of automation. What most power users dislike is mixing these updates with other ones (typically for commercial reasons).
What you want assumes having patches for every version that was ever released in the extreme case. How do you propose not doing so when you have limited resources? Firefox offers an ESR release, you can use that if you want.
Re: Update Regarding Add-Ons in Firefox
#475Earlier quoted context omitted.
> And to the downvoters: doesn't this entire fiasco ENTIRELY PROVE MY POINT? No. All it proves is that certificates expire (which is a Good Thing (tm)). If you depend on online certificates to verify content, something like this can theoretically happen.
Just because a cert expires is not a valid reason to disable functionality with no override available to the user. You may already know, you can override when visiting a website with an expired cert (once or forever). Yet nobody at Moz seemed to think it a good idea to allow it for extensions. Great.
Re: Update Regarding Add-Ons in Firefox
#476I'm not gonna bother with 'studies' or manual workaround - I'm just going to wait for an update. In the meantime I'm enjoying trying out Vivaldi[1] - really reminds me of opera 3/4, that I loved. 1: https://vivaldi.com
Hmm, I'm not sure switching to a closed source browser is in any way an upgrade... Especially when you could switch to the unbranded/nightly firefox builds, disable addon signature checking and continue using the only independent FOSS browser remaining.
Anyway, used to be Firefox had a lot more going for it than being open source. Now that's really the only thing left I can think of.
Re: Update Regarding Add-Ons in Firefox
#477Earlier quoted context omitted.
Extensions have dramatically more access to powerful APIs to affect the browser. They can be used to perform a great variety of annoying, intrusive or downright malicious actions which a website is incapable of. Of course they have much more stringent policy. Chrome implements mandatory addon signatures as well, and only Google can sign them.
I doubt google has certificates that run out automatically. Rather, the best way is with each signing to include signing the date and not allow the certificate to expire retroactively.
Re: Update Regarding Add-Ons in Firefox
#478Earlier quoted context omitted.
I doubt google has certificates that run out automatically. Rather, the best way is with each signing to include signing the date and not allow the certificate to expire retroactively.
All signing certificates expire. They must. It's a fundamental part of the security model, because otherwise a malicious actor could take an old, comprimised cert and inject it into Firefox, allowing them to run malicious 'signed' addons. This attack would work the exact same way in Chrome, so Chrome will expire it's certificates too.
Is it really necessary? Aren't there other possible ways of invalidating a certificate other than its date?
Re: Update Regarding Add-Ons in Firefox
#479Can we take a moment and consider the side effects? This is a once in a lifetime chance for Google & Co. to get a glimpse of all those sly fuckers hiding behind adblockers. This effectively uncloaked a very specific subset of Internet users and exposed them to the very companies that they've been actively trying to avoid. Not just those who avoid Chrome, but those who take extra steps to explicitly evade the tracking…
Re: Update Regarding Add-Ons in Firefox
#480Earlier quoted context omitted.
So that's pretty unfair. 1) They state they are working on a fix for normal, release channel users who don't want to run studies 2) they tell you to temporarily run studies to get the fix within up to 6 six hours (could be faster; set expectation) 3) You can explicitly install nightly or 66.4 before it's pushed if you want a fix now Yes, it's unfortunate, I'd expect them to meet it head on, push a tested fix in a tim…
Not saying that their current actions are wrong , just that the optics of it are terrible for them. There was a chain of bad decisions that led them here though: 1) thinking it's ok to disable software after its installed (using cert expiration -- I'm ok if the cert was revoked but that's a totally different discussion), 2) Taking more control of people's local software than many people are comfortable with, especial…