Live data from Hacker News

Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

nakedsecurity.sophos.com

51–60 of 104 posts

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#51
post #44

It's funny to read this and the previous articles about the loss of freedom in Firefox, then see the description on its download page ( https://www.mozilla.org/en-US/firefox/new/ ): "Download Mozilla Firefox, a free Web browser. Firefox is created by a global non-profit dedicated to putting individuals in control online." I find the "appeal to security" argument that's being increasingly popular these days as nothing…

It seems like you haven't read the article. Users are still allowed to install any extension from outside the garden they want.

Users are still allowed to install any extension from outside the garden they want.

It's yet another hoop to jump through, one that further splits "developers" and "users" and makes it harder to be a "casual developer" - one who just wants to make an extension and share it among a small group.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#52
post #2

With each passing day, Mozilla tries harder and harder to get me to stop using their browser. If not for Chrome being the only viable alternative, they would have long since succeeded. Wreck the address bar algorithm? Ugh. Move the tabs on top? Ugh. Force me to keep download history? Ugh. Bury all the configuration options (like JS features) into about:config? Ugh. Turn the UI into a poor Chrome imitation? Ugh. Turn…

It's too bad to see that your comment is getting downvoted. I think it hits on some important issues. From what I can tell, Mozilla's own Firefox feedback stats support what you're saying. https://input.mozilla.org/en-US/?product=Firefox It's currently showing 77% of the reports about Firefox as being 'sad', while only 23% are 'happy'. It gets even worse if Firefox OS and Firefox for Android are included, too. In tha…

I never knew about that page to this day. I left a 'happy' piece of feedback. Should I have a serious issue, I'd probably look for a feedback page to report my problems, and would find it.

So I think the feedback there is seriously skewed towards "unhappy".

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#53
post #50

My startup, that shall go nameless, provides a service used mainly by the tech illiterate. Early in our first beta we determined we needed to log client side errors since there is quite a lot going on in there, so we quickly implemented a system that phones homes for every uncaught exception and error. Since we didn't filter the source, immediately after we were getting flooded with third party javascript errors. But…

If only the system were just about malware.

I remember when Chrome kicked any youtube-downloading extensions out of the chrome store. What happened? A few people downloaded non-chrome store extensions, but most of them downloaded the ones that were left in the store - the malware extensions that promised to download youtube but didn't. Huge spike in malware on Chrome installs that I saw.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#54
I'm wondering how the EFF feels about this, amogst others.

HTTPS Everywhere is currently only available via their website because it's actually securer than though AMO. If mozilla wall-gardens firefox in the interest of security, I guess they've got some serious issues to settle.

I also wonder bit what happens to developers who need a small userbase to tests their alphas/betas before publishing, as well as custom-built extensions.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#55
post #46

From the announcement: For developers hosting their add-ons on AMO, this means that they will have to either test on Developer Edition, Nightly, or one of the unbranded builds. Does this mean that developers won't be able to test the add-ons on official stable binaries end users will consume their add-ons on? Good luck with that.

I find this unbelieveable too. Developers being unable to test the addons in the same browser that end-users use is stupid.

That aside, I honestly can't see the value of the developer edition at all.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#56
post #14

I can totally see why such a thing would be required. I have always wanted to have add-ons vetted by someone I can trust. This will be really effective at least on windows where softwares randomly install shitty add ons and hijack the browser. And mozilla not likely to give in to unreasonable requests from governments because if they are not then add ons should be the least of our worries.

"I have always wanted to have add-ons vetted by someone I can trust."

That's fine, but what about those, who want to homebrew their own plug-ins, experiment with something from GitHub etc? Mozilla could make signed plug-ins a default choice, but not prevent others. A good model, imho, is implemented on Android -- your (only) default choice is Google Play, but if you know what you are doing, you can install any app from anywhere. This way users, that need a hand holding, are protected, but more tech savvy ones will not have their freedom denied.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#57

"This, of course, raises the question, "Will the unbranded or the Developer builds be sufficiently similar to the Release versions out in the real world that developers can stand by their testing results?"" Yes. It's the same code with different logo.

Different theme as well, and some other things (like the preferences dialog).

Testing proper integration on those aspects will get pretty hard.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#58
post #44

Earlier quoted context omitted.

It seems like you haven't read the article. Users are still allowed to install any extension from outside the garden they want.

Users are still allowed to install any extension from outside the garden they want. It's yet another hoop to jump through, one that further splits "developers" and "users" and makes it harder to be a "casual developer" - one who just wants to make an extension and share it among a small group.

> one who just wants to make an extension and share it among a small group.

That's a fair point, but I don't think it's that bad. I do this all the time with Chrome, which already has walled garden:

"Hey guys, I made a Chrome Extension that inlines all the images in our shitty issue tracking app rather than having to download them all. Extract the zip, visit chrome://extensions, enable developer mode, and load that folder."

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#59
post #38

Earlier quoted context omitted.

Microsoft already disproved this belief with Window’s UAC mechanism. Unless you have an unusually savvy user-base, you have to assume that a non-trivial percentage of people will approve any prompt which is claimed to give music, games, coupons, porn, etc. Just to illustrate how unworkable this is currently, Facebook had to include a huge warning in the developer console telling you not to XSS yourself because people…

In which case they will also download and run SomethingSagaCheats.exe without second thought. Should Firefox disable exe downloads without a setting to turn them on? What about users who download SomethingSagaCheats.jpg and rename it to exe before running? We should disable all downloads then, no? In general I do not like restricting rights to protect people. Now Mozilla is no government, but the same basic idea is g…

> At some point you have to tell someone they are responsible for their own online safety, give them the resources to educate themselves, and let them face the consequences if they choose not to.

If you follow the Mozilla security blogs, they've spent the last couple of years removing the ability of not-quite-malware to alter the browser without both the user opting-in and having an easy way to disable anything if they change their mind. That doesn't stop outright malware but it removes one of the legal fig-leaves which ad-ware vendors rely on and exactly supports your stated goal above by allowing a user to learn how to manage add-ons and remove something annoying without having their decision reset by the adware.

The real problem, however, is that it's currently fantasy to assume that any has enough information to make these decisions because a) the permissions models are still basically all-or-nothing and b) the halting problem has not yet been solved. Unfortunately, it's not just a question of tweaking the permissions models – as Android has shown, all that does is train users to approve blindly because every single app requests access to just about everything. That's not something we can fix overnight because it involves both things like better permissions models and changing the structure of the environment to be closer to something like WebIntents where many classes of add-on are only executed in response to specific user actions.

Until we reach that promised land, however, I don't see the big deal to Mozilla requiring you follow a free signing process for an extension so add-ons can easily be killed if needed and publishing something deceptive will require you to burn a developer account. It's not like they're talking about anything based on the content of the add-on.

Re: Firefox to get a “walled garden” for extensions, Mozilla to be sole arbiter

#60

I'm wondering how the EFF feels about this, amogst others. HTTPS Everywhere is currently only available via their website because it's actually securer than though AMO. If mozilla wall-gardens firefox in the interest of security, I guess they've got some serious issues to settle. I also wonder bit what happens to developers who need a small userbase to tests their alphas/betas before publishing, as well as custom-bui…

The Mozilla blog post answered all of these questions but the sophos click-bait had to leave them out to support their narrative:

https://blog.mozilla.org/addons/2015/02/10/extension-signing...

The short answer is that you can still have AMO sign an extension even if you distribute elsewhere (e.g. the way password managers like to ship one installer for everything) and the nightly / developer builds will allow unsigned extensions for obvious reasons. They are planning a private-app signing process but the details aren't public yet.

Post reply on HN