13 ms·
It's the "no override" part that concerns me. I created and maintain an extension that is used by visually-impaired people around the world (it has been transl
by nathanb 11y ago
It's the "no override" part that concerns me.
I created and maintain an extension that is used by visually-impaired people around the world (it has been translated by volunteers into Dutch and Chinese, for example).
Occasionally a Firefox update breaks this extension. OK, fine, that's the cost of doing business. Of course, the automated compatibility report that Firefox creates is utterly useless; it almost never catches the breakage. But that's a side rant....
There can be a decent turnaround lag (sometimes on the order of a few days) to get a new version of an extension reviewed by addons.mozilla.org. In the meantime, I have made a habit of building a new version of the extension and giving it to anyone who asks. Some people rely on it to use the web and can't wait for Mozilla to do their thing (another side rant: I once stupidly forgot to check in a key resource. I've since changed my development process to keep this from happening again. But the non-functional extension that I pushed passed Mozilla's review just fine. Makes me wonder how much value the review process is really adding.)
If I want to be able to continue this process, I will need to sign the extension myself (and who knows what histrionics Firefox will throw if a user tries to replace an extension with one that has the same UUID but a different signature!)
- brighteyes 11y ago> There can be a decent turnaround lag (sometimes on the order of a few days) Actually, the link says > Files submitted for signing will go through an automated review process. If they pass this review, they are automatically signed and sent back to the developer. This process should normally take seconds You may be thinking of a different type of review process, the signing one sounds almost instantaneous.
- tomjen3 11y agoIf it passes. Nobody knows what it checks for or how it works.
- icebraining 11y agohttps://github.com/mozilla/amo-validator https://github.com/mozilla/amo-validator
- Animats 11y agoThat's for non-public add-ons. If you submit a public add-on, even a minor update, it has to go through the AMO bureaucracy. I currently have an update that was uploaded on July 10, 2015, and is at queue position of 64 of 137. There are no code changes; it's just being updated because Mozilla changed their build system. This seems to be part of Mozilla's effort to be more like the Apple and Google stores. Mozila AMO - Learn to embrace the pain.
- imakesnowflakes 11y agoI have one uploaded on Mar 12, 2015, it is at position 25 right now. And it has been at around that position for quite a while.
- kpcyrd 11y agoActually, it's their effort to prevent AMO from ending up as malware riddled as the Chrome Store. Addons are running in the chrome context and are thus pretty powerful. It's trival to compromise the whole computer if they aren't reviewed.
- piyush_soni 11y agoI wouldn't think Chrome Web store is full of Malware. Yes, it's not free of those, but the bad ones are quickly removed by both Chrome's policing, and users' flagging. That's how Mozilla should go forward. The problem with manual reviewing is, it depends on the 'volunteers' time availability, and a stupid Review system which is NOT FCFS. You are told you are 37th out of 150 in the queue, but you see that you either remain at that position while others are being approved, your queue position goes both up and down, and some times your add-on is instantly approved even when you are 100th in the queue. All this takes many days even if your users are waiting for a critical fix. This is the biggest turn off in uploading add-ons for Firefox.
- soapdog 11y agoYou can sign the addons and distribute it on other channels. If you want to have it on AMO then it takes a while to review. The process is done by volunteers
- yAnonymous 11y agoWe need a signed extension that allows unsigned extensions.
- lexicality 11y agoYou mean like Greasemonkey?
- yAnonymous 11y agoI wasn't aware GM allows making changes to the browser. Does it?
- cpeterso 11y ago> If I want to be able to continue this process, I will need to sign the extension myself This seems like a good approach to me. Instead of Mozilla itself signing developers' extensions, why can't Mozilla issue certificates so developers can sign their own extensions locally? If a developer turns rogue, Mozilla can revoke their certificate.
- gerv 11y agoBecause bad guys can just keep getting new certs when their old ones are revoked, unless you do identity validation (which costs money as it requires actual humans, so the certs can't be cheap or free).
- schrodinger 11y agoReviewing plugins costs somewhere around the same amount of human time/money, no?
- malka 11y agoIf their review are as thorough as Android app's one, they cost about nothing.
- reubenmorais 11y agoAdd-on reviews are done largely by volunteers.
- soapdog 11y agothe addons signage is an automated process.
- bung 11y agoSuper noob question: Would it make sense for FF to realize a version which an extension is approved for? You create an extension capable for 1.0, they release 1.1, any client who has 1.1 has the extension automatically disabled? Assuming this is your business and you dont mind going through the approval process, then your users would have a better experience with this process no? Being notified they simply can't use it yet?
- jsingleton 11y agoI don't use many extensions but I'm finding I have to use more as Mozilla remove features from Firefox. For example you can no longer set the User Agent string on a per site basis natively in Firefox preferences [0]. This would be very handy to force HTML5 video on BBC News when you don't want to install flash [1]. I only discovered this setting was deprecated by finding that bug report whilst researching the blog post. [0] https://bugzilla.mozilla.org/show_bug.cgi?id=933959 https://bugzilla.mozilla.org/show_bug.cgi?id=933959 [1] https://unop.uk/dev/how-to-watch-bbc-news-videos-on-a-desktop-without-flash-in-firefox/ https://unop.uk/dev/how-to-watch-bbc-news-videos-on-a-deskto...
- chriswarbo 11y ago> I don't use many extensions but I'm finding I have to use more as Mozilla remove features from Firefox. To me, that's the way Firefox should work: a fast, lightweight browser, with a powerful extension system. I get disappointed when Mozilla add "features" to Firefox, like PDF viewers, Pocket, etc.
- TazeTSchnitzel 11y agoThe PDF viewer is rather important if only for security.
- doodpants 11y agoHow is having a built-in PDF viewer more secure than downloading the PDF and viewing it in Adobe Reader or Foxit? Is it just that those readers have vulnerabilities that Firefox doesn't?
- rockdoe 11y agoYes. The Firefox viewer sits on top of the JavaScript sandbox, which is the same sandbox that has to withstand attacks from pretty much everything on the internet and has been very hardened over the years (same for other browsers). Ironically it had a vulnerability last week, but that's ONE and that's why it got so much attention. Adobe Reader and similar have had hundreds.
- mbrownnyc 11y agoTo note, there is a client-side workaround that allows whitelisting of ALL unsigned extensions (they might consider creating a whitelist of UUIDs or something "humans" can handle like the name of an extension). I was able to change the following and uBlock and Ghostery immediately started working in the "Aurora" build: go to about:config ; set xpinstall.signatures.required = false
- Cthulhu_ 11y agoDo you test your extension against pre-release versions of Firefox? That's kinda what they're for.
- nathanb 11y agoSometimes. With the new ultra-frequent release cycle, as a volunteer maintainer I don't always have the time. And sometimes it breaks in ways that are not visible to me (I run Linux, for example, so bugs that show up on OSX or Windows only are going to be caught by users. These are few and far between, but have happened.)
- grincho 11y agoHi, Mozilla developer here, speaking for only myself. I'm not sure why we don't make this clearer on the wiki page, but I think the reason there's no override is that any malware installation routine would simply activate it and continue on its merry way. (Disclaimer: I didn't work on this feature and am going by recollection and my own logic.) We see many copies of Firefox infested with rogue add-ons the user didn't ask for or isn't even aware of. Sometimes these add-ons even ship with big-name software, with no opt out or with the opt out squirreled away in some dark corner. Typically, they do one or more of the following: (1) spy on the user, (2) add affiliate codes for money, (3) cause performance problems and crashes. The network is a pretty hostile place these days. It's no longer 14-year-olds playing around for fun; there are moneyed interests in the game. And the sorts of people who don't frequent HN are pretty much helpless and clueless in the perpetual tug of war between various companies and mafias. As a "user agent", we have the opportunity defend users who lack the sophistication to root around and remove invasive software they didn't ask for. Of course, if you're reading this, you're in a different category. You have a better idea which software to trust, and you know how to scour your machine if something gets past you. That's why nightlies and the Developer Edition let you do whatever you want: you aren't the ones who need hard-coded protections to shield you from pref-twiddling installers. I hope that provides some needed context. Safe surfing, all!
- piyush_soni 11y agoIt's been a few months already, and Mozilla is still 'undecided' on what will happen to Enterprise add-ons. The only two options you are giving us are: 1) Either remain on 'ESR' branch, which is always outdated, OR, 2) Reveal private Enterprise source code to you to get it signed (it might even be illegal for employees to do that). Both of them could be unacceptable to many organizations.
- callahad 11y agoThere will also be automated, unbranded builds of Firefox Stable that allow you to disable the signing requirement, but are otherwise bit identical.