3 ms·
The major problem was building a feature into the product that allowed for pushing add-ons without users knowledge much less active consent in the first place,
by UmmNope 9y ago
The major problem was building a feature into the product that allowed for pushing add-ons without users knowledge much less active consent in the first place, there is no benign use for this kind of functionality.
- lenzm 9y agoYou could use add-ons to manage optional functionality a la Atom. Users can enable and disable add-ons to customize their browser and some come enabled by default. If you were migrating to this method of customization it would absolutely make sense to push an enabled add-on that replaces functionality you took out of the main app.
- akamaozu 9y agoWhy is this downvoted? It sounds like a valid reason for being able to auto-install add-ons.
- TooFastIndeed 9y agoBecause this is not the scenario that is being denounced here. A brand new add-on with functionality unrelated to the product is being installed without consent or even notification - that's capital M Malware peddling.
- bigbugbag 9y agoIs this a thing ? History shows mozilla removing functionality but never replacing it. And then it's up to volunteers to make an extension to fill the gap, until mozilla breaks the extension or drops the extensions engine altogether. For exemple australis and classic theme restorer.
- Sylos 9y agoThis is bullshit and you know it. If you want to shittalk Mozilla, then at least try to be honest.
- TheRealPomax 9y agoyou mean the automatic update process, which can change every single byte of every file in every directory under Firefox's control? Because unless you want to live in a world where your browser can't automatically apply security patches and upgrade critical components, the fact that the application can update itself is very much not the actual problem (and with the new web extension addon system rathern than the old XUL system, addons are actually way less security-compromising-in-potentio than updates to the actual browser itself)
- okasaki 9y agoIn Linux distributions you get it from the distribution repository, and automatic updates are disabled. So at least it's reviewed by a third party.
- bigbugbag 9y agoThe automatic update process fails because it does not have right to install software on my box. The power of setting permissions and not blindly trusting software just because it is floss. I would not want it to have this kind of power as the security patches and critical updates are provided by the kind people managing the distro repositories, and if it could update itself it would remove the third party patches required because mozilla has been refusing for 15 years to integrate correctly in my desktop environment but did integrate in the main competitor.
- Zancarius 9y agoI'd argue there's a vast difference between an automatic update for something that was already manually installed, by the user, and automatically installing something without any indication to the user that it was installed. Worse, it's impossible to argue that this was even a useful extension. I don't watch television, and I don't keep up with any popular modern shows. I had no idea what Mr. Robot was until looking through this thread, and the description text for the addon was, at first glance, suspicious. This was a terrible idea and isn't even remotely analogous to applying security updates automatically. If I have something I specifically installed, fine, I can expect those addons to be updated automatically. I don't expect them to side load something I don't even want. "Delight fans" my ass. You have to be a fan first, and I'm not even sure most people who are fans of Mr. Robot would think this is a particularly good idea. Funny enough, the only thing I can think of that's even remotely similar to this is the "Hell, Dolly" plugin for WordPress, and that's installed out of the box as part of the distribution.
- TooFastIndeed 9y agoAutomatically updating an already enabled add-on is hardly the same thing as silently pushing a new one. Security updates were and still are configurable to be installed after prompting, also when they are installed automatically I am notified that this has happened. There is also an implicit trust in the vendor that only security-related functionality should be changed in a security update.