31 ms·
> Because any extension or sufficiently capable malware on your system can change about:config values, meaning that if Mozilla ever makes a mistake in the exten
by grumdan 9y ago
> Because any extension or sufficiently capable malware on your system can change about:config values, meaning that if Mozilla ever makes a mistake in the extension approval process and lets a malicious extension slip through, or you get such malware on your PC, then that extension/malware would be able to flip that config bit and open the flood gates for all malicious extensions.
If such a malicious extension or other malware got installed, it could already do anything another malicious unsigned extension could, so I don't see how having this setting weakens security under the assumption that there's already malicious code running.
If we assume a system is compromised, it may as well install other malware as normal binaries instead of a Firefox extension.
- Sylos 9y agoIt's much easier to hide the flipping of one about:config value in your code than it is to hide a full-fledged spyware suite. Same for OS-level malware, which can only do so much suspicious things before it's noticed by antivirus software or the user.
- grumdan 9y agoJust flipping the about:config bit alone doesn't help much though. Any malicious extension installed after changing the setting would still have to have some payload with similar malicious behavior. Moreover, even if Firefox was compiled without support for that setting, malware could patch the Firefox binary (or download and install a malicious version) to disable the check and then it'd still be able to hide itself as a Firefox extension instead of a binary somewhere else on the system. Once there's malicious code running on the system, it's game over and a flag disabling installing more malware using one out of many possible methods is not going to help much. However, not having the setting may help for users that get tricked into toggling it through some web page telling them to and then installing a malicious extension, but that's a different scenario than an already compromised system.