5 ms·
This would not be a problem if Mozilla had sided with users for once and allowed us to install xpi extensions from outside their app store.
by totfz 8y ago
This would not be a problem if Mozilla had sided with users for once and allowed us to install xpi extensions from outside their app store.
- INTPenis 8y agoAre you saying the extensions are signed? Becuase if they're not I can't imagine not being able to side-load them. And if they are, with the amount of Firefox forks we have, it should be trivial to create one that allows for side-loading unsigned or 3rd party signed extensions. Hopefully without too much source modification, just creating a distribution of Firefox would easiest to manage.
- fbender 8y agoI‘m pretty sure there is an un-branded release version of Fx on the Mozilla website that allows side-loading and allows disabling the signature verification. I don‘t have a link ready and on mobile so I cannot easily check.
- TazeTSchnitzel 8y agoYou can if you use the Developer Edition. It's permanently disabled in the normal version because malware would piggyback on the browser to steal passwords and so on. Obviously Mozilla have no problem with people wanting to make their own extensions and so on.
- Krasnol 8y agoWeird, I have 63.0.3 as far as I see the normal version and had no problem downloading and with that updating the November version of "bypass-paywalls" which was also affected from the releases page here: https://github.com/iamadamdev/bypass-paywalls-firefox/releases https://github.com/iamadamdev/bypass-paywalls-firefox/releas...
- TazeTSchnitzel 8y agoThat means it's signed with Mozilla's signature. Actually, I think extensions can maybe be signed by Mozilla even if they're not on addons.mozilla.org.
- totfz 8y agoYes, but Mozilla will refuse to sign extensions that are not hosted in their app store.
- falien 8y agoNo they wont (and don't) but it's possible they will choose to not sign these extensions, probably depending on their lawyers.
- fbender 8y agoTheir addon tool includes a well documented facility to sign an extension without listing it in the addon store so you can host it somewhere else. This can e.g. be used for company-internal extensions.
- zaarn 8y agoAddons can be unlisted, ie, they don't show up on a.m.o but you can download and install them as normal.
- techload 8y agoThanks for the link. Installed without problems.
- quarterlyresult 8y agoI wonder to what extent that helps prevent malware from installing a malicious addon to Firefox, because by using the same mechanism as cheating in video games, you can hot-patch a running browser process to disable the functionality to keep it from installing unsigned addons. Technically, in Windows you would just call WriteProcessMemory to modify memory content of another process.
- fbender 8y agoIt‘s the injection vector. People used to sideload malicious addons a lot by „accident“ when a rogue website told them to („You must install X player to see this video. Click here …“).
- zcid 8y agoWould it be difficult to set up a list of allowed signatures in Firefox? By making it unintuitive for the average user to modify, you would prevent most bad actors from succeeding but still allow power users to control their own experience.
- fbender 8y ago„This cool trick gives your Firefix super powers“ articles will appear instantly. This happened before with noobs following instructions to copy & paste code into the developer console(!), which pwned quite a few Facebook (and other) accounts. Same for banking websites, intranets, … social engineering works well on the unsuspecting. This is btw why browser vendors implemented measurements to make it harder to copy & paste into the dev console, as well as disallowed pasting „javascript:“ URLs to the address bar.
- superkuh 8y agoTelling people to use a buggy beta is not acceptable. This is anti-user and pro-corporation.
- Spivak 8y agoFirefox Developer Edition isn't beta.
- AnaniasAnanas 8y agoIsn't the developer edition the replacement for Aurora? (which is supposed to be more unstable than beta)
- fbender 8y agoAurora is no more because it was not necessary for stability (when nightly merges to beta it is already very stable, this improved a lot over time) and incurred a cost on speed of development (one less stop for the train to ride). DevEdition is now based on Beta and extremely stable. I use it alongside the stable version on both of my main computers in an equal way and I have max. 1-2 issues in DevEdition in a year (and those issues do not even prevent me from doing my work).
- shaki-dora 8y agoThis would not be a problem if internet users had respect for anybody’s interest, including their own beyond the time frame of “right now”. Because the mental gymnastics one has to go through, including in this thread, to somehow morally justify what is essentially just “I want it for free, everything, waaaa” is a contortionist’s dream. So after you all successfully fight soft paywalls, will you feel better when one half of publishers is bankrupt, and the other half only allows subscribers to read anything? Is that the improvement you seek?
- daveFNbuck 8y agoI don't think current trends indicate hard paywalls as the future. Instead, it looks like news organizations are going to publish exclusively into walled gardens like FB.
- Spivak 8y agoWhich outside of admitting the complete dependence of news on social distribution platforms is pretty much what journalists actually want -- a low-friction account you can use to enforce free tiers.
- betterunix2 8y agoWhy would it be wrong for a publisher to only allow subscribers to read articles? If that is the business model that works in the 21st century then publishers should absolutely do it. The bigger question is whether or not users should only be allowed to run software the neatly aligns with the publishers' business plans (and those of other corporations -- video game companies, business software vendors, etc.). Personally, I think business plans should be based on reality and not based on courts ordering people to pretend that reality is something else. In this case it is not even hard for publishers to enforce their paywalls -- they can simply refuse to serve page content before the payment is made, instead of just asking the browser to not render the content (which is like handing someone a newspaper and then saying, "don't read anything until you pay!").
- 8y ago
- the8472 8y agoI would even say mozilla invited this to happen by assuming sole authority which addons can get installed. They created a single point of failure. Now that SPOF gets exploited.
- dralley 8y agoI'm not convinced this is a worse evil than the previous situation, which was that any and every crapware installer injected browser plugins/toolbars without consent.
- crankylinuxuser 8y agoCaveat emptor is always better than a petty dictatorship. And that's what Moz is being these days; emulating the Apple App model, the Windows Phone app model, and other obnoxious "you have to ask us permission to do stuff on your device" rules. Id rather take toolbar hell. We'd have more functionality overall.
- Spivak 8y agoOf course you would rather take the toolbar hell. Because you're not the one who will be installing random toolbars. This is really no different than saying: "I'd prefer that when a company that has to make a decision that affects millions of users they go with the option that's best for me" What's somehow worse is that you can literally have your cake and eat it too -- just install Dev or Nightly, you're exactly the advanced user those branches are targeting.
- the8472 8y agoBut you can't effectively write useful addons for everyone because you can only hand them to dev/nightly users. Mozilla is saying "your contribution is not welcome due to US laws" to people who don't even live in the US.
- Spivak 8y agoThis view is bonkers. You can still install extensions outside AMO. And you can install unsigned extensions in Dev and Nightly. Is changing your release branch really that much more of a burden than flipping a preference?
- wvenable 8y agoYes.
- ubernostrum 8y agoif Mozilla had sided with users for once Yes, you should definitely switch to Chrome instead, which has a sterling track record of respecting you as a human and not as a revenue source. Or maybe knock off the hyperbole and start asking whether there are tradeoffs being made in favor of increased security for the average user. Which does require a more nuanced view than Braveheart-style screaming about freedom.