6 ms·
This seems to be by design: when these things are available, spyware -- especially on Windows -- will be quick to make malicious changes in all these if they ca
by mrmr1993 8y ago
This seems to be by design: when these things are available, spyware -- especially on Windows -- will be quick to make malicious changes in all these if they can.
It's a pain, but I can see the compromise. If it makes the average Firefox user more vulnerable, there's definitely a case to protect them, even at the expense of its more capable users.
- rhizome 8y agoif spyware has permissions to change ".firefox-prefs" doesn't it have permission to change about:config items, too?
- mrmr1993 8y agoYes, this leads Firefox to be fairly conservative with its permissions. In general, blocking userspace from installing extensions and otherwise running malicious code stops FF from being exploited. Blocking all of these options blocks the OS from bad behaviour, especially where the user may expect a new computer/phone to have the default behaviour. The vendors of phones and personal computers seem to have an interest in interfering with users' internet access; perhaps it is a good decision that Firefox does not let them.
- xte 8y agoActually homeManager can manage Firefox, installing extensions etc... Only it's a hack-ish and not much reliable way. So no, actual Mozilla strategy does NOT work to stop malware's on Windows nor commercial OEMs customization, as a matter of fact made only life of pro users and admin harder and open the door for less safe setup (for instance extensions added via homeManager may not get updated by FF).
- mrmr1993 8y agoWe would and should expect that it is be possible: unless Firefox signs configuration changes per-user, server-side (violating their privacy intentions), the whole configuration code is open source, and can easily be easily used or reverse engineered to make an external editor. This doesn't change that a sanctioned API invites abuse far more readily than reverse-engineering, especially when spyware is less frequently updated than Firefox itself. That there isn't a sanctioned API, and that the de facto API can and does change every version, is an advantage for Firefox against potential attackers. If this is something you are sorely lacking, Firefox has also been straightforward to modify and compile, in my experience. You can always share a patch and enjoy these features as part of a smaller community, without compromising the userbase as a whole.
- xte 8y agoNo software trick can fix OS unsafe design. Also "protecting users" limiting their power means jails them, not really protecting. End users are adult, not child, and developers are others adults with ZERO right on their software's user. If people want safer systems better learn to avoid commercial software, nothing else can help them.
- mrmr1993 8y agoI can agree in general, but, for now, disabling a firefox --install maliciousaddon.xpi and firefox --setconfig keyyoudontwant=valueyoudontlike is enough barrier to stop a majority of bad actors. None of us want users to click yes through install screens, having toolbars and spyware installed for the average user, but that has been the reality of those APIs thus far. Perhaps a more fine-grained permission model is needed for cross-application changes, but I can't think of anybody actively working on it in an OS.
- xte 8y agoHaving a simple text-based config with a repo, like [AddOns] ensure-ffpkg AddonName [Themes] set-default ThemeName install ThemeA, ThemeB [Settings] key:val ... and have the AddonName downloaded with GNUPG signature check from an official Mozilla repo is by far more save that demand using interactive GUIs. Simply ask at startup to accept "potentially dangerous" extensions if you specify a local .xpi file it the same. What you describe is the classic Windows approach that have proved enough to be ineffective and only useful for commercial practice. Mozilla is formally a foundation and Firefox is formally a FOSS project...
- AnaniasAnanas 8y agoI doubt that nowadays many of the average Firefox users are really average computer users.
- Semaphor 8y agoOur (German) site has mostly photographers who are not very (computer) technically inclined. Yet we have 20% FF users.
- toastal 8y agoFirefox had color management and color profiles support years before the other browsers. I'd venture to guess this is why it's favorite among photographers.