5 ms·
In collaboration with Disconnect, we have compiled lists of domains that serve fingerprinting and cryptomining scripts. Now in the latest Firefox Ni
by founderling 8y ago
In collaboration with Disconnect, we have compiled
lists of domains that serve fingerprinting and
cryptomining scripts. Now in the latest Firefox
Nightly and Beta versions, we give users the option
to block both kinds of scripts
Isn't this something that content blockers like umatrix already excel at? Why put it into the core of Firefox?
I would prefer to see Firefox giving more power to extensions. For example, it is still impossible to make an extension that makes a typed in url use https per default. Because it is not possible for an extension to know if a network request stems from the user typing it, using a bookmark or one of the other many ways a browser can be triggered to do a network request. So typing urls in Firefox keeps being dangerous because it will load the url per http by default.
- meruru 8y agoI prefer to have features like this in core so I don't have to give a ton of permissions to a third party. I hope it becomes powerful enough to replace uMatrix.
- founderling 8y agoExtensions are analyzed by the Firefox team: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/AMO/Policy/Reviews#Submission_Guidelines https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/AMO... If the review process is still insecure (That is how I understand you reply) I would prefer them to put their energy into this. Analyzing popular extensions in depth (and giving them some 'in depth analyzed' badge) so you do not have to trust a third party.
- meruru 8y agoI don't know how much I can trust the review process. I believe they have relaxed it a bit recently: https://blog.mozilla.org/addons/2017/09/21/review-wait-times-get-shorter/ https://blog.mozilla.org/addons/2017/09/21/review-wait-times... >Add-ons built on the WebExtensions API will now be automatically reviewed. This means we will publish add-ons shortly after uploading. Human reviewers will look at these pre-approved add-ons, prioritized on various risk factors that are calculated from the add-on’s codebase and other metadata.
- cimmanom 8y agoBecause the vast majority of users have no idea that that's something they can or should be using. Power users like you and I can disable this if we like, using about:config.
- floatingatoll 8y agoUsers who are prohibited from installing addons (or otherwise unable/unwilling) would benefit greatly from not needing to install an addon to be protected.
- ocdtrekkie 8y agoExtensions are the primary source of malware I find on PCs, and they're fantastically cross-platform. I just degunked a MacBook Pro the other day that looked like the worst of Windows XP, all done via Chrome extensions shipped from the Chrome Web Store directly. Firefox does a better job at vetting extensions, but the reality is extensions have incredibly deep access to sensitive data, and they bypass every other security measure on your PC. HTTPS? Pointless if you've got a list of extensions installed on your browser. The EFF's Privacy Badger has been my sole extension for a while, but as Firefox Tracking Protection has expanded, I've found Privacy Badger catching less and less, since Tracking Protection blocks them first. I will probably retire my use of Privacy Badger pretty soon, because it's just becoming superfluous.