3 ms·
There's already been some good discussion on this, I find this comment the most enlightening: https://news.ycombinator.com/item?id=36591247#36591664 https://ne
by DistractionRect 3y ago
There's already been some good discussion on this, I find this comment the most enlightening:
https://news.ycombinator.com/item?id=36591247#36591664 https://news.ycombinator.com/item?id=36591247#36591664
Basically it's intended to be a user defined middle ground between allowing permissions everywhere vs the developer hand curating a list of allowed sites.
- jchw 3y ago> user defined Hmmm... > We need to have ability to set the list of quarantined domains remotely. > Filing as confidential for now, > "Only some extensions monitored by Mozilla are allowed on this site to protect your data." I didn't know Mozilla was the user of my local Firefox instance :P (Well, doesn't matter much to me honestly. I only use LibreWolf.)
- DistractionRect 3y agoAs commented, 116 will have a UI to allow the user to better control this. As I understand it, this just a safetly precaution. They will likely default opt out unmonitored extensions from certain high value sites (banks, email, etc) and allow users to explicitly opt back in. This, to me, seems perfectly reasonable
- jchw 3y agoOh no, I love it when developers ship features that'll be perfectly reasonable in the next release, and people defend that as if it's some kind of catch 22 versus what they actually shipped. What I said describes accurately the actual thing they shipped. A remote kill switch that's nearly completely opaque to the user. That's what shipped today. If you want Mozilla to get a free pass, that's your business. To me, what they shipped matters and said about it matters too. It says a lot about Mozilla that they seemingly didn't see how this would look optically, or perhaps simply don't care. And no, "Chrome is worse" is not a good answer. I don't want good to be the enemy of great, but I'm not making excuses for enshittification either.
- DistractionRect 3y agoWhile I concede what shipped today has potential to be abused, I reserve my outrage until that actually happens. We're both operating on assumptions. Mine is based on the discussion and work taking place in: https://bugzilla.mozilla.org/show_bug.cgi?id=1837670 https://bugzilla.mozilla.org/show_bug.cgi?id=1837670 You're assuming this will be (ab)used before that lands, if it ever lands. However, we're both just making conjecture until one of those realities (or another) is observed.
- jchw 3y agoMozilla ran out of good will for me after they used Firefox Studies to promote some Netflix thing, although at this point "whatever Mozilla is doing to torch user trust" has become a forgettable quarterly event, so I honestly can't remember many of the other things they've done that have agitated me. As it is, I have to use Fennec F-Droid on Android to have any hope at a decent browsing experience, and even then installing add-ons that aren't allowed by Mozilla is a Kafkaesque nightmare, instead of being a prompt I can bypass, even in this fork with about:config enabled, unlike the upstream Firefox for Android where they have about:config disabled and I'm not even sure if you can install extensions outside the select few Mozilla enables.
- Someone1234 3y agoThat doesn't make sense. If the true purpose of this was to give organizations (or individual users) the ability to control specific websites that extensions couldn't run on for security/sensitivity reasons, then why is it only a subset of extensions that Mozilla determines? A true user-defined restrict list could, in theory, be a useful feature but as I said, this feature is NOT "here's a list of websites, don't allow ANY extensions to run on it" it is instead "Mozilla is supplying a list of websites, which you can override, but in both cases Mozilla will determine which 'trusted' addons can run on those specific websites using rules/procedures only Mozilla knows and controls." Claiming this is meant to be org/user controllable is very inaccurate. Just because there's some about:config stuff doesn't mean a Mozilla website list and a Mozilla "trusted" addon list are anywhere close to "intended to be user defined." In fact the evidence shows that is objectively not true.
- DistractionRect 3y agoThere's some confusion here that needs to be dispelled. First, there's two categories of add-ons: - add-ons that get audited by Mozilla - add-ons that do not The ones they audit enjoy Mozillas endorsement in the app store, and an exemption from the quarantined sites setting. The quarantined sites setting only differentiates between the two categories. The audited apps are known to be non malicious, so they are exempt from the quarantined sites setting. The other add-ons are unknowns, and this sets a default access level. The ability to granularly opt extensions in/out is being worked on, and will likely ship with 116, per the comment I linked: https://bugzilla.mozilla.org/show_bug.cgi?id=1837670 https://bugzilla.mozilla.org/show_bug.cgi?id=1837670