4 ms·
Think high sensitivity sites like banking. Personally, I'd love to be able to flag sites as only having a limited whitelisted set of extensions, as they are a
by BaseballPhysics 3y ago
Think high sensitivity sites like banking. Personally, I'd love to be able to flag sites as only having a limited whitelisted set of extensions, as they are a serious potential security risk. And I'm fine with the browser shipping with sane defaults. I don't want to have to manually tune this for my family members.
Come to think of it, even better would be to attach this feature to whole containers...
- jeroenhd 3y agoI understand this position, but I do see several trackers ("telemetry") get blocked by uBlock on my bank's website. This type of telemetry can go die in a fire for all I'm concerned, but these trackers are particularly devious with their constantly changing domains and URLs. Addons that allow for things like regex matching are the only solution that seems to work because the Pihole blacklist doesn't seem to block them sufficiently. Mozilla has already killed off malicious addons by enforcing their signature requirements. I'm not sure what this adds, I doubt Mozilla will hire someone to monitor the changes to banking URLs around the world (a necessity if this is indeed intended to make banking safer).
- BaseballPhysics 3y ago> I understand this position, but I do see several trackers ("telemetry") get blocked by uBlock on my bank's website. Which is why I'd leave uBlock whitelisted. I never said I want to block all extensions! > I doubt Mozilla will hire someone to monitor the changes to banking URLs around the world uBlock effectively does this for advertising domains. Why is that any different?
- jeroenhd 3y agoThe tricky thing is what extensions should be whitelisted and what extensions shouldn't. uBlock is easy, but what about Consent-O-Matic? What about GreaseMonkey and friends? What about Stylus? Where do you draw the line? uBlock was just an example, of course. There are other addons that do more complex auto detection.
- drdaeman 3y agoIn my experience, banking websites are notoriously ass-backwards and need more hacks and patches than many other websites. I’ve specifically used Greasemonkey to fix bank breaking pasting into fields and blocking password managers by splitting login form into deliberately broken pieces.
- fragmede 3y ago> Mozilla has already killed off malicious addons by enforcing their signature requirements. I don't think those signing requirements do what you think they do.
- jeroenhd 3y agoThey've nipped the crap inserted by adware in the bud. Sure, anyone who can pass a simple malware scan can get an addon published, but there's no doubt in my mind that getting rid of unsigned addons has helped a lot.
- impissedoff1 3y agoThat's what incognito is for. And what you should use regardless
- BaseballPhysics 3y agoWhat? No. I've never used incognito mode for that purpose. I still want my banking site to be able to, for example, drop persistent cookies (for example, to indicate I'm comfortable bypassing two factor on that device).
- depereo 3y agoWhen I went looking into this feature I saw they're developing a negative permissions list for addons, so you can create exceptions for i.e ublock or dark reader or whatever for specific websites, disallowing them to access your data on that page.
- ilyt 3y agoOkay? You have "malicious" extension. Why would you allow it to run everyhere ? What would just limiting the "fix" of blocking it to inevitably only some set of US banks (as I doubht they get the all URLs to every bank in the world) achieve?
- BaseballPhysics 3y agoIt's not about known malicious extensions, it's about known trusted extensions. Are you really not understanding this threat model?
- JohnFen 3y agoHmm, I thought I understood until your comment here. It being about known trusted extensions makes no sense to me -- so I guess I'm not understanding the threat model at all. If an extension is known and trusted, why does there need to be a Mozilla-controlled kill switch for it?
- BaseballPhysics 3y agoIt's the reverse. The purpose of the feature is to put known trusted extensions on a whitelist for sensitive sites while blacklisting everything else. In my case I'd put uBlock on my "yes I trust this extension" list and when I visit my banking website only that extension would be active. It's also not "Mozilla-controlled". It's a feature that will, in the future, come with sensible defaults, just as uBlock does with their default blocklists, but in 116 the user will be able to more fully configure the feature. Meanwhile, in 115 the feature isn't active by default because the extension whitelist and domain list are empty.
- horsawlarway 3y agoHow do they know what sites I consider sensitive? How do they establish trust for an extension? How many dollars do you want to wager that they are building this feature with the intent to get sued so that they can be forced by the courts to turn it on for sites like youtube?