3 ms·
But if they know there was a malicious update, being distributed through infrastructure they control, why not immediately block it altogether? (The notion that
by rst 3y ago
But if they know there was a malicious update, being distributed through infrastructure they control, why not immediately block it altogether? (The notion that they have an explicit list of every, say, bank, stockbroker, crypto exchange, etc., so they could disable it for only those is... awfully suspect.)
- kemayo 3y agoBecause this would block it from hitting some high-value sites before they know there was a malicious update. I would imagine that once they know about it it'd also get added to the blocked-extensions list.
- JohnFen 3y agoThe only way this approach could work is if they prevent any extensions from being in force on such websites from day 1. I can't imagine that's their plan unless they really are trying to chase away the few FF users left.
- kemayo 3y agoPer the article, quarantined sites will only allow "monitored" extensions to run. I presume that this means extensions for which they actually do verify that updates are non-malicious, which probably includes most of the popular extensions. Hard to say exactly which -- uBlock was called out as being one in the article, but there's nothing on its addon page[1] specifically flagging it as being on that list. [1]: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/ https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...