3 ms·
It's not about known malicious extensions, it's about known trusted extensions. Are you really not understanding this threat model?
by BaseballPhysics 3y ago
It's not about known malicious extensions, it's about known trusted extensions.
Are you really not understanding this threat model?
- JohnFen 3y agoHmm, I thought I understood until your comment here. It being about known trusted extensions makes no sense to me -- so I guess I'm not understanding the threat model at all. If an extension is known and trusted, why does there need to be a Mozilla-controlled kill switch for it?
- BaseballPhysics 3y agoIt's the reverse. The purpose of the feature is to put known trusted extensions on a whitelist for sensitive sites while blacklisting everything else. In my case I'd put uBlock on my "yes I trust this extension" list and when I visit my banking website only that extension would be active. It's also not "Mozilla-controlled". It's a feature that will, in the future, come with sensible defaults, just as uBlock does with their default blocklists, but in 116 the user will be able to more fully configure the feature. Meanwhile, in 115 the feature isn't active by default because the extension whitelist and domain list are empty.
- horsawlarway 3y agoHow do they know what sites I consider sensitive? How do they establish trust for an extension? How many dollars do you want to wager that they are building this feature with the intent to get sued so that they can be forced by the courts to turn it on for sites like youtube?
- BaseballPhysics 3y ago> How many dollars do you want to wager that they are building this feature with the intent to get sued so that they can be forced by the courts to turn it on for sites like youtube? Good god, the conspiracy theories are next level with this one...
- JohnFen 3y agoAh, I get it. Thank you. > It's also not "Mozilla-controlled". It's not? The bugzilla entry at https://bugzilla.mozilla.org/show_bug.cgi?id=1832791 https://bugzilla.mozilla.org/show_bug.cgi?id=1832791 says We need to have ability to set the list of quarantined domains remotely. Which sounds pretty Mozilla-controlled to me. I hope that Mozilla will allow reasonable user control over all of this. I'm aware of their stated plans, but until we don't know what will be until they actually implement them.
- horsawlarway 3y agoThere is no such thing as a "known trusted extension" ever since they killed sideloading extensions and forced auto-updates. 10 years ago not force updating extensions was also a thing they moved behind a flag, and then just dropped. Also - if you want to blacklist certain extensions from certain sites, you abso-freaking-lutely can already... see: https://github.com/mozilla/policy-templates/blob/master/README.md#extensionsettings https://github.com/mozilla/policy-templates/blob/master/READ... you want the `restricted_domains` field. It gets worse - Mozilla is the fucking worst at checking submitted extensions. They tried to the play into the whole "app store" thing that Google/Apple were doing, but those are justifiable cost centers at those two companies in a way that just doesn't work for a player like Mozilla. Mozilla's store checks for extensions are fairly pathetic. You can submit a near empty shell with excessive permissions, get approved the first time, then auto-update to a new release (which will deploy to users immediately thanks to auto-updates). That new version has to pass a battery of useless automatic SAST checks, which will happily highlight all sorts of things it doesn't like (it flags words like "hello" because it contains a curse word) but which won't do shit to check if you're hoovering up credentials, browsing data, tracking users, etc. If you're unlucky, at some point in the next 24 months you'll trigger a real review from Mozilla and get caught. To be blunt - I have 15 years experience writing extensions. I don't like Google. If you think Mozilla is better you're wrong.