3 ms·
If the server is yours it will probably be rejected. Definitely will be rejected by Mozilla. Userscripts is a notable exception of this rule as in this case th
by ameshkov 3y ago
If the server is yours it will probably be rejected. Definitely will be rejected by Mozilla.
Userscripts is a notable exception of this rule as in this case the user instructs the extension what JS to execute.
- Wowfunhappy 3y agoYes, but Chrome allows users to sideload extensions.
- ameshkov 3y agoFirefox kinda also does. In both cases side loading is rather painful experience, thanks to all the malware that is exploiting the extensions feature.
- Wowfunhappy 3y agoFirefox extensions don't need to be listed in the web store, but they must be signed by Mozilla, no exceptions. I have used both browsers, and I find sideloading in Chrome to be completely painless. I use many sideloaded extensions in Chrome (mostly because I wanted to make small edits to existing extensions). I guess I'm trying to figure out whether all this fuss is really a limitation of Manifest v3, or merely Chrome Web Store policy. If the latter, I don't see a problem as long as sideloading is possible, and I really hope UBlock Origin will just go that route. Sideloading is the real freedom which everyone should rally around and protect. (I am extremely unhappy with Mozilla's approach to this, if you can't tell.)
- ameshkov 3y agoThe most problematic part of MV3 (removing part of the webRequest API functionality) is a part of the platform. This remote JS stuff is a CWS policy.
- Wowfunhappy 3y agoSo what can the webRequest API do that couldn't just be accomplished via Javascript injection? From my perspective—admittedly not really understanding how UBlock Origin works—Javascript is basically all-powerful on a web page. Once you have that, I'm surprised that anything else could be a meaningful restriction. (I appreciate you answering my questions!)
- ameshkov 3y agoJS is important, but it’s only a part of what’s required. webRequest allows the extension to manipulate web requests: blocking or redirecting them. MV3 tries to replace the old webRequest with a declarative alternative and it’s almost impossible to provide a declarative rule for every possible use case.
- lxgr 3y agoJavascript is very powerful, but simple injected Javascript can't e.g. undo requests (from other scripts or just normal resources like third-party images) that have already happened. An injected script is not guaranteed to run before the site's own scripts, I believe. Other than that, you can probably really do everything you could do with the webRequest API, but the complexity of doing it essentially reduces to the halting problem: You'd have to statically analyze all Javascript loaded by the page and figure out if it's going to do any requests you don't want to happen and then rewrite these parts. Maybe there's clever things you could do by shimming all web APIs that can issue HTTP or other requests, but that also doesn't sound fun. On the other hand, with an API that just gets to veto every outgoing request, you can trivially achieve the same goal. Another area where in-page Javascript is limited compared to an extension is the same origin policy. A very fancy ad-blocking extension could e.g. run an image classification AI on third-party image resources and hide the ones that look like visually distracting, flashing etc. ads by default – in-page Javascript can't.
- Wowfunhappy 3y agoThank you! I guess the main problem is figuring out which elements are ads. Blocking certain requests is a handy way to do that, at least for as long as external ad servers are the norm. > Simple injected Javascript can't e.g. undo requests (from other scripts or just normal resources like third-party images) But could you detect the request, see what element it loaded in, and then hide that element? Or is that much more complicated than I'm imagining?
- vetinari 3y ago> Firefox extensions don't need to be listed in the web store, but they must be signed by Mozilla, no exceptions. There is. But you must be running firefox on Linux, on specific distribution (i.e. Debian or Fedora), built by that distribution and the extension has to be installed system-wide by root. Then the signature won't be enforced.
- Wowfunhappy 3y agoSo in a sense you're not running Firefox anymore, you're running a derivative from your distro which modified the source code. (I do appreciate that they do this, however.)
- fwn 3y agoOn Firefox for Android all extensions must be present in the AMO store at the time of installation, no sideloading - even of signed addons. Mozilla banned non-store extensions in their last Firefox for Android overhaul a few years ago and afaik does not plan to allow them again. This is the reason why the anti-paywall extensions are all gone/DMCAed. It's a massive power shift away from the user. No idea why Mozilla did that.
- zarzavat 3y agoHow do you develop extensions then? Surely it must be possible somehow.
- NBPEL 3y agoNot impossible, at all. The answer is Firefox Nightly or Firefox Developer, you're freely to install unsigned addons in these editions.
- fwn 3y ago> Not impossible, at all. The answer is Firefox Nightly or Firefox Developer, you're freely to install unsigned addons in these editions. I do use Firefox for Android Nightly. How would I install an unsigned addon there? I don't think it's possible. ... but if it were, this would be very useful to get the Anti-Paywall addons back.
- NBPEL 3y agoIt's called Sideload XPI, iirc Firefox Nightly allows you to sideload XPI if you enable Experimental by tapping Firefox logo in About 7 times. But it's easier with Ice Raven or Smart Cookie Web Preview: - https://old.reddit.com/r/browsers/comments/18ezd3g/iceraven_now_allows_extensions_to_be_installed/ https://old.reddit.com/r/browsers/comments/18ezd3g/iceraven_... - https://github.com/CookieJarApps/SmartCookieWeb-Preview/releases/ https://github.com/CookieJarApps/SmartCookieWeb-Preview/rele...
- mx20 3y ago
- lxgr 3y agoGetting non-technical users used to regularly sideloading extensions sounds like a recipe for disaster in terms of security. I'm also not sure if sideloaded extensions can receive automatic updates, but the much bigger problem is getting people used to sideloading unsigned extensions with full web site access: Tech support scammers will have a field day with that.
- Wowfunhappy 3y agoIt wouldn't be good for security. But I fundamentally believe that user freedom—the ability to do what big tech would rather they did not, such as adblocking—fundamentally depends on sideloading. You simply can't have one without the other. You're trusting the vendor to decide which software is safe, but that vendor will inevitably also consider which software makes them money. On platforms where sideloading is either impossible (iOS) or usual (Android), adblockers are completely inaffective. The gatekeepers simply don't allow them to exist. This is true even though the maker of iOS ostensibly (!) isn't ad supported. > I'm also not sure if sideloaded extensions can receive automatic updates They can't (at least without some external software), which is why the ability to load remote Javascript would be important. For less frequent updates, they could prompt the user.
- no_wizard 3y agoThere’s a legal avenue for this kind of thing too: pass laws that enforce clear and transparent rules around what the gatekeeper can do and give legal recourse to participants to hold said gatekeeper accountable if they break them.
- Wowfunhappy 3y agoBut it's still like putting the coal companies in charge of the EPA. You can add laws and mandates to try to tie their hands, but they're going to push the boundaries as much as they possibly can. You could have app approvals go through some truly public, government-run agency... except frankly I'd object to that too on free-speech grounds.
- 3y ago
- vGPU 3y ago> Unsigned extensions can be installed in the Developer Edition, Nightly, and ESR versions of Firefox, after toggling the xpinstall. signatures. required preference in about:config So I guess not in regular?
- Wowfunhappy 3y agoExactly, not in regular, in those builds the xpinstall flag is ignored. A lot of people recommend switching to Developer Edition to use unsigned extensions, but that's aligned to the Beta update channel. There's no way to get stable releases + unsigned extensions. Whatever the security argument, I find this completely antithetical to user freedom, especially given that it's allowed in Chrome! I just can't believe that Mozilla is the one restricting their own users. (It's also news to me that unsigned extensions can be enabled in ESR, I thought it was just Nightly and Developer. That's nice I guess.)
- vGPU 3y agoAgreed, it’s definitely not in line with their stated philosophy. Sadly, Mozilla has been drifting away from it more and more lately.