4 ms·
TIL: putting code on the firefox addons site makes it secure by pure magic.
by rational-future 12y ago
TIL: putting code on the firefox addons site makes it secure by pure magic.
- mcpherrinm 12y agoWhere "magic" is a review: https://addons.mozilla.org/en-US/developers/docs/policies/reviews https://addons.mozilla.org/en-US/developers/docs/policies/re...
- emn13 12y ago...and reviews by others, and a process by which known bad extensions get taken down. It's not watertight (as the recent abuses in the chrome web store illustrate), but it's better than nothing.
- shock 12y agoAFAIK, Chrome extensions don't go through a review process. SmoothGestures was just one extension that got a new developer and then started submitting every visited url to their servers.
- emn13 12y agoWell, there's certainly some central control even if it's not formal review. Of course, review wouldn't catch everything anyway (I think the ability to identify and block bad actors is more important than the a priori review).
- mey 12y agoIt gives a clear path to revocation of bad actors as well as future updates.
- rational-future 12y agoIt also gives a ton of power to a few large organisations at the expense of small dev shops and advanced users.
- mey 12y agoFirefox doesn't prevent you from installing code directly. I am stating what I find valuable in their add-on marketplace.
- emn13 12y agoTIL: people too lazy to write three whole words are more interested in sarcasm than saying something sensible.