4 ms·
and yet: https://addons.mozilla.org/en-US/firefox/addon/privacy-badger-firefox/?src=search https://addons.mozilla.org/en-US/firefox/addon/privacy-badge... Give
by justcommenting 12y ago
and yet: https://addons.mozilla.org/en-US/firefox/addon/privacy-badger-firefox/?src=search https://addons.mozilla.org/en-US/firefox/addon/privacy-badge...
Given the inconsistency of EFF and Mozilla's "policy" on this issue, plausible context to what's written might include something like an inability to upstream HTTPSEverywhere into Firefox by default due to political pushback from large advertising sponsors of Mozilla. EFF certainly resolved these issues for PrivacyBadger, which nevertheless has problems of its own.
Similarly, working with Mozilla to make AMO more secure for everyone by default seems like a pretty straightforward and desirable option for EFF. it's unclear why that hasn't happened here..and perhaps having useful code upstreamed into a larger project doesn't earn people enough credit and recognition. maybe we'll see a BetterAMOEverywhere extension that would enable EFF to integrate HTTPSEverywhere into AMO. ;-)
Yet here we are in 2014 with HTTPSEverywhere not baked into Firefox by default default and a world in which non-techies can't even find what should be browser-integrated functionality in the same place they find most other extensions. Awesome.
The effect for most users is not unlike the the sort of bikeshedding over GPL vs. BSD licenses that has kept so much of the internet in plaintext [0].
[0] as mentioned in phk's 'operation orchestra' talk
- edraferi 12y ago...working with Mozilla to make AMO more secure for everyone by default seems like a pretty straightforward and desirable option for EFF. it's unclear why that hasn't happened here. The bug report [1] was closed as WONTFIX. Essentially, AMO is more worried about malicious updates by extension authors than hijacking of legitimate extensions: The "hijacking" we worry about is from the addon authors themselves: we review and OK a benign add-on and then it self-updates into malware or adware. This is not a hypothetical worry. The EFF isn't going to do that, obviously, but the number of entities we trust to that extent who cannot simply host on AMO is so small that we can't spare the coding resources to create an exception mechanism. [1] https://bugzilla.mozilla.org/show_bug.cgi?id=999014 https://bugzilla.mozilla.org/show_bug.cgi?id=999014
- justcommenting 12y agoto me, WONTFIX is just a signal that personal conversations with Mozilla devs as humans--or at least a more subtle understanding of why Mozilla's not budging--are that much more important as next steps. and i don't necessarily disagree with the technical merits of EFF's position, either. but what does it say about EFF if they don't feel the same way about PrivacyBadger being available through AMO? seems inconsistent, if we're to take the given rationale at face value. and more broadly, it seems clear that if EFF's goal is to maximize the number of people using HTTPSEverywhere, the status quo for providing access to their code is not optimal. i hope Mozilla/EFF will be able to work out a solution that increases the availability of HTTPSEverywhere's functionality.