logoalt Hacker News

Sephr10/01/20241 replyview on HN

Doesn't this behavior from Mozilla staff indicate that using Firefox extensions at all is a security issue?

This shows that the reviewers may not be competent enough to catch actual malware uploaded to their add-ons site.


Replies

Aachen10/02/2024

Yes. I never took the review process seriously, I assumed people could publish pretty much whatever. Today I learned it's meant to be tight as well as that you can't run your own code anymore; that it needs to go through review or you get to reinstall every time you start your browser.

I've held out for a long time with Mozilla, trusting they thought it's a useful thing to do when they partner with Facebook to make privacy preserving adtech. This is a big ask of me though. I don't use it myself but I'm constantly running into limitations on Android and, at work, iOS because you can't simply do what you want on the devices without all sorts of hoops and fearmongering surrounding having actual access to your own device—the stuff I use my phone for simply doesn't run without root and one can't even make a full system backup without. It's not your device. Learning this about Firefox makes me feel it's not my browser...