Hacker News new | ask | show | jobs
by octosphere 2541 days ago
> Improved extension security and discovery:

> New reporting feature in about:addons allows you to report security and performance issues with extensions and themes.

> Redesigned extensions dashboard in about:addons provides easy access to information about your extensions, including data and settings access required by each extension. Find high quality, secure extensions via the Recommended Extensions program in about:addons, which now displays user count and ratings for each extension.

> "Recommended” badges for these extensions also appear on AMO. More extensions will be added over time.

I welcome the new changes to the extension ecosystem. For too long extensions were unsupervised and malicious code was allowed to run (remember the Stylish fiasco[0] where your browsing history was siphoned off?).

App stores and extension ecosystems need to be policed with a lot more rigour and code needs to be inspected so that the extension does what it says in the description and nothing more. No ulterior motives. No 'monetizing' of user data, and no surreptitious phoning home to a command and control server with your browsing history.

[0] https://www.ghacks.net/2017/01/04/major-stylish-add-on-chang...

2 comments

Does the new system really stop those shenanigans though? I see notifications for what major areas an addon requires. I don't get notifications if an addon tries to reach out to the internet. Has anyone seen such a notification?
Mozilla do actually do a lot of manual code review, especially for new addons. That was one issue with the big extension migration; it was taking forever for new style addons to be approved.