Hacker News new | ask | show | jobs
by acdha 4136 days ago
The Mozilla blog post answered all of these questions but the sophos click-bait had to leave them out to support their narrative:

https://blog.mozilla.org/addons/2015/02/10/extension-signing...

The short answer is that you can still have AMO sign an extension even if you distribute elsewhere (e.g. the way password managers like to ship one installer for everything) and the nightly / developer builds will allow unsigned extensions for obvious reasons. They are planning a private-app signing process but the details aren't public yet.