Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It would be interesting to receive replies instead of downvotes.


"Their transition from an open source project to an organization receiving millions from the Google search box."

You can be both things. Generally it's nice to be paid for your work.

"The restrictions (based on security reasons) to install an extension from a site different than mozilla addons"

If someone convinces you to install a malicious browser extension (easily done in a world where people will click OK on basically anything) they can spy on and control everything you do online.


> If someone convinces you to install a malicious browser extension (easily done in a world where people will click OK on basically anything) they can spy on and control everything you do online.

Do you think then that for example desktop software must be installed from a central company like Microsoft because someone can convince you to install it from every website?

And also: do you think that Mozilla was really doing security inspections in the early days? No, it wasn't, the extensions had all kind of security bugs. I think it was more about control.


You can install extensions from any site. You'll only get an additional prompt if you're not installing from the mozilla add-on site.

You can think it was about control, but this could not be farther from truth.

<disclaimer>I work for mozilla</disclaimer>


An additional prompt means less conversions.

There are alternative methods that Mozilla could do, like bringing a Mozilla certificate to host the extension in your own site without an extra prompt.


And how would we decide to whom to extend the certificate? To whom should we entrust "conversions"?

You are talking around the larger problem, which is a huge one for many extension and app ecosystems (e.g. Google Play, where weak-AI scanners fail to stop malware and spamware).

Mozilla uses community review, which works much better but is of course imperfect, a human thing.

No one that I know of has solved this larger problem. I would be interested in research pointers and tips (not complaints).

/be


I work for Mozilla, but speak for myself. If you think it was about control, then you don't know how Mozilla works. We fight larger players with one arm tied behind our back because of our commitment to making things open and interoperable. We do it gladly, because we know that sometimes our reference implementation won't be the best implementation, and even if we fail, we want the tech to live on. Every day I have or overhear a discussion about making certain what we build doesn't privilege our own solutions over others. Are we perfect at this? No. Sometimes security of our users trumps a completely level playing field. But every time we have to slightly close a technology, know that it's done extremely begrudgingly.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: