I'm looking forward to capability-based systems with microkernels, since they really improve on the situation, but I think it'll take a while until we get some major ones. Maybe Google's Fuchsia will establish itself soon enough, who knows? (We'll also have to see what can be done about hardware security, since any software mitigation could potentially be rendered useless by insecure hardware.)
Linux gets there a different way. The standard way to install applications is from the package manager and essentially all of the applications in there are trustworthy (because they're all open source and if they did anything seriously user-hostile, someone would fork it and that version would be the one in the package manager). Meanwhile the package managers do actually add nearly everything that isn't user-hostile, so the need to install anything from another source, while still possible, is rare enough that most people never have to do it.
And binaries downloaded via web browser don't even have the execute bit set by default. You can still do it, but you have to know how, and the people who know enough to know how to do it generally know enough to be suspicious when doing it.
And even then, things typically run as the user rather than root/administrator, so they can't alter the system or anything other than that one user's (presumably backed up) home directory.
Having even more granular permission would be even better, but restricting the harm to one home directory of one user and only in cases of users who are at the same time knowledgeable and stupid has already handled basically the entire problem.
The difference is that Linux repositories are less noteworthy to attack, have a more distributed culture not ruled by capitulating lawyers, and can actually jurisdiction shop.
The ultimate problem is a lack of a cross-software security model of the OSs, Linux included. User-based isolation is cool and all, but orthogonal to the modern world [0]. For decades we've been continually looking for better ways of isolating local apps, while also rejecting centralized control. We keep looking, while centralization keeps ratcheting.
I'm still hopeful that a well done capability (handle-based) system would go a long way, but not fully solve it. Unfortunately that means shedding off POSIX/LSB rather than duplicating the entire monolithic OS environment for every security context.
[0] Where say even a local LAN IP address is security-critical information!
And they still work precisely because the user can do that.
> For decades we've been continually looking for better ways of isolating local apps, while also rejecting centralized control.
The main issue is that there is so little real benefit in it. It's possible to isolate e.g. LibreOffice so that it can't access anything it shouldn't, but in general the authors can be trusted not to be doing anything nefarious to begin with, so what you're really doing is limiting the damage in the event of compromise. In which case you're still pretty screwed, because it inherently needs access to your documents, so the focus has not surprisingly been on preventing compromise rather than mitigating after the fact.
> We keep looking, while centralization keeps ratcheting.
The motivations behind the rise in centralization are authoritarian and pecuniary rather than any legitimate security concern. Trying to prevent it by finding alternative ways to improve security is like trying to repeal the DMCA anti-circumvention rules by finding alternative ways to reduce piracy. They'll never be satisfied because their motivations aren't the stated ones.
It's a dream. Kept alive by a very diligent community, but let's not kid ourselves that it's a very strong assumption.
> In which case you're still pretty screwed, because it inherently needs access to your documents
Access to the specific document you presently want to edit (say through an OS-provided file select dialog or equivalent cli) is much different than unfettered access to all of your files.
> The motivations behind the rise in centralization are authoritarian and pecuniary rather than any legitimate security concern
People do choose say Apple products precisely because of the curated Disneyland App store. Centralizers certainly have their selfish motives, but people are driven into their arms looking for safety. Browsers are used for software distribution precisely because they're a sandbox - there's much less fear of the unknown than running a random exe.
This is one thing I like about Android. You can avoid requesting file permissions for your app by using native intents for file access. I think its the same for other stuff, like email. As much as I loathe Googles control over Android, I think this is a good thing.
And you can install an anti-paywall extension in Firefox.
The moment you concede the Linux "well you can work around it" argument is the moment you have to stop arguing on pure absolute principle and start arguing about practicality and the relative difficulty of workarounds.
And of course the next step would be DMCA takedowns for applications in the appstore. Everyone's computer would effectively be under US jurisdiction.
"It's not gonna happen. Firefox would be dead by now if it still allowed users to customize their webbrowser and make Firefox unusable (as in slow, unstable, and btw insecure), because users wouldn't keep up with that for too long. They'd just use another browser. This may be okay with you for now because you know how to protect yourself against misconfiguration, but in the long run Mozilla needs market share to stay relevant and be able to compete with the richest companies on this planet."
Substitute in any positive feature that puts the user in control of their web browsing experience, power over something means the power to break it too, using that as a reason to remove functionality is stupid.
Doubly so when you pile on the "omg if they do this mozilla is doomed" hysterics.
If the problem in your point of view is that I didn't /prove/ how big of a problem sideloading was then yes, I didn't even attempt to do that. There's a separate subthread on that question.
That's why your logic is flawed. If a construct can be used to "prove" various known-false statements then it has no value in proving anything.
> If the problem in your point of view is that I didn't /prove/ how big of a problem sideloading was then yes, I didn't even attempt to do that. There's a separate subthread on that question.
There is no proof of it there either. The most popular platforms (Android on mobile and Windows on desktop) allow the user to load their own applications, showing not only that it can't be a major cause of failure in the market but that it seems to be a characteristic of the player with the most share.
Yes, if... But it can't. That criticism of my statement didn't make sense.
> There is no proof of it there either. The most popular platforms [...]
I meant this: https://news.ycombinator.com/item?id=18583257
It applies directly. Anything that gives the user a choice can make the user experience worse for a user who makes the wrong one. But it also makes it better for a user who makes the right one in a way different from what the developer would have had to use as a default -- because sometimes something is right for 70% of the users, so it should be the default, but the other 30% are better off with something else. Taking away the choice makes the 30% worse off to benefit the 10% of the 70% that would have chosen incorrectly for themselves. That is not a relative advantage.
> I meant this: https://news.ycombinator.com/item?id=18583257
I'll reply there, but note that you haven't addressed my point -- other platforms survive and indeed have the largest share without prohibiting users from installing software, even when competing directly against others that do.
You are saying it, but not making any argument or offering any evidence for what you're saying.
Not to mention this "telemetry" process is entirely opaque, and used to justify decisions like this in a very Ex Cathedra sorta way, where you either accept the conclusions they have made from data you can't see, or be treated like your opinion is irrelevant.
Its a very hostile way to run a supposedly "Open Source" project.
It's under a GPL-compatible license. Fork it and do what you like.
This is a pretty FUD-y way to FUD your FUD.
Then why is that not itself an obvious solution? Use that data to provide a default-on blacklist of known-malicious addons. Then you have a blacklist rather than a whitelist, so it can justifiably be more difficult for the user to override it and the user has no motivation to do so for a malicious addon they didn't intentionally install to begin with.
It also gives you the opportunity to allow the user to specify a blacklist provider, so that if the original vendor ever gets compromised because they're forced to operate in an oppressive jurisdiction, they can farm out the low-resource task of hosting the blacklist to someone who isn't compromised, and the user (or the distribution packaging the browser) can make that determination for themselves.
Blacklisting depends on a limited supply of whatever you're trying to control. UUIDs are not limited.
More generally, if you come up with an obviously superior solution to a problem that someone else has claimed is important and difficult, and has spent considerable resources addressing, perhaps it would be more constructive to investigate or ask questions to test your understanding of the situation before assuming and asserting that the other people are doing it all wrong?
I'm not saying mozilla has the best possible solution here. I don't know what that would be. I do know (I work for mozilla though not in this area) that the step was taken to address real, and very active, threats to security, privacy, and stability.
Which is a good reason not to use the extension ID as the sole method to enforce the blacklist, and is why anti-malware software generally uses a signature-based approach.
> More generally, if you come up with an obviously superior solution to a problem that someone else has claimed is important and difficult, and has spent considerable resources addressing, perhaps it would be more constructive to investigate or ask questions to test your understanding of the situation before assuming and asserting that the other people are doing it all wrong?
You're implying this is a novel problem that hasn't been widely studied by everyone and that they're not actually doing it all wrong.
> I do know (I work for mozilla though not in this area) that the step was taken to address real, and very active, threats to security, privacy, and stability.
There are many ways to solve a problem by trading it for a set of different problems. Centralized authoritarian control is exactly that. And those things can be popular in the same way anything that externalizes costs and internalizes benefits can be -- because that type of thing seems attractive to the people not directly paying the cost of it. Until the victims (in this case the developers and users whose apps you prohibit) devise a way to protect themselves. Then you end up in an antagonistic relationship with your users and addon developers. What's the cost of that?
Meanwhile there are other solutions that don't do that.
You must see that your ideas are not working. Have you been able to attract new users, or even prevent existing users from leaving? No? So then how can you be so convinced that you are right?
Firefox is software, not an experience. Winning over people that don't care is not an accomplishment, even if you could do it. Trying to be better than Google at nannying your lower functioning users from hurting themselves is futile, and punishes everyone else.
You're feverishly stripping away everything that made Firefox superior. Driving away developers who have made unique extensions that cannot be replicated elsewhere.
And for what? What is your end game? Have you seen the Chrome store? It's awful! The majority of extensions are very low quality and often misleading. And they are unresponsive and have to employ strange hacks to do things that Firefox extensions did very simply (like taking a screenshot, or interacting with other extensions).
And what is your ideal outcome? To have Firefox be considered a good browser by Google's standards? How about what the users standards?
You are trying to slowly turn emacs into an cheaper Microsoft Word. And patting yourself on the backs for doing it.
The people operating the repository want people to use it. They don't want them getting things from untrustworthy places. But if they can just prohibit that, they can be tyrants -- refusing beneficial software that the user wants because the monopoly provider has a conflict of interest or is being coerced by someone else.
By contrast, if the user can load the beneficial application themselves then the repository has the incentive to prevent that from happening (and thereby discourage users from doing that in general) by carrying it themselves. And the fact that there can be competing repositories means that the one that carries the most beneficial software and the least user-hostile software can be the one that wins in the marketplace. But not if the vendor locks everyone else out and becomes an abusive monopolist.
All the more reason to have a supported way to do it. If they require the malware to replace the Firefox binary with a different one, what happens when it does? The user ends up with twelve pieces of malware instead of one because the original malware author didn't bother to support browser updates properly and the user ends up with a browser full of publicly known security vulnerabilities.
> And then Linux is also niche enough as a consumer OS that it's just not as attractive for malware in the first place.
People have been claiming that as the reason there was so much more malware on Windows for decades. Then Windows adopted some of the same types of measures as Linux and the amount of Windows malware fell off considerably.
The rise of Chrome is responsible for all of Mozilla's lost share. But major factors causing Chrome to gain share are being the default on the most popular mobile platform (Android) and being heavily promoted on google.com for many years.
Making it harder to install addons (and breaking all the old ones) is one of the things contributing to Mozilla losing share to Chrome. People used to use Firefox over Chrome because of all the great addons, which they then broke, leaving users with less reason not to use Chrome (which was significantly faster until Firefox Quantum). In other words, the causation is exactly the opposite of what you're suggesting.
Not giving any technical and ux credit to chrome for also being a major factor for firefox's loss of market share is disingenuous IMO.
I want to have a profile for my work, and a personal profile. Chrome provides that, and Firefox, last time I checked, required multiple hoops to enable and also blocked me from having more than one open.
I would even contribute funding to that if Firefox had a "Fund this feature".
If all the add-ons had kept working on FF, then I probably wouldn't have switched browsers.
Users will leave in droves if...Firefox allows you to install third-party extensions if you choose to do so? I don't get it.
And no Mozilla should not be thinking in terms of "market share". There is no market! Mozilla is a non-profit. They should not be sharing the same paradigm as Google. And it is this vanity-driven pursuit of "brand prestige" and "market share" that has ruined things.
It makes business sense for Google's platform for them to do things the way they do. It makes absolutely no sense for Mozilla to emulate Google. The very fact that Mozilla can just afford to make unique software without the constraints of the market, supported by donors, is a strength, not a weakness. They should be leveraging it instead of trying to "stay relevant" and compete with Google on Google's terms.
And this whole incident is a disgrace. If it wasn't for Mozilla getting between users and their software, then this takedown would be nearly irrelevant, as it would be that much easier for users to install it. It would probably even disincentivize take-downs like this, because they would be so futile.