You are saying it, but not making any argument or offering any evidence for what you're saying.
You are saying it, but not making any argument or offering any evidence for what you're saying.
Not to mention this "telemetry" process is entirely opaque, and used to justify decisions like this in a very Ex Cathedra sorta way, where you either accept the conclusions they have made from data you can't see, or be treated like your opinion is irrelevant.
Its a very hostile way to run a supposedly "Open Source" project.
It's under a GPL-compatible license. Fork it and do what you like.
This is a pretty FUD-y way to FUD your FUD.
Then why is that not itself an obvious solution? Use that data to provide a default-on blacklist of known-malicious addons. Then you have a blacklist rather than a whitelist, so it can justifiably be more difficult for the user to override it and the user has no motivation to do so for a malicious addon they didn't intentionally install to begin with.
It also gives you the opportunity to allow the user to specify a blacklist provider, so that if the original vendor ever gets compromised because they're forced to operate in an oppressive jurisdiction, they can farm out the low-resource task of hosting the blacklist to someone who isn't compromised, and the user (or the distribution packaging the browser) can make that determination for themselves.
Blacklisting depends on a limited supply of whatever you're trying to control. UUIDs are not limited.
More generally, if you come up with an obviously superior solution to a problem that someone else has claimed is important and difficult, and has spent considerable resources addressing, perhaps it would be more constructive to investigate or ask questions to test your understanding of the situation before assuming and asserting that the other people are doing it all wrong?
I'm not saying mozilla has the best possible solution here. I don't know what that would be. I do know (I work for mozilla though not in this area) that the step was taken to address real, and very active, threats to security, privacy, and stability.
Which is a good reason not to use the extension ID as the sole method to enforce the blacklist, and is why anti-malware software generally uses a signature-based approach.
> More generally, if you come up with an obviously superior solution to a problem that someone else has claimed is important and difficult, and has spent considerable resources addressing, perhaps it would be more constructive to investigate or ask questions to test your understanding of the situation before assuming and asserting that the other people are doing it all wrong?
You're implying this is a novel problem that hasn't been widely studied by everyone and that they're not actually doing it all wrong.
> I do know (I work for mozilla though not in this area) that the step was taken to address real, and very active, threats to security, privacy, and stability.
There are many ways to solve a problem by trading it for a set of different problems. Centralized authoritarian control is exactly that. And those things can be popular in the same way anything that externalizes costs and internalizes benefits can be -- because that type of thing seems attractive to the people not directly paying the cost of it. Until the victims (in this case the developers and users whose apps you prohibit) devise a way to protect themselves. Then you end up in an antagonistic relationship with your users and addon developers. What's the cost of that?
Meanwhile there are other solutions that don't do that.