> use unbranded or developer builds
Is that such a problematic thing?
Is that such a problematic thing?
> Most fundamentally, the full Firefox team does not have a common understanding of the role, function, and operation of cryptographic signatures for Firefox add-ons. For instance, although there are several good reasons for signing add-ons (monitoring add-ons not hosted on AMO, blocklisting malicious add-ons, providing cryptographic assurance by chaining add-ons to the Mozilla root), there is no shared consensus on the fundamental rationale for doing so.
https://wiki.mozilla.org/Add-ons/Expired-Certificate-Technic...