Here’s an article by Mozilla stating the power of default settings:
https://blog.mozilla.org/blog/2019/06/04/when-it-comes-to-pr...
e: immaigne people down-voting facts https://www.bleepingcomputer.com/news/security/-particle-chr...
> That's just a huge gaping security hole
> If that is indeed how Firefox is designed
that's the whole point I'm trying to make! goddamit stop working on assumption and hypothetical thinking I'm a lunatic, this is a real issue and the actual way firefox works, how do you think all password manager work?
here look yourself https://support.mozilla.org/en-US/kb/permission-request-mess...
and guess what permission the language extension need?
https://addons.mozilla.org/en-US/firefox/addon/automatic-spe...
https://news.ycombinator.com/item?id=21323832
We're not talking about password managers here, we're talking about spelling checkers. If a spelling checker can read passwords, then Firefox has a problem that that has nothing to do with spelling checkers or password managers. You cannot safely use any plugin.
Now, it's possible that Firefox does indeed have this very serious problem, I don't know. But I think it's much more likely that the FF engineers did the obvious thing and excluded password fields from being accessed by plugins by default if they can access text fields. If this were not the case, the complaint would not have been, "FF doesn't have native spell checking", the complaint would have been, "FF has this gaping security hole through which you can drive an M1 Abrams tank."
you're not listening and you're having a very strong opinion on a topic you don't know about, which makes having a discussion frustrating, tedious and very unhackernews-like, the data is before your eyes, believe what you will.
but if you are unwilling to listen, then why ask and answer?
What permission is that? The only permission I see is "Access your data for all websites." If that includes passwords, then FF has much bigger problems than not having native spell checking.
Yes, the text on that page can be interpreted as supporting your position. Still, "Offer a password manager..." is not quite the same thing as "silently read all of your passwords and do whatever the extension wants with them..." I have a very hard time believing that the latter is the case and that no one has sounded the alarm on this yet.
Also, add-ons have been deprecated in favor of extensions.