If anyone from Firefox is reading these, I'd love a way to link an extension to a Github repository with a particular hash, and have users be able to verify that the code in the extension actually matches what's in the repo. Currently, even if an extension "lives" on GitHub, there's no way to know that what's in the extension library matches what's on Github.
Chrome is very strict, as of the last several months, about what they allow. There's even a sticky in the support group for people whose extensions have been stuck in review for more than 3 weeks:
https://groups.google.com/a/chromium.org/forum/?utm_medium=e...
Chrome is getting more granular in their approval process, but it seems that they're still a bit behind.
SmallPeePeeMan 13 hours ago [dead] [–]
I’m an extension reviewer at adding.mozilla.org. Extensions that request certain permissions are manually reviewed. Others are automatically approved. Recommend extensions are ALWAYS manually reviewed for each update.
I'm curious what the _manual review_ process looks like. There are so many questions that come to mind: Is it a single person or multiple individuals reviewing the extension? Does it require the reviewer to be familiar with the code base of the extension? Wouldn't that be a significant burden, or are these reviews cursory? Do the reviews take 10 minutes? 30 minutes? days? Is the review documented? Can the review be public? Do they review the source code on github/gitlab/etc or are they reviewing the submitted file(s)?Not ideal, but it's better than nothing.
I'm reminded of the ArchLinux AUR, which deals with a problem kind of like this. AUR managers show a diff of what changed in a package on each update.
Perhaps one could make extension auditing easier by scripting together a Git repository from extracted xpis, and presenting updates as patches to that repository. This is probably only viable for high-security environments - it's not with it in the common case.
Of course, the real fix would come from Firefox itself: it should provide signed extensions and a way to tie them back to Git repositories with source code, which would eliminate the need for the above automation, and allow people to crowdsource extension auditing.
My experience: I have a moderately popular extension that initially only supported a couple sites so I set the permissions accordingly. I would extend permissions every time I added support for another site. However, with each permission increase my extension gets completely disabled for every user with a very scary warning that suggests something nefarious is happening. With each permission update I would lose HALF of my users. My alternatives are activeTab (awful user experience) or just being greedy with my permissions. I went with the latter.
[0] https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
Perhaps it would be possible to create more granular controls, although I don't think it would be a simple task.
The current situation, is unfortunately bad for both users who must grant scary permissions to use useful extensions, and for extension authors who must ask for permissions that are more broad than what they really need, because it is the only option.
I believe Pushbullet got caught using too many permissions recently.