Firefox 115 can remotely disable any extension on any site
lapcatsoftware.com
lapcatsoftware.com
However this feature can be disabled, or otherwise overridden at this time by the end user when following the documentation[0].
I can understand the concern here, but this change is being communicated, can be user managed, and the best faith interpretation I can come up with, is in fact for security purposes. It creates restrictions on (at least from Mozilla’s perspective) untrusted extensions. I mean how many extensions are there that do act maliciously? It probably isn’t trivial.
I highly recommend you use a minimum amount of extensions anyway. The OP’s extension is a good one from what I can tell but I really only use uBlock Origin, Bitwarden, and tab containers at this point. I guess whenever I use Gnome I end up having to use their extension too which is frustrating but a different story.
Will have to pay attention to this feature. Thanks for sharing the link.
[0]: https://support.mozilla.org/en-US/kb/quarantined-domains
I support plenty of end users on Chrome and Edge at work and will happily oblige my wife by installing and configuring Chrome on all her devices. Firefox is what works for me and what I am comfortable using at this time. Unusable was certainly a hyperbole on my part.
I've never used Linux full-time, but from my understanding, neither GNOME Web nor Konqueror are Blink-based. Are they missing critical power user features?
> Despite being a component of GNOME, Web has no dependency on GNOME components, so it can be potentially installed on any system supporting GTK and WebKitGTK.
If not, your only way of fighting back is using Firefox and Safari, so that people still make websites that work in something else than Chrome and Google's monopoly isn't complete.
Then I have no way of fighting back, because I don't use Apple machines and Firefox no longer meets my needs and I have significant performance problems with it.
Over years I've found it really useful to accurately test web-page developments for Apple device compatibility on Linux distros without needing an Apple device or emulator.
That is not to imply the surrounding browser 'chrome' and UI is equivalent - but rendering certainly is close enough that most of the time pixel-accurate comparisons are valid.
Even Debian keeps up-to-date with latest webkit upstream. E.g. right now (Jul 5th 2023) Debian's libwebkit2gtk 2.40.2-1~deb12u1 (on Debian 12 Bookworm) shows this Changelog:
webkit2gtk (2.40.2-1~deb12u1) bookworm-security; urgency=medium
* Rebuild for bookworm-security.
* The WebKitGTK security advisory WSA-2023-0004 lists the following
security fixes in the latest versions of WebKitGTK:
- CVE-2023-28204 and CVE-2023-32373 (fixed in 2.40.2).
-- Alberto Garcia <berto@igalia.com> Wed, 14 Jun 2023 11:00:05 +0200
webkit2gtk (2.40.2-1) unstable; urgency=high
* New upstream release.
* debian/rules:
- Pass -VNone to dh_makeshlibs for javascriptcore to keep the behavior
of the debhelper compat level 11 and earlier.
-- Alberto Garcia <berto@igalia.com> Tue, 30 May 2023 10:19:01 +0200totally different experience, FF ESR decided to update itself just the other day and break a bunch of stuff out of the blue, because of course moz://a knows better what I need and when I need it. It is very sad people like me need to put up with this abusive behaviour because the alternatives are worse
They disabled the setting to enable XUL extensions.
They disabled a bunch of extensions I had installed on firefox android.
As long as FF doesn't buy into Manifest v3.
Which it will.
Because it will.
I would have been OK with it if it didn't come with the loss of functionality.
Good times figuring out why users couldn't access certain sites after ignoring the vague opt-out message, good times.
As for telemetry, I’m talking about this particular incident, where the “user studies” feature was used to force an unrelated update:
Because they've been doing the exact same thing to that, packing it away more and more, slowly killing off the parts that made it a great power user and developer browser by just making them a little bit harder to use or get to every time.
And "it's confidential" is the worst possible answer but it's still the one they gave us.
> The best faith interpretation I can come up with, is in fact for security purposes. It creates restrictions on (at least from Mozilla’s perspective) untrusted extensions. I mean how many extensions are there that do act maliciously? It probably isn’t trivial.
My best interpretation of that is it allows organizations to more easily allow some extensions while disallowing others.
This is of course, complete speculation and if it was for enterprise management reasons, Mozilla should have clearly communicated it.
The reason this feature is there is that many extensions play poorly with or should not have access at all to specific sites. For example, Grammarly has no business accessing a corporate billing system and IT might want to disable access. In other cases an extension slows a site massively and a user might want to say, "not that site" to an extension. This could be the start of a big end-user improvement, especially if it can be managed by users and installers.
I say this because I already have had to modify a text file in my profile to get firefox to do what I want (tree style tabs without dupe tab-bar on top).
also, by "firefox 225" I wonder how easy it will be to arbitrarily modify a 'protected' app/system text file (this is already difficult on smartphones)
What security problem would be addressed by this? Why would Mozilla need to disable "untrusted" extensions for only certain websites? Why would a website need to be quarentined from an extension, instead of the other way around?
I would think that the remote kill switch for a specific extension addresses the actual security concerns, or Mozilla just not allow 'untrusted extensions' by default on any website.
I don't think Mozilla is evil for doing this, but I do find the motivation for this confusing.
Come to think of it, even better would be to attach this feature to whole containers...
This type of telemetry can go die in a fire for all I'm concerned, but these trackers are particularly devious with their constantly changing domains and URLs. Addons that allow for things like regex matching are the only solution that seems to work because the Pihole blacklist doesn't seem to block them sufficiently.
Mozilla has already killed off malicious addons by enforcing their signature requirements. I'm not sure what this adds, I doubt Mozilla will hire someone to monitor the changes to banking URLs around the world (a necessity if this is indeed intended to make banking safer).
Which is why I'd leave uBlock whitelisted. I never said I want to block all extensions!
> I doubt Mozilla will hire someone to monitor the changes to banking URLs around the world
uBlock effectively does this for advertising domains. Why is that any different?
uBlock was just an example, of course. There are other addons that do more complex auto detection.
I’ve specifically used Greasemonkey to fix bank breaking pasting into fields and blocking password managers by splitting login form into deliberately broken pieces.
I don't think those signing requirements do what you think they do.
What would just limiting the "fix" of blocking it to inevitably only some set of US banks (as I doubht they get the all URLs to every bank in the world) achieve?
Are you really not understanding this threat model?
If an extension is known and trusted, why does there need to be a Mozilla-controlled kill switch for it?
In my case I'd put uBlock on my "yes I trust this extension" list and when I visit my banking website only that extension would be active.
It's also not "Mozilla-controlled". It's a feature that will, in the future, come with sensible defaults, just as uBlock does with their default blocklists, but in 116 the user will be able to more fully configure the feature. Meanwhile, in 115 the feature isn't active by default because the extension whitelist and domain list are empty.
How do they establish trust for an extension?
How many dollars do you want to wager that they are building this feature with the intent to get sued so that they can be forced by the courts to turn it on for sites like youtube?
Good god, the conspiracy theories are next level with this one...
> It's also not "Mozilla-controlled".
It's not? The bugzilla entry at https://bugzilla.mozilla.org/show_bug.cgi?id=1832791 says
We need to have ability to set the list of
quarantined domains remotely.
Which sounds pretty Mozilla-controlled to me. I hope that Mozilla will allow reasonable user control over all of this. I'm aware of their stated plans, but until we don't know what will be until they actually implement them.Also - if you want to blacklist certain extensions from certain sites, you abso-freaking-lutely can already... see: https://github.com/mozilla/policy-templates/blob/master/READ...
you want the `restricted_domains` field.
It gets worse - Mozilla is the fucking worst at checking submitted extensions. They tried to the play into the whole "app store" thing that Google/Apple were doing, but those are justifiable cost centers at those two companies in a way that just doesn't work for a player like Mozilla.
Mozilla's store checks for extensions are fairly pathetic. You can submit a near empty shell with excessive permissions, get approved the first time, then auto-update to a new release (which will deploy to users immediately thanks to auto-updates). That new version has to pass a battery of useless automatic SAST checks, which will happily highlight all sorts of things it doesn't like (it flags words like "hello" because it contains a curse word) but which won't do shit to check if you're hoovering up credentials, browsing data, tracking users, etc.
If you're unlucky, at some point in the next 24 months you'll trigger a real review from Mozilla and get caught.
To be blunt - I have 15 years experience writing extensions. I don't like Google. If you think Mozilla is better you're wrong.
> ...for various reasons, including security concerns.
Security is just a red herring.
Who wins with this move? The cynic in me (who is usually annoyingly right) says Google. Mozilla loses even more trust from its users and Firefox now has a tool to disable ad blockers on websites of their biggest competitor^Wsponsor if they reach a suitable mutual agreement (read: G pays enough for it). Win-win for all the parties that have a say in this. Not users of course, but that's life.
Yes, this is what got my spidey-sense tingling, too.
This replaces the Gnome Extensions app and the browser extension.
If only Xfce supported wayland.
In the release notes which 95% of users don't read, and in a text label hidden in a toolbar menu. No informed consent or prompt to opt-in. And Mozilla hasn't disclosed their criteria for inclusion of websites, and what they plan to use it for.
I agree with you that Mozilla has certainly dropped the ball regarding this change. Much like pocket, the Mr Robot ARG, the Quantum update, DoH with Cloudflare as the default provider, and so on. But again all but the Quantum update have been user configurable, and in my experience, have not been reverted unlike my browser preferences on Windows, where Edge hijacks anything and everything with very little recourse.
that's... not a valid argument for this discussion? market share and user conservatism has no connection to concerns about basic safety affecting everyone
judgement should be applied equally, every user and every product
I believe the intention was to argue against the notion that 95% of users don't read release notes. The contention seems to be that, because Firefox users are more technical (or enthusiast, perhaps), more than 5% of Firefox users would read be aware of this change.
Now I agree that this change is not being communicated properly but to claim that the Firefox user is similar to the average computer user is not something I would agree with.
Is Mozilla content with that market share? If not, it must act with the assumption that its users are average.
Likewise... who's to blame if a rogue addon isn't responded too?
Same arguments get bundled about stuff for iOS and it's absolutely responsible for companies to be proactive about issues with stuff like automatic updates because failure to do is, in aggregate, is worse because of stuff like zero days.
I don't know their exact argument, but I would assume a better place for a notice like this would be a popup or some kind of tiny tooltip window when you update to Firefox 115 that says "hey, we can disable an extension at any time if we find reason to believe they're acting untrustworthy and misbehaving, you can disable that behavior by going here."
I cannot fathom how someone would disagree with this user experience suggestion around this new feature.
I guess I need to read every line of the source code, too. After all, they publish the code, so that's fair warning.
> Likewise... who's to blame if a rogue addon isn't responded too?
The person who chose to install it.
Given that Firefox auto-updates, and most of the time doesn't put up a "What's New" type page after the update installs, I don't think it's reasonable to expect that most users would even know that there's a separate release notes page, let alone that they should read it.
Are users giving informed consent for Google's ability to remotely disable Android apps or Apple's ability to do the same on iOS?
The ability to disable malware as it is discovered seems to be a very common pattern.
If you include the bundled malware scanners on MacOS and Windows, it's taking place on them as well.
No, but we expect Google to be user-hostile. We expect the opposite of Mozilla.
This feature does seem like it's designed to help defend against bad plugins, but in other hands it could be a source of worry.
This why Brave has far surpassed Firefox at this point.
- Good privacy defaults
- Adblocking
- The iOS browser actually has ad-blocking (this alone is why I shy every layman away from Firefox, fuck Mozilla for specifically locking those users out in the cold)
- Choose your own blocklists
- Anti-fingerprinting
- Soon cookie auto-delete
- Soon port scan blocking
- WebRTC protection
- HTTPS upgrading (less relevant these days but hey)
- IPFS
- Tor
They also have a viable business model beyond “pay me off, Google”. And that is not to mention how Mozilla has chosen to soak their entire culture in ultra-progressive nonsense instead of rooting it in tech.
Yes, Brave appending affiliate links was scummy (although not particularly harmful to their users). But that is quite some time ago now.
I was a Mozilla / Firefox stan for a very very very long time. I still love Thunderbird, especially the progress they’re making now. But Firefox (and to a lesser point Mozilla) has completely lost its way.
I keep forgetting Mozilla is a political action organization that occasionally distributes web browsers. Or at least that's how they envision themselves. Maybe if they focused more on the bug-fixing and the browser-making and less on trivial updates they wouldn't be at < 5% market share right now.
Two things coming in the (near?) future:
- vertical tabs get a number or background color when collapsed, helping visual differentiation and memorization
- tab ‘+’ button moved to more convenient location
Bookmarks don’t have tags, and I haven’t heard much noise about planned improvement (or users needing improvement) there.
Key words "at this time". In a few versions maybe they take that away and you can't block ads ok YouTube because Google threatened them.
Building the capability and hiding the options in the about config is opening the door to a lot of bad decisions later on.
https://www.ghacks.net/2023/04/20/mozilla-removes-bypass-pay...
But they still have to sign it, even if you're offering your extension somewhere else.
https://blog.mozilla.org/addons/2015/02/10/extension-signing...
And since they already built the requisite system needed to fulfill Google's demand, they won't be able to claim it would be too much work to implement. They're setting themselves up to readily comply with the demand when it comes.
Given the number of extensions silently purchased by people seeking to spy and push malware, I've minimized the use of extensions that aren't vetted in advance by Mozilla/Firefox.
> Recommended extensions undergo full code review by staff security experts to provide a strong additional security check.
https://blog.mozilla.org/en/products/firefox/firefox-recomme...
Though this kind of thing will generally be removed by the extension block list, not merely blocked from working on some domains.
It's up to another layer of security to help the user not install extensions (or any other software) that they do not want on their machine.
This security is a farce anyway. Firefox is installed in the user profile so any sufficiently advanced malware can just patch the firefox binary and embed itself in there or disable this nonsense. The extension shenanigans is just done to take away user control, with the excuse being to protect users from malware.
That makes zero sense from security perspective.
It would be like asking antivirus to only let virus access D:\ drive...
But even in the very best case, it's yet another custom "premium support" feature either way, like the Public Suffix List. They should push for standards instead, these kinds of things are always leaky and sometimes dangerous.
Anyway. I just meant that extensions are not trustworthy just because they're installed. Malicious vectors exist, and protecting people from themselves / them understandably not being an up-to-date expert in all things tech by the millions-to-billions is largely a good thing.
For now.
You used to be able to install any extension in firefox mobile, but they blocked that without any option to override it.
> However this feature can be disabled, or otherwise overridden at this time by the end user when following the documentation[0].
Nefarious features 'enabled by default' is the standard of Firefox. What else have they switched on behind the user's back then?
> I highly recommend you use a minimum amount of extensions anyway. The OP’s extension is a good one from what I can tell but I really only use uBlock Origin, Bitwarden, and tab containers at this point. I guess whenever I use Gnome I end up having to use their extension too which is frustrating but a different story.
You might as well use Brave Browser at this point.
All the fixups, for five: browser.fixup.alternate.* (multiple) browser.fixup.dns_first_for_single_words browser.fixup.fallback-to-https (If I type something in the url bar I damn well mean it! It'd be fine if it tried others, but it tries them and then stays on them, meaning I have to retype urls to get it to load the actual thing I want.) There's a few others that I don't _need_ but do use that I'm not including here.
System-provided custom CAs, for another, and removing the CAs I don't trust and am not likely to be impacted by removing. I don't need or want trust in a Turkish CA, for example. Cert stuff in particular gets worse every year, and here's another specific example of that: security.certerrors.permanentOverride. Enough said, I hope. At least they give me the option to make it temporary again.
There's no GPSD support in any easily available Firefox: https://bugzilla.mozilla.org/show_bug.cgi?id=1250922#c24 and they're going to remove it (again) because they didn't maintain it: https://bugzilla.mozilla.org/show_bug.cgi?id=1803234. Now I need dbus and geoclue, I guess. Where are the docs on how? I think it's clear enough that Firefox is not being made for the _users_ with this topic.
There are more, but I hope this is enough to show that they exist. These are the most egregious, for me - if they were removed I would stop using the web entirely the same way I've stopped using my cell phone for everything except work.
findbar.highlightall is essential for me
extensions.pocket.enabled
hide "are you sure" dialog when opening about:config
browser.urlbar.clickselectsall (now defunct)
extensions.checkCompatibility & friends (not sure if still necessary since I can't recall why I'm using it in the first place)
browser.backspace_action (might be platform dependent?)
browser.tabs.tabMinWidth
browser.compactmode.show
user.js customization because when I use tree style tabs there's redundant UI elements
What domains are in this "new quarantined domain list"?
> I really only use uBlock Origin, Bitwarden, and tab containers at this point.
Stylus, Privacy, Bypass Paywalls, and OneTab are up there in "essential" extensions.
Now, this is an extension I didn't know I needed. I'm baffled that there are some things without which the web is unusable for me. Looking at my extension list, on Firefox I have:
- ClearURLs - Clickbait remover for YouTube - Cookie Autodelete - Firefox Multi-account container - I don't care about cookies (not updated since bought by Avast) - Privacy badger - Tampermonkey - Tridactyl - uBlock Origin
I feel like I'm pretty conservative with the add-ons that I install, yet I can't comfortably browse the web if I'm missing one of them. When did everything go so wrong?
It is possible to reject consent instead of blindly accepting them with IDCAC... and also the Avast thing
Consent-O-Matic submits those forms on your behalf. I don't want that. I'd rather not participate at all.
Yes, the web is hostile. It's frankly incredible we're still allowed the power to control our user agents like we do. If the web was built today it would be a locked down nightmare controlled 100% by corporate interests.
In an ideal world governments are accountable to a well-educated populace and enact the will of the people to rein in the excesses of the greedy and powerful. Of course that is not how it currently works, but that is the ideal to strive for.
Karl Marx showed 150 years ago that a state under capitalism is a capitalist state and therefore predominated by the interests of capital itself, an observation that has never been refuted.
Is that sarcasm? It was a terrible point.
And any lack of efficacy of said regulation is straightforwardly due to corporate influence on governments.
I was fine with this solution. Most people don't care this much about privacy, and the govt is already violating it harder than anything else.
Corporate nightmare.
Tell me what the banner on https://gdpr.eu/ says.
How come I live under those same regulations yet don't have any such annoying popups on my sites? I thought they were cause by that regulation?
Thos awful regulations don't go far enough. GDPR is 1% of the step in the right direction. Any pain is like the first initial pain from poking at a boil. The sane reaction is to lance that fucker with extreme prejudice not friggn back off and let it continue slowly eating you alive.
The best way to deal with that crap is to use uBlock Origin's cosmetic filters to simply remove those prompts from the page. No extra extension needed, and you don't need to opt-in or opt-out. Remove the prompt and ignore it.
The css property 'user-select' exists to allow developer stop user from select something like button text by accident. But end up abused so heavily. And you can neither disable all of them because you don't know if they use it in good faith.
Adblock is interesting because for adblock to work, you need some engineer hours working to find a good filter to delete ads on websites that don't have active countermeasures, and potentially in websites all over the world in languages as well (I'm bilingual, and I see that ublock origin still works in non-english websites).
Now if you throw in websites with active adblock countermeasures, it seems the proposition that a free, mostly self-governed extension all has that figured out just seems impossible, but it seems to work quite well (albeit with a few notable blocking failures, especially at Facebook which has extremely aggressive anti-adblock features)
I often have to manually delete tracking elements that make my URLs long and nasty, but I just realized that only happens when I copy a link that I haven't visited yet. ClearURL has been on my back this whole time!
You can disable this behaviour by setting `dom.event.clipboardevents.enabled` to False; However this also disables copy functionality on sites.
My own speculation is that this is them warding against extension-takeovers, where people sell off their semi-successful extension to some company which then fills it up with spyware. If Mozilla fills up their quarantine list with domains that're easy targets for stealing valuable information (banks, etc), that'd reduce the incentive to do such takeovers.
My charitable guess for this one is block things like Honey (which essentially slurps your browsing history in return for affiliate discounts) from things like banking websites. But I'll disable it for now and see what the UI is later.
I haven't tried servo since right after the transition to the Linux foundation. It seemed good for most of my browsing already, but with a bad ui. I looked for any good tickets for new contributors but all I found was something about xml parsing that I am unqualified for, plus I hate xml. If we could throw out weight behind it I think it could be an alternative for everything that shouldn't be a web app or native app.
I don't buy that. If they learn that an extension has been taken over, then they can just block the extension.
Also, why the domain list? If some extension has started cryptomining, why will Mozilla protect me only when I visit selected domains? And why the tight lips?
The goal would be to stop compromised extensions from being able to hit high value targets even before anyone has realized they're compromised. They won't get that valuable window in which the malicious update has gone out, but nobody has realized that it was malicious.
> If some extension has started cryptomining, why will Mozilla protect me only when I visit selected domains?
Because they're not protecting against cryptomining, they're protecting against data theft, which is naturally going to focus on certain high-value domains.
I can't imagine that's their plan unless they really are trying to chase away the few FF users left.
I presume that this means extensions for which they actually do verify that updates are non-malicious, which probably includes most of the popular extensions. Hard to say exactly which -- uBlock was called out as being one in the article, but there's nothing on its addon page[1] specifically flagging it as being on that list.
[1]: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...
Your solution is reactive. If I install a useful extension but want to ensure it can't access internal or sensitive websites (least privilege, basic cybersecurity) why would I want to wait until Mozilla disables the extension, after it is discovered to be malicious?
This seems to provide a user-controllable override of an extension's settings to enhance security, and I'm here for it.
That's just configuration, easy to change. And if they change that configuration in response to a lawsuit, Mozilla can play the victim and say their hand was forced.
If they had to ban uBlock Origin outright that would probably kill Firefox's (already abysmal) install base. Neither Mozilla nor Google wants that; they want Firefox to remain as an obscure but technically viable competitor. What they're doing now is laying the groundwork for banning uBlock Origin on only some websites while allowing it to continue working on most. This let's Google have their cake and eat it too; Firefox surviving as nominal competition to Chrome but no longer blocking ads on Youtube.
https://news.ycombinator.com/item?id=36591247#36591664
Basically it's intended to be a user defined middle ground between allowing permissions everywhere vs the developer hand curating a list of allowed sites.
Hmmm...
> We need to have ability to set the list of quarantined domains remotely.
> Filing as confidential for now,
> "Only some extensions monitored by Mozilla are allowed on this site to protect your data."
I didn't know Mozilla was the user of my local Firefox instance :P
(Well, doesn't matter much to me honestly. I only use LibreWolf.)
As I understand it, this just a safetly precaution. They will likely default opt out unmonitored extensions from certain high value sites (banks, email, etc) and allow users to explicitly opt back in. This, to me, seems perfectly reasonable
If you want Mozilla to get a free pass, that's your business. To me, what they shipped matters and said about it matters too. It says a lot about Mozilla that they seemingly didn't see how this would look optically, or perhaps simply don't care.
And no, "Chrome is worse" is not a good answer. I don't want good to be the enemy of great, but I'm not making excuses for enshittification either.
We're both operating on assumptions. Mine is based on the discussion and work taking place in: https://bugzilla.mozilla.org/show_bug.cgi?id=1837670
You're assuming this will be (ab)used before that lands, if it ever lands.
However, we're both just making conjecture until one of those realities (or another) is observed.
If the true purpose of this was to give organizations (or individual users) the ability to control specific websites that extensions couldn't run on for security/sensitivity reasons, then why is it only a subset of extensions that Mozilla determines?
A true user-defined restrict list could, in theory, be a useful feature but as I said, this feature is NOT "here's a list of websites, don't allow ANY extensions to run on it" it is instead "Mozilla is supplying a list of websites, which you can override, but in both cases Mozilla will determine which 'trusted' addons can run on those specific websites using rules/procedures only Mozilla knows and controls."
Claiming this is meant to be org/user controllable is very inaccurate. Just because there's some about:config stuff doesn't mean a Mozilla website list and a Mozilla "trusted" addon list are anywhere close to "intended to be user defined." In fact the evidence shows that is objectively not true.
First, there's two categories of add-ons:
- add-ons that get audited by Mozilla - add-ons that do not
The ones they audit enjoy Mozillas endorsement in the app store, and an exemption from the quarantined sites setting.
The quarantined sites setting only differentiates between the two categories. The audited apps are known to be non malicious, so they are exempt from the quarantined sites setting. The other add-ons are unknowns, and this sets a default access level.
The ability to granularly opt extensions in/out is being worked on, and will likely ship with 116, per the comment I linked:
The majority of device with web browsers cannot use Safari. I can't use it at all.
Not on any of my devices.
https://blog.mozilla.org/addons/2015/02/10/extension-signing...
all the bugzilla items: https://bugzilla.mozilla.org/buglist.cgi?bug_status=UNCONFIR...
if you have access to their project tracking, it's under WEBEXT-1351 (would love if someone can post the entire reasoning for the feature here, as their conversations are now behind login which i didn't bother to secure)
The code for what the user can see/allow per-domain https://hg.mozilla.org/mozilla-central/rev/4399291987d9 (not released as far as i can tell) you can see the file locally via `resource://gre/modules/ExtensionPermissions.sys.mjs` in your address bar.
and lastly, the dev doc on how to push those values to live user browsers https://firefox-source-docs.mozilla.org/toolkit/mozapps/exte...
this is already how it works on Firefox for android, with NO USER WHITELIST OPTION... the only workaround on android is to add another hidden setting that points to a user-defined collection in addons.mozilla.org, which will be the allowed extension list instead of mozilla's.
edit; HOLY SHIT!!! just updated firefox for android, and they removed access to about:config there in the last version! (ps: they had already removed since 2020 for "regular lowly users" who do not install experimental version, their words. Now it is also removed from f-droid stable build since last version. I didn't see it mentioned on the release notes, so they either strong armed the maintainer or slipped changes past them)
It's a shame, because I can see where this will lead to beyond the obvious of just extensions today. The domains list will be tied to country codes. So it will become a situation where "if country X then block politically objectionable domain Y!" where Y can be a site that criticizes the ruling party or the usual crew of copyright carpetbaggers wanting various sites blocked from the browser end, etc. And it will actually cover a lot of scope, you already see some of this beginning where they have started blocking some US states from viewing pornography, but with this method, you can block an entire country from all porn domains at once just by making the browser refer to a master blacklist.
On the bright side, Firefox may be able to soon access the lucrative North Korean market since all domains will be blocked.
https://blog.mozilla.org/netpolicy/2023/06/26/france-browser...
https://www.dailymail.co.uk/news/article-12234299/We-want-po...
https://lapcatsoftware.com/articles/StopTheMadness-Firefox.h...
Mozilla restricts extensions on some domains on Firefox 115 - https://news.ycombinator.com/item?id=36591247 - July 2023 (91 comments)
How can you say it's not new when it's literally in the release notes for yesterday's Firefox update?
> For at least the last couple of years (maybe longer, that's just how long I've used Firefox on Windows) some sites are hardcoded not to allow extensions to run on them.
Yes, the setting extensions.webextensions.restrictedDomains is old, and it applies to every extension, including uBlock Origin. The domains are all Mozilla. Here's the complete list:
accounts-static.cdn.mozilla.net,accounts.firefox.com,addons.cdn.mozilla.net,addons.mozilla.org,api.accounts.firefox.com,content.cdn.mozilla.net,discovery.addons.mozilla.org,install.mozilla.org,oauth.accounts.firefox.com,profile.accounts.firefox.com,support.mozilla.org,sync.services.mozilla.com
Edit: oops, looks like 115 is the next ESR version, does that mean it gets this "feature" but for a long time will not get proper UI go control it? :-(
example.org, paypal.tld, stripe.com, deutsche-bank-24.tld, bankofamerica.tld, apis.google.com, www.facebook.com/plugins/, platform.twitter.com/widgets
I used to use violentmonkey to fix websites that I don't like for various reasons. After they rewrote firefox mobile they tried to and mostly succeeded in getting rid of extensions, which IIRC they claimed they didn't know people cared so much about. Now you need a firefox account and firefox nightly (with even more telemetry) to use perfectly working extensions which aren't included in their whitelist. In what way does this show respecting its users' extension choices?
Because comments like this add nothing to the discourse. They're angry opinions that serve only to attract controversy. I'd call it flamebait except I do think the comments are made in good faith, even if they aren't constructive or particularly interesting.
Just use Brave.