Come to think of it, even better would be to attach this feature to whole containers...
Come to think of it, even better would be to attach this feature to whole containers...
This type of telemetry can go die in a fire for all I'm concerned, but these trackers are particularly devious with their constantly changing domains and URLs. Addons that allow for things like regex matching are the only solution that seems to work because the Pihole blacklist doesn't seem to block them sufficiently.
Mozilla has already killed off malicious addons by enforcing their signature requirements. I'm not sure what this adds, I doubt Mozilla will hire someone to monitor the changes to banking URLs around the world (a necessity if this is indeed intended to make banking safer).
I don't think those signing requirements do what you think they do.
Which is why I'd leave uBlock whitelisted. I never said I want to block all extensions!
> I doubt Mozilla will hire someone to monitor the changes to banking URLs around the world
uBlock effectively does this for advertising domains. Why is that any different?
uBlock was just an example, of course. There are other addons that do more complex auto detection.
I’ve specifically used Greasemonkey to fix bank breaking pasting into fields and blocking password managers by splitting login form into deliberately broken pieces.
What would just limiting the "fix" of blocking it to inevitably only some set of US banks (as I doubht they get the all URLs to every bank in the world) achieve?
Are you really not understanding this threat model?
Also - if you want to blacklist certain extensions from certain sites, you abso-freaking-lutely can already... see: https://github.com/mozilla/policy-templates/blob/master/READ...
you want the `restricted_domains` field.
It gets worse - Mozilla is the fucking worst at checking submitted extensions. They tried to the play into the whole "app store" thing that Google/Apple were doing, but those are justifiable cost centers at those two companies in a way that just doesn't work for a player like Mozilla.
Mozilla's store checks for extensions are fairly pathetic. You can submit a near empty shell with excessive permissions, get approved the first time, then auto-update to a new release (which will deploy to users immediately thanks to auto-updates). That new version has to pass a battery of useless automatic SAST checks, which will happily highlight all sorts of things it doesn't like (it flags words like "hello" because it contains a curse word) but which won't do shit to check if you're hoovering up credentials, browsing data, tracking users, etc.
If you're unlucky, at some point in the next 24 months you'll trigger a real review from Mozilla and get caught.
To be blunt - I have 15 years experience writing extensions. I don't like Google. If you think Mozilla is better you're wrong.
If an extension is known and trusted, why does there need to be a Mozilla-controlled kill switch for it?
In my case I'd put uBlock on my "yes I trust this extension" list and when I visit my banking website only that extension would be active.
It's also not "Mozilla-controlled". It's a feature that will, in the future, come with sensible defaults, just as uBlock does with their default blocklists, but in 116 the user will be able to more fully configure the feature. Meanwhile, in 115 the feature isn't active by default because the extension whitelist and domain list are empty.
> It's also not "Mozilla-controlled".
It's not? The bugzilla entry at https://bugzilla.mozilla.org/show_bug.cgi?id=1832791 says
We need to have ability to set the list of
quarantined domains remotely.
Which sounds pretty Mozilla-controlled to me. I hope that Mozilla will allow reasonable user control over all of this. I'm aware of their stated plans, but until we don't know what will be until they actually implement them.How do they establish trust for an extension?
How many dollars do you want to wager that they are building this feature with the intent to get sued so that they can be forced by the courts to turn it on for sites like youtube?
Good god, the conspiracy theories are next level with this one...