Новый Mozilla Firefox с новыми расширениями
Стильно, модно, молодёжно.
Mozilla Foundation публикует победную запись в блоге: Make your Firefox browser a privacy superpower with these extensions.
И внезапно выясняется, что
With this extension, I see that for every page you load in your browser, there is a
POST
tohttp://136.243.163.73/
. The posted data is garbled, maybe someone will have the time to investigate further.
Ну и развязка: Firefox Add-On With 220,000+ Installs Caught Collecting Users' Browsing History.
Где там было сравнение производительности движков? «Servo ворует ваши личные данные вдвое быстрее, чем Gecko и XUL».
Ну и, для тех, кто забыл, 2 года назад вся эта ахинея начиналась так:
More Secure Extensions
Because extensions built with the Add-on SDK can request XPCOM privileges, they could still introduce unintentional security and stability issues into Firefox. Even add-ons written by well-meaning developers can accidentally introduce vulnerabilities that could allow malicious code to execute with the full privileges of the browser. WebExtensions uses its manifest.json to mitigate this by requiring add-on authors to declare up front which permissions their code will need to operate. Unlike the Add-on SDK, WebExtensions does not allow arbitrary XUL/XPCOM access, so even insecure/vulnerable code is limited to its whitelisted subset of functionality. This vastly reduces the vulnerability surface of a WebExtension, leading to faster review times and a more stable browser.