Firefox 8 to block unapproved add-ons
Puts an end to sneaky add-ons installed by other software
Computerworld - Starting with Firefox 8, Mozilla will automatically block browser add-ons installed by other software until users approve them, a company product manager announced yesterday.
Software-bundled add-ons have been a problem for Firefox users, who have sometimes been surprised to find browser extensions show up on their machines without their consent.
An add-on included with Skype, for example, caused such a high number of browser crashes that Mozilla added it to a list of banned extensions last January. And in 2009, an add-on that Microsoft silently slipped into Firefox left browser users open to attack, a fact that Microsoft itself admitted.
"While some of these applications seek the user's permission beforehand, others install add-ons into Firefox without checking to make sure the user actually wants them," said Justin Scott, product manager for add-ons, on a Mozilla company blog.
Scott ticked off numerous issues with such add-ons, ranging from slowing down Firefox's startup and page loading times to not keeping up with Firefox's feature and security updates. "Most importantly, they take the user out of control of their add-ons," Scott said.
Changes slated for Firefox 8, which will hit Mozilla's "Aurora" preview channel next week and is scheduled to release in final form on Nov. 8, will return control to users, argued Scott.
If Firefox 8 finds that another program has installed an add-on, the browser will automatically disable it until the user has agreed to its installation. "Users that want the functionality provided by a third-party-installed add-on can easily allow the installation, while users who don't can cancel or ignore the prompt," said Scott.
Previously-installed add-ons will also be tagged when users upgrade to Firefox 8, and won't be enabled until the user explicitly agrees.
Developers who follow Mozilla's rules -- asking users to opt-in -- will be affected as well as those who try to slip an add-on by users, something that immediately raised questions.
"We have an installer on Windows that installs an add-in to Firefox (via an .exe). Its only job is to install the add-on and the user is agreeing to install the add-on," said Michael Kaply, a former IBM developer who now consults with corporations on customizing Firefox for their workers or clients. "How do we keep this prompt from appearing in this case?" Kaply asked in a comment appended to Scott's blog.
Mozilla didn't have an answer for Kaply.
"Firefox unfortunately doesn't have any way of knowing if the user was ever asked about installing the extension," acknowledged Alex Faaborg, a principal designer at Mozilla, in another comment. "So the only way to ensure user control is to ask them when Firefox launches."
Scott echoed that, saying that impact of bad add-ons outweighed the pain that will be felt by developers who abide by the rules. "Unfortunately, the extent of unwanted add-ons installed through these methods has caused us to take action, but we're confident that users who truly want such add-ons to be installed will opt in when Firefox prompts them," he said.
Users can try out the new add-on management features by downloading Firefox 8 after it lands on the Aurora channel next week.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed . His e-mail address is firstname.lastname@example.org.
- Google reverses field, promises to restore Chrome's scrollbar arrows
- Update: Google ships Chrome 33, patches 28 bugs
- Mozilla's top exec defends in-Firefox ads, revenue search
- Mozilla taps in-Firefox ads as it searches for more revenue
- Mozilla ships Metro Firefox beta for Windows 8
- Mozilla defers Firefox's new 'Australis' UI to April
- Mozilla resets Metro Firefox ship date to mid-March
- Mozilla ships Firefox 26 with opening click-to-play move
- Mozilla banked $274M in '12 from Google-Firefox search deal
- Google trumpets Chrome's SPDY gains
Read more about Desktop Apps in Computerworld's Desktop Apps Topic Center.
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
Red Hat Enterprise Linux - The Original Cloud Operating System
Linux adoption is growing against a number of measures, such as the
number of supercomputers that run Linux and the size of the contributing...
- OpenStack Hype vs. Reality: CIO Quick Pulse Open-source architecture can enable IT departments to build infrastructure-as-a-service (IaaS) clouds running on standard hardware.
- Building a Bridge to the Next Generation Data Center Selecting a widely adopted operating system is a foundational component of a standardization strategy.
- OpenStack and Red Hat: IDC White paper Most OpenStack deployments are by public cloud providers that are early adopters of technology and use OpenStack in a do-it-yourself deployment and support...
- Webinar: Building a Big Data solution that's production-ready Big data solutions are no longer just a nice-to-have.
- Meg Whitman presents Unlocking IT with Big Data During this Web Event you will hear Meg Whitman, President and CEO, HP discuss HAVEn - the #1 Big Data platform, as well... All Desktop Apps White Papers | Webcasts