Поиск в Поддержке

Избегайте мошенников, выдающих себя за службу поддержки. Мы никогда не попросим вас позвонить, отправить текстовое сообщение или поделиться личной информацией. Сообщайте о подозрительной активности, используя функцию «Пожаловаться».

Подробнее

Extensions Security Deficit

  • 1 ответ
  • 0 имеют эту проблему
  • 4 просмотра
  • Последний ответ от James McAllister-Barnard

more options

I am observing a trend where popular extensions, such as the "I don't care about cookies" extension, change ownership and become derelict and/or malware, as clearly pointed out in recent reviews for the extensions. However, it takes multiple clicks to get to this information in the reviews, and there is very little curation.

I understand it is likely highly infeasible to audit extensions for malware in any comprehensive way, however I definitely feel that there is room for enhancement of the present processes.

I think this extension search process should be more proactive in informing users of these events. For example, rather than just displaying a star rating next to the extension name, displaying chronological trends would be more information-dense. Like if recent reviews are trending negative. This could also reward and incentivise extensions which are properly supported, (and not malware), displaying that their reviews are maintaining / increasing positivity over time.

A supporting feature could be publicising changes of ownership of an extension prominently - "This extension has changed ownership N times, the most recent change was Y-date to X-owner. Reviews have trended Z since that time".

Is something like this being worked on already? If so I am interested in contributing to it.

I am observing a trend where popular extensions, such as the "I don't care about cookies" extension, change ownership and become derelict and/or malware, as clearly pointed out in recent reviews for the extensions. However, it takes multiple clicks to get to this information in the reviews, and there is very little curation. I understand it is likely highly infeasible to audit extensions for malware in any comprehensive way, however I definitely feel that there is room for enhancement of the present processes. I think this extension search process should be more proactive in informing users of these events. For example, rather than just displaying a star rating next to the extension name, displaying chronological trends would be more information-dense. Like if recent reviews are trending negative. This could also reward and incentivise extensions which are properly supported, (and not malware), displaying that their reviews are maintaining / increasing positivity over time. A supporting feature could be publicising changes of ownership of an extension prominently - "This extension has changed ownership N times, the most recent change was Y-date to X-owner. Reviews have trended Z since that time". Is something like this being worked on already? If so I am interested in contributing to it.

Все ответы (1)

more options

Also, I note that the community fork of the "I don't care about cookies" extension --

https://addons.mozilla.org/en-US/firefox/addon/istilldontcareaboutcookies/?utm_source=addons.mozilla.org&utm_medium=referral&utm_content=search

appears lower in search results and displays a security warning flag, compared to the original extension --

https://addons.mozilla.org/en-US/firefox/addon/i-dont-care-about-cookies/?utm_source=addons.mozilla.org&utm_medium=referral&utm_content=search

which presents no security warning yet is according to the comments both derelict and malware.

Seems like undesirable behaviour of these flags. Inverse, really, of their purpose.

Полезно?

Задать вопрос

Для ответа на сообщения вы должны войти в свою учётную запись. Пожалуйста, задайте новый вопрос, если у вас ещё нет учётной записи.