Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Mozilla bans all extensions that execute remote code
#1
Information 
Quote:
[Image: mozilla-block-addons.png]

Mozilla added a number of extensions for the Firefox web browser that execute code remotely to the organization's blocklist in the beginning of November.

The bugzilla listing shows only IDs of the extensions and (almost) no names but the move appears to have affected several translation add-ons for the browser that injected Google Translate or Bing Translate code into websites to provide users of the web browser with page translation functionality.

The developers of Page Translator and Google Translate this page revealed recently that their extensions were banned by Mozilla. Several other translator extensions, Babelfox, Google Translate Element or Bridge Translate seem to be affected by the ban as well.

The developer of Page Translator offers insights into what happened in the past couple of days. The extension used Google Translate or Microsoft Translator libraries to provide Firefox users with in-line language translation capabilities. It downloaded the JavaScript file and injected it into pages to provide on-page translations.

Mozilla disallowed execution of external remote code for listed extensions for some time. Extensions listed on AMO were not allowed to execute remote code; the same was not true in all cases for self-hosted, read unlisted, extensions.

The developer had the extension removed from AMO when Mozilla made the initial policy change but did offer it as an unlisted add-on to users. According to him, the extension was used by thousands of users who used it to translate pages in Firefox.

Mozilla put the extension on a blacklist which killed it remotely in all Firefox installations that did not have the blacklisting functionality disabled.

An exchange with a Mozilla representative confirmed Mozilla's stance on the matter.

Quote:I've read your article, but unfortunately this is not a restriction we will be lifting.

If you find a way to provide this feature in compliance with our policies, we'd be willing to lift the block in a way that you could submit a new version for your users.
...
Continue Reading
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
GFYI [Official] Wise Video Converter Pr...
WINNERS, Your win ...jasonX — 04:26
Advanced SystemCare PRO 17
Advanced SystemCare ...zevish — 10:04
Brave 1.65.114
Release Channel 1....harlan4096 — 06:53
Brave Search: Answer with AI takes over,...
Brave Search's new...harlan4096 — 06:33
Waterfox G6.0.12
Waterfox G6.0.12​ ...harlan4096 — 15:56

[-]
Birthdays
Today's Birthdays
avatar (36)RobertUtelt
Upcoming Birthdays
avatar (43)wapedDow
avatar (42)techlignub
avatar (41)Stevenmam
avatar (48)onlinbah
avatar (49)steakelask
avatar (43)Termoplenka
avatar (41)bycoPaist
avatar (47)pieloKat
avatar (41)ilyagNeexy
avatar (49)donitascene
avatar (49)Toligo

[-]
Online Staff
There are no staff members currently online.

>