Skip to main content

Firefox add-ons ‘more difficult’ to hijack, Mozilla claims. But are they?

firefox classic theme restorer add negates version 29 features
Image used with permission by copyright holder

As we reported yesterday, Google had to address an issue with Chrome and tainted browser extensions “Add to Feedly” and “Tweet This Page” that began to spit out unwanted ads, prompting a backlash from users and banishment by Google. After such an incident, you might be concerned that other Web browsers, like Mozilla’s ultra-popular Firefox, could be susceptible to similar shenanigans, and perhaps rightly so.

If you ask Mozilla, however, that issue is not likely to crop up for Firefox users. Here whats a Mozilla spokesperson had to say when asked about the possibility of Firefox add-ons getting hijacked with ad-spamming code the way “Add to “Feedly” and “Tweet This Page” were on Chrome.

Recommended Videos

“For add-ons hosted on addons.mozilla.org, all version updates are code reviewed and tested by a member of our review team, and it needs to pass all of our review policies to be pushed to users via auto-update,” Mozilla’s spokesperon said. “One such policy is that all unexpected changes, such as advertising, needs to be explicitly opt-in. This all makes it more difficult for this kind of hijacking to be effective for add-ons listed on Mozilla Add-ons.” 

According to ghacks.net though, Mozilla Firefox isn’t exactly bulletproof when it comes to add-on hijacks. Ghacks.net indicates that one Firefox add-on dubbed Autocopy was developed, then sold to a company called Wips. Once Autocopy was acquired by Wips, it was then re-jiggered to include code containing ad generating instructions, thereby exploiting a Mozilla add-on approval loophole. 

It’ll be interesting to see what Google, Mozilla, and other heavyweight browser makers will do to ensure that tainted, reengineered browser add-ons don’t sully the web surfing experience for their users.

What do you think? Sound off in the comments below.

Update 1/28/14: A Mozilla rep reached out to us, offering this statement regarding Wips and AutoCopy.

“Version 1.0.8 of AutoCopy is not sending all browsing data to Wips. That can be verified by looking at the source code or installing version 1.0.8 and looking at the network traffic. After version 1.0.8, Wips submitted a new version of Autocopy that sent more data, but that version didn’t pass review. Version 1.0.8 is the latest public version available on Mozilla add-ons and is what the majority of users have installed.”

Topics
Konrad Krawczyk
Former Digital Trends Contributor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
Mozilla Firefox’s new add-on lets you surf the web with your voice
mozilla apple google microsoft lawsuit headquarters

Mozilla is bringing a voice assistant to its Firefox browser. The company has released an experimental, new add-on that lets you surf the web with just your voice. Called Firefox Voice, it’s capable of recognizing natural-language speech and can do much more than simply fire up websites on command.

Firefox Voice offers the ability to perform a whole bunch of browser-related tasks hands-free. Once installed, you can ask it to open websites, switch to another tab, take the current web page’s screenshot, and more. You can invoke it either by clicking the add-on’s button or pressing the keyboard shortcut. Firefox Voice also understands natural language which means you don’t necessarily have to stick to specific commands.

Read more
I finally switched from Chrome to Mozilla Firefox — and you should too
mozilla firefox chrome review comparison 2020 mozillafirefoxcomentillustration

I have been in an on-and-off relationship with Mozilla Firefox for the past five years. Every time I’d get ecstatic over a major new Firefox update -- hoping to, at long last, break free from the hegemony of Google Chrome -- my hopes would be crushed as soon as I began browsing the web like I normally do.

Firefox's performance would fall noticeably short and struggle to keep up with my workflow, sending me scurrying back to Google Chrome after a few minutes of poking around. No matter how compelling the rest of Mozilla’s offerings were, they could never convince me to hit that "Yes" button whenever Firefox asked whether I’d like to set it as my default browser. Catching up to Chrome almost started to seem like a far-fetched goal for Firefox -- until recently.

Read more
This Lenovo ThinkPad is almost $1,800 off today!
A press photo of the ThinkPad X1 Carbon Gen 11.

One of the best laptops for a busy computer-heavy workplace is the Lenovo ThinkPad. For years, this tried and true laptop and 2-in-1 has delivered a fast and reliable Windows experience to many a 9 to 5 go-getter. Processor speed and power evolve year over year, and new features are added to these laptops all the time. This also means you’ll be able to find discounts on older machines, which is precisely what we came across while scouring through Lenovo ThinkPad deals:

Right now, as part of Lenovo’s doorbuster sale, you’ll save $1,800 on the purchase of a brand-new Lenovo ThinkPad X1 Carbon Gen 11 when you order through Lenovo.

Read more