I don't want to know how many browsers do not verify #XPI signatures anymore... Like zombies, walking around

If you disabled xpinstall.signatures.required make sure you reenable it now! :firefox: :doomguy:

And pass this reminder on to your peers and channels

Follow

@martin it isn't like having xpinstall.signatures.required set to false exposes you to danger if you don't run Windows

the reason why the feature came to be was because windows share/ad/spyware kept installing toolbars and other unwelcome things into Firefox locally without Mozilla being able to remotely keep those away and the browser free

if you're using a package manager and don't install random shit from the internet, this isn't really a threat vector for you

Sign in to participate in the conversation
chaos.social

The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!