I question the security of addon vetting
I am looking for an addon which displays times in different locations. I find one, FoxClock, which initially seems to meet my need. However, although the developer says its safe, and it has a Recommended badge, text in the app description says "Access your data for all websites." This may be 'honest' but it seems to be honest at the level of a thief saying "I'm going to rob you." WHY would a clock app need access to my data for all websites? Why would a clock app displaying on my desktop, not my browser, need to access any info about my data for any website? Poor coding? Lazy coding? Dangerous coding? Is this only a result of less than nuanced messaging by the developer or Mozilla, by using a generic message, rather than one which accurately states the 'access' is only for specified installation needs? Or another understandable safe reason? I'd like an explanation, since it does call into question the degree of security offered by Mozilla.
All Replies (3)
चयनित समाधान
Yes just been looking at the extension: which took me to foxclocks.org
and then this https://www.scamadviser.com/check-website/foxclocks.org
and this
Company Rating We see that the owner of the website is using a service to hide his/her identity.
Tags Payment Methods - Reliable
It is not open source: Source code released under All Rights Reserved
I def would not use it, but . . . I am enough of a freak not to want this sort of unknown.
Still many people are not as bothered as I am
Have you looked for another 'clock'
https://addons.mozilla.org/en-US/firefox/addon/worldclock/ Permissions and data Data collection:
The developer says this extension doesn't require data collection.
I can understand why that wording raises a red flag. The permission is quite broad, and Firefox’s own explanation says it can allow an extension to read the content of webpages and data entered into them, so I wouldn’t ignore it just because the add-on has a Recommended badge. At the same time, the permission doesn’t necessarily mean the developer is actually collecting or sending all that information. It can simply be required by the way the extension interacts with Firefox. I’d check exactly what FoxClock uses that permission for before installing it. I’d apply the same principle to any tool handling data, including something like Phonexa: the requested permissions should make sense for what the software actually does.
Thanks guys for your replies. I'll just have to continue looking.