Windows 10 reached EOS (end of support) on October 14, 2025. If you are on Windows 10, see this article.

Mozilla Support में खोजें

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More
Solved

I question the security of addon vetting

mishak072

I am looking for an addon which displays times in different locations. I find one, FoxClock, which initially seems to meet my need. However, although the developer says its safe, and it has a Recommended badge, text in the app description says "Access your data for all websites." This may be 'honest' but it seems to be honest at the level of a thief saying "I'm going to rob you." WHY would a clock app need access to my data for all websites? Why would a clock app displaying on my desktop, not my browser, need to access any info about my data for any website? Poor coding? Lazy coding? Dangerous coding? Is this only a result of less than nuanced messaging by the developer or Mozilla, by using a generic message, rather than one which accurately states the 'access' is only for specified installation needs? Or another understandable safe reason? I'd like an explanation, since it does call into question the degree of security offered by Mozilla.

I am looking for an addon which displays times in different locations. I find one, FoxClock, which initially seems to meet my need. However, although the developer says its safe, and it has a Recommended badge, text in the app description says "Access your data for all websites." This may be 'honest' but it seems to be honest at the level of a thief saying "I'm going to rob you." WHY would a clock app need access to my data for all websites? Why would a clock app displaying on my desktop, not my browser, need to access any info about my data for any website? Poor coding? Lazy coding? Dangerous coding? Is this only a result of less than nuanced messaging by the developer or Mozilla, by using a generic message, rather than one which accurately states the 'access' is only for specified installation needs? Or another understandable safe reason? I'd like an explanation, since it does call into question the degree of security offered by Mozilla.

All Replies (3)

चयनित समाधान

Yes just been looking at the extension: which took me to foxclocks.org

and then this https://www.scamadviser.com/check-website/foxclocks.org

and this

Company Rating We see that the owner of the website is using a service to hide his/her identity.

Tags Payment Methods - Reliable

It is not open source: Source code released under All Rights Reserved

I def would not use it, but . . . I am enough of a freak not to want this sort of unknown.

Still many people are not as bothered as I am

Have you looked for another 'clock'

https://addons.mozilla.org/en-US/firefox/addon/worldclock/ Permissions and data Data collection:

   The developer says this extension doesn't require data collection.

I can understand why that wording raises a red flag. The permission is quite broad, and Firefox’s own explanation says it can allow an extension to read the content of webpages and data entered into them, so I wouldn’t ignore it just because the add-on has a Recommended badge. At the same time, the permission doesn’t necessarily mean the developer is actually collecting or sending all that information. It can simply be required by the way the extension interacts with Firefox. I’d check exactly what FoxClock uses that permission for before installing it. I’d apply the same principle to any tool handling data, including something like Phonexa: the requested permissions should make sense for what the software actually does.

Thanks guys for your replies. I'll just have to continue looking.

प्रश्न पूछें

You must log in to your account to reply to posts. Please start a new question, if you do not have an account yet.