Whitelist Attack!

Ask for help about NoScript, no registration needed to post
SurelyHatIngTheTACO

Whitelist Attack!

Post by SurelyHatIngTheTACO »

Firefox's TACO add-on update to v3.01 altered my NoScript Whitelist without my permission. Even after I uninstalled TACO, the “abine:” protocol is among the mandatory items, (e.g., “about:”), on my NoScript Whitelist. How do I fix this?

Especially if you uninstalled TACO v3.0, check your NoScript Whitelist!
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 ( .NET CLR 3.5.30729)
SurelyHatIngTheTACO

Re: Whitelist Attack!

Post by SurelyHatIngTheTACO »

seems like this "attack" violates Mozilla Policies on "Changing of Defaults and Unexpected Features"

TACO changed settings or features in other add-ons (NoScript) and wrongly does so as an update (v2.0 -> v3.0) of an already public add-on (TACO)

AND

Did not clearly state what changes TACO makes to NoScript
Change is NOT 'opt-in'
No 'opt-in' dialog
Uninstalling TACO did not restore NoScript settings

see policy at https://preview.addons.mozilla.org/en-U ... es/reviews

"If you have a question about an Editor's review of an add-on, want to report a policy violation, or want to suggest that your add-on be recommended, please email amo-editors@mozilla.org ." https://preview.addons.mozilla.org/en-U ... es/contact

if other people have similar issues, someone should complain to Mozilla. . .
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 ( .NET CLR 3.5.30729)
Alan Baxter
Ambassador
Posts: 1586
Joined: Fri Mar 20, 2009 4:47 am
Location: Colorado, USA

Re: Whitelist Attack!

Post by Alan Baxter »

SurelyHatIngTheTACO wrote:Firefox's TACO add-on update to v3.01 altered my NoScript Whitelist without my permission. Even after I uninstalled TACO, the “abine:” protocol is among the mandatory items, (e.g., “about:”), on my NoScript Whitelist.
Confirmed with TACO 3.02. Seems to happen only if NoScript is already installed when TACO is installed or updated.
How do I fix this?
I don't know.
Especially if you uninstalled TACO v3.0, check your NoScript Whitelist!
Yup. It's still there, even after TACO is uninstalled.

@Giorgio:
What's the significance of this change? I'd like to be able to say if I complain to AMO about TACO's apparent effect on NoScript.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.4) Gecko/20100611 Firefox/3.6.4
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Whitelist Attack!

Post by Giorgio Maone »

Alan Baxter wrote:@Giorgio:
What's the significance of this change? I'd like to be able to say if I complain to AMO about TACO's apparent effect on NoScript.
IIRC the Abine guys asked me how to add the abine: protocol (which they use for UI stuff) to the whitelist, and I explained the API but also told them about the need of warn the user before making any change (otherwise this is a clear violation of the No Surprises Policy).
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.4) Gecko/20100611 Firefox/3.6.4
Andrew@getabine.com

Re: Whitelist Attack!

Post by Andrew@getabine.com »

What's happened? In trying to respond quickly to user requests around NoScript and TACO interactions we added a change to the NoScript whitelist to account for the operation of the privacy controls of Abine.

The version with this change should have had more user notification. Furthermore, we fail to remove this setting upon uninstalling - we definitely should clean up everything on un-install. We are working on fixing this right now. We'll make this update available in one hour at the link below, as well as part of the next update. Until then just directly remove "abine:" form "noscript.mandatory" in about:config.

http://www.getabine.com/updates/

Our apologies -- making this change was an attempt to quickly address user concerns, but really should have been done in a different way.

-Andrew
andrew@getabine.com
Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.70 Safari/533.4
Guest

Re: Whitelist Attack!

Post by Guest »

Andrew@getabine.com wrote:. . .we added a change to the NoScript whitelist to account for the operation of the privacy controls of Abine.
. . .
-Andrew
andrew@getabine.com


It seems to me that such a change to NoScript by Abine's TACO "cannot be introduced into an update of an already-public add-on; you must have the opt-in change process as part of the initial public nomination." https://addons.mozilla.org/en-US/develo ... n-defaults

If what Abine did violates Firefox add-on policy, I do not care what excuse Abine offers, as that is irrelevant. The only question that remains for me is whether Abine's TACO is treated now by Mozilla consistent with Mozilla add-on policy. Otherwise, my trust in all add-ons, in Firefox and in Mozilla will be further eroded, as it already has been somewhat by the entire Abine TACO fiasco to date.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 ( .NET CLR 3.5.30729)
Guest

Re: Whitelist Attack!

Post by Guest »

Mozilla’s continued inaction in the Abine TACO debacle may be a harbinger of doom for Firefox; although I hope not.

Did anyone complain to amo-editors@mozilla.org about Abine TACO policy violation?
NCSA_Mosaic/2.0 (Windows 3.1)
Post Reply