How would I sign a firefox addon that a developer no longer has up on the addon page but I saved it ?


Recommended Posts

You'd have to submit it to Mozilla, but they'll only allow that if the original license allowed for you to do so.

So how do I find the original license holder ? So I can ask if it is ok ?

Someone already did it with the addon but it doesn't work right. The old one works great after manually installing it.

The alternative is compile firefox yourself and disable that sodding extension signing rubbish.

 

That's a horrible idea, up there with not using any AV or firewall on a computer 

The proper solution is to find a maintained extension that does the same thing, there is always an alternative 

 

That's a horrible idea, up there with not using any AV or firewall on a computer 

The proper solution is to find a maintained extension that does the same thing, there is always an alternative 

It's not even remotely related to not using a firewall or AV.

If I want to load an extension or make my own and use it, I damn well will, I couldn't give a ###### what mozilla try to do to stop me, you can't even compare someone writing an extension for a web browser and the browser having ###### unwanted 'you cant use this' protection against someone not using anti-virus software or a firewall to stop viruses/trojans/dodgy network traffic. Not even similar.

...

If I want to load an extension or make my own and use it, I damn well will, I couldn't give a ###### what mozilla try to do to stop me, you can't even compare someone writing an extension for a web browser and the browser having ###### unwanted 'you cant use this' protection against someone not using anti-virus software or a firewall to stop viruses/trojans/dodgy network traffic. Not even similar.

You know you don't have to pay to have your addons signed right? Simply uploading them to addons.mozilla.org results in them getting signed.

I have no idea why anybody would be upset about addon signing.

You know you don't have to pay to have your addons signed right? Simply uploading them to addons.mozilla.org results in them getting signed.

I have no idea why anybody would be upset about addon signing.

It's not about cost, why the heck should I have to upload what I've written to mozilla for something that is not going to be released just for them to 'inspect it'? That's like saying games companies should give away their games to motherboard manufacturers so they can 'inspect how it runs' on their motherboards and certify it.

unpack the extension, update the manifest file, zip as xpi, submit for signing, get a link to the extension and use it for yourself. Worst case scenario: extension is rejected due to coding issues and you have to update the code.

It's not about cost, why the heck should I have to upload what I've written to mozilla for something that is not going to be released just for them to 'inspect it'? That's like saying games companies should give away their games to motherboard manufacturers so they can 'inspect how it runs' on their motherboards and certify it.

Then sign it yourself, Mozilla have said multiple time they aren't going to be the only people who can sign addons.

And game devs do give free copies of their games to hardware companies to see how it runs, it's great marketing for both of them.

Then sign it yourself, Mozilla have said multiple time they aren't going to be the only people who can sign addons.

But doesn't that defeat the purpose of signed addons if you can just sign it yourself.

No? The whole point of code signing is so that you know the file is unchanged from the author.

Anybody can take an addon and sign it, but they can't make it appear to be from the original author.

Then sign it yourself, Mozilla have said multiple time they aren't going to be the only people who can sign addons.

And game devs do give free copies of their games to hardware companies to see how it runs, it's great marketing for both of them.

Go and read the mozilla post on the issue, you cannot sign them yourself, they MUST be uploaded to mozilla and have them approve and sign them
Edit: Here you go; https://blog.mozilla.org/addons/2015/02/10/extension-signing-safer-experience/

"Extension files that aren’t hosted on AMO will have to be submitted to AMO for signing. Developers will need to create accounts and a listing for their extension, which will not be public."

Why not use the Firefox Developer Edition in this case?

because developer with e10 is crap (slow and constant crashes with flash). It's better to sign for your personal use the extension and be done with it.

Well, as far as I know only Nightly and the Developer Edition (Aurora too?) has an override for the signing enforcement.

yes. I still think it's easier to submit the extension by yourself and get a signed version for your personal use (as long as you don't have to modify code to go through the automatic signing process) if you want to keep using a "stable" firefox version

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • A coalition of publishers sued OpenAI and Microsoft over scraping content without consent by Hamid Ganji Image via Depositphotos.com AI companies often rely on readily available internet content to train their chatbots and provide users with instant answers. This method of AI training is fast and relatively inexpensive, but using a website’s content without permission or compensation is not something publishers like to see, and this is exactly why Microsoft and OpenAI are now being sued. As reported by Bloomberg, a group of publishers that collectively own nearly 400 newspapers has filed a lawsuit against OpenAI and Microsoft. The coalition argues that the two companies scraped their content to build AI chatbots like ChatGPT and Copilot without paying any compensation. The complaint, filed in the U.S. District Court for the Southern District of New York, argues that while AI products have generated billions of dollars in market value using publishers’ work, none of that value has been shared with the publishers. The plaintiffs are seeking statutory damages and injunctive relief for alleged copyright infringement and violations of the Digital Millennium Copyright Act. “Defendants systematically and secretly crawled the Publishers’ websites—including content behind paywalls and other access restrictions—and copied the Publishers’ articles, stories, and other original works onto their own servers without authorization,” the complaint states. The publishers also described the AI boom as a “death knell for local journalism” if AI companies that scrape content for free are not held accountable. Former New Jersey Attorney General Matthew Platkin and his law firm, Platkin LLP, are representing the publishers. “Our models empower innovation, are trained on publicly available data, and are grounded in fair use,” OpenAI spokesperson Drew Pusateri told Bloomberg. This is not the first lawsuit involving the unauthorized use of publishers’ content by AI firms, but it is one of the largest coalitions ever formed against the free use of content by AI chatbots. In 2024, OpenAI and Microsoft also faced a similar lawsuit from eight newspapers that claimed AI products were benefiting from their content without permission.
    • Rufus alternative Ventoy now supports Windows 11's mandatory update, fixes major boot bug by Sayan Sen While Microsoft has its own official Media Creation Tool used for making bootable USB media, there are some popular third-party utilities as well which offer additional options like bypassing system requirements, Microsoft Account creation, and more. One of these is Ventoy, and the software has received its latest update today. In fact, the app actually got a slew of updates over the last couple of days, three version releases in total, to be specific. The first release, version 1.1.13, was pulled as there was some unspecified error in the update, and as such, the corrected version 1.1.14 was pushed out. Following that on very short notice, 1.1.15 was published as well. For those unfamiliar, Ventoy is an open-source utility that lets users create a bootable USB drive once and then simply copy ISO, WIM, IMG, VHD, or EFI files onto it without repeatedly formatting the drive. It supports both legacy BIOS and UEFI boot modes, Secure Boot, and a wide range of operating systems, making it one of the most versatile tools in the category. The biggest change in version 1.1.14 is an updated Secure Boot shim file aimed at resolving the UEFI CA 2023 issue, which is basically a compatibility problem that has affected Secure Boot environments on some systems. If you recall, we reported about severe boot issues on HP devices following the release of updated Secure Boot 2023 keys. For anyone who may not be aware, back in early 2024, Microsoft announced that it was updating Secure Boot keys as they were going to become 15 years old in 2026, which is also when they are set to expire. As such, the new 2023 certificates have been rolling out with the newest Windows 11 updates. Updated boot manager and Secure Boot certificates are crucial for protection against malware like bootkits. These are mandatory updates. Alongside that, the VentoyPlugson graphical plugin configurator was updated in sync with the release. The update also introduces a new VTOY_SECURE_BOOT_POLICY option within the Global Control plugin, giving users more flexibility in managing Secure Boot behavior. Ventoy has also received a fix for a startup issue when Secure Boot was disabled. Microsoft does officially allow users to boot systems without Secure Boot as long as the PC is Secure Boot capable. The full changelog is given below: Update secure boot shim file to solve the UEFI CA 2023 issue. The new release use a new CA, so you need to enroll the new key for the first boot time. VentoyPlugson update synchronously. Global control plugin add a VTOY_SECURE_BOOT_POLICY option. Fix the boot issue when Secure Boot is disabled in the UEFI firmware. You can download the latest version of the app here on Ventoy's official GitHub repo or from Neowin software stories.
    • Windows 11 is fine, no issues on any of the machines I've run it on since release. The stricter security requirements are a good thing, sometimes the baseline needs to change and people will winge, but it is what it is. Happened with the move from 9x to NT - broke compatability Happened with XP SP2 when security started to become a serious consideration Certainly happend with Vista that brought in UAC, the concept of not running as admin (something that has been the norm in Linux/Unix from pretty much the start) and a completely new driver stack. Windows 11 will probably get looked back at as the point where even consumer and SMB IT was dragged kicking and screaming into a somewhat secure by default configuration.
    • Bluestacks has been emulating Android on Windows for fifteen years. It's janky and riddled with ads though, so WSA looked like it was going to be a huge improvement over the emulator experience. Too bad Microsoft dropped the ball on that.
    • Classic. China would be nothing without Western, Japanese, and South Korean technology.
  • Recent Achievements

    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
    • Dedicated
      Scoobystu earned a badge
      Dedicated
    • First Post
      Tom Schmidt earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      441
    2. 2
      +Edouard
      172
    3. 3
      PsYcHoKiLLa
      134
    4. 4
      Michael Scrip
      78
    5. 5
      Xenon
      77
  • Tell a friend

    Love Neowin? Tell a friend!