Comment by jasonkostempski

9 years ago

Before, we didn't need to trust them, because we didn't have to. We had all the code, we could verify the code we can read is the code in the binary we use via checksums. Now the code contains the ability to go fetch arbitrary code behind our backs and run it against our will. Firefox is now malware and it's a real damn shame.

> Now the code contains the ability to go fetch arbitrary code behind our backs and run it against our will.

How is that not what automatic updates are?

  • Right. I trust my browser vendor to send me automatic updates without me reviewing because I believe that's net good for my security. I'd prefer to live in a world where I don't have to question that.

    • There are definitely situations like corporate networks where automatic updates need to be quarantined and tested before rolling them out to all the machines, but since I don't pay a dedicated sysadmin to run tests on all my software on my personal computer before I receive updates, I'm content to trust my browser to update itself and hope it doesn't break anything.

      It's disheartening when the update is a marketing tie-in.