<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mozilla Add-ons Blog &#187; security</title>
	<atom:link href="http://blog.mozilla.com/addons/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mozilla.com/addons</link>
	<description>Official Blog of Mozilla Add-ons</description>
	<lastBuildDate>Thu, 19 Nov 2009 18:52:14 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>No Surprises</title>
		<link>http://blog.mozilla.com/addons/2009/05/01/no-surprises/</link>
		<comments>http://blog.mozilla.com/addons/2009/05/01/no-surprises/#comments</comments>
		<pubDate>Sat, 02 May 2009 04:25:59 +0000</pubDate>
		<dc:creator>Justin Scott (fligtar)</dc:creator>
				<category><![CDATA[developers]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=488</guid>
		<description><![CDATA[Surprises can be appropriate in many situations, but they are not welcome when user security, privacy, and control are at stake. Mozilla is committed to guarding these principles, and we feel that a policy should be adopted that explicitly details our stance on these issues in regard to add-on modifications. The text of our proposal [...]<script type="text/javascript">SHARETHIS.addEntry({ title: "No Surprises", url: "http://blog.mozilla.com/addons/2009/05/01/no-surprises/" });</script>]]></description>
			<content:encoded><![CDATA[<p>Surprises can be appropriate in many situations, but they are <b>not</b> welcome when user security, privacy, and control are at stake. Mozilla is <a href="http://www.mozilla.org/about/manifesto">committed</a> to guarding these principles, and we feel that a policy should be adopted that explicitly details our stance on these issues in regard to add-on modifications. The text of our proposal is below.</p>
<blockquote><p>Changes to default home page and search preferences, as well as settings of other installed add-ons, must be related to the core functionality of the add-on.  If this relation can be established, you must adhere to the following requirements when making changes to these settings:</p>
<ul>
<li>The add-on description must clearly state what changes the add-on makes.</li>
<li>All changes must be &#8216;opt-in&#8217;, meaning the user must take non-default action to enact the change.</li>
<li>Uninstalling the add-on restores the user&#8217;s original settings if they were changed.</li>
</ul>
<p>These are minimum requirements and not a guarantee that your add-on will be approved.
</ul>
</blockquote>
<p>We welcome all constructive feedback and comments on this proposal, preferably in the <a href="http://groups.google.com/group/mozilla.dev.amo/topics">AMO Newsgroup</a>.</p>
<p><a href="http://sharethis.com/item?&wp=2.8.6&amp;publisher=7e0eb025-1057-4238-a77c-a634ef8a9d63&amp;title=No+Surprises&amp;url=http%3A%2F%2Fblog.mozilla.com%2Faddons%2F2009%2F05%2F01%2Fno-surprises%2F">ShareThis</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/addons/2009/05/01/no-surprises/feed/</wfw:commentRss>
		<slash:comments>30</slash:comments>
		</item>
		<item>
		<title>Better Safe than Sorry</title>
		<link>http://blog.mozilla.com/addons/2009/02/08/better-safe-than-sorry/</link>
		<comments>http://blog.mozilla.com/addons/2009/02/08/better-safe-than-sorry/#comments</comments>
		<pubDate>Sun, 08 Feb 2009 19:53:10 +0000</pubDate>
		<dc:creator>Justin Scott (fligtar)</dc:creator>
				<category><![CDATA[developers]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=306</guid>
		<description><![CDATA[Over on the Adblock Plus blog, Wladimir Palant has posted two great articles on how to avoid making some common mistakes in extension development that lead to security vulnerabilities. I highly recommend extension authors check out his posts:

Displaying web content in an extension &#8211; without security issues
Five wrong reasons to use eval() in an extension

The [...]<script type="text/javascript">SHARETHIS.addEntry({ title: "Better Safe than Sorry", url: "http://blog.mozilla.com/addons/2009/02/08/better-safe-than-sorry/" });</script>]]></description>
			<content:encoded><![CDATA[<p>Over on the <a href="http://adblockplus.org/blog/">Adblock Plus blog</a>, Wladimir Palant has posted two great articles on how to avoid making some common mistakes in extension development that lead to security vulnerabilities. I highly recommend extension authors check out his posts:</p>
<ul>
<li><a href="http://adblockplus.org/blog/displaying-web-content-in-an-extension-without-security-issues">Displaying web content in an extension &#8211; without security issues</a></li>
<li><a href="http://adblockplus.org/blog/five-wrong-reasons-to-use-eval-in-an-extension">Five wrong reasons to use eval() in an extension</a></li>
</ul>
<p>The information in these posts is very important for all add-on authors to know, and one of my goals in the coming months is to bring these best practices into one document that is kept up-to-date.</p>
<p>Justin</p>
<p><a href="http://sharethis.com/item?&wp=2.8.6&amp;publisher=7e0eb025-1057-4238-a77c-a634ef8a9d63&amp;title=Better+Safe+than+Sorry&amp;url=http%3A%2F%2Fblog.mozilla.com%2Faddons%2F2009%2F02%2F08%2Fbetter-safe-than-sorry%2F">ShareThis</a></p>]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/addons/2009/02/08/better-safe-than-sorry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
