C
CharlieDontSurf
Do we at least know that the extensions listed on the
Yes and no, I guess. There's a lot of developer eyeballs looking over
that stuff, so the ones on those sites should be alright. Just don't be
first in line when your fave extension is ported over to 1.0PR
There's at least one badly-designed extension that managed to earn its
own vulnerability alert at some security sites:
http://xforce.iss.net/xforce/xfdb/16971
And here's a developer recounting how he *almost* introduced a security
hole in one of his extensions:
http://weblogs.mozillazine.org/weirdal/archives/006137.html
Mozilla, Mozillazine, and mozdev sites are clean?
Yes and no, I guess. There's a lot of developer eyeballs looking over
that stuff, so the ones on those sites should be alright. Just don't be
first in line when your fave extension is ported over to 1.0PR

There's at least one badly-designed extension that managed to earn its
own vulnerability alert at some security sites:
http://xforce.iss.net/xforce/xfdb/16971
And here's a developer recounting how he *almost* introduced a security
hole in one of his extensions:
http://weblogs.mozillazine.org/weirdal/archives/006137.html