this post was submitted on 29 Oct 2025
        
      
      479 points (99.2% liked)
      Technology
    75756 readers
  
      
      7114 users here now
      This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
        founded 2 years ago
      
      MODERATORS
      
    you are viewing a single comment's thread
view the rest of the comments
    view the rest of the comments
It is possible that any developer could just say "none" even if the extension does collect data? If it has to be manually disclosed, this won't stop malicious actors. Only trustworthy extension developers would disclose this.
Since some extensions are "mozilla-approved", I guess they test it regularly, it wouldn't be hard to verify if one is really sending anything despite their disclosure.
@This2ShallPass @themachinestops As an extension developper on Mozilla's store, yes it's definitely possible. There's some automatic review process but what you state in your implicit data consent disclosure (that's how they call it) is up to the developer.
However, the extension can't access all websites unless you specifically allow it while installing. There's an "All websites" permission, so if it's that or if it includes some kind of sketchy site then it's a bad sign.
Finally, just like any web page, you can always inspect an extension and check the network requests to see if it's doing malicious stuff. If so, then you can report it.
But since mozilla accounts are free and only require a verified email, they could just create another one. It's an endless game of whack-a-mole!