Hi Monsieur Fabrice, 

On Wednesday, February 19, 2014 7:55:10 AM UTC+8, Fabrice Desré wrote:
> 
> We need a way to install apps from local sources for that to work. Which
> 
> means that we need to transfer the app and enough meta-data to replicate
> 
> the installation on another device. And we need to make that not be a
> 
> security hole or an easy way to steal paid apps...
> 

Yes, these are very valid and reasonable points. 

However given the Web nature of FireFox OS itself, there's isn't much standing 
in the way of malicious intent to steal paid apps hosted online either. 

For example, one could root the device to extract the HTML5 source files, alter 
the manifest, re-package the app and host it on a 3rd-party server where other 
users could then install the app 'legitimately'. 

We could possibly avoid that by translating the HTML5 source into C/C++, 
compiling to binary and assigning each binary package a unique 
checksum/identifier that Mozilla could track globally, but somehow it seems to 
me this would philosophically be no different from the Apple or Google approach 
and a step backwards for software freedom. 

Or we could just accept /sdcard/ as a valid host domain and apply 
navigator.mozApps.installPackage("/sdcard/<app package>") the same way it 
currently handles apps hosted on HTTP servers. 

Please share with us what Mozilla's views are on this matter. 

Many thanks and best regards, 


Hugh
_______________________________________________
dev-b2g mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-b2g

Reply via email to