Increased security when installing extensions
By Remigiusz Bondarowicz2beR. Thursday, September 6, 2012 8:56:40 AM
security, no lock-in, Extensions
Extensions hosted from addons.opera.com are carefully moderated and as such they can be installed in Opera with a minimum of effort. However, since we have no way of knowing the moderation practices of third-party repositories, we need to be more careful with them.
Having studied how people install and use extensions we came to the conclusion that current security dialog is somewhat deficient, in that many users will simply click-through it and add new repositories to the trusted list, without fully understanding the consequences of such an action.
For that reason, we decided to "raise the security bar" and make installation of third-party extensions require a little more thought. Starting with this build we block installation of extensions from all repositories that are not already in the trusted list. Those who understand the risks can click on the help button in the new dialog to find how how to add further repositories to their trusted list. With this change we hope to eliminate accidental additions.
This build also includes a small but nice collection of bug fixes. Enjoy and thanks in advance for the feedback.
Known Issues (see also issues from previous snapshots):
- The Extensions help page is subject to further changes
WARNING: This is a development snapshot: It contains the latest changes, but may also have severe known issues, including crashes and data loss situations. In fact, it may not work at all.
Download
Changelog
Desktop
- DSK-359702 Installation of third-party extensions needs to be safer
- DSK-372133 [Mac] Address field drop-down blinks
- DSK-372147 [Mac] Crash when closing/opening tabs with keyboard short cuts
- DSK-361961 [Linux/FreeBSD] Text in badge positioned too low
- DSK-368636 [Linux/FreeBSD] Multiple selected urls can't be dragged and dropped from links panel to filemanager
- DSK-369738 Sound notifications fail
- DSK-330884 Mouse action does not always apply to the current tab after switching tabs
- DSK-366218 Address bar focused instead of page when using extensions that open new tabs
- EDIT: The Linux/FreeBSD builds have been updated with working plugin wrappers
Yet another snapshotOpera 12.10 beta candidate, now with support for Retina Macs
Comments
D1sasterp1ece # Thursday, September 6, 2012 2:24:13 PM
QuHno # Thursday, September 6, 2012 2:33:24 PM
edit:
For all who have the same problem:
Menu -> Settings -> Preferences -> Advanced -> Security -> Trusted Web sites
add the repository, done.
Ruari Odegaardruario # Thursday, September 6, 2012 2:37:25 PM
Originally posted by QuHno:
Yep, the help page will be updated later, read the known issues:I can't find and hints about how to change the repository list in the help...
Originally posted by Remigiusz Bondarowicz:
That said "Preferences > Advanced > Security > Trusted Websites..." is what you are after.The Extensions help page is subject to further changes
Originally posted by QuHno:
This file is only written (in your profile directory by default) after you start adding sites. So in a clean profile with no sites yet added, it will be empty.there is no path\trusted_repositories.ini where to look up in my clean install
ll3mo # Thursday, September 6, 2012 2:39:05 PM
(windows 8 rp x64, x64 build, hwa and other stuff off)
minho # Thursday, September 6, 2012 2:40:55 PM
press F2
drop down arrow is missing!
Ubuntu 12.04 amd64, Opera x64, hwa off
netmain # Thursday, September 6, 2012 2:41:17 PM
minho # Thursday, September 6, 2012 2:41:35 PM
Originally posted by zombie:
Has the Linux plugin crasher been fixed?
No.
hurug # Thursday, September 6, 2012 2:41:36 PM
Ruari Odegaardruario # Thursday, September 6, 2012 2:42:44 PM
Originally posted by zombie:
Since it is not in the changelog, no!Has the Linux plugin crasher been fixed?
The fix is done internally but may or may not be in the next snapshot, it is reliant on some other changes that are still being tested. It will come with a bunch of other updates when they are all ready.
Rest assured when it is fixed it will be mentioned in the Changelog.
DanielDD64 # Thursday, September 6, 2012 2:43:28 PM
Ruari Odegaardruario # Thursday, September 6, 2012 2:45:17 PM
Originally posted by hurug:
Unless you are forever using new, different repositories (and let's be honest who does that) it is unlikely to make a big difference to you.Let's hope it will not make installing nice extensions too difficult.
If you use the main repository only, it will have no effect. If you use a few alternative repositories, you add them once and you are done. It shouldn't really be a major inconvenience to anyone.
QuHno # Thursday, September 6, 2012 2:47:42 PM
Originally posted by ruario:
Yep, the help page will be updated later, read the known issues:
Thanks, I did, I thought that was something different.
You caught me during editing my post btw.
Patrick O'Reillypaddy2k # Thursday, September 6, 2012 2:48:03 PM
Originally posted by ruario:
Thanks for the update Ruari, I was starting to get quite frustrated that the issue (which is pretty big for Linux users) hasn't even been acknowledged in the updates that had been released since it first broke. Perhaps it could be added to the post above as a known issue so others don't have to go digging through these comments.Originally posted by zombie:
Since it is not in the changelog, no!Has the Linux plugin crasher been fixed?
The fix is done internally but may or may not be in the next snapshot, it is reliant on some other changes that are still being tested. It will come with a bunch of other updates when they are all ready.
Rest assured when it is fixed it will be mentioned in the Changelog.
I need a namequangltm # Thursday, September 6, 2012 2:49:36 PM
edit: i 'll try in tomorrow, have to sleep now
edit 2: I think no
Spadar ShutSpShut # Thursday, September 6, 2012 2:50:02 PM
andrew walkercatbert303 # Thursday, September 6, 2012 2:52:18 PM
It looks like there's a Javascript error causing this,
Uncaught exception: SyntaxError: JSON.parse: Property name (in double quotes) expected: ebar_bo
But interestingly everything works fine if I open twitter in a private tab (and the 12.0 series of builds are fine too)
minho # Thursday, September 6, 2012 2:52:58 PM
Example: http://www.banca-de-revista.com/ (xxx content)
opera:cpu report 98% and Opera becomes very slow.
Ubuntu 12.04 amd, Opera x64, hwa and webgl off, E2140 cpu
Ruari Odegaardruario # Thursday, September 6, 2012 2:53:01 PM
Originally posted by DD64:
Slightly yes, but you only have to do it once.In my opinion, this makes it more complicated to install an extension from other sources.
Originally posted by DD64:
Wouldn't ignore? That is pretty hard to do. A lot of people don't read the big red warning in this blog post and get pretty annoyed when a Next build doesn't start or plugins fail.It would be better to make a more specific warning-message that user wouldn't ignore.
Ruari Odegaardruario # Thursday, September 6, 2012 2:58:01 PM
Originally posted by paddy2k:
The known issues say to read the previous known issues and it is in the known issues for an earlier snapshot. I also acknowledged the issue in the comments of that snapshot.Thanks for the update Ruari, I was starting to get quite frustrated that the issue (which is pretty big for Linux users) hasn't even been acknowledged in the updates that had been released since it first broke.
Perhaps it could be added to the post above as a known issue so others don't have to go digging through these comments.
As it happens we knew the issue before before we released the first snapshot that demonstrated the problem. One of my colleagues noticed it on internal builds following the last big Core update. The fact it wasn't in the known issues immediately was an oversight on my part. I am usually asked about Linux/FreeBSD issues that should be highlighted in the snapshots, however my focus was on the 12.02 release at the time and I forgot to get this added initially.
Ruari Odegaardruario # Thursday, September 6, 2012 3:01:22 PM
Originally posted by minho:
We plan to have more yes, but not in the short termWhat about fixes to themes and tab bar on linux?
wangfengwangf35 # Thursday, September 6, 2012 3:15:46 PM
Extended settings can not be saved, turn off and on opera, has returned to the default settings
xpsp3 32/ win7 32 opera12.5
minho # Thursday, September 6, 2012 3:24:43 PM
http://www.nfl.com/
Ubuntu 12.04 amd, Opera x64, hwa and webgl off, E2140 cpu
celeborn1 # Thursday, September 6, 2012 3:25:56 PM
http://files.myopera.com/celeborn1/files/Operagpu.jpg
DirectX acceleration is blocked due to Catalyst is older than 10.2.
But, I'm using Catalyst 10.9 for my HP dv6-3100et. It has switchable graphics. HD5650+Intel HD Graphics. The latest driver from HP. I guess Opera is confused by hybrid graphic cards.
minho # Thursday, September 6, 2012 3:39:46 PM
http://tunein.com/
Firefox 15: http://files.myopera.com/minho/albums/3631672/ff.png
This build: http://files.myopera.com/minho/albums/3631672/opera.png
Ubuntu 12.04 amd, Opera x64, hwa and webgl off, E2140 cpu
elg2001 # Thursday, September 6, 2012 3:41:48 PM
==============
For your safety, you can only install extensions from
To find out how to add the current website to the trusted sources list, click the
==============
Kamaleshkamalesh # Thursday, September 6, 2012 3:43:18 PM
(OSX v10.7.4)
Chocimierchocimir # Thursday, September 6, 2012 4:22:36 PM
Jimtoyotabedzrock # Thursday, September 6, 2012 4:44:49 PM
For instance, if you install a 3rd party extension it would be prudent to self review the updates to that extension
Originally posted by MaxVL:
http://css3test.com - 50% only Why?
Opera 12.02 - 53%
FF 16 beta - 55%
Chromium 23 - 62%
Opera 12.5 removes the old CSS Speech properties, which is why there is a drop.
CraigPD # Thursday, September 6, 2012 5:24:49 PM
Originally posted by ll3mo:
Also confirmed on XP when initiating chat - sometime after build 1546.Like the latest 4-5 snapshots (i already reported this), gmail or google+ random brings the cpu to 50%, only closing the tab stops this. Opera:cpu show an usage like 2-3%.
(windows 8 rp x64, x64 build, hwa and other stuff off)
Surferz Worldsurferzworld # Thursday, September 6, 2012 5:25:44 PM
--
Ubuntu 12.04, 64 bit, Opera Standard theme, Unity DE, Ambiance, HWA Off, WebGL Off.
PavelGemorroj # Thursday, September 6, 2012 5:27:22 PM
Bhikkhu PesalaPesala # Thursday, September 6, 2012 5:53:18 PM
DSK-372504 WAV files don't play is a deal-breaker for me in Opera 12.xx
Test Page.
audio/wav is set to Open in Opera. Works in 11.64 on Win XP Home SP3.
Bhikkhu PesalaPesala # Thursday, September 6, 2012 6:04:16 PM
vux777 # Thursday, September 6, 2012 6:04:51 PM
Originally posted by christoph142:
Not sure if it's only me, but since I updated to this snapshot, Facebook's photo-popups close immediately after opening without loading the comments section on the right side of it.
Win8 x64
no problems here with FB photos and comments (popups and old stile album)
Win 7 x64
rseiler # Thursday, September 6, 2012 6:05:50 PM
Originally posted by ll3mo:
Like the latest 4-5 snapshots (i already reported this), gmail or google+ random brings the cpu to 50%, only closing the tab stops this. Opera:cpu show an usage like 2-3%.
I've seen multiple people mention the opera:cpu reporting issue now. Is there a known issue with this page misrepresenting actual usage?
Originally posted by andrew walker:
For a few builds (since the first spdy one?) I've been having problems with twitter not loading properly. The timeline appears but there's no compose tweet box, who to follow, trends, infinite scrolling etc...
I don't see this here. Could userJS/extension/content blocker be running interference for you?
tenplus1 # Thursday, September 6, 2012 6:53:54 PM
Flash plugin still crashing, nothing plays at all...
Darko Panticpdarko # Thursday, September 6, 2012 6:57:57 PM
Just to remind you:[dare@arch opera-next-12.50-1583.i386.linux]$ ./opera-next
Illegal instruction
[dare@arch opera-next-12.50-1583.i386.linux]$
Thanks for (not)caring about users who use and love Opera.
gibson # Thursday, September 6, 2012 7:01:40 PM
Originally posted by Opera Desktop Team:
DSK-366218 Address bar focused instead of page when using extensions that open new tabs
Actually, for me, all new tabs were incorrectly not focused on the page (I don't use extensions), which is annoying when navigating with the keyboard a lot (like on a laptop).
It seems okay so far, but I still have those randomly ignored keyboard shortcuts. Must file ticket...
gibson # Thursday, September 6, 2012 7:03:08 PM
Originally posted by minho:
Indeed, in the last three or four builds. Win 7 x32 build.Unusable on Fedora 17 x32 yet.
Many random NSLs...
ClashCityRockerclashcityrocker # Thursday, September 6, 2012 7:21:08 PM
Ruari Odegaardruario # Thursday, September 6, 2012 7:32:30 PM
Originally posted by pdarko:
What processor do you run?Can we get more info, ANY info, about Illegal instruction error.
Showing comments 1 - 50 of 196.
Latest 12.10 (Marlin) Snapshot
Got feedback?
-
Desktop Team FAQ
We recommend that you read the FAQ before participating.
-
Report a bug
If you've found a bug in Opera, find out how to report it.
-
Feature requests
This is the place to post your feature requests. Opera employees monitor this forum