In its efforts to make users aware of how add-ons affect their privacy, Mozilla seems to have recently started requiring extension makers to disclose how their add-ons collect and use data.
But what looked like a good idea is turning out to be a nightmare for some developers. Long-time developers who have built useful add-ons for Firefox are watching their reputations get shredded with these disclosures.
And no, it’s not because they’ve been sneakily spying on users. Instead, it’s because the disclosures are so vague that users are confused about what they mean. For example, the Return YouTube Dislike add-on picked up an update recently, and the disclosure resulted in users seeing a scary warning claiming that the add-on collects personally identifying information.
Any normal person who cares about their privacy would likely get rid of the extension immediately after seeing the warning. In reality, however, the tool only sends a randomly generated ID and video link to tally dislike votes. But the new Firefox prompt does not explain any of that context.
The issue was brought to light by Ajay, the developer behind the SponsorBlock extension. In a thread on Mozilla’s Discourse forum, he wrote that “the upgrade flow for existing extensions is scary.”
The root problem is how blunt Mozilla’s categories are. There is no middle ground between collecting harmless anonymous identifiers and hoarding sensitive private records.
Everything gets lumped into the same ominous bucket. It leaves developers no space inside the prompt to explain why a permission even exists.
Given how common it is to see rogue extensions hijacking data like clipboards and crypto keys, people are naturally on edge whenever a browser flags fresh warnings.
Ajay even went so far as to propose a solution to the mess:
- Better upgrade flow for existing extensions: Provide a way for extensions to explain to users what is happening. Ideally, Firefox should say that this is a new requirement being introduced, and not a change in permission. A customizable “Learn more” button would help here.
- Splitting off collection and transmission: There is a big difference between the following phrases: “The developer says the extension will collect browsing activity”, “The developer says the extension will transmit browsing activity”, “The developer says the extension may transmit browsing activity.”
- Allow an explanation to be included with mandatory permissions so that extensions with privacy preserving features can inform installers how they are safe.
- Include the domains the extension has permission for somewhere in the prompt to inform the user that collection and transmission will only happen on those sites.
Luckily, it seems like Mozilla is listening. In the same thread, a Mozilla staffer from the Add-ons team responded, admitting that the system has some blind spots.
They acknowledged that they need to address the difference between transmitting and collecting data, alongside showing which websites an add-on can actually touch.
Mozilla has been trying hard to tighten browser protections lately, even experimenting with options to block extensions on sensitive sites like banking portals.
Yet terrifying users with vague, half-baked permission dialogs is only alienating the community developers who keep people using Firefox in the first place.
At the time of this writing, there’s no word on whether Mozilla will make any changes. We’ll keep track of the situation and will share updates when we hear more. So stay tuned to our Mozilla Firefox coverage for the latest.

