Are the downloaded data themselves signed? I don't like the idea that someone in charge of my DNS could cause their own extensions to be installed. Just requiring https is _not_ enough, as the DigiNotar debacle demonstrated...
Posted Dec 2, 2011 12:21 UTC (Fri) by ovitters (subscriber, #27950)
[Link]
No idea, there is a whole writeup at https://lwn.net/Articles/459786/. Installation is not automatic btw, you have to confirm it, that is handled locally. Website cannot automatically install, nor automatically update extensions.