No, it does not. David, this is just wrong. Existing add-ons do not become suddenly insecure.
What it does is allow you to install add-ons not signed by mozilla. Essentially the same thing as installing software not originating from the iOS and/or Mac AppStore, or the Ubuntu/Fedora/etc distro repositories, or the Windows Store, or the Play Store.
The signing stuff might protect some less tech-savvy users from installing "You need this codec to play this porn video" malware add-ons, same as the other walled gardens I listed do too (tho most I listed have still a door in the wall that you can unlock and open yourself, unlike Firefox Desktop).
But that's it. It is a "seal of approval" scheme saying that mozilla reviewers decided something is secure enough and has an OK quality (and wasn't forced to remove by US laws/authorities courts yet), implemented using DRM. It reduces the chances that users will install something malicious by accident/incompetence.
If users still run their add-ons from AMO, then there is no difference. Unless a bad actor can either MITM AMO connections or compromise the AMO servers. At which point the users has a lot more problems already than potentially malicious browser add-ons.
What it does is allow you to install add-ons not signed by mozilla. Essentially the same thing as installing software not originating from the iOS and/or Mac AppStore, or the Ubuntu/Fedora/etc distro repositories, or the Windows Store, or the Play Store.
The signing stuff might protect some less tech-savvy users from installing "You need this codec to play this porn video" malware add-ons, same as the other walled gardens I listed do too (tho most I listed have still a door in the wall that you can unlock and open yourself, unlike Firefox Desktop).
But that's it. It is a "seal of approval" scheme saying that mozilla reviewers decided something is secure enough and has an OK quality (and wasn't forced to remove by US laws/authorities courts yet), implemented using DRM. It reduces the chances that users will install something malicious by accident/incompetence.
If users still run their add-ons from AMO, then there is no difference. Unless a bad actor can either MITM AMO connections or compromise the AMO servers. At which point the users has a lot more problems already than potentially malicious browser add-ons.