> Do we trust them or don't we?
GP trusts them for reviewing external extension code, and ensure that it does not contain malware, but not for not inserting exception to their own telemetry if they wrote the code themselves.
Or, more likely, they feel that having two independent actors collaborating on the extension (one by writing and the other by reviewing) yields a more trustworthy outcome than either actor on their own.
That was a rhetorical question.
Mozilla have given us plenty of reasons to not trust them, which makes it hilarious that anybody would think it's noteworthy they're reviewing the code of Raymond Hill of all people.
We could tell it was rhetorical, to imply the position was ridiculous. But when accepting nuance there is a real answer.
> Raymond Hill of all people.
As good as he's been, he's still just one person with a hobby project. Yes please review it!
And what if he gets hacked?