16 ms·
Speaking for myself here, but I'm not concerned that Mozilla might push malware into Firefox installations. I'm concerned about the lack of judgement in pushing
by skymt 9y ago
Speaking for myself here, but I'm not concerned that Mozilla might push malware into Firefox installations. I'm concerned about the lack of judgement in pushing an extension with a vague, scary-sounding name and description simply for a cross-marketing tie-in, and I'm worried that it could have damaged the trust ordinary users have in Firefox.
- pmlnr 9y ago> I'm not concerned that Mozilla might push malware into Firefox installations Nobody is concerned about that, in my opinion. I'm concerned someone will push malware through Mozilla into Firefox installations. Pushing addon installs should not be possible at all.
- kibibu 9y agoI'm concerned about Mozilla pushing software written by the Mr Robot marketing department.
- y_u_no_rust 9y agoIs the plugin opensource, where can we vet it? I can't find it on github or anything like I can with the other plugins I use
- callahad 9y agoThe source lives at https://github.com/gregglind/addon-wr/ https://github.com/gregglind/addon-wr/
- Ajedi32 9y agoLooking over [the contributors list][1], looks like the plugin was written entirely by Mozilla employees. So, no "Mr Robot marketing department", as some commenters here have been speculating. [1]: https://github.com/gregglind/addon-wr/graphs/contributors https://github.com/gregglind/addon-wr/graphs/contributors
- acqq 9y agoIt's technicality. The description is still: "Looking Glass is a collaboration between Mozilla and the makers of Mr. Robot to provide a shared world experience." It doesn't matter who technically coded it. "Mr Robot marketing department" was obviously deciding about its existence, behavior and content -- if that description is true. But looking at the source of the extension, I find the following URLs inside: https://www.red-wheelbarrow.com/forkids/ https://www.red-wheelbarrow.com/forkids/ https://red-wheelbarrow-stage.apps.nbcuni.com/forkids/activitysheet/ https://red-wheelbarrow-stage.apps.nbcuni.com/forkids/activi... So it seems it is some marketing, the question is which company now, and do they change?
- rhys91 9y agoI'm not sure why this is downvoted. I work in advertising as a conceptual creative. My entire career is about creating ideas like this for brands. An art director and copywriter sat in a room together over two days and came up with lots of different ideas to generate PR for Mr. Robot. They presented the ideas to a creative director, who went through the work and picked the one he felt was most suitable. They presented it to the client, who supported the idea. There would have been some line of communication from the creative agency, whoever owns Mr Robot, a media/PR agency and Mozilla. The idea was bought by the client, had the agency liaise with media/PR, got in touch with Mozilla with an undisclosed donation and the add-on was coded.
- acqq 9y agoThe biggest problem, for me, is that these extensions obviously get less scrutiny in Mozilla organization. The "core" is made with a lot of "eyes" taking care that not something "wrong" for the user enters the code base. Then some marketing people both in and outside of Mozilla push something that is probably not passing the same strict reviews. It points to the organizational problem in Mozilla. Re: "not sure": don't worry, some people do this not for the content but for the author, some lack reading comprehension and some just press the wrong button. Just vote yourself, and if you reply, say that you agree, don't mention the word you mentioned.
- callahad 9y agoI'm not entirely comfortable with how this all went, but it's at least worth noting that the add-on was written entirely by Mozilla engineers.
- UmmNope 9y agoThis is the opposite of comforting
- UmmNope 9y agoWell it is - one could expect this sort of crap pushed by marketing/bizdev via management but the fact that Mozilla engineers actively collaborated on this is a sign of deep normative inadequacy among the people who are supposed to be the last line of defense against this sort of thing.
- TheRealPomax 9y agoYou seem to either not understand or ignore that even in a company like Mozilla, there are decisions made by marketing that end up having to be implemented by engineers. It might be a non-profit, but it's a non-profit corporation with salaried employees, not a loose assembly of people purely in it for the love of a browser. If the incredibly high up people say X needs to happen, you make X happen.
- TooFastIndeed 9y agoI understand it all too well, but when Mozilla is posing as a public benefit company with the "good of the Internet" as its mission this kind of stuff is inexcusable and should be called out all the louder.
- Mithaldu 9y agoIt's a non-profit with a duty specifically different from "make profits" and there are consequences to this. To quote an ex-mozilla employee: "" Because the Mozilla Foundation is a nonprofit corporation, it has a specific legal purpose for existing spelled out explicitly in its articles of incorporation: "The specific purpose of the Corporation [here meaning the Foundation] is to promote the development of, public access to and adoption of the open source Mozilla web browsing and Internet application software." If Mozilla Foundation were to ignore this mandate, it would jeopardize the nonprofit, tax exempt status of the foundation "" In this case they are definitely ignoring the mandate, and this should never remotely have happened. Source of the legalese: https://static.mozilla.com/foundation/documents/mf-articles-of-incorporation.pdf https://static.mozilla.com/foundation/documents/mf-articles-...
- mshenfield 9y agoThis thread needs to lighten up. It's one goofily named add-on pushed to a miniscule number of users in an opt in program. Firefox and their judgement are fine.
- siimtalvik 9y agoit was an opt-out program actually. Studies are enabled by default.
- mshenfield 9y agoSee the dev's response on the "slippery slope" thread. You had to go into about:config to enable it.
- pilif 9y agoThey can also push new browser releases though. They are also auto-installed by default. The exception is that an addon can do slightly less damage than a compromised browser itself.
- Parcissons 9y agoI deeply hate this update methodology. Some hippster fresh from university decides that the gui, approach, functionality i use daily is no longer needed and pushes his rewrite into a release. One click later im stuck with this, because all the bundled crap is hijacking the "security" for a ride. If any software developer would truely respect users, he would offer updates as seperate packages, where users can opt out of non-security ones- and those updates humanity votes with there feet against, vannish into the bin of useless software.
- pilif 9y agoImagine the complexity of maintaining the software when every patch must anticipate a fragmented mess of different pieces of patches being installed on target systems. Imagine the explosion of testcases required. At that point, it’s probably better to just stop feature development and do nothing but security patches, which of course will lead to stagnation and which will also lead to fragmentation as many more incompatible releases of the same software will be out in use. This will make it even harder for developers to adapt new technologies. Imagine how bad the already messy caniuse.com would look when every single browser version would be supported forever and could be individually configured feature by feature. Especially as people somewhat versed in technology (I think it’s safe to call HN audience that), I think there is advantage in going with the flow and adapting to new releases and UI paradigms. Otherwise we'd still be running on DOS and us developers would still have to support it. Relevant XKCD: https://xkcd.com/1172/ https://xkcd.com/1172/
- bigbugbag 9y agoEver heard of debian ? Then maybe you've heard of debian backports ? I'm asking because debian and backports are doig exactly that: separating security patches from the rest, not for a browser but for a whole OS and every applications including firefox. also this xkcd is not relevant. the point here is that mozilla has quite a history of breaking userspace earning them the reputation of "making far-reaching and very short-sighted decisions in a vacuum."[1] [1]: http://forums-test.mozillazine.org/viewtopic.php?p=14736466#p14736466 http://forums-test.mozillazine.org/viewtopic.php?p=14736466#...
- elil17 9y ago> I'm concerned someone will push malware through Mozilla into Firefox installations. Mozilla installing a bunch of addons that look like viruses ends up preventing users from being able to identify actual viruses.
- ryanlol 9y agoEnd users being users prevents them from identifying actual viruses.
- jopsen 9y agoI suspect it's a plan to make some functionality optional... Or opt out.. Ie. code spitting and reducing bloat, and speeding up development by providing some features as add-ons...
- jotux 9y agoI'm worried my work Security/IT department will see it, freak out, and blanket ban Firefox on all machines for 6 months.
- 45h34jh53k4j 9y agoyour work security team loves mr robot, it will be fine...
- chris_wot 9y agoNo, it really will not. My workplace saw that OpenOffice had a security issue, and banned it AND LibreOffice. Nothing I can do about it. Can’t argue. Trust is very, very easily lost and incredibly hard to regain. And it can hit innocent third parties. It’s very, very wrong to do anything that could destroy trust.
- franga2000 9y agoHave they seen the shit that's been found in Microsoft Office? It seemed like there was a new RCE every week for while.
- chris_wot 9y agoI didn’t say it was logical.
- bigbugbag 9y agoIf this does not happen at your workplace, it will certainly happen at some other workplace around the world.
- WhitneyLand 9y agoI don’t see the harm in a good organization contributing lot of value to this world having a little fun. Some of the comments are mentioning IT managers banning firefox, those will be the same IT managers doing all the other pennywise/pound foolish things that make you try not to work on their team in the first place. Maybe it’s actually good to put something scary sounding in there to raise awareness. It could help people understand that scary phrases are not the most common sign of foul play. When the real hackers come for you, they usually dont look scary at all.
- pavel_lishin 9y ago> I don’t see the harm in a good organization contributing lot of value to this world having a little fun. One potential downside is that now people might not pay close attention to the installed addons. "Oh, must be some Mozilla thing", as GoldenDwarf quietly consumes user CPU cycles to mine cryptocurrency for someone else.
- flamedoge 9y agoThis calls for.... anti mining extension. like adblock, miningblock.
- deleted 9y ago[deleted]
- ryanisnan 9y agoI don't look to my browser's implementation to "have a little fun". This is a foolish decision on Mozilla's part.
- WhitneyLand 9y agopoor argument. ostensibly the only reason to separate business from pleasure is out of practical concerns. without stating practical concerns there’s no way consider the validity of your comment. who knows, you may totally change my mind, but as it stands it makes it difficult to disagree or agree with you.
- code_duck 9y agoHopefully this helped people who were scared by it learn how to analyze add-ons for trustworthiness.
- TylerH 9y agoWhat's scary about "Looking Glass"? It's not named something like "PrivacyRemover" or "SpamEmailer" or anything.
- bigbugbag 9y agoWhat was wrong about apple automatically adding a U2 album to itunes library ? Same here for looking glass, we do not want corporations to be in control of our stuff. Mozilla showing that they have built the capacity to auto install addons into your browser is quite the issue, you can rest assured that some are already working on ways to abuse this. That they have done it as a promotional marketing trick and not or something useful or serious sends the wrong kind of message on top of it.