8 ms·
> The amount of negative press this received nearly cancels out all the positive news from Quantum's release barely a month ago. Which is silly, IMO. What did
by GunlogAlm 9y ago
> The amount of negative press this received nearly cancels out all the positive news from Quantum's release barely a month ago.
Which is silly, IMO. What did this addon actually do, besides be installed without user consent? If this article is correct, the addon was installed automatically but was not 'activated'. Seems like a fuss over nothing, to me, but somebody correct me if I have the details wrong.
- DonHopkins 9y agoThe point is that Mozilla prides themselves on transparency, but the name of the config option was "extensions.pug.lookingglass" -- meaningless buzz words with no reference to Mr. Robot -- and the description was just "MY REALITY IS DIFFERENT THAN YOURS" -- an enigmatic Alice in Wonderland quote. It's actively trying to be opaque. That's the opposite of transparency. Curious adventurous people install the test build because they want to try out new features and extensions. Those are the users who are most likely to know about and use "about:config". The config option and description of the plugin are mysterious and enigmatic, which tempts your curiosity into turning it on to see what it does, because you presumably trust that Mozilla wouldn't distribute just any old extension that didn't have a purpose other than scanning and modifying the content of every web page, inserting dynamic content adjacent to keywords, and advertising a TV show.
- Yoric 9y agoTo be fair, this was part of a hint in a scavenger hunt, so being opaque is pretty much required in that context. Did it actually display an ad? I didn't see anything such on my Firefox.
- DonHopkins 9y agoIf being opaque is pretty much required, then Firefox is absolutely the wrong context for that extension, whose whole point is transparency. It's not that it displays an ad, it's that it IS an ad. Not only that, but it also parasitically hooks in and wastes resources (memory, cpu time, battery life) in each and every tab visiting each and every web page. That's yet another reason it's totally inappropriate in the context of Firefox, which is trying to dig itself out of the hole of being slow and bloated.
- Yoric 9y ago> If being opaque is pretty much required, then Firefox is absolutely the wrong context for that extension, whose whole point is transparency. Fair point. > It's not that it displays an ad, it's that it IS an ad. If it's an add, it's the most well-hidden ad in history, since you need to find both a hidden preference to turn it on and a specific and non-documented website to let it display anything. > Not only that, but it also parasitically hooks in and wastes resources (memory, cpu time, battery life) in each and every tab visiting each and every web page. No, it doesn't.
- Crespyl 9y agoAdvertisement or not, it is software created for the purpose of marketing, increasing brand awareness/engagement. More importantly, it is software that has nothing to do with improving FireFox, collecting telemetry, error reports, running tests, experimental features, or anything else the Shield Studies program is ostensibly to be used for.
- Yoric 9y ago> More importantly, it is software that has nothing to do with improving FireFox, collecting telemetry, error reports, running tests, experimental features, or anything else the Shield Studies program is ostensibly to be used for. I agree that delivering it through Shield was not a good idea.
- DonHopkins 9y ago>If it's an add, it's the most well-hidden ad in history So well hidden, it's practically underwater. http://www.paulgraham.com/submarine.html http://www.paulgraham.com/submarine.html Yet in spite of how well hidden it was (or rather, because of), we're now all talking about Mr. Robot, somehow. Funny how that works! > No, it doesn't [parasitically hook in and waste resources]. [...] since you need [...] a specific and non-documented website to let it display anything Yes it does hook into and waste resources and potentially display ads on ALL web pages. Hover text injected into headline on Washington Post #39: https://github.com/mozilla/addon-wr/issues/39 https://github.com/mozilla/addon-wr/issues/39 Have you read the source code? background.js: https://github.com/mozilla/addon-wr/blob/master/addon/background.js https://github.com/mozilla/addon-wr/blob/master/addon/backgr... content-script.js: https://github.com/mozilla/addon-wr/blob/master/addon/content-script.js https://github.com/mozilla/addon-wr/blob/master/addon/conten... The extension literally injects ads for Mr. Robot in the form of popup tooltips with links on every web page that contains certain keywords. And it also wastes memory, CPU time and battery life for web pages not containing those keywords. How much more like parasitic adware does it have be before you can see that it walks and quacks like a duck, because its intended purpose is to advertise a television show? https://news.ycombinator.com/item?id=15936727 https://news.ycombinator.com/item?id=15936727 >It injects a blob of CSS and some JavaScript into every tab, then it does a regular expression search of every text node on each page, filtering out everything but paragraphs, then for each occurrence of a keyword in the text, it creates a new text node to split the current text node, then inserts a new span element between them, containing its own text node, then it creates an additional tooltip element containing six text nodes, five br elements, and one anchor element linking to https://support.mozilla.org/kb/lookingglass https://support.mozilla.org/kb/lookingglass , and it also configures css class names to associate all those new nodes it created with the blob of css styling and animations that it injected. If you wanted to develop your own malicious adware like Superfish that injects your own ads into every web page, this code and the browser hijacking techniques it uses would be an excellent starting point. Browser Hijacking: https://en.wikipedia.org/wiki/Browser_hijacking https://en.wikipedia.org/wiki/Browser_hijacking Threat Introduced via Browser Extensions: https://blog.sucuri.net/2014/10/threat-introduced-via-browser-extensions.html https://blog.sucuri.net/2014/10/threat-introduced-via-browse... How to find Chrome extensions that inject ads into any webpage I browse? https://superuser.com/questions/893843/how-to-find-chrome-extensions-that-inject-ads-into-any-webpage-i-browse https://superuser.com/questions/893843/how-to-find-chrome-ex...
- aaroninsf 9y agoAdd-on was also closed source. "Here, let me push closed source partner marketing materials on your bandwidth to you." Directly contradictory to espoused values they trade on. Shameful.
- cuckcuckspruce 9y agoIt's almost worse they didn't make any money for it. Shows what price they put on your privacy and autonomy.
- ovao 9y ago"Even when turned on no user data was collected or shared."
- wasted_intel 9y agoHow can that possibly be a downside? If they had made money, people would be even more up in arms. If anything, this reinforces the “Easter egg” intent of the extension; it serves no other purpose.
- jotux 9y ago>Add-on was also closed source. What made you think it was closed source? The source for the add-on: https://github.com/mozilla/addon-wr https://github.com/mozilla/addon-wr
- tomc1985 9y agoNot very different from Pocket nor Hello?
- Sir_Substance 9y agoNeither of which should have been included in the core browser (even though I quite liked hello, and have been using appear.in, it's more stable cousin, for years now)
- whalesalad 9y agoIt's not what the extension did or did-not do, it's the fact that Mozilla was originally a champion of privacy, open-source, and free software. The entire purpose of this browser was to escape the corporate bullshit of Netscape/AOL. I switched from Chrome to the latest Firefox browser due to the awesome work the team has done on bringing it into the future. Then I find out that it comes pre-loaded with Pocket and this dumb ass game extension for a TV show promotion? Are you joking?! Fool me once...at least you can expect the level of integration you get within Google/Chrome. This was completely incongruent with the ethos of Mozilla and Firefox. That is why this is a big deal. It's a huge slap in the face to those of us who choose to use this software because we know it WON'T do things like this.
- endisukaj 9y agoWhat's wrong with Pocket?
- zipppy 9y agoIt's not about what's right or wrong about Pocket.
- yarrel 9y agoWhat's right with it? If I want to install it I will. I don't, but Mozilla feel that is their choice to make, not mine. You can't remove it (and disabling it is hard enough), so you cannot reduce the attack surface of your browser if you don't use it. It's also really badly integrated into the new mobile version.
- david-cako 9y agoIt being installed without user consent is pretty shitty, but this whole time I was under the impression that it was enabled by default, which is insane. If it wasn't in fact enabled, it's still dumb, but to me a misstep in respecting the user and not a complete breach of trust.
- Crespyl 9y agoIts existence is fine, in fact I wouldn't even mind seeing more collaborations of its kind. The problem is that auto-deploying marketing software (inert or not) over a channel expressly described as being a tool for development, debugging, and testing, is a breach of trust, and/or an indicator of massive process failure within the Mozilla organization.
- jimktrains2 9y ago> Which is silly, IMO. What did this addon actually do, besides be installed without user consent? Should be > Which is silly, IMO. What did this addon actually do, besides break a trust and confidence that's been hard won over many years?
- revelation 9y agoIt was activated, but not activated-activated (in that the addon gracefully decided to not do anything). But obviously we can't delegate that decision to the addons, that's why the addons pane exists after all. Which begs the question: if you had to do something to activate it anyway, why abuse the "studies" sidechannel to install something that is deactivated, when you could just as well prompt to install it when it's meant to be activated?
- DonHopkins 9y agoThe "studies" sidechannel is the ideal place to distribute a deactivated plugin if you want curious people to activate because they want to test out new features. People subscribe to the studies sidechannel BECAUSE they want to try out new features, and those people tend to know about and use about:config, so it's likely many people will enable it, to see what it does. And here's a bug report about something it does: https://github.com/mozilla/addon-wr/issues/39 https://github.com/mozilla/addon-wr/issues/39
- stordoff 9y ago> People subscribe to the studies sidechannel BECAUSE they want to try out new features AFAIK, you are opted-in by default - I recently had to disable it on a clean installation.
- Crespyl 9y agoYou're right that "studies" is designed for distributing/testing experimental features, among other development and debugging uses. I'd dispute any characterization of LookingGlass as a FireFox feature though, and feel very strongly that using Studies to distribute marketing software (inert or not) was an entirely inappropriate use of the tool. Mozilla being willing to use Studies (or having a process that allows for it to be used) in this way means that, although I was fine with the extra telemetry, debugging, a/b testing, etc., I cannot trust Studies to be used strictly for development related things.
- jacquesm 9y agoWhat it did is that it broke user trust, something that Mozilla used to be quite big on. Very bad mistake imo.
- Yoric 9y agoHow did it break user trust? I mean, I see that some people are unhappy, and I can't say that this stuff was thoroughly thought out, but this was an add-on whose only effect on user's computer was... nothing, by design, unless you opted-in.
- Sir_Substance 9y ago>Which is silly, IMO. What did this addon actually do, besides be installed without user consent? 1) Demonstrated that Mozilla has the ability to silently push addons without any kind of notification to the user that their browser behavior has been patched. 2) Demonstrated (allegedly) that there are privacy and security related preferences in Firefox that are reverting themselves to less-safe defaults without user interaction, aka Microsoft preferences. 3) Demonstrated Mozilla's marketing department lacks the good sense to respect these capabilities for the loaded gun they are It's not about what they did, it's about what they could do. Mozilla doesn't need these tools, and these tools are dangerous. Why did they make them? Why shouldn't we ask Mozilla to remove them?
- jotux 9y ago>Demonstrated that Mozilla has the ability to silently push addons without any kind of notification to the user that their browser behavior has been patched. If you allow firefox updates they can silently push any code on to your machine, right?
- itronitron 9y agoyes, and most people have grudgingly accepted the semi-weekly FF updates in order to receive the latest security updates... to hijack that update contract to push a marketing agenda is counter productive
- PurpleRamen 9y agoUpdates are under public view, and users can trust that this process is hard to infiltrate. Silent addon-installations in the background, which appearently can be even pinpointed to specific usergroups, are not. Mozilla can anytime do anything on your system, without anyone watching them, and people just learned the hard way about it.
- JoshTriplett 9y ago> 3) Demonstrated Mozilla's marketing department lacks the good sense to respect these capabilities for the loaded gun they are This is the most critical issue, by far. Apparently nobody ran this by any reasonable person or went through any reasonable review process before shipping it.
- niftich 9y agoIt's unfortunate, I agree; but it's the principle of the matter. This was the company who extolls privacy, openness, and attracts (among others) the sort of people who are uneasy at competing browsers shipped by advertising companies, or old-guard software shops pivoting into more profitable ways to leverage their installbase. This was the company who branded, then re-branded themselves as champions of a more people-conscious web. The exact company who should've known better. Even their apology, though probably sincere, has a tinge of corporate, marketing wishwash. Maybe it's just the title, but a "We Messed Up" would've been punchier without being vulgar, instead of this bury-the-headline-style "Update on..." crap all too familiar from security vulnerabilities.
- wybiral 9y agoThe point is that they make a browser. I don't want anyone installing random stuff for a TV show into the program I use to access the internet without my consent. Another example: https://blog.mozilla.org/press-uk/2017/10/06/testing-cliqz-in-firefox/ https://blog.mozilla.org/press-uk/2017/10/06/testing-cliqz-i... > This experiment also includes the data collection tool Cliqz uses to build its recommendation engine. Users who receive a version of Firefox with Cliqz will have their browsing activity sent to Cliqz servers, including the URLs of pages they visit.
- Sylos 9y agoAnd directly following your quote: > Cliqz uses several techniques to attempt to remove sensitive information from this browsing data before it is sent from Firefox. Cliqz does not build browsing profiles for individual users and discards the user’s IP address once the data is collected. Cliqz’s code is available for public review and a description of these techniques can be found here.
- blub 9y agoIt's irrelevant whether spyware is open source or it uses anonymisation techniques. Installed without explicit consent + collecting data = spyware.
- Sylos 9y agoRetrofitting something into a definition does not help anyone. We have more precision available than calling it "spyware" can deliver, so argue around that. If you think their anonymisation techniques are faulty or you have reason to believe that Cliqz will violate the law by collecting personal data, then bring that forth.
- wnevets 9y agoI kinda agree, I feel like this very important detail is being overlooked or out right ignored for the sake of raising pitchforks.
- notatoad 9y agoIf mozilla is willing to ship adware in their browser, how can i continue to trust them? the fact that this advertisment was innocuous is totally irrelevant, the problem is that there's nobody in the chain between marketing and product release that had the sense to say "hey, that's a terrible idea, we shouldn't do that to our users".