Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

9 years ago (support.mozilla.org)

Many people seem to be shocked because Mozilla installed an add-on automatically. In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all?

The main question is what behavior is being introduced. I haven't researched deeply, but apparently the add-on does nothing until the user opts-in on studies.

  • Speaking for myself here, but I'm not concerned that Mozilla might push malware into Firefox installations. I'm concerned about the lack of judgement in pushing an extension with a vague, scary-sounding name and description simply for a cross-marketing tie-in, and I'm worried that it could have damaged the trust ordinary users have in Firefox.

    • > I'm not concerned that Mozilla might push malware into Firefox installations

      Nobody is concerned about that, in my opinion. I'm concerned someone will push malware through Mozilla into Firefox installations. Pushing addon installs should not be possible at all.

      31 replies →

    • I don’t see the harm in a good organization contributing lot of value to this world having a little fun.

      Some of the comments are mentioning IT managers banning firefox, those will be the same IT managers doing all the other pennywise/pound foolish things that make you try not to work on their team in the first place.

      Maybe it’s actually good to put something scary sounding in there to raise awareness. It could help people understand that scary phrases are not the most common sign of foul play. When the real hackers come for you, they usually dont look scary at all.

      17 replies →

    • Hopefully this helped people who were scared by it learn how to analyze add-ons for trustworthiness.

  • The major problem is that they installed an add-on without properly communicating what it was. A somewhat smaller problem but still a big problem is that was an utterly frivolous add-on that shouldn't have been pushed to people who didn't explicitly want it. But the biggest problem is that Mozilla seems to have trouble understanding why any of those two would be a problem, I want my browser vendor to be serious and not play silly games that can so easily backfire.

    Yeah, add-ons from Mozilla merits the same trust as the browser. But this cuts both ways, this stuff undermines my and probably more people's trust in the browser.

    • So this is the first response from Mozilla in the Gizmodo article:

      “Firefox worked with the Mr. Robot team to create a custom experience that would surprise and delight fans of the show and our users. It’s especially important to call out that this collaboration does not compromise our principles or values regarding privacy. The experience does not collect or share any data,” Jascha Kaykas-Wolff, chief marketing officer of Mozilla, said in a statement to Gizmodo. “The experience was kept under wraps to be introduced at the conclusion of the season of Mr. Robot. We gave Mr. Robot fans a unique mystery to solve to deepen their connection and engagement with the show and is only available in Firefox.”

      This is horrible. They pushed out this crap under false pretenses as a study and obfuscated it. Don't talk the ethics talk if you're not prepared to do the ethics walk.

      12 replies →

    • I completely agree. A browser sits on a bit of a higher plane than most other pieces of technology these days, as it is so important. I have no reason to doubt the ability or intent of the developers involved with this add-on, but there is zero reason for it to be pushed to everyone without consent. I use Firefox because I want to trust my browser and not have to worry about it doing dumb shit behind my back. This goes against that very notion.

    • Being serious is quickly becoming a lost art. I don't know if the majority of the userbase really enjoys it, but I can't wait till the current fashion of treating your users like 3-year-olds blows through.

      1 reply →

    • > I want my browser vendor to be serious and not play silly games that can so easily backfire.

      I would not care about silly stuff, like say a christmas easter egg. But this wasn't meant as a silly joke.

    • The major problem was building a feature into the product that allowed for pushing add-ons without users knowledge much less active consent in the first place, there is no benign use for this kind of functionality.

      11 replies →

    • This. I love Mozilla, but between automatic change of default search engine in 57.0.1, pushing changes that broke most of my extensions and now this, I am starting to feel anxious...

      1 reply →

  • If this were the first incident, and they quickly backtracked on it, then maybe we can give them a pass. But this isn't the first case of somewhat shady behavior. Remember the "user-enhancing" sponsored tiles a few years ago?

    https://twitter.com/dherman76/status/433320156496789504

    > Excited to share the launch of @mozilla @firefox Tiles program, the first of our user-enhancing programs

    The problem there wasn't just the idea of putting ads in the browser, it was also the way in which they tried to present it as a useful addition just like every other ad company tries to defend ads

    • That tweet sounds like doublespeak, but Directory Tiles really did have some genuinely good ideas mixed in with the bad.

      I don't know how far we got with it, but one of the ideas was to serve a generic bundle of ads, and then select which ones to display locally, based on an entirely private, client-side analysis of the browser's history. Now, that probably shouldn't have been on the new tab page, and probably not in Firefox at all, but if ads are going to be the way we fund the Internet, then that sounded like the best possible outcome: better targeting without remote tracking. Heck, even Brave ran with the idea for a while: https://brave.com/about-ad-replacement/

      5 replies →

    • There are things I don't agree with that Mozilla does, but I will stand up for that one. The idea behind the "tiles" was to try to figure out a way to do privacy-respecting ads. And if you look at how it actually worked... it was actually a really good plan for how that could happen.

      Mozilla's job is to find ways to push the web forward in ways that respect humans, and ads are, well, how the web mostly gets funded. So it's entirely within bounds for them to try to figure out ways to make ads work without invading people's privacy.

      1 reply →

  • This is being added to the browser, outside the realm of security updates, through what is supposed to be a UX improvement program, for commercial purposes. It's written by a commercial company that produces advertisement content. It's not clear this code is audited.

    Sorry, but I'm uninstalling firefox. They have broken the basic trust I have in them as a user to not push arbitrary code to my machine against my interests.

  • To some extent, the line between code in the browser core and code in an add-on coming from Mozilla is arbitrary. However, it's a line that Mozilla themselves have drawn. We've been trained to be vigilant when choosing and installing add-ons, to read the list of permissions the add-on is asking for and judge whether we want to take the risk. The implicit messaging to users has been that if you let through a bad add-on that degrades the browser in some way, it's your fault. (Indeed, we're supposed to sympathise with Mozilla when 'badly-written' add-ons slow down the browser and make Mozilla look bad.)

    Mozilla have presented "add-ons" as a line where users are supposed to be responsible for what to "trust", over and above the choice to install the browser in the first place. They can expect those users to be watching that line carefully.

    (Incidentally, I would still dislike this functionality - moreso even - if it was in the browser core.)

  • > If someone distrusts their add-ons, why trust their browser at all?

    "Well, I'm your bank. You already gave me authority to reinvest all your savings. Why are you mad now that I invested everything into bitcoin futures?"

    What exactly does "trust" mean? We might have given mozilla such a widespread access exactly because we trust them not to abuse it. Stuff like this undermine that trust.

    • Maybe not be the best analogy since that is exactly what banks do with your money while it's parked in your savings account - invest it in whatever they feel like. Probably not Bitcoin futures because the bank manager doesn't want to, but there's nothing stopping them from doing exactly that.

      1 reply →

    • Before, we didn't need to trust them, because we didn't have to. We had all the code, we could verify the code we can read is the code in the binary we use via checksums. Now the code contains the ability to go fetch arbitrary code behind our backs and run it against our will. Firefox is now malware and it's a real damn shame.

      3 replies →

  • Dumping odd stuff that's not clearly from Mozilla and is poorly explained, without warning, is a fast road to lost trust.

    I'm using Firefox 57 heavily (typing this in it), and actually really like it for a change. This after years and years and years and years of wanting to like Firefox but finding it completely and absolutely unusable due to performance issues.

    (Chrome has been ... faster, but insanely aggravating in all sorts of ways, including utter and complete contempt from Google and the Chrome devs for users. The frustrations are rapidly mounting.)

    Mozilla have just cost themselves some portion of their advanced user test base through abuse of trust. I really wish they'd not do that.

  • > In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all?

    An appropriate response here would be to decide that you no longer trust their browser at all.

    It's hard to quantify trust exactly. I'm fine with trusting the partly-closed-source Google Chrome build, including the proprietary Chromecast, Hangouts, etc., plugins, because I believe that the people writing them are generally reasonable. I don't have a good formal proof that they're generally reasonable people, and I never will - that's why it's trust. If they start installing marketing gimmicks, certainly they have the technical ability to do that, but I will lose my trust that they're reasonable people.

    Here's an analogy: I trust a small number of my friends with keys to my apartment because I think they'll make reasonable use of that access. If they decide to show up at 3 AM with a keg and three tubas without telling (let alone asking) in advance, I technically have no grounds to complain that they abused their access - but I'll certainly not be calling them friends any more.

    • >I technically have no grounds to complain that they abused their access.

      I would argue that since they knew you were giving them access on the assumption that they would not do things like that, you would have grounds to complain. Similarly, I installed Firefox on the understanding that it would not phone home with opt-out telemetry, advertise third party products, or syntergise with acquired properties. Mozilla has, in the past few months, done all three.

      I like Firefox, though, so I'd rather kick the tubas out of Mozilla than go kick them off my individual installation. Does the public have any power over Mozilla's governance?

      1 reply →

    • What do we know about marketing gimmicks hidden in Chrome? If they are not made in the form of add-ons, or if they are add-ons but Chrome has a way to hide them (as it hides Flash), we just never know. I bet Google's marketing gimmicks, if any, are not open-source either, and not included in Chromium.

      Hence, as you said, the only way is to trust Google here, without much ability to verify.

      1 reply →

  • > I haven't researched deeply, but apparently the add-on does nothing until the user opts-in on studies.

    It adds some css to a list of words:

    https://github.com/gregglind/addon-wr/blob/da464ac8f1c3b0894...

  • What it bugs me is not that Mozilla pushed and extension into my/their browser but the behavior of the extension itself. It literally broke some pages, disrupting my use experience more than it was supposed to do (or at least I hope it was not intended). Peoples who complain about Mozilla pushing this just failed to check the basic browser options and should blame themselves instead. Anyway Mozilla seem to have rised quite a lot of attention about the secuirity and the privacy of their own browser with this stunt, so... it was a success, I guess?

  • Then why not install it when the user opts in? Installing this kind of crap automatically is sleazy.

  • Somebody trusted their browser, because never before they attempted such things as installing code that has nothing to do with the browser and is an advertisement gimmick.

    I am genuinely astonished that somebody up the corporate tree at Mozilla thought this is a good idea. I mean, I get the appeal of getting the money and doing the cool IRL tie-in to the show, but that's not just how you do it. If I am a fan of a particular actor, I don't expect him/her to suddenly be in my bedroom when I come home one day. I would prefer to invite them first (if I am so inclined).

    The trust here is specifically trusting them not to do such things. Which now has been violated. And the fact that CMO says anything else than "Man, did we screw up! We're so sorry, would never happen again!" is deeply sad and concerning.

  • You're assuming people trust firefox or mozilla.

    I do not trust mozilla, they've repeatedly proven they cannot be trusted. I do not trust firefox, because a piece of software is open source software does not mean it should be trusted.

  • >If someone distrusts their add-ons, why trust their browser at all?

    You mean like when they set the default search to Bing?

  • > it doesn't really matter since the code is coming from Mozilla

    For now, yes. Until someone finds a way to push a "study" through which is not from someone "trusted".

    > If someone distrusts their add-ons, why trust their browser at all?

    Well, trust is rather simple to break, and this - remote installing things - was not part of my original trust I put in Firefox 1.0. I know things change. This is not one I tolerate, and you are right: I will not trust a browser after a step like this.

    Besides the trust, it's unexpected data. Probably don't effect many on big data plans, and is probably a tiny extension this time, but it's still data I have not asked for.

Previously:

* https://github.com/gregglind/addon-wr/issues/36

There are several scary things about this:

- Unknown Mozilla developers can distribute addons to users without their permission

- Mozilla developers can distribute addons to users without their knowledge

- Mozilla developers themselves don't realise the consequences of doing this

- Experiments are not explicitly enabled by users

- Opening the addons window reverts configuration changes which disable experiments

- The only way to properly disable this requires fairly arcane knowledge Firefox preferences (lockpref(), which I'd never heard of until today)

  • > Unknown Mozilla developers can distribute addons to users without their permission

    "In related news, unknown website developers can distribute programs and run them in your browser. Additionally, it's been determined that browsers sometimes download changed versions of themselves without your permission. Worst of all, we've determined that sometimes the program you download and run yourself on your computer does stuff it didn't say it would do!"

    In all seriousness, I understand this is an important issue, and needs to be addressed, but we've obviously gotten to the point as a society recently where no news can't be played up for hype by pundits and commentators for their own benefit (and probably without realizing they are doing it in a lot of cases).

    The whole way this is being presented (by many here, not to pick on the parent) as a new chunk of the sky falling is what I find really troublesome. No, chicken littles, the sky isn't falling, but there is some interesting shit going on up there that deserves a look.

    I fail to see how getting half the people frothing at the mouth and the other half downplaying it just to try to keep some sanity in the discussion helps for a good outcome.

    • > "In related news, unknown website developers can distribute programs and run them in your browser. Additionally, it's been determined that browsers sometimes download changed versions of themselves without your permission. Worst of all, we've determined that sometimes the program you download and run yourself on your computer does stuff it didn't say it would do!"

      No they can't, despite mozilla removing the option to prevent this, I have an extension preventing website to run code in my browser without my permission. it happens to be one of the most popular firefox extension: noscript. (also umatrix and request policy).

      No the browsers do not download changed version of themselves, they do not have the administrative permissions required to install programs on my box. I get my update from the official distro repository on my terms.

      I do not download and run programs, they come from the distro repository. This is a matter of trusting the package maintainers but up until now this has served many people well.

      It seems you guessed wrong and it does not work the same for everybody, some of us have chosen to take the extra step required for this kind of misadventure to be unlikely.

      1 reply →

  • Just coming up to speed, apologies for the potentially obvious questions.

    1. Can you explain what you mean by "unknown Mozilla developers?" Unknown to whom?

    2. Can you provide more detail on what specific configuration changes are reverted when opening the add-ons window? That sounds like a fairly serious bug.

    3. What is the specific "this" you're trying to "properly disable?" You shouldn't have to dive into things like lockpref.

    Mozilla (and other browser vendors) have the ability to push updates to their browsers outside of the normal release cadence. In many cases, these updates are distributed as add-ons, as they're cleanly separated from the rest of the browser internals, but that's just an implementation detail. If you visit about:support in Firefox, you should see a table of "Firefox Features," which are exactly that. Their source lives at: https://hg.mozilla.org/mozilla-unified/file/tip/browser/exte...

    For example, we used a system add-on to control the gradual roll-out of multiprocess Firefox, and the New Tab page is also implemented as an add-on called "activity-stream."

    • I'll try to answer in the parent's place, since I've been watching this issue.

      > Can you explain what you mean by "unknown Mozilla developers?" Unknown to whom?

      Unknown in the sense that this extension wasn't documented at all, there was no Bugzilla issue for it and it's not clear whether it was properly vetted by QA. Whether you argue that this kind of silent push updates is good or bad, I think they aren't tested as well as in-browser functionality. This is a necessary consequence of "let's try it and revert if something breaks or people complain".

      More so, a rolled back Shield study will be invisible to the users, so any problems will be impossible to debug. This is made worse by the fact that most, if not all Shield studies are opt-out, so the user won't be notified.

      > Can you provide more detail on what specific configuration changes are reverted when opening the add-ons window? That sounds like a fairly serious bug. > What is the specific "this" you're trying to "properly disable?" You shouldn't have to dive into things like lockpref.

      People have reported that extensions.ui.experiment.hidden reverts after viewing the add-ons list. I haven't tried it myself, but you can find details in that Reddit thread.

      Others have noticed that the Shield studies checkbox sometimes (possibly on version bumps) reverts to enabled. I can't overstate how bad this is; it's basically cheating the users' trust. Lately, Mozilla has been doing some pretty nasty things for an organization that takes pride in caring about the privacy of its users.

      Are you aware of the complaints regarding Windows telemetry? Edge, for example, sends full browsing history to Microsoft by default. Should Mozilla follow suit? Because that's exactly what Pioneer does and, while it's not opt-out yet, Firefox advertises enabling it.

      As for the rest of the system add-ons, they're either poorly documented (if they are at all), poorly named ("Presentation"), or seem concerning from a privacy point of view (e.g. Activity Stream, Follow-on Search Telemetry, Photon onboarding, Presentation, Web Compat Reporter).

      For anyone curious, Presentation seems to be an implementation of a proposed Web API that allows browsers to find and talk to devices in their neighbourhood. Does that include location/proximity beacons like this old proposal https://hacks.mozilla.org/2013/06/the-proximity-api/ ? Do users really want Firefox to tell advertisers where they're shopping? That's the same kind of "experience improvement" that the spyware of yore used to bring.

      Why should Pocket be an add-on with superpowers? There was quite a bit of backlash over it a while ago, but Mozilla didn't budge, and some employees actually spread misinformation (not to say "lied"). And actually none of my system add-ons seems to be providing any important functionality (if you disregard the new tab page, for which I haven't seen yet a privacy policy). Looking at Shield studies ( https://www.jeffersonscher.com/sumo/shield.php ), it's even worse: most are surveys, advertisements, asking the user to enable Pioneer (i.e. send full browsing history to Mozilla).

      3 replies →

  • > Mozilla developers can distribute addons to users without their knowledge

    I think for most people this is the stickiest point. Other commenters have said things along the lines of, "well if you trust their browser you should be able to trust their add-ons" and I do, mostly, trust their add-on here... but I really don't like how it slipped into my Add-Ons without telling me. For every other Add-On I have to click an explicit blue button, so I know what's in and what's out.

    In today's landscape, Add-Ons have massive potential as security threats. For instance, would a savvy user who is security-aware (most users on HN, I assume) install an Add-On like Gmail Checker Plus[0]? Without digging in, it's hard to be 100% certain what this Add-On is and isn't doing with my Gmail content (I have no reason to assume anything nefarious, it's just an example). My browser Add-Ons should be off-limits to any sort of tampering without my permission, as well should be my bookmarks and auto-fill info. If I broke into your house and changed your bedsheets, you'd rightly be creeped out... nothing was stolen, new bedsheets don't affect you in any significant way, but it's still wrong and weird and hurts trust.

    0. https://addons.mozilla.org/en-US/firefox/addon/checker-plus-...

    • They could (should?) have a non-user visible addons stash for this kind of functionality. Putting it in the Add-ons UI is a bad idea.

  • I think this was a very bad move, because Mozilla installed adware in all of its browsers. The fact that it was installed through an add on, though, seems irrelevant. Mozilla developers can distribute arbitrary code to all users because they write the browser. The add on just makes this particular bit of code user visible.

Looks like it's a promo for Mr Robot, which is really not ok.

> What's happening? Are you a fan of Mr Robot? Are you trying to solve one of the many puzzles that the Mr Robot team has built? You’re on the right track. Firefox and Mr Robot have collaborated on a shared experience to further your immersion into the Mr Robot universe, also known as an Alternate Reality Game (ARG). The effects you’re seeing are a part of this shared experience.[0]

EDIT: looking at this[1] comment, perhaps it's not a promo?

[0]: https://support.mozilla.org/en-US/kb/lookingglass [1]: https://www.reddit.com/r/firefox/comments/7jh9rv/what_is_loo...

  • Wow. So Mozilla lets advertisers push extensions to your browser? Is that right or am I misunderstanding something?

    • It seems to be developed by Mozilla employees, which is less terrible than allowing actual third-party addons, and it's disabled by default, but still - pretty distasteful.

    • > So Mozilla lets advertisers push extensions to your browser?

      Of course not.

      Mozilla can install extensions if you have "shield studies" enabled. They use extensions it to run UI studies and things like that. I think you have to opt-in to each study individually if you want to be part of it. Enabling the studies in your settings only means "notify me when there's a new study I can participate in".

      See https://support.mozilla.org/en-US/kb/shield and https://wiki.mozilla.org/Firefox/Shield/Shield_Studies

      Now they have partnered with Mr Robot to use the same feature to offer some sort of "Alternate Reality Game".

      9 replies →

  • From the page:

    > No changes will be made to Firefox unless you have opted in to this Alternate Reality Game.

    Also, from the same page for those that appreciate irony:

    > One of the 10 guiding principles of Mozilla's mission is that individuals' security and privacy on the internet are fundamental and must not be treated as optional. The more people know about what information they are sharing online, the more they can protect their privacy.

    • > No changes will be made to Firefox unless you have opted in to this Alternate Reality Game.

      That can't possibly be true. I had it installed, and I'm on my work machine using Firefox Developer Edition. I didn't opt in to any ARG.

      14 replies →

    • > No changes will be made to Firefox unless you have opted in to this Alternate Reality Game.

      How does it not occur to them that this is a clear lie?

      3 replies →

  • The ads during the show are super cringey. It's not as bad as the Alexa product placement, but still

  • Seems kind of like it is part of an ARG. I can't say I'm totally against something like that; Mozilla's gotta make money somehow, and as long as it's not selling out user privacy it's a better tradeoff than Chrome.

  • If it was a promo, it would be a real bad promo. I did not watch Mr Robot and that quote did not made me aware of it until people started referencing it here.

    The extension is for shield study, when you install Firefox for the first time it asks if you want to take part in it (it is enabled by default though)

    • Mr Robot is a tv show repeatedly showing how you can pwn other people computer by pushing seemingly innocuous code.

      It has been praised for its technical accuracy, basically the show warns us about exactly what mozilla did as this could be exploited to hack into computers.

  • > Looks like it's a promo for Mr Robot, which is really not ok.

    From what I've heard (I work for Mozilla), this is promo for Firefox. As I just wrote elsewhere in this thread: I believe the idea is that Mr. Robot fans use Firefox to participate in the ARG, not that Firefox users suddenly start watching Mr. Robot. So if anything I'd expect that Mozilla pays Mr. Robot for this.

    • That would be an idiotic waste of money by a non-profit organisation considering the audience of Mr Robot.

    • > So if anything I'd expect that Mozilla pays Mr. Robot for this.

      The irony is that Mr. Robot is owned by Universal, a subsidiary of Comcast. So much for that commitment to net neutrality.

      1 reply →

This happened to me yesterday, so I looked for it.

The Extension actually does nothing, but invert (make them upside down) a few words on specific sites.

It's an experiment called "PUG ARG" to check whether page contents sniffing works. Its page doesn't reference any Bugzilla issue or Wiki page, while https://wiki.mozilla.org/Firefox/Shield/Shield_Studies/Queue doesn't list it.

The source code references https://support.mozilla.org/kb/lookingglass, which (as of now) only says "test - 12817".

The add-on tests whether specific words can be detected on sites; the current list has nice picks like "revolution" and "privacy". Of course, this is only a test, but in the future Firefox might look for specific terms in the pages you load and do specific things based on them.

The other thing it's doing is to send an extra header to three specific sites: https://github.com/gregglind/addon-wr/blob/da464ac8f1c3b0894.... I suppose the words and the domain are a reference to the Mr. Robot series.

The add-on describes itself as an "Augmented Reality Game Experience" and was made by a certain "PUG Experience Group": https://github.com/gregglind/addon-wr/blob/da464ac8f1c3b0894....

Of course, Shield Studies are supposed to be a way of making "more informed product decisions based on actual user needs".

https://www.reddit.com/r/firefox/comments/7jh9rv/what_is_loo...

1) Mozilla uses weird, spooky language in an add-on.

2) Users are justifiably concerned.

3) Mozilla explains that the add-on is actually anodyne; the developers responsible were having fun with an opt-in research service.

4) Some users try to justify their initial overreaction by painting Firefox as mysterious, dangerous entity, fabulating conspiracy theories about one of the most forthright and open OSS companies in the world.

Really, guys. If Mozilla was hellbent on invading your privacy, do you really think they would proudly entitle their tracker "Looking Glass". Or would they call it debugservice_1223?

  • Thanks for the positive take, but I do think that folks are justified in their anger.

    Even though the add-on itself was innocuous, the context around its scope, delivery, and presentation were not what they should have been.

    • Justified in their concerns, certainly. But not in their seething, frothing paranoia.

      We have people comparing the installation of a near-stub browser add-on by the browser vendor, to full-on home invasions.

      The language was a mistake and should have not been pushed out, or maybe even written to begin with. Mozilla ought to remember how skittish their userbase can be.

  • 3.5) Most users insist that this isn't okay, that addon installations should be approved by the owner of the computer.

    This isn't about what the addon itself does or does not do, it's the principle of force-pushing unwanted content without prior affirmative consent.

    This would apply even if the addon was just a stub that didn't have any executable code in it. In this case, it's worse: an ad.

    • I would agree with you, if the add-on in question was not developed, shipped, and offered by the people who made the browser, of which the add-on sandbox is a part.

      In my view, that sandbox is a trusted area between the browser and the user.

      Mozilla has the privilege accorded to it as the developer of the browser, to modify the addon sandbox so long as they don't infringe on my interests, e.g., security, stability, privacy, speed.

      For example, Chrome automatically disable extensions that ask for too many new permissions upon update. Chrome will also make it difficult to add extensions that are not listed on the chrome store.

      If we remove the right for browser developers to install, uninstall and alter add-ons, then we're essentially forcing them to modify the browser instead, which is overkill for the add-on in question.

      At the end of the day, if you can't trust the developers of your browser, then you should install another one and disable add-ons entirely.

      3.5 falls into 4.

    • When you install Firefox it asks whether you want to take part in these studies. You can also change the setting at any time in preferences (about:preferences#privacy section).

  • > 3) The developers responsible were having fun with an opt-in research service.

    Having fun at whose expense, though? Widely deployed platforms used for extremely sensitive, personal materials shouldn't be subjected to "for fun experiments". That's the height of unprofessionalism.

    What if the add-on had a bug, or an unintended side effect? Come on.

  • 1) One day you wake up and somebody is watching TV in your living room.

    2) you freak out. Who is this guy? I didn't invite anyone last night!

    3) The guy turns around and it's just your mate Chad. He didn't mean any harm, just wanted to watch TV and hang out.

    4) This is not on, Chad is a psycho.

    Intentions don't really matter: they've just demonstrated a scary and invasive capability without any warning. Minimizing it doesn't help.

    • This "scary and invasive capability" has been included in almost every larger piece of software for years and is widely accepted to be a mostly good thing - it's called automatic updates. Considering updates allow pushing native, even admin-level code, this capability of pushing little bits of JS becomes benign in comparison. Therefore, the only thing that's left to worry about are their intentions. And I, for one, would rather trust the goodness of Mozilla's intentions than Google's or Microsoft's.

      3 replies →

    • This would work better if chad lived in the same house and you shared the living room.

  • > do you really think they would proudly entitle their tracker "Looking Glass"

    They actually called it telemetry, but IIRC in the early firefox version it was a proprietary extension (I don't remember the name) which spurred the gnu iceweasel into existence to provide the browser without the proprietary spying extension.

In the Preferences, scroll down to "Data Collection and Use", and disable everything.

I know that you only need to need to turn off "install and run studies", but this has now cost Mozilla all telemetry data from me, and I encourage everyone to do the same.

  • I've switched to Waterfox, because of things like this (including the Cliqz issues). I'm all for Mozilla making money and trying things, the problem is the way in which they do it. They fail to respect the users enough to communicate things, and have not been behaving like a user-friendly transparent company for some time now. I was a big enough fan to regularly donate and urge friends to do the same, but something has gone wrong inside the company.

    • I heard about Waterfox, but support for legacy extensions is a huge warning sign. I don't want to be stuck on FF56 technology forever.

  • Why can't I see the "install and run studies" option? Is it because I'm using Finnish language Firefox?

What the fuck Mozilla? You can't just sideload extensions that are literally ads. There is no universe in which this is even a little bit okay.

http://qutebrowser.org/

  • And this is exactly what I'm going to do, switch to a simple browser, in my personal computers. If they programmed firefox to be capable of doing thinks like this, then definitely I cannot trust them anymore.

Go to settings, look in Firefox Data Collection and Use.

Why are these turned on automatically? Plus, I turned mine off, and now they're back on again, with this looking junk installed.

What the heck Mozilla? What happened to caring about the users? We definitely can't trust Mozilla anymore.

  • Firefox has a tendency of resetting it's settings. I think the UI calls it "Refresh", but it's basically yet-another-nagbar that we all know and hate.

Out of literally all the software vendors I know, including the one I'm working for, Mozilla is the one I'd have least expected to allow such a thing. I'm very surprised (Negatively, needless to say)

  • Mozilla has been a dumpster fire for quite a while now.

    • Mozilla has been going downhill very fast since Brendan Eich was removed as CEO. There was some controversy at the time and it made sense why he was removed, but it seems clear now that Mozilla took the wrong choice in removing him as it seems he was keeping the ship on course. Now it is floundering from numerous sides.

      I think Mozilla should look into getting him back before they all end up losing their jobs.

  • I would have said the same thing until they integrated the W3C Encrypted Media Extensions. It's clear they lost their way some time ago.

    • Why? They allowed proprietary extensions (e.g. Flash) from the start. I don't like it, but I don't see how it represents a loss of their way. Mozilla was never GNU.

      2 replies →

    • I don't like EME either, but not implementing it would've killed any chance of regaining users: "Oh look, Firefox Quantum looks awesome, I should try it. ... Never mind, it doesn't play Netflix". Implemeting it, but disabling it by default was a good choice. People will have to consciously click "I accept DRM" to use it, which might get them to read more about what it is and ultimately raise awareness about how terrible it is.

      1 reply →

Mozilla Firefox installer is signed by a code-signing certificate. But at the very end it means nearly nothing: if the developer cannot be trusted, no amounts of certificates, green bars, smart screens, stores and walled gardens can fix that.

That's a very important point to grasp, as I hear a lot of voices nowadays claiming that the modern security model (read walled gardens of all kinds) is the universal panacea.

Just the opposite, it brings a false sense of security making you more vulnerable. It also tends to inhibit a healthy and free market competition when a lot of potentially good software suppliers are gated off from the walled gardens from the start.

  • In general though, what is the alternative to trusting the source and distributor of a piece of content? As you've noted, if you can't trust the developer, the walled garden is irrelelvant... But if you can't trust the data source, isn't basically everything about the medium irrelevant?

    In contrast, if you do trust the data source, why is a walled garden model of security worse than alternatives?

Somewhat tangential to this particular issue, but this is a good lesson for developers in why you should be dry and explicit in your writing.

Sure `alert("FFFUUU WHY U NO WORK");` keeps you entertained for 5 minutes while you debug a problem but when that accidentally gets to prod...

  • I see you, but your example outlines a problem with the process/workflow, not with the developer.

    • GP meant the style of writing English, not code. Funny messages almost always end up causing problems at the end of the day.

HOLD THE PHONE

The support thread links to https://support.mozilla.org/en-US/kb/lookingglass.

That page says, in a clearly delineated box,

> No changes will be made to Firefox unless you have opted in to this Alternate Reality Game.

PLEASE EXPLAIN THIS INCONSISTENCY.

  • Hopefully, it's a bug, and that addon wasn't intended to be installed (much less active) universally like it is.

    That doesn't make it OK, but it would make me look at them with suspicion instead of hostility.

    • >Hopefully, it's a bug, and that addon wasn't intended to be installed (much less active) universally like it is.

      hey look, a voice of reason!

      seriously. Mozilla is a company that has a long track record of dedication to openness and the free and open internet

      this isnt Google, facebook, etc

      let's all take a step back and give them a little benefit of the doubt here, until we get some facts on what happened.

      for everyone else...

      WANT TO JOIN THE MOB? I'VE GOT YOU COVERED! COME ON DOWN TO GR3YH47'S PITCHFORK EMPORIUM!

      I GOT 'EM ALL! SETTING UP SHOP IN HACKERNEWS MEANS BIG SALES!

      CHEAP TRADITIONAL FORKS! ON SALE!

      Traditional ---E

      Left Handed 3---

      Fancy ---{

      DEFECTIVE CLEARANCE ARE EVEN LOWER!

      ---F

      ---L

      ---e

      NEW IN STOCK. DIRECTLY FROM LICHTENSTEIN. EUROPEAN MODELS!

      ---€

      ---£

      *some assembly required

      6 replies →

  • Even if installed, the add-on only initializes if `extensions.pug.lookingglass` is set to true in about:config. That preference defaults to false.

Ffs .. I've just checked my addons b/c of the headline and sure enough it has been installed against my will.

I've been very loyal to mozilla over all these years but this really is not ok. If they keep doing shit like this I'll switch to a fork.

I just wanted to add a few things.

1. I notice it yesterday, only because Avast was showing I have a low trust level Add-On installed in Firefox.

2. I googled it, and the first results was from Mozilla, showing it was part of their studies and experiment.

3. That was Ok, because I trust Mozilla, although somewhere in the back of my mind I thought every studies were supposed to be opt-in, since I have a few Add On installed in the week and I dont restart my browser, I thought i might have clicked it by mistake.

4. Now I am reading this through, I am more then worried. If I am reading the online comment correctly, Mozilla installed an Add On without user permission, enabled, collected data, and not for their own UX studies but a third party.

And to make the matter worst, that Add-On is now gone. It disappeared in my Add on Screen now I just check. Call me old fashion but that is not how i view privacy.

Like I said before, Mozilla's management and culture has a tendency of self destruction and messing things up right after they start being good. Still this is turning around much quicker then I thought.

  • I cant find any indication that Mozilla was collecting any data from this addon, either for themselves or for anyone else. The only way anyone would even be affected by it is by going to one of 3 hard-coded websites owned by the network behind Mr. Robot (a show known for putting easter eggs all over the web) and hovering over some text. It's definitely a dick move, but it isn't spyware as some people are saying, just a very poorly executed promotion.

  • It seems to have disappeared from about:addons because the "study" has ended. In about:studies I see:

    > pug-experience

    > Complete • My reality is different than yours

If they state as an explicit principle that no addons/studies are actually enabled unless the user opted in, then I’m going to give them the benefit of the doubt that if that happened to users that did not opt in, it was a terrible mistake (I.e a bug).

I can tolerate bugs, much more than I can tolerate sneaky app behavior. But I hope the statement about explicit opt-in will be repeated, and this will be explained.

At first I thought it must have been users that explicitly had opted in, but with so many users claiming they haven’t, it seems unlikely.

The next possibility is that preview versions have things opt-out instead of opt in (because in preview versions you need more data from users - typical for closed alphas etc) - but then this should be very clearly explained on download/install.

  • Just installed Firefox a week ago on OS X. Just checked and I have Looking Glass installed. I'm usually very careful when installing software about things like this. I don't recall ever opting in to anything (including error reporting). So my guess is it's a default you have to disable in settings.

  • I haven’t understood whether this thing is completely inert or actually does anything without opt in.

    If it is downloaded and listed without opt-in, but only actually invoked after opt-in, then I’ll call it acceptable (not great, but not terrible either)

Mozilla can't stop doing crap like this. I love the engineering behind it and thr tech but I don't want any of your shenanigans. This makes me affraid to update.

I like Mozilla a lot. And this extension doesn't really bother me, since it's benign.

But oh boy, do they have a talent for always doing benign and harmless things that look bad at first glance. It's almost like they want to turn away typical messaging board users.

Menu > Options > Privacy & Security > untick Allow Firefox to install and run studies

I deliberately kept that enabled initially but if they're going to use it for Adware..

  • If you're still using Firefox after this it's probably safest and best just to disable everything under Firefox Data Collection and Use

While I agree that releasing this as an undocumented extension was a poor PR move, in practical terms, I don’t see how this is any more insidious than the ‘no internet’ dinosaur jumping game built in to chrome.

Both are first-party. The difference seems to be that the dinosaur game keeps you entertained, where as this hopes to promote awareness of privacy/security.

  • >"I don’t see how this is any more insidious than the ‘no internet’ dinosaur jumping game built in to chrome."

    You don't see the difference between a built-in game (included in the installation of Chrome) vs. Mozilla pushing an add-on to a Firefox installation using a channel meant for helping to improve the browser?

    • Mozilla could have just as well pushed this as part of the binary via auto-update.

FF 57 installed from Debian unstable repository has "Data reporting is disabled for this build configuration" - which disabled, in theory, the shield "studies" as well. I don't know who made this decision at Debian, but thank you.

And this is one of the reasons I stopped my yearly donation to the Mozilla foundation even if I love the new FF. If they need money so badly they should push their donation campaign and keep their products clean instead of pushing some shady alliances with big corporations.

So, a lot of people in this thread are saying that Mozilla is a non-profit. There are in fact two Mozillas. One is the Mozilla Foundation, which is the non-profit. They are not involved with Firefox development, as I understand it. The Mozilla Corporation, which I think is owned by the non-profit, does the development. I think the foundation just does cute videos and outreach and other things not directly related to writing software. I also understand that if you donate money to the Mozilla foundation, the money would not make it to Mozilla corp and thus would not pay for the salary of any Firefox hacker.

I've never quite understood how exactly does this financial arrangement work and I would be grateful to anyone who could explain this to me.

I don't remember if this is opt-in or not, but I do not have it in my Firefox. Maybe I just removed it myself immediately after first install, when I went through to update all of the privacy and other browser settings.

I agree that it seems like a crappy extension, and people should be upset about things being preloaded to their browser.

But there's a point here to be made, that if you're concerned about privacy at all today, you need to look at the settings of any software after you install it. It doesn't matter how much previous trust you have for the developers. This should just be default behavior so that any surprise is met immediately, and not after any damage it could perform has been done.

Anyone know how I can turn off Firefox sending technical details and interactions?

Everytime I turn this off, and restart FF it's on again.

58.0b11

  • If you are on a Nightly or Developer build, you can not turn it off, I asked on Mozilla’s IRC.

    Downloading these builds is considered opt-in into telemetry, and toolkit.telemetry.enabled is hardcoded to enabled, the opt-out checkbox literally does nothing, I was told. And about:config confirmed this.

    • Okay, having a checkbox that does nothing is really bad. The fact that the privacy policy only just says something like "this policy might not apply to non-release builds", without actually having a policy for those also is more than questionable.

Doesn't bother me at all - I am fully acclimated to the idea that the browser and other applications do run arbitrary A/B test and other code all the time.

I switched to waterfox for quite awhile. I've lost trust in mozilla when they bundled "Pocket" and people then didn't think much of it. When you lose ability to control the browser its no longer a fair game. Bundling addons, changing settings, ads and "enhancements" no one asked for, all eroded trust. Not to mention its aping Chrome more and more each version. We need more firefox forks, not less. Chrome has dozens, because the privacy threat from google is obvious: firefox hdoesn't have that much forks,because its trusted by distro makers to be safe(but its not, as mozilla just proved). People are upset when this implicit assumption that Firefox is the only browser(among modern graphical browsers) you can trust is actually false.

Better yet, it appears that these "studies" (read: Mozilla pushing addons to your browser without notification or permission) are default opt-out.

Will they stop doing it? Of course not. I can't recall any time that this company has changed course in response to outcry.

It's a PR disaster from Mozilla. I was once a Mozilla rep and I'm ashamed of this. Studies like these should always be turned off by default and the user can opt in voluntarily. But launching Firefox and digging into the preferences to find that I'm enrolled into some studies by default is unethical for me. Sadly, I'll have to switch to Brave or some other privacy concerned browser until I see an official statement and action from Mozilla. I'm sure the management there have something to do with all of this.

I actually discovered this because my browser would not stop running at 100% cpu utilization about 3 days ago, not doing anything, just sitting at Google.com with one tab open. It freaked me out because I couldn't find any documentation on the extension. Once removed Firefox was running fine again. I guess I'm relieved to know it wasn't some malware or something more sketchy, but I am wondering what it was doing pegging my cpu at 100% whenever my browser was open...

  • Whatever you experienced is very unlikely to be caused by this add-on. The add-on only initializes if you manually dig into about:config and enable `extensions.pug.lookingglass`. Otherwise, it just starts up once at browser launch, checks that preference, and shuts itself down. (https://github.com/gregglind/addon-wr/blob/59659431fd2a75c33...)

    If you're able to consistently reproduce the issue, please let me know.

I'm using FF57 and did not get this addon. Was I just lucky?

  • Running FF58. I don't have it either. I also don't agree to stuff unknowingly. It's clearly spelled out in the settings under privacy that you can agree to this stuff. Nothing I've seen suggests this isn't happening. People are saying things but no one is backing up any accusations with any proof yet.

  • Same with 57.0 on macOS 10.12.

    Edit: I have FF Studies disabled under about:preferences#privacy. I guess that is the reason why it is not installed on my machine.

I just checked my installation of Firefox and this addon was present as well. The developers involved (Greg Lind et al) should acknowledge this and apologize.

  • Same, why is this in my addons..?

    I really don't understand what they were thinking.

I checked out FF for the zillionth time the other week after the Quantum release hoping to love it, but the deep Pocket integration was just too offputting. Turning it off requires some Googling. There were other irritating commercial things too. It’s a shame. FF is probably the most important open source project in the world and it’s a shame they do stuff like this. I’m still on Chrome :(

  • Firefox bought Pocket. So it's a first-party feature.

    • I cant help but feel mozilla bought pocket because they wanted to justify the included adware nature of it as a first and foremost priority, after all the supposed logic of including it was all about reducing costs for mozilla..

  • > but the deep Pocket integration was just too offputting

    You mean the single button that does literally nothing until and unless you click on it?

    • Yep, that button was really annoying. And the Pocket thing on the home screen, too. And the fact that I had to Google to figure out how to disable it.

      If you must know why, I don't want promos for particular web properties in my browser. I find Pocket to be annoying conceptually (a service to help you carry around all the things you didn't and won't read—eww, no, no thank you), and I don't want to look at it every day. I don't want to have to Google to figure out how to disable it. I don't want my browser to come with nonsense I need to disable.

      > You mean the single button that does literally nothing until and unless you click on it?

      This must be the kind of mentality that leads people at FF to do silly things like mentioned on this thread, or having "just one button" for their acquired web property. That's the opposite of how great product minds think. Great product people think "how can I REMOVE this button?" Not "how can I get away with having it?"

      1 reply →

    • Add a couple more buttons and hey, you've got a toolbar going.

      Why can't they just make a web browser that's... just a web browser? Chrome has never had buttons to email pages with gmail, record videos onto YouTube, share pages on G+ etc.

      3 replies →

From the wikipedia article. linked in the ticket

> Shield Studies are available on all channels. Individual studies can be opt-out or opt-in and any and all data being collected will be declared openly. After confirming willingness to participation, a self expiring add-on will be installed on the user's machine.

Mozilla is only installing an experimental feature ass an add-on if they opt in.

As of about 5:30 GMT it looks like the addon was automatically removed from my browser. I know I saw it a couple hours ago.

What I really do not understand is why this game thing was installed automatically given that websites can ask the user to install an extension when they land on a webpage. A popup that is part of Firefox shows up and asks the user if he really wants to install it.

Is the "Unknown" part in the title really unknown, or just Mozilla trying to protect its developer(s) from pitchforks? If it's really "unknown", then that's the really concerning part.

I haven't noticed this extension sending data to outside services. Did somebody find if/where it does that? If it is sending personal or browsing-related data out, we can flood the servers with garbage.

Posted here a few days ago about how Mozilla being for-profit joined at the hip with a non-profit seems kind of shady, and got dogpiled for it. Then they do this as a tie-in for Mr. Robot.

Vindication!

I use Firefox 58 beta developer edition in the USA and this extension didn't install automatically...

Maybe the government need to start sponsoring Mozilla so that they stop doing things like this.

This is disappointing rather. When Mozilla spent $$ in advertising Firefox Quantum in the internet media articles, they could have mentioned this at least somewhere in them.

Mozilla takes in about half a billion dollars per year, has anyone considered the consideration for which this money is being paid ?

  • That's FUD. Mozilla is a 501(c)3 non-profit, and our audited financial statements and IRS Form 990 can be found at https://www.mozilla.org/en-US/foundation/annualreport/

    • Mozilla is... both. There's the Mozilla Foundation which is a nonprofit and the Mozilla Corporation which is very much not.

      I've never quite understood what each Mozilla does, but AIUI, the Firefox development is all done by Mozilla Corp and the nonprofit does stuff like make those cute videos about how Firefox is going to save the world and make us all smiley and multiethnic.

      I've talked to a number of Mozilla employees, and they also seem confused about the relationship between the corp and the foundation.

      2 replies →

    • From the link you posted:

      " The majority of Mozilla Corporation’s revenue is from royalties earned through Firefox web browser search partnerships and distribution deals around the world. Mozilla Corporation’s revenue and income support for CY 2016 was $506M, as compared to $414M in CY 2015. "

      Let's assume that "browser search partnerships" is what google/yahoo paid for having their search engine be the default in the search bar - "distribution deals" sounds just the sort of thing this thread is concerned with.

      So: half a billion figure - check, shady consideration for the money - check until proven otherwise. FUD you.

      1 reply →

This is the second spyware extension in recent memory.

How hard is it to fork Firefox with all this stuff hardcoded off?

https://support.mozilla.org/en-US/kb/lookingglass

The Mr. Robot series centers around the theme of online privacy and security. One of the 10 guiding principles of Mozilla's mission is that individuals' security and privacy on the internet are fundamental and must not be treated as optional. The more people know about what information they are sharing online, the more they can protect their privacy.

...which you've done by installing a fishy-looking addon without our permission and making us less likely to trust you?

Well-done, Mozilla.

  • >Firefox and Mr Robot have collaborated on a shared experience to further your immersion into the Mr Robot universe

    I guess that sounds slightly better than "Firefox and Universal Cable Productions".. oh wait..

    At least it's an authentic immersion into the world of dubious computer ethics.

  • If you clicked on the link about shield studies you'd see it says they're opt in, did you not getting prompted about it?

    • Apparently it's getting loaded anyway for some people that say they had "Studies" disabled and/or "Studies" itself became re-enabled.

      The whole idea of slipping paid advertorial content into what are billed as "research" kind of gives the lie to this whole thing and is why I never turn these on in any product. Which is also why it's now "opt-out" by default, and why it will eventually not be an option at all. It's all for our own good, you see.

      15 replies →

    • Apparently the addon is installed anyway, it just doesn't "change anything in Firefox" if not opted-in. I have to wonder why install it at all if it's not to be used.

      Mozilla really needs to be more transparent about this kind of stuff.

    • I did not opt in and I have the "Looking Glass - MY REALITY IS JUST DIFFERENT THAN YOURS." extension enabled.

      Adding my me-too because I was fully convinced this was user error until I saw it myself. The opt-in is busted.

    • > If you clicked on the link about shield studies you'd see it says they're opt in, did you not getting prompted about it?

      No, I had Firefox test pilot with `Video Min` addon, I was not prompted about he `Looking Glass` I removed all addons from Mozilla and their test pilot yesterday. There is only one thing that keeps me away from moving to Brave browser https://news.ycombinator.com/item?id=15648179

      Firefox Pioneer is literally a spy and tracking addon:

      >Pioneer is an opt-in program that allows collection of richer data from Firefox.

      I did not install it.

      1 reply →

    • I remember this prompt (sending Mozilla crash/performance data) and disabled it a long time ago, and I don't have the add-on currently.

      Often these days I disable every "Help us with information" box, both on close/commercial software and even open source software. I mean I'd like the help the community, but I really no longer like submitting any type of tracking information or even debugging information. Everyone is already clamoring for my data, and I guess it's more of a mentality of I don't want to give it away for free. They already get so much for free.

      I'll still file a bug report on bugzillas and compile stack traces on faults. But I want to do it myself, explicitly.

    • I did not knowingly opt-in to any shield studies, and I see it installed for me. I guess it's possible that I clicked on something without reading it.

      Anyways, I've taken the opportunity to opt-out of Firefox.

      1 reply →

Between broken font handling and this Looking Glass thing whatever it is Firefox 57 (Quantum) has been less than stellar.

This is what it looks like: https://imgur.com/a/mriUw

It scared the hell out of me! Are these guys losing their minds?

It was reported as a bug and the response thus far is indeed underwhelming for such a severe issue: https://bugzilla.mozilla.org/show_bug.cgi?id=1424977

Having issues with your extra? Beginning with Firefox 57 (in discharge), just additional items manufactured utilizing WebExtensions APIs, the new innovation for Firefox expansions will work.

The cringe-worthy construction "different than" which should be "different from" makes this episode even worse.

Just checked and saw the Looking Glass add-on installed on my work laptop.

I've uninstalled Firefox and will be removing it from all of my computers. I had just started slowly migrating back to it with the performance enhancements in the latest update, but honestly I don't think I can get past a breach of trust at this level.

  • I switched to Vivaldi a few months back and tried out FF57 recently. I really wanted to move back to FF again, but two weeks in, the performance enhancements just seem really overrated. The UI is still draggy, load times are not great.

    I ended up going back to Vivaldi.

  • Are you switching to Chrome, the browser that sends your every keystroke back to HQ?

    • Google does a lot of things but they've never betrayed my trust by installing an extension in conjunction with a third party without telling me.

      Google does track a lot of my data but they provide useful services in exchange, and in addition they make it pretty easy to see what data they have on me. Also Google's data is its competitive advantage so our interest in protecting my data from 3rd parties is aligned.

      In short, Google tracks me sure, but they're pretty transparent about it. I do think some of the things Google does with Chrome and it's market position is less than stellar so I'm still exploring other options. If you have any suggestions I'd be happy to hear them.

      4 replies →

    • Well, does it matter if I use Chrome, which sends everything I do back to Google Analytics, or if I use Firefox, which also sends my interaction with the Addon menu to Google https://news.ycombinator.com/item?id=15421708 ?

      In a previous discussion, a Mozilla employee gave me as official statement that if I don’t trust Google, I shouldn’t use Firefox.

      If I have to trust Google anyway, I can at least use the better browser.

      Disclaimer: Until today, I’ve defended Mozilla in all such discussions, and kept the same PoV that you have presented here, but I just can’t do that anymore, when Mozilla is now just as evil as Google.

      2 replies →