Comment by blauditore

9 years ago

Many people seem to be shocked because Mozilla installed an add-on automatically. In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all?

The main question is what behavior is being introduced. I haven't researched deeply, but apparently the add-on does nothing until the user opts-in on studies.

Speaking for myself here, but I'm not concerned that Mozilla might push malware into Firefox installations. I'm concerned about the lack of judgement in pushing an extension with a vague, scary-sounding name and description simply for a cross-marketing tie-in, and I'm worried that it could have damaged the trust ordinary users have in Firefox.

  • > I'm not concerned that Mozilla might push malware into Firefox installations

    Nobody is concerned about that, in my opinion. I'm concerned someone will push malware through Mozilla into Firefox installations. Pushing addon installs should not be possible at all.

    • > I'm concerned someone will push malware through Mozilla into Firefox installations.

      Mozilla installing a bunch of addons that look like viruses ends up preventing users from being able to identify actual viruses.

      1 reply →

    • They can also push new browser releases though. They are also auto-installed by default.

      The exception is that an addon can do slightly less damage than a compromised browser itself.

      4 replies →

    • I suspect it's a plan to make some functionality optional... Or opt out..

      Ie. code spitting and reducing bloat, and speeding up development by providing some features as add-ons...

  • I don’t see the harm in a good organization contributing lot of value to this world having a little fun.

    Some of the comments are mentioning IT managers banning firefox, those will be the same IT managers doing all the other pennywise/pound foolish things that make you try not to work on their team in the first place.

    Maybe it’s actually good to put something scary sounding in there to raise awareness. It could help people understand that scary phrases are not the most common sign of foul play. When the real hackers come for you, they usually dont look scary at all.

    • What do you mean having a little fun ?

      Firefox is bleeding market share and has been for a while. Despite this, revenue and profit is at an all time high for mozilla which is weird as the revenue comes from sending theirs users to google for being profiled and exposed to ads. Meanwhile long time users lose faith and trust in mozilla and firefox.

      Not exactly the best time to be caught having "a little fun" move showing that they will sneakily install stuff in your browser without asking.

      Then again mozilla is "making far-reaching and very short-sighted decisions in a vacuum."[1]

      [1]:http://forums-test.mozillazine.org/viewtopic.php?p=14736466#...

      7 replies →

    • > I don’t see the harm in a good organization contributing lot of value to this world having a little fun.

      One potential downside is that now people might not pay close attention to the installed addons. "Oh, must be some Mozilla thing", as GoldenDwarf quietly consumes user CPU cycles to mine cryptocurrency for someone else.

      2 replies →

  • Hopefully this helped people who were scared by it learn how to analyze add-ons for trustworthiness.

  • What's scary about "Looking Glass"? It's not named something like "PrivacyRemover" or "SpamEmailer" or anything.

    • What was wrong about apple automatically adding a U2 album to itunes library ?

      Same here for looking glass, we do not want corporations to be in control of our stuff. Mozilla showing that they have built the capacity to auto install addons into your browser is quite the issue, you can rest assured that some are already working on ways to abuse this.

      That they have done it as a promotional marketing trick and not or something useful or serious sends the wrong kind of message on top of it.

The major problem is that they installed an add-on without properly communicating what it was. A somewhat smaller problem but still a big problem is that was an utterly frivolous add-on that shouldn't have been pushed to people who didn't explicitly want it. But the biggest problem is that Mozilla seems to have trouble understanding why any of those two would be a problem, I want my browser vendor to be serious and not play silly games that can so easily backfire.

Yeah, add-ons from Mozilla merits the same trust as the browser. But this cuts both ways, this stuff undermines my and probably more people's trust in the browser.

  • So this is the first response from Mozilla in the Gizmodo article:

    “Firefox worked with the Mr. Robot team to create a custom experience that would surprise and delight fans of the show and our users. It’s especially important to call out that this collaboration does not compromise our principles or values regarding privacy. The experience does not collect or share any data,” Jascha Kaykas-Wolff, chief marketing officer of Mozilla, said in a statement to Gizmodo. “The experience was kept under wraps to be introduced at the conclusion of the season of Mr. Robot. We gave Mr. Robot fans a unique mystery to solve to deepen their connection and engagement with the show and is only available in Firefox.”

    This is horrible. They pushed out this crap under false pretenses as a study and obfuscated it. Don't talk the ethics talk if you're not prepared to do the ethics walk.

    • I've been using Firefox for 90% of my browsing for a few years now and really want to continue to do so but I really wish Mozilla would stop shooting themselves in the foot already. This once again gives the impression that they have some teams that aren't in touch with the reality on the ground, that these types of initiatives hurt their chances of gaining more users.

      5 replies →

    • > Don't talk the ethics talk if you're not prepared to do the ethics walk.

      Exactly.

      > "The experience does not collect or share any data," Jascha Kaykas-Wolff, chief marketing officer of Mozilla, said

      Looking in the sources of the extension, it adds additional HTML header to every HTML request to https://www.red-wheelbarrow.com/forkids/ pages. The activity of the users there could of course be tracked and the data dependent on the extension being active collected. Good try Mr. marketing officer of Mozilla delivering Mr. Robot ad using the mechanism for the "studies."

      > "Firefox worked with the Mr. Robot team to create a custom experience that would surprise and delight fans of the show and our users."

      Obviously fail. Surprise, yes. Delight? No.

      3 replies →

    • What are the odds that [current] Chief Marketing Officer Jascha Kaykas-Wolff is also the highest-ranking person in the organization to have signed off on this?

      If they'd decided to sneak in a Mr Robot-themed easter egg I wouldn't really care. The fact that they decided to use a debugging/telemetry permission to push out a stupid marketing gimmick makes me question the judgement of everyone involved.

      Much like some other situations in the political arena over the past 2-3 decades, I don't care that much about what was done but the decision to do it makes me question the judgement of people that I'm supposed to trust to make good decisions.

    • > [...] The experience does not collect or share any data [...]

      Wrong (unless proven otherwise).

      From the Shield Studies FAQ[1]:

      > What data do Shield Studies normally collect?

      > [...]

      > Mechanism:

      >> - at STARTUP, SHUTDOWN, INSTALL, UNINSTALL, - send a `shield-study` packet containing the Unified Telemetry Environment.

      As was stated before, users report that they have had this extension pushed to their browser without their prior consent to sending any telemetry data.

      [1]: https://wiki.mozilla.org/Firefox/Shield/Shield_Studies

  • I completely agree. A browser sits on a bit of a higher plane than most other pieces of technology these days, as it is so important. I have no reason to doubt the ability or intent of the developers involved with this add-on, but there is zero reason for it to be pushed to everyone without consent. I use Firefox because I want to trust my browser and not have to worry about it doing dumb shit behind my back. This goes against that very notion.

  • Being serious is quickly becoming a lost art. I don't know if the majority of the userbase really enjoys it, but I can't wait till the current fashion of treating your users like 3-year-olds blows through.

    • agreed. nothing is more frustrating to me than when my windows computer delivers an error message with a “ :( “

  • > I want my browser vendor to be serious and not play silly games that can so easily backfire.

    I would not care about silly stuff, like say a christmas easter egg. But this wasn't meant as a silly joke.

  • The major problem was building a feature into the product that allowed for pushing add-ons without users knowledge much less active consent in the first place, there is no benign use for this kind of functionality.

    • you mean the automatic update process, which can change every single byte of every file in every directory under Firefox's control? Because unless you want to live in a world where your browser can't automatically apply security patches and upgrade critical components, the fact that the application can update itself is very much not the actual problem (and with the new web extension addon system rathern than the old XUL system, addons are actually way less security-compromising-in-potentio than updates to the actual browser itself)

      4 replies →

    • You could use add-ons to manage optional functionality a la Atom. Users can enable and disable add-ons to customize their browser and some come enabled by default. If you were migrating to this method of customization it would absolutely make sense to push an enabled add-on that replaces functionality you took out of the main app.

      4 replies →

    • Automatically updating an already enabled add-on is hardly the same thing as silently pushing a new one.

      Security updates were and still are configurable to be installed after prompting, also when they are installed automatically I am notified that this has happened. There is also an implicit trust in the vendor that only security-related functionality should be changed in a security update.

If this were the first incident, and they quickly backtracked on it, then maybe we can give them a pass. But this isn't the first case of somewhat shady behavior. Remember the "user-enhancing" sponsored tiles a few years ago?

https://twitter.com/dherman76/status/433320156496789504

> Excited to share the launch of @mozilla @firefox Tiles program, the first of our user-enhancing programs

The problem there wasn't just the idea of putting ads in the browser, it was also the way in which they tried to present it as a useful addition just like every other ad company tries to defend ads

  • That tweet sounds like doublespeak, but Directory Tiles really did have some genuinely good ideas mixed in with the bad.

    I don't know how far we got with it, but one of the ideas was to serve a generic bundle of ads, and then select which ones to display locally, based on an entirely private, client-side analysis of the browser's history. Now, that probably shouldn't have been on the new tab page, and probably not in Firefox at all, but if ads are going to be the way we fund the Internet, then that sounded like the best possible outcome: better targeting without remote tracking. Heck, even Brave ran with the idea for a while: https://brave.com/about-ad-replacement/

  • There are things I don't agree with that Mozilla does, but I will stand up for that one. The idea behind the "tiles" was to try to figure out a way to do privacy-respecting ads. And if you look at how it actually worked... it was actually a really good plan for how that could happen.

    Mozilla's job is to find ways to push the web forward in ways that respect humans, and ads are, well, how the web mostly gets funded. So it's entirely within bounds for them to try to figure out ways to make ads work without invading people's privacy.

    • Maybe if that was actually the goal, it might have been a good thing. But all I received was marketing blabla to tell ads are enhancement.

      And if Mozilla really are different, then they should communicate different - honest.

This is being added to the browser, outside the realm of security updates, through what is supposed to be a UX improvement program, for commercial purposes. It's written by a commercial company that produces advertisement content. It's not clear this code is audited.

Sorry, but I'm uninstalling firefox. They have broken the basic trust I have in them as a user to not push arbitrary code to my machine against my interests.

  • Have fun in Lynx. that's probably the only browser that wouldn't do something like this.

    Well maybe Safari, not because Apple wouldn't, but because they just don't care enough about ad revenue.

    Chrome: They leech everything they can get away with, granted it goes only to Google, but you know it's just to feed their never-ending ad-revenue goal.

    MS: They bypassed IE only ads, and went on to build ads into the entire OS.

    • The truth is that there have been other text-only browsers both before and after lynx. I have tried every one I could ever find, since the 1990s. Some of them seem to have been forgotten. IMO, whatever is in todays package collections is not a true representation of all text-only browsers ever written. Most times when someone cites "lynx", as is common on HN, I interpret this as a signal they are not too familiar with text-only browsers. IMO, lynx is relatively big, slow and clunky with too many options; definitely not the best text-only browser I have used.

      I happen to like text-only browsers for viewing HTML (e.g HTML tables), tcpclients like netcat for making TCP connections, and my own software for generating HTTP requests. Almost all websites work[FN1], with zero "loading time" as one may experience when using "modern" browsers to do these tasks. I can easily get the content I want (text, with option to download images, PDF, video, etc.) and skip the stuff I dont want. No autoloading of resources. I choose what I want.

      Surprisingly, the web is actually getting more, not less text-friendly. Today I can often get text encapsulated in JSON, Markdown, etc. instead of wrapped in HTML, making parsing even easier.

      There is heaps of Javascript written by others available on the web today but as a user I have little interest in running it. I would rather write my own.

      FN1. "work" means I get the body the page that contains the content.

      5 replies →

    • I'm running Firefox via Debian, and I intend to continue running Firefox via Debian - I trust that the outcry in the Debian community would be so huge if the Firefox maintainer (or any other maintainer) allowed this sort of code from upstream through.

      2 replies →

    • Software companies are like music bands. You might like their current album but next year they could totally sell out and go pop :)

      Me, I keep it underground (qutebrowser at the moment) but I'm constantly in search of something better

      2 replies →

    • > Well maybe Safari, not because Apple wouldn't, but because they just don't care enough about ad revenue.

      Truthfully, this is why I use Safari. Apple makes money by selling me devices and services, Mozilla and Google are both driven by ad revenue. Even good actors within these companies are working within a framework where the customer is the product.

      .. also Safari saves like 15% on battery.

      1 reply →

    • what about otter ? waterfox ? uzbl ? poseidon ? netsurf ? falkon ? k-meleon ? Iron ? Iridium ? Liri ? Min ?

      To cite some of the browsers you overlooked in your snarky comment.

      3 replies →

  • > It's written by a commercial company that produces advertisement content. It's not clear this code is audited.

    Do you have any evidence of this?

    Assuming their normal processes for SHIELD studies were followed, a _lot_ of different people have to review the plugin before it gets approved: https://wiki.mozilla.org/Firefox/Shield/Shield_Studies#Who_A...

    Edit: Also, the contributors list on the plugin's GitHub repo lists exclusively Mozilla employees: https://github.com/gregglind/addon-wr/graphs/contributors

  • What browser are you going to use instead?

    • Firefox 57's sweeping changes ruined most of my vim-like ui customizations (vimperator, vimfx). For 2 months I've switched to qutebrowser and palemoon as a backup and dont miss firefox at all.

      If you're looking for a browser with first-class vim compatibility qutebrowser is outstanding.

      I've also found palemoon to be a perfectly boring/stable/functional variant of firefox without all the drastic/breaking changes (vim plugins work quite well also)

      1 reply →

To some extent, the line between code in the browser core and code in an add-on coming from Mozilla is arbitrary. However, it's a line that Mozilla themselves have drawn. We've been trained to be vigilant when choosing and installing add-ons, to read the list of permissions the add-on is asking for and judge whether we want to take the risk. The implicit messaging to users has been that if you let through a bad add-on that degrades the browser in some way, it's your fault. (Indeed, we're supposed to sympathise with Mozilla when 'badly-written' add-ons slow down the browser and make Mozilla look bad.)

Mozilla have presented "add-ons" as a line where users are supposed to be responsible for what to "trust", over and above the choice to install the browser in the first place. They can expect those users to be watching that line carefully.

(Incidentally, I would still dislike this functionality - moreso even - if it was in the browser core.)

> If someone distrusts their add-ons, why trust their browser at all?

"Well, I'm your bank. You already gave me authority to reinvest all your savings. Why are you mad now that I invested everything into bitcoin futures?"

What exactly does "trust" mean? We might have given mozilla such a widespread access exactly because we trust them not to abuse it. Stuff like this undermine that trust.

  • Maybe not be the best analogy since that is exactly what banks do with your money while it's parked in your savings account - invest it in whatever they feel like. Probably not Bitcoin futures because the bank manager doesn't want to, but there's nothing stopping them from doing exactly that.

    • No, the bitcoin futures were my point. Of course they can re-invest in principle but the trust is tgat they won't invest them into something that is an obvious risk.

      And no, they can't: In many countries there are regulations forbidding high-risk investments with regular savings accounts for exactly that reason.

  • Before, we didn't need to trust them, because we didn't have to. We had all the code, we could verify the code we can read is the code in the binary we use via checksums. Now the code contains the ability to go fetch arbitrary code behind our backs and run it against our will. Firefox is now malware and it's a real damn shame.

    • > Now the code contains the ability to go fetch arbitrary code behind our backs and run it against our will.

      How is that not what automatic updates are?

      2 replies →

Dumping odd stuff that's not clearly from Mozilla and is poorly explained, without warning, is a fast road to lost trust.

I'm using Firefox 57 heavily (typing this in it), and actually really like it for a change. This after years and years and years and years of wanting to like Firefox but finding it completely and absolutely unusable due to performance issues.

(Chrome has been ... faster, but insanely aggravating in all sorts of ways, including utter and complete contempt from Google and the Chrome devs for users. The frustrations are rapidly mounting.)

Mozilla have just cost themselves some portion of their advanced user test base through abuse of trust. I really wish they'd not do that.

> In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all?

An appropriate response here would be to decide that you no longer trust their browser at all.

It's hard to quantify trust exactly. I'm fine with trusting the partly-closed-source Google Chrome build, including the proprietary Chromecast, Hangouts, etc., plugins, because I believe that the people writing them are generally reasonable. I don't have a good formal proof that they're generally reasonable people, and I never will - that's why it's trust. If they start installing marketing gimmicks, certainly they have the technical ability to do that, but I will lose my trust that they're reasonable people.

Here's an analogy: I trust a small number of my friends with keys to my apartment because I think they'll make reasonable use of that access. If they decide to show up at 3 AM with a keg and three tubas without telling (let alone asking) in advance, I technically have no grounds to complain that they abused their access - but I'll certainly not be calling them friends any more.

  • >I technically have no grounds to complain that they abused their access.

    I would argue that since they knew you were giving them access on the assumption that they would not do things like that, you would have grounds to complain. Similarly, I installed Firefox on the understanding that it would not phone home with opt-out telemetry, advertise third party products, or syntergise with acquired properties. Mozilla has, in the past few months, done all three.

    I like Firefox, though, so I'd rather kick the tubas out of Mozilla than go kick them off my individual installation. Does the public have any power over Mozilla's governance?

    • Just switch to waterfox, you'll get the best of firefox and none of the mozilla nonsense. This is what I did after finally getting fed up with mozilla not caring about user and just doing as they please to try to get more revenue and marketshare.

  • What do we know about marketing gimmicks hidden in Chrome? If they are not made in the form of add-ons, or if they are add-ons but Chrome has a way to hide them (as it hides Flash), we just never know. I bet Google's marketing gimmicks, if any, are not open-source either, and not included in Chromium.

    Hence, as you said, the only way is to trust Google here, without much ability to verify.

    • I have never seen marketing gimmicks in Chrome, apart from the choice of default search/new tab page.

> I haven't researched deeply, but apparently the add-on does nothing until the user opts-in on studies.

It adds some css to a list of words:

https://github.com/gregglind/addon-wr/blob/da464ac8f1c3b0894...

  • i'm on nightly and the default was to opt me in. that's some shady shit. i'm pissed.

    mozilla is rapidly burning through over a decade of hard-earned trust and goodwill. i install firefox on other people's machines. i'm not a good user to piss off.

    am i gonna have to wait for servo to mature and make an unmozillad servo? what a sad reality that would be.

    this is not the browser we were looking for.

    • if you're on Nightly, this is literally what you signed up for: all the experimental settings and all new functionality turned on by default so that you can be part of the test bed of users and devs that can report back to the larger developer community through Bugzilla when things aren't working the way they should be. Complaining about the fact that Nightly did exactly what it's supposed to is kind of ridiculous.

      6 replies →

What it bugs me is not that Mozilla pushed and extension into my/their browser but the behavior of the extension itself. It literally broke some pages, disrupting my use experience more than it was supposed to do (or at least I hope it was not intended). Peoples who complain about Mozilla pushing this just failed to check the basic browser options and should blame themselves instead. Anyway Mozilla seem to have rised quite a lot of attention about the secuirity and the privacy of their own browser with this stunt, so... it was a success, I guess?

Then why not install it when the user opts in? Installing this kind of crap automatically is sleazy.

Somebody trusted their browser, because never before they attempted such things as installing code that has nothing to do with the browser and is an advertisement gimmick.

I am genuinely astonished that somebody up the corporate tree at Mozilla thought this is a good idea. I mean, I get the appeal of getting the money and doing the cool IRL tie-in to the show, but that's not just how you do it. If I am a fan of a particular actor, I don't expect him/her to suddenly be in my bedroom when I come home one day. I would prefer to invite them first (if I am so inclined).

The trust here is specifically trusting them not to do such things. Which now has been violated. And the fact that CMO says anything else than "Man, did we screw up! We're so sorry, would never happen again!" is deeply sad and concerning.

You're assuming people trust firefox or mozilla.

I do not trust mozilla, they've repeatedly proven they cannot be trusted. I do not trust firefox, because a piece of software is open source software does not mean it should be trusted.

>If someone distrusts their add-ons, why trust their browser at all?

You mean like when they set the default search to Bing?

> it doesn't really matter since the code is coming from Mozilla

For now, yes. Until someone finds a way to push a "study" through which is not from someone "trusted".

> If someone distrusts their add-ons, why trust their browser at all?

Well, trust is rather simple to break, and this - remote installing things - was not part of my original trust I put in Firefox 1.0. I know things change. This is not one I tolerate, and you are right: I will not trust a browser after a step like this.

Besides the trust, it's unexpected data. Probably don't effect many on big data plans, and is probably a tiny extension this time, but it's still data I have not asked for.