Comment by skymt
9 years ago
Speaking for myself here, but I'm not concerned that Mozilla might push malware into Firefox installations. I'm concerned about the lack of judgement in pushing an extension with a vague, scary-sounding name and description simply for a cross-marketing tie-in, and I'm worried that it could have damaged the trust ordinary users have in Firefox.
> I'm not concerned that Mozilla might push malware into Firefox installations
Nobody is concerned about that, in my opinion. I'm concerned someone will push malware through Mozilla into Firefox installations. Pushing addon installs should not be possible at all.
> I'm concerned someone will push malware through Mozilla into Firefox installations.
Mozilla installing a bunch of addons that look like viruses ends up preventing users from being able to identify actual viruses.
End users being users prevents them from identifying actual viruses.
I'm concerned about Mozilla pushing software written by the Mr Robot marketing department.
I'm not entirely comfortable with how this all went, but it's at least worth noting that the add-on was written entirely by Mozilla engineers.
5 replies →
Is the plugin opensource, where can we vet it? I can't find it on github or anything like I can with the other plugins I use
12 replies →
This thread needs to lighten up. It's one goofily named add-on pushed to a miniscule number of users in an opt in program. Firefox and their judgement are fine.
2 replies →
They can also push new browser releases though. They are also auto-installed by default.
The exception is that an addon can do slightly less damage than a compromised browser itself.
I deeply hate this update methodology. Some hippster fresh from university decides that the gui, approach, functionality i use daily is no longer needed and pushes his rewrite into a release. One click later im stuck with this, because all the bundled crap is hijacking the "security" for a ride.
If any software developer would truely respect users, he would offer updates as seperate packages, where users can opt out of non-security ones- and those updates humanity votes with there feet against, vannish into the bin of useless software.
3 replies →
I suspect it's a plan to make some functionality optional... Or opt out..
Ie. code spitting and reducing bloat, and speeding up development by providing some features as add-ons...
I don’t see the harm in a good organization contributing lot of value to this world having a little fun.
Some of the comments are mentioning IT managers banning firefox, those will be the same IT managers doing all the other pennywise/pound foolish things that make you try not to work on their team in the first place.
Maybe it’s actually good to put something scary sounding in there to raise awareness. It could help people understand that scary phrases are not the most common sign of foul play. When the real hackers come for you, they usually dont look scary at all.
What do you mean having a little fun ?
Firefox is bleeding market share and has been for a while. Despite this, revenue and profit is at an all time high for mozilla which is weird as the revenue comes from sending theirs users to google for being profiled and exposed to ads. Meanwhile long time users lose faith and trust in mozilla and firefox.
Not exactly the best time to be caught having "a little fun" move showing that they will sneakily install stuff in your browser without asking.
Then again mozilla is "making far-reaching and very short-sighted decisions in a vacuum."[1]
[1]:http://forums-test.mozillazine.org/viewtopic.php?p=14736466#...
> Firefox is bleeding market share and has been for a while.
http://gs.statcounter.com/
In all fairness, Firefox has overtaken IE.
2 replies →
non sequitur. either it’s right or it’s wrong, whether or not you like the org as a whole doesn’t change that.
even so to briefly chase your point, do you believe they are doing net good, and some things are looking more positive, like the servo work? my only point is that criticism works on a relative scale. i agree there are things they could do better, but i still prefer they exist.
3 replies →
> I don’t see the harm in a good organization contributing lot of value to this world having a little fun.
One potential downside is that now people might not pay close attention to the installed addons. "Oh, must be some Mozilla thing", as GoldenDwarf quietly consumes user CPU cycles to mine cryptocurrency for someone else.
This calls for.... anti mining extension. like adblock, miningblock.
1 reply →
I don't look to my browser's implementation to "have a little fun". This is a foolish decision on Mozilla's part.
poor argument. ostensibly the only reason to separate business from pleasure is out of practical concerns. without stating practical concerns there’s no way consider the validity of your comment.
who knows, you may totally change my mind, but as it stands it makes it difficult to disagree or agree with you.
3 replies →
I'm worried my work Security/IT department will see it, freak out, and blanket ban Firefox on all machines for 6 months.
your work security team loves mr robot, it will be fine...
No, it really will not. My workplace saw that OpenOffice had a security issue, and banned it AND LibreOffice.
Nothing I can do about it. Can’t argue. Trust is very, very easily lost and incredibly hard to regain. And it can hit innocent third parties. It’s very, very wrong to do anything that could destroy trust.
2 replies →
If this does not happen at your workplace, it will certainly happen at some other workplace around the world.
Hopefully this helped people who were scared by it learn how to analyze add-ons for trustworthiness.
What's scary about "Looking Glass"? It's not named something like "PrivacyRemover" or "SpamEmailer" or anything.
What was wrong about apple automatically adding a U2 album to itunes library ?
Same here for looking glass, we do not want corporations to be in control of our stuff. Mozilla showing that they have built the capacity to auto install addons into your browser is quite the issue, you can rest assured that some are already working on ways to abuse this.
That they have done it as a promotional marketing trick and not or something useful or serious sends the wrong kind of message on top of it.