← Back to context

Comment by Ajedi32

9 years ago

> It's written by a commercial company that produces advertisement content. It's not clear this code is audited.

Do you have any evidence of this?

Assuming their normal processes for SHIELD studies were followed, a _lot_ of different people have to review the plugin before it gets approved: https://wiki.mozilla.org/Firefox/Shield/Shield_Studies#Who_A...

Edit: Also, the contributors list on the plugin's GitHub repo lists exclusively Mozilla employees: https://github.com/gregglind/addon-wr/graphs/contributors

Unfortunately the most important person involved didn't get to review the plugin before it was installed on my computer. Me.

  • OK, I have to rant a bit on this.

    I worked at Mozilla for about four years (2011-2015), on MDN. It's built as a wiki, with wiki features open to everyone. The code is all open source and on GitHub. Its issues and tasks and roadmap are tracked in a public bug tracker. We operated in a public IRC channel. We didn't have to do that. We could have just built something targeted to only be used by the technical writing staff at Mozilla, and never bothered to open it up or make the code available or make it transparent about who wrote articles and when. In fact, it's much more work to do all the things we did (and not just in terms of implementing features, but also in terms of dealing with spammers and trolls and other malicious people who wouldn't have had access in a less open system), but we did it anyway because Mozilla is a radically open and transparent organization. But... in four years, not many people from outside Mozilla ever joined in and got involved with actually contributing (either code or articles or edits to articles or housekeeping or suggesting/arguing for ideas of how to improve MDN).

    And I've been doing open source for much longer than that, and I see exactly the same pattern: a handful of folks do all that work, and go to the trouble of being open and transparent and providing ways for people to see what's going on and get involved... but people don't.

    And then those same people willingly install the software and use it every single day, and complain that they were never consulted, or never got a chance to review, or never got to provide input. You had chances to look at the source code, to see what was being checked in, to read the referenced Bugzilla bugs on commits, to leave comments on them, to submit alternative ideas. You didn't. You did install Firefox, though (assuming your claim is correct that this was installed on your computer). By installing the software while not participating in the process, you absolutely gave your "review" of it, and your "review" was "just make a browser for me for free and don't bug me about how".

    Now, if you want to be involved, go start watching Bugzilla and the Mozilla project wiki pages, and CC yourself on stuff and join mailing lists. Because it's Mozilla. You can do that. If you don't want to do that, or you don't think it's worth your time to do that, then don't do it. But don't then come charging onto HN to complain that nobody consulted you. People practically got on their hands and knees and begged you to join in the process of making Firefox and other open source software, and you decided not to.

    • I think you misunderstood. I don't want to review the damn source code. I don't have time to do that. I am pretty sure the Mozilla developers are all better developers than I am as well, so my contributions there would be a complete waste of time.

      However, when you decided that the source code I could review would be installed on my computer without my consent, then I do object. It's my computer. It runs things that I choose to run on it, not things your marketing/sales department thinks my computer should run.

      Additionally I find your rant about "open source is for all of us to contribute and if you don't shut the fuck up" wholly ridiculous.

      11 replies →

    • You want to point us towards where ... on Bugzilla and the Mozilla project wiki pages and the source code and all the other things you mentioned ... this addon was discussed?

      4 replies →

    • As someone who could contribute technically to Firefox but doesn't, let me add my perspective.

      First of all, Firefox is a huge and complex project notorious for its legacy code and architecture. It's not a project that I would find pleasant to work on without getting paid. The only reason I might start working on it for free was if I wanted a job at Mozilla.

      Second, it seems to me (as an outsider) that the biggest problem with Mozilla is its management. Any work I contribute to the browser will just be a feather in their cap, and they will still be making bad decisions that I can't meaningfully push back on. The solution for me then would be to fork the whole browser (which has already been done multiple times). However now I'm no longer working with Mozilla, I'm basically fighting them. Without paid, experienced engineers familiar with the Firefox codebase (or a PR budget), there's no reason to believe those forks can "win."

      Third, Firefox is just so large that I could spend my whole life and have a negligible impact.

      Fourth, as an outsider I'd always be "the wingnut who doesn't work at Mozilla." Perhaps if there were several companies sponsoring Firefox development, there would be more of a social place to fit in.

      In conclusion, the state of the web today has left me feeling powerless. If I do nothing it's not necessarily because I'm lazy, but because I see nothing to be done.

    • One of the reasons people are angry, is that this type of investigation has been made as hard as possible currently.

      Posts are being removed from bugzilla and threads being locked. The code itself comes from a random github repo, not affiliated with mozilla/firefox. (https://github.com/gregglind/addon-wr/)

      https://bugzilla.mozilla.org/show_bug.cgi?id=1424977

      people here were asking why normal process wasn't followed. No answer or links to resources.

      another closed discussion here:

      https://bugzilla.mozilla.org/show_bug.cgi?id=1425187

      and here:

      https://bugzilla.mozilla.org/show_bug.cgi?id=1425171

      I appreciate your input as someone who knows the process, but this really wasn't followed this time.

      edit: they've changed the repo now. so it's redirected to https://github.com/mozilla/addon-wr