Comment by crote
21 hours ago
> Firefox now verifies and displays Qualified Website Authentication Certificates (QWACs) in accordance with eIDAS regulations.
Interesting that they just buried this in the middle without even a screenshot, considering how hostile Mozilla has been to the proposal in the past[0].
Considering that they previously made quite strong arguments that implementing QWAC would undermine security by completely bypassing the existing CA trust process and violate user's privacy by leaking browsing activity to third parties: what changed?
It does seem to fit into a wider movement, though. Mozilla previously explicitly considered WebUSB, WebHID, and WebMIDI as "harmful" as they lacked an effective mechanism against hostile websites tricking users into permanently compromising their hardware. This switched to "neutral" without addressing the underlying issue, seemingly just to satisfy some users asking for parity with Chrome out of a convenience argument. Same with Firefox happily jumping onto the AI bandwagon, and only backtracking after major public outcry.
Not to be dramatic, but Firefox seems hellbent on rapidly turning into a reimplementation of Chrome, completely ignoring its raison d'être. Will there be any traditional user-serving browsers left a few years from now?
[0]: https://s3.documentcloud.org/documents/21330628/mozilla.pdf
It seems like Mozilla negotiated with the EU to assuage their security concerns[0].
[0]: https://securityriskahead.eu/
I'm glad to hear that! Someone should probably update the Wikipedia page they link to in the changelog, then.
> Firefox seems hellbent on rapidly turning into a reimplementation of Chrome
You can rest assured that Mozilla will never copy Chrome's updating the mouse coordinates during dragstart, drag and dragend events.
"the spec doesn't specify what the properties should be set to, just that they should be set and we currently set them to 0."
https://bugzilla.mozilla.org/show_bug.cgi?id=505521
16 years and no sign of a resolution. I look forward to celebrating the day that bug becomes old enough to split a six pack with me.
Edit: It was first filed on July 21, 2009 so it will soon be 17.
So it's old enough already in Europe.
So that's basically state legalized and enforced MITM and scamming framework (unless I'm mistaken about tech details)? Yay for progress, I guess... :(
> Will there be any traditional user-serving browsers left a few years from now?
One can hope that by then Ladybird has landed. There was some rumblings about an alpha release come 2027 so "few years" might actually be achievable if the speed remains constant.
I’m waiting for the Gemini people to (re-)discover HTML 3.2 or 4.0. Maybe this then becomes a slightly bigger movement as all current browsers should support it and there are plenty much smaller/more efficient browsers available from back in the time.
> This switched to "neutral" without addressing the underlying issue, seemingly just to satisfy some users asking for parity with Chrome out of a convenience argument.
Well... millions of Chrome users played guinea pigs for WebUSB and the security issues proved to be theoretical in the end, while (particularly in the Arduino/ESP32 community) more and more people were pissed off at the lack of these features in Firefox.
Has Firefox not had containers until now????
I've been using containers in Firefox for years
I hope they do the same for the file system access API!
Mozilla’s executives don’t want to get arrested. It’s one thing to tell the Kazakhs to stuff it. Quite another to tell the EU, especially if any of them like overseas vacations.
Which is why these kinds of ultimatums NEED to be fought against, and aggressively. There ought to be NO room for any government to tell an open source project which features they must--or cannot--implement. Allowing this sort of thing is how you kill open source software. (Which may actually be their goal...)
But, if Mozilla wanted to acquiesce, they could release an EU-only version instead of weakening the trust/security of their browser for everyone.
Also, imagine the backlash that would happen if some part of the United States executive branch demanded the same thing the EU is demanding here.
If they are solely doing it for legal reasons, I would expect some form of malicious compliance - like an accompanying blog post explaining how it'll be marked as "Firefox is legally required to tell you the EU considers this page safe. We disagree. [Learn More]" and that the mark will only be shown to EU users.
Complying to the exact letter of a stupid law to avoid getting sued is understandable. Voluntarily complying to the broadest interpretation without any pushback is not.
The problem with QWACs and eSTAZI is a saturation attack by govt. against people. If Mozilla will display that message it will need to do it on all connections with QWACs, and 99.99% will be safe, initially. So govt. can demand them to remove misleading message. And Mozilla can't detect when govt. will use their CA to do a MITM attack on their political opposition and display message only then.
Have you ever heard the phrase "show me the man and I'll show you the crime"? The Europeans have and will not be happy if Mozilla does something like this.