Live data from Hacker News

Dear Mozilla, please stop spamming

palant.de

61–70 of 126 posts

Re: Dear Mozilla, please stop spamming

#61
> A year ago I reported a security issue in Mozilla Basket (not publicly accessible). The essence is that subscribing anybody to Mozilla’s newsletters is trivial

I don’t see how signing someone up to a newsletter is a security vulnerability.

Re: Dear Mozilla, please stop spamming

#62
post #53

Earlier quoted context omitted.

How much money does pocket actually generate? It blows my mind that mozilla would pull a java and have us install a figurative toolbar.

pocket is such a useful tool that I have a hard time understanding this comment.

It's a tool I have perfectly good alternatives for I already use that keeps using screen and menu space in my browser. I.e. why does my context menu have a "save to pocket" option despite me not being signed up for it, that I only ever will click accidentally? I don't mind there being a Pocket integration in Firefox, I somewhat mind it getting in the way if I don't want to use it.

Re: Dear Mozilla, please stop spamming

#63
post #34

Earlier quoted context omitted.

The whole point of Firefox _is_ to make network requests. All of the features above aren't leaking your user data or fingerprinting you, they're assisting you in what the applications purpose is... to make network requests. Not to mention firefox is an open-source project, so you could go look at all the network communication it makes when it starts up. All of these options are configurable anyways. I think you're lo…

>All of the features above aren't leaking your user data or fingerprinting you, they're assisting you in what the applications purpose is... to make network requests. And you can prove this how? All I'm saying is think twice before blindly trusting a tech company, because Mozilla is no longer the fun and friendly company we once knew. They are very much a rank and file data mining company now, generating tons of cash…

What kind of objectionable data mining do you claim they do? The requests cited above don't exactly give much potential for that.

Re: Dear Mozilla, please stop spamming

#64

Earlier quoted context omitted.

>I don't really see a problem with any of these? You seriously don't have an issue with being fingerprinted and tracked every single time you open an application on your computer? The point is that there should be zero. I should not have a single outgoing network request triggered by opening a web browser to a blank page until interacting in some way. The fact that we've lost this as a standard is terrifying to me.

Honestly you sound paranoid. What if a dev wants to add instrumentation to make sure a page is loaded? What if you have some weird OS version, CPU, or kernel that might crash 1% of app opens?

A web page is not an app. It is a sandboxed rendered template that should not be able to crash due to a web page nor care about what OS, CPU or kernel the user is running. If a user wants to give that information away, then they should be prompted.

Re: Dear Mozilla, please stop spamming

#65
post #18

Mozilla is ethically compromised at the highest levels. They’ve made a shift over the last few years from a scrappy, low-rent, nonprofit dedicated to helping the web to just another data mining tech company. Just try setting your Firefox browser to a blank page with no requests on startup and watching the Wireshark log if you think otherwise.

Mind posting sources for your claims of ethical compromise?

Renee DiResta: Mozilla Fellow, Director of Research at New Knowledge

https://www.mozillapulse.org/profile/410

New Knowledge is the organization that setup a fake Russian botnet, and then tried to push a narrative about how the Republican candidate in an Alabama Senate race was being assisted by this "Russian election interference"... anybody involved with that organization is a scumbag - it has zero redeeming qualities. Renee has been making the rounds lately on Youtube, informing everyone about how much of a threat these operations are (not her organizations fabricated ops, the totally real ones). I haven't yet found the prime mover in this, but her activities are well aligned with those of the DoD ratcheting up the scaremongering about the (according to them) active Chinese operations against the US population. So there is a pretty strong push for further internet lockdown measures being made right now by these people - and Mozilla is associated. At this point I would not be at all surprised to hear Mozilla announce RealID browser integration.

Re: Dear Mozilla, please stop spamming

#66
post #34

Earlier quoted context omitted.

The whole point of Firefox _is_ to make network requests. All of the features above aren't leaking your user data or fingerprinting you, they're assisting you in what the applications purpose is... to make network requests. Not to mention firefox is an open-source project, so you could go look at all the network communication it makes when it starts up. All of these options are configurable anyways. I think you're lo…

> The whole point of Firefox _is_ to make network requests. Just to point out, that "the whole point of Firefox" is to make the network requests I want . eg from my perspective it's a tool like (say) cURL that has a specific purpose. It's a subtle difference, but an important one. :)

Every one of the requests that 43920 listed in a request in service of you, the user. The first is to detect captive portals, which is something you'll find very important if you're behind a captive portal. The second is for OCSP certificate validation, which helps ensure your safety while browsing. The third is checking for updates, which again is for your benefit.

Re: Dear Mozilla, please stop spamming

#67
post #22

Earlier quoted context omitted.

> Just try setting your Firefox browser to a blank page with no requests on startup and watching the Wireshark log if you think otherwise OK, so I just did this, and I don't really see what the issue is. Looking at Wireshark, I see requests for: * detectportal.firefox.com, which is used to detect whether you're connected to a captive portal network and need to sign in before you can connect to the internet. As far as…

>I don't really see a problem with any of these? You seriously don't have an issue with being fingerprinted and tracked every single time you open an application on your computer? The point is that there should be zero. I should not have a single outgoing network request triggered by opening a web browser to a blank page until interacting in some way. The fact that we've lost this as a standard is terrifying to me.

How often do you open a web browser to then not interact with it? Does it make a meaningful difference if it instead slows down the first request triggered by you to make the captive portal and OCSP checks, and moves the update request to a random time?

Re: Dear Mozilla, please stop spamming

#68
post #53

Earlier quoted context omitted.

How much money does pocket actually generate? It blows my mind that mozilla would pull a java and have us install a figurative toolbar.

pocket is such a useful tool that I have a hard time understanding this comment.

I eventually disabled Recommended by Pocket on my new tab screen because the recommendations were typically clickbaity and being on the new tab screen, it would many times divert me from whatever more important original action I meant to take.

The creators probably had good intentions, but Recommended by Pocket seems almost like a dark pattern.

Re: Dear Mozilla, please stop spamming

#69

So they emailed you about a new service; shrug . Of all the "spam" you could possibly receive this is by far the most useful. What is it with all Firefox/Mozilla hating as of late? They don't seem to be able to do anything right in the eyes of some people, and seem to be held to a ridiculously high standard (far higher than anyone else).

When I opt out (or never opted in) and am still sent promotional material, it is an explicit message that the company disrespects me. Responding to that with shrug is layering more disrespect on top of it. Disrespect for users is a cardinal sin, and quickly reaches unforgivable levels if left unchecked. It is simply incorrect that this is an issue of bias against Mozilla. Other companies behaving worse doesn't make it acceptable - in fact, Mozilla's image of being "better" makes these kinds of infractions worse.

Re: Dear Mozilla, please stop spamming

#70

Earlier quoted context omitted.

Honestly you sound paranoid. What if a dev wants to add instrumentation to make sure a page is loaded? What if you have some weird OS version, CPU, or kernel that might crash 1% of app opens?

A web page is not an app. It is a sandboxed rendered template that should not be able to crash due to a web page nor care about what OS, CPU or kernel the user is running. If a user wants to give that information away, then they should be prompted.

The "app" is Firefox, not the web page.
Post reply on HN