Live data from Hacker News

Dear Mozilla, please stop spamming

palant.de

91–100 of 126 posts

Re: Dear Mozilla, please stop spamming

#91
post #20

Earlier quoted context omitted.

What browser would you suggest instead? I feel a bit cornered, especially now that literally every alternative is based on chromium.

This site suggests IceCat, Ungoogled Chromium, Iridium or Pale Moon: https://spyware.neocities.org/articles/browsers.html The also have a guide for enhancing privacy in Firefox

I would consider IceCat, but it looks like development has fallen behind Firefox considerably.

I mean no offense by this but I consider myself a privacy wonk and that website is a bit too tin foil hat even for me.

I think we're in a bad way as far as choices go for browsers these days, but Firefox seems like the best of a bad situation to me. If people are still concerned, they should take a look at the changes made to Firefox for the Tor browser.

Re: Dear Mozilla, please stop spamming

#92
post #61

> A year ago I reported a security issue in Mozilla Basket (not publicly accessible). The essence is that subscribing anybody to Mozilla’s newsletters is trivial I don’t see how signing someone up to a newsletter is a security vulnerability.

In some countries, it's not allowed without verification. This could get Mozilla in hot waters so I would fix it. How hard can it be?

Re: Dear Mozilla, please stop spamming

#93
post #86

Earlier quoted context omitted.

First of all, the story has actually changed a couple of times. So if you really want to understand the timeline - you are going to need to refer to archives of those articles. Second, the "small experiment" had a budget of at least $100k that they are willing to admit to - traceable money that flowed through people related to the USDS and DoJ. You know that Obama repealed the ban on domestic propaganda before he lef…

> New Knowledge's objective was to deceive voters. From reading the article, the group's¹ objective wasn't to deceive voters, it was to research how these tactics worked. Are you suggesting that a single $100k research project was sufficient to alter the course of an election with a $51M advertising budget? As near as I can tell, that's just how the right-wing media is trying to spin it. Certainly if I were to actual…

> ...the group's¹ objective wasn't to deceive voters...

"The report does not say whether the project purchased the Russian bot Twitter accounts that suddenly began to follow Mr. Moore. But it takes credit for “radicalizing Democrats with a Russian bot scandal” and points to stories on the phenomenon in the mainstream media. “Roy Moore flooded with fake Russian Twitter followers,” reported The New York Post."

Deception.

> Which seems to have involved at least one New Knowledge member but it seems wasn't actually run by New Knowledge.

Reid Hoffman, the billionaire funding AET wrote an apology. What does he have to apologize for? Well he paid AET $750k, AET paid New Knowledge at least $100k of that to run this disinformation campaign. So you can knock it off with the "at least one member... seems wasn't run by New Knowledge..." Obviously my patience has run thin on this - it has been proven that Morgan is a liar and that New Knowledge was deeply involved.

https://medium.com/@reidhoffman/truth-and-politics-1a532bc6c...

As I said, they've change their story more than once. When Morgan was pressed on the leaked internal report's clearly political goals, he said that "it didn't ring a bell".

Oh, and go check out their release of the report they provided the Senate Select Committee on Intelligence in December. What, you didn't know that this politically motivated organization with an agenda was asked to inform the Senate about Russian interference in US election? Yeah, they were - and did, in December. Checkout the timestamp on that pdf - not December... weird...

> That said, I find it hard to believe you're arguing in good faith when you're drawing parallels between a limited spread of misinformation centered around a single event with literally murdering people.

When you say "limited spread" do you actually mean "completely unrestrained"? And no. I find it hard to believe that you don't see the parallels between the justifications for unethical experimentation conducted on an unwitting population during the cold war, and the rationalization you've provided in this thread. It has nothing to do with deaths, it has everything to do with the ethics and the non-zero cost to individuals. In the cold war a statistically insignificant portion of the population involuntarily paid a heavy price, in this "experiment" (it wasn't, the leak shows it was a political action) a statistically insignificant portion of the population was convinced that their president was a traitorous Russian agent and driven mad with impotent rage.

Re: Dear Mozilla, please stop spamming

#94

The screenshot in the post shows also a "optin" property, set to "true". Perhaps that should be set to "false" instead? But anyway, "optout" ought to take priority IMHO.

I would expect this is a GDPR compliance thing, moving to only opt-in for non-transactional contact (as is required).

But that doesn't explain how or when it was set.

Re: Dear Mozilla, please stop spamming

#95
post #3

In a similar vein, I'd appreciate it if Mozilla would stop using updates to Firefox as a mechanism to re-enable misfeatures I've explicitly disabled like Pocket integration and the "recommend X feature|extension while you are browsing but don't forget we totally respect your privacy!" settings. :-/

I've never seen the described behaviour. Have you checked bugzilla.mozilla.org if this is a known problem?

Re: Dear Mozilla, please stop spamming

#96

Earlier quoted context omitted.

What browser would you suggest instead? I feel a bit cornered, especially now that literally every alternative is based on chromium.

Brave. And what's wrong with Chromium?

It reinforces Google's control of the internet, and helps convince webmasters that the only browser they need to test for is Chrome.

Re: Dear Mozilla, please stop spamming

#97
post #80

Earlier quoted context omitted.

Yeah, portal checking and update checking are surely things 99% of people appreciate. Captive portal popup seems like an obvious UX improvement for 99% of people. I wonder how many people on HN even know how to trigger it if the browser didn't try to do it for you. Update checking and over the air updates make obvious sense to me given that my mother and girlfriend will click "Remind me tomorrow" for years on the mac…

> I wonder how many people on HN even know how to trigger it if the browser didn't try to do it for you. For anyone wondering: Just try and open literally any http page (note: no s). I use groklaw.net.

That's getting harder and harder as people add HSTS.

There's still neverssl.com, but with the most popular pages using HSTS like Google Facebook and Reddit, captive portal detection is essential for your average user.

Although I wish the IETF would make a standard for doing this at the network level as part of DHCP rather than the current ridiculousness we have. Captive portals are just the buggiest shit.

Re: Dear Mozilla, please stop spamming

#98
post #66

Earlier quoted context omitted.

Every one of the requests that 43920 listed in a request in service of you, the user. The first is to detect captive portals, which is something you'll find very important if you're behind a captive portal. The second is for OCSP certificate validation, which helps ensure your safety while browsing. The third is checking for updates, which again is for your benefit.

Don't get me wrong, I do agree with the 2nd two, though I haven't really thought through the first use case. :) I'm mainly just replying to the poster that attempted to say that since Firefox already makes network requests, ~anything should be ok.

A captive portal is a login screen of a service that prevents other activity unless logged in.

My guess is that Firefox will not try to check for updates or other things if it notices that the detectportal-request was not successful (i.e. the user is not logged into the hotel-wifi or something like this yet).

Re: Dear Mozilla, please stop spamming

#99

Much as I am a happy user of Mozilla products especially Firefox, incidents such as this makes me lose respect for the organization.

There's an opt-in flag set in the data on the screenshot.

Something went wrong and the author (that's the ABP-creator, right?) is just making a mountain out of a molehill.

Re: Dear Mozilla, please stop spamming

#100
post #3

In a similar vein, I'd appreciate it if Mozilla would stop using updates to Firefox as a mechanism to re-enable misfeatures I've explicitly disabled like Pocket integration and the "recommend X feature|extension while you are browsing but don't forget we totally respect your privacy!" settings. :-/

I've disabled Pocket via about:config and despite a year worth of updates, I honestly had never had the issue of it reenabling. And that is both on Windows with Auto-Update and Linux via package manager.
Post reply on HN