Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

191–200 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#191
post #111
post #67

I have a bunch of privacy-enhancing addons installed, which have now all been disabled. If I hadn't read HN this morning, I wouldn't even have known why. Until now, I had no idea that it was even possible to remotely disable my addons. And now Mozilla are saying that the "fix" is to allow them to install & run "studies" on my machine? What are they smoking? I'm having a hard time trusting a company that randomly & re…

I enjoy a nice cup of outrage in the morning just like the next guy, but this one is really weak and lacks that fresh taste of evil conspiracy that I really crave. You use a browser that has remote update capability, which allows them to install and run new software on your machine all the time. There is a whole separate section of the Preferences that says "Privacy" in large print that has a section that clearly ide…

Here's the thing, though: yes, we most certainly are giving them a lot of trust by allowing them to install software on our machines. Which means outrage when they screw up is totally justified, because they broke that trust.

Here's a metaphor: Let's say you let someone seemingly trustworthy watch your kid. (In this metaphor you have a kid). And they let your kid get a broken arm through gross negligence (let's say they passed out drinking beer), and then someone said "well, obviously, you should have never trusted that person, after all, they can do anything with your kid while you're gone, so why are you outraged?" You probably would still be pretty outraged right? You would certainly question your decision to trust them, but at the end of the day you have to trust someone, you'd be a complete shut-in if you could never hire a baby-sitter.

Re: Update Regarding Add-Ons in Firefox

#192

Earlier quoted context omitted.

What's the difference to the user between "to check revocations too, sure" and what happened?

checking revocations lists != certificate expiry

Revocation lists are often tied to certificate expiry, purging entries that are no longer valid due to expiry.

Re: Update Regarding Add-Ons in Firefox

#193
post #4

An article that mentions a timeframe of “the next few hours”, but doesn't have any timestamp besides a date without a timezone.

You can hover the date to see the full timestamp, it's 2019-05-04 07:01:35 UTC-7.

It's an annoying UX antipattern, the only thing worse being not adding the on-hover text at all. Displaying date and time should be the default.

HN has this problem too.

Re: Update Regarding Add-Ons in Firefox

#194
post #158

I'm not gonna bother with 'studies' or manual workaround - I'm just going to wait for an update. In the meantime I'm enjoying trying out Vivaldi[1] - really reminds me of opera 3/4, that I loved. 1: https://vivaldi.com

Will Vivaldi let me put the tabs on bottom where they belong?

Yes, Vivaldi supports tabs on your choice of any of the 4 sides of the window.

Re: Update Regarding Add-Ons in Firefox

#196

Earlier quoted context omitted.

> How hard is that? If you think that’s trivial, I challenge you to go build it. It might seem warranted in hindsight, but thinking about all failure cases ahead of time is hard. If it weren’t, we’d not have bugs.

Cool, yeah, noone can complain unless they can personally do it all better. Do you think that's workable? I don't think it's trivial. The critical element here appears to be "who gets the final say" and not "this is to hard to code". They manage to disable the "Enable" button for addons, and managed to consider this situation enough to provide a justification that (paraphrasing) "we do this when we don't want the add…

No, you can complain. I specifically object to “How hard is that?” which is an entire class in itself. Stuff often is inherently hard and when you don’t know internals of a project and don’t work on it, you may have no concept of how hard it is. Don’t pretend you do. Saying “How hard is that?” carries the notion that everyone working on that thing you don’t know is sloppy, malignant or stupid.

“I wish it would do that.” is a much more charitable way to phrase your complaint.

Re: Update Regarding Add-Ons in Firefox

#197
post #124

Earlier quoted context omitted.

Sir, this is Hacker News.

Yes, we are all quite advanced enough to footgun ourselves with abandon :) For everyone else, the fix is magically healing their browser without any intervention at all, and some of my high-skilled tech friends haven’t even noticed yet because they’re weekending and this all resolved itself before they realized it. Never underestimate the burden that being an “expert” places on your future time spend.

That hadn't occurred to me, but the fact that this is occurring on a weekend probably mitigates the impact to organizations that operate Monday-through-Friday.

Sucks for the Mozillans who are scrambling right now though. Hope they get a long weekend to compensate.

Re: Update Regarding Add-Ons in Firefox

#199

On Android I get this: >We rolled out a hotfix that re-enables affected add-ons. The fix will be automatically applied in the background within the next few hours. For more details, please check out the update at https://support.mozilla.org/en-US/kb/add-ons-failing-install... Which is like "we did something we shouldn't have causing unauthorised changes to your computer, so we're going to make unauthorised changes to…

As I understand it, you agree to the terms of Studies as part of the ToS agreed to on installation. You can disable it later. And--while it was a ridiculous mistake--they didn't make any "unauthorized changes" to your computer. They just let a certificate expire and your computer, running the same code it always had, stopped trusting it.

Hiding behind ToS is ridiculous. Nobody reads them and a moral company should never assume that because its in the ToS they actually have informed consent.

Re: Update Regarding Add-Ons in Firefox

#200

I know Firefox isn't being malicious, but ugh, this seems like the worst possible PR move for this, optics wise. "Hey so uh, we accidentally broke your browser, so you need to opt-in to becoming a guinney pig. But don't worry! You probably were already opted in anyway and just didn't realize it! Also it might take six hours to work."

So that's pretty unfair. 1) They state they are working on a fix for normal, release channel users who don't want to run studies 2) they tell you to temporarily run studies to get the fix within up to 6 six hours (could be faster; set expectation) 3) You can explicitly install nightly or 66.4 before it's pushed if you want a fix now Yes, it's unfortunate, I'd expect them to meet it head on, push a tested fix in a tim…

It is too late to listen to reason. Many commenters have spent their Saturday morning pushing a narrative that appeals to emotion.
Post reply on HN