Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

331–340 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#331

Can we take a moment and consider the side effects? This is a once in a lifetime chance for Google & Co. to get a glimpse of all those sly fuckers hiding behind adblockers. This effectively uncloaked a very specific subset of Internet users and exposed them to the very companies that they've been actively trying to avoid. Not just those who avoid Chrome, but those who take extra steps to explicitly evade the tracking…

>Surely Mozilla, the privacy advocate

Re: Update Regarding Add-Ons in Firefox

#332

Earlier quoted context omitted.

Really? Because being the bottleneck (i.e. single point of failure) responsible for approving all addons is exactly what bureaucrats would want to do ;-) The non-bureaucratic thing to do, as has been pointed out many times of course, would be to give users the power to override the cert signing check as an advanced option.

It is, in fact, an "advanced option", in about:config.

But that option only works in nightly builds, not Firefox release builds. If an option doesn't honour what it claims to, imho it might as well not be there.

Re: Update Regarding Add-Ons in Firefox

#333

Earlier quoted context omitted.

But that's the point. Either the installer does something malicious or it doesn't. If it does you lost the game. If it doesn't then a simple check is sufficient. Everything else is security theater which makes life worse for everyone. Also, they could still run the verification and prompt the user instead of just forcing the decision.

On a typical Linux install, the Firefox binary is not writeable by a malicious extension installer that runs with user privileges. Thus baking the check into the binary fully protects the integrity.

Then overrides could also be made configurable as root.

Re: Update Regarding Add-Ons in Firefox

#334

Earlier quoted context omitted.

Switch to what? Chrome? Because you don't like having to re-opt-in to studies? That would be ludicrous given Google's privacy track record. Opera? They're owned by a Chinese investment firm now. Edge? MS's whole OS is based on data collection.

Typing this from a new Brave install. Just switched from Firefox after their handling of this.

The handling, or the bug itself? Sound like the damage control is fine (although worrying that they have no way to distribute hotfixes more rapidly than this).

The bug in the first place, on the other hand, seems pretty negligent. Not that it's incomprehensible, just pretty stupid.

Anyhow, good luck with brave!

Re: Update Regarding Add-Ons in Firefox

#335

Earlier quoted context omitted.

Not saying that their current actions are wrong , just that the optics of it are terrible for them. There was a chain of bad decisions that led them here though: 1) thinking it's ok to disable software after its installed (using cert expiration -- I'm ok if the cert was revoked but that's a totally different discussion), 2) Taking more control of people's local software than many people are comfortable with, especial…

What does optics mean in this context?

Public perception. For instance, one of the first comments on their post is this:

> Why not just post a link to the fix that can be installed WITHOUT enabling Studies? This sounds like a clever plan to get more people to share their data via Studies…

I definitely don't agree with that guy, and I doubt that's a majority opinion, but asking people to use a workaround that benefits them (Mozilla) after they broke things for a lot of people is bad publicity for sure. For what it's worth I think Mozilla is doing the right thing here, just it's not going to make them look great.

Re: Update Regarding Add-Ons in Firefox

#336

So, I left Chrome for all the b's they were doing with/to the web. Now Mozilla is fcking it up, too. Which browser to choose now?

IE6. No, I'm only half-serious. ;-) Remember when the Web was mostly about sharing information, browsers didn't silently auto-update nor break in the process of doing so, organisations didn't add invasive "telemetry" to everything, and things would mostly stay working because the pace of change was generally much slower? Now that the "keep pushing it forward and breaking things" trendchasers seem to have gotten their…

I understand what you mean and I think I feel quite the same.

"The web" has just become so... "strange" in the way everything works and we take care of it or however you'd like to call it. Often it's just broken with full intention to do just to push some new shiny technology on us. And I'd really like if it wasn't that way.

Re: Update Regarding Add-Ons in Firefox

#337
post #328

Earlier quoted context omitted.

nowadays they seem to make it a hobby to make negative headlines at least once every quarter. I fear there will be no negative repercussions for the leadership. Basically, the management set their own salaries, the entire work force gets a 40% yearly bonus, and they have no one from the outside to report to. On top of all of this, the money flows regardless of what anyone is doing. (While there is a yearly loss of 10…

This is categorically untrue, and unhelpful.

some things I wrote I can not prove, that is right. I would love to revise my negative opinion in light of better evidence.

Re: Update Regarding Add-Ons in Firefox

#338

IMHO it seems problematic, that they can remotely push code changes, including replacement of trusted certificate, and bypass package managers. I don't expect software to (significantly?) change during runtime, outside of what was packaged, signed, distributed and installed as part of apt/yum/pacman/etc. I understand (not that I like or agree with) that some apps are just embedded web browsers, and load everything ex…

If you didn't have browsers auto updating no-one would update them manually, meaning bad news for web developers wanting to take advantage of newer features.

I understand the appeal of that for developers but it comes at the cost of users agency and control of their own system, I've been very annoyed with even simple UI changes in firefox updates as I simply didn't ask or want any such change. Reading other comments here it's clear I'm a dying breed of old and stubborn users that prefers full control and agency over my own system. Making it easier for web developers to implement new features is absolutely not a tradeoff I'd make willingly at the cost of my systems consistency and reliability. Also the reason I use firefox is because of all the major browsers vendors they seem the most aligned with those values although this seems to be changing more and more every year.

Re: Update Regarding Add-Ons in Firefox

#339

IMHO it seems problematic, that they can remotely push code changes, including replacement of trusted certificate, and bypass package managers. I don't expect software to (significantly?) change during runtime, outside of what was packaged, signed, distributed and installed as part of apt/yum/pacman/etc. I understand (not that I like or agree with) that some apps are just embedded web browsers, and load everything ex…

Software developers optimize for overall utility, not paranoia.

Re: Update Regarding Add-Ons in Firefox

#340

Earlier quoted context omitted.

If you didn't have browsers auto updating no-one would update them manually, meaning bad news for web developers wanting to take advantage of newer features.

I understand the appeal of that for developers but it comes at the cost of users agency and control of their own system, I've been very annoyed with even simple UI changes in firefox updates as I simply didn't ask or want any such change. Reading other comments here it's clear I'm a dying breed of old and stubborn users that prefers full control and agency over my own system. Making it easier for web developers to im…

The incentive structures of society (capitalism, if you're so inclined, but I don't think this is unique to capitalism) are incompatible with your wishes.
Post reply on HN