Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

411–420 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#411
post #408

Earlier quoted context omitted.

This has nothing to do with "studies" and should be pushed as a general fix. There is just no excuse. What if this had been a security incident?

Then it seems it’s a good thing they had a system in place that could deliver the quick fix in less than a day, on a Friday evening, when shipping a normal fix could have — is — taking longer to ship than that quick fix did.

> it’s a good thing they had a system in place that could deliver the quick fix

No, it's not. "Studies" is not a security-related mechanism and it didn't exist in the past, when fixes were rolled out very quickly anyway for security reasons. "Studies" should not be relied on to be a fix-delivery mechanism, because it just isn't.

This is not even about privacy, it's simple good engineering sense.

Re: Update Regarding Add-Ons in Firefox

#412
post #52
post #18

Instead of enabling studies just click on this link. It installs that specific "study" (hotfix) without installing anything else. https://storage.googleapis.com/moz-fx-normandy-prod-addons/e...

How do I uninstall this? It doesn't show up anywhere after installation.

I'm pretty sure the only thing this "add-on" does is install a certificate to your browser's trust store. You can remove the certificate by going to Options > Privacy & Security > View Certificates > Authorities > Mozilla Corporation > signingca1.addons.mozilla.org > Delete or Distrust.

You can manually install the certificate instead of using the "add-on" in the OP. Copy https://pastebin.com/rpByJV9P to a text file, change the extension to .crt, and then use the Import button in the Authorities tab I mentioned before.

Re: Update Regarding Add-Ons in Firefox

#413
post #393
post #386

Earlier quoted context omitted.

How is this better then enabling studies, a setting that is already part of Firefox? Installing add-ons from random sources can be risky. But anyways, I'm not sure why, but the addons on my main computer remained enabled... unlike my 2 other computers.

It's cryptographically signed by Mozilla. The signature is much more important than the source.

I clicked that link and it displayed a puzzle piece with a one-way/no-entry symbol (https://i.stack.imgur.com/eVpMr.png)... not sure how I can know that this was signed by Mozilla, a company that I trust less every year

Re: Update Regarding Add-Ons in Firefox

#414
post #312

Earlier quoted context omitted.

> Would it connect to 802.11m WiFi router? Sure. It's using OS networking APIs. Or running in a virtual machine. > Would you consider it secure enough to open your banking website on it? If I'm running 20 year old software, it's probably to interact with a legacy system. There are still businesses that run on like 486's with Windows 3.1. This is more common than you think! > The bar is whether the machine is usable (…

> For all they know I'm using the software in a museum, 20 years from now, about this era of computing. And then you'll simulate a time appropriate for the device/software. As a date before 2038 to not have unix time overflow. Or 2000. Or any other time specific bug. Or how often did you have to "fix the internet" for one of your relatives because their damn CMOS battery died? Yeah, time seems to be quite relevant fo…

My point wasn't that I want to run a museum, but that intentionally turning software into a time bomb is silly and adds very little security value. At least those other ways it happens accidentally.

Re: Update Regarding Add-Ons in Firefox

#415
post #389

Earlier quoted context omitted.

FWIW I think it's pretty easy to test if someone is using an adblocker anyway. (I see sites do the "It looks like you're using an adblocker" thing all the time). I don't know if there's any realistic way to entirely hide that.

That's a bit different though- generally speaking those messages show up when the javascript tracker can't talk to the server it's communicating with. Even though it's "detecting" the adblock it isn't able to send information back from the client about it.

> Even though it's "detecting" the adblock it isn't able to send information back from the client about it.

Sure they can, they can just send back a resource request. It could even be for like an image with a query string attached with it, it doesn't have to be an ajax request necessarily.

Re: Update Regarding Add-Ons in Firefox

#416
post #411

Earlier quoted context omitted.

Then it seems it’s a good thing they had a system in place that could deliver the quick fix in less than a day, on a Friday evening, when shipping a normal fix could have — is — taking longer to ship than that quick fix did.

> it’s a good thing they had a system in place that could deliver the quick fix No, it's not. "Studies" is not a security-related mechanism and it didn't exist in the past, when fixes were rolled out very quickly anyway for security reasons. "Studies" should not be relied on to be a fix-delivery mechanism, because it just isn't. This is not even about privacy, it's simple good engineering sense.

It seems like your objection to the Normandy system is that the UX surrounding it includes the word “Studies”. I am grateful they chose in this instance to prioritize repairing addons worldwide over the confusion that word has caused you and potentially others. I assume, having seen this and other such comments delivered with outrage rather than thankfulness today, that they will re-evaluate the UX surrounding the Normandy system to ensure that it more clearly designates non-study changes as such.

Re: Update Regarding Add-Ons in Firefox

#417

Can we take a moment and consider the side effects? This is a once in a lifetime chance for Google & Co. to get a glimpse of all those sly fuckers hiding behind adblockers. This effectively uncloaked a very specific subset of Internet users and exposed them to the very companies that they've been actively trying to avoid. Not just those who avoid Chrome, but those who take extra steps to explicitly evade the tracking…

I can't help but consider the tinfoil hat aspects of this matter. I would like to learn more about the sequence of events that lead to this snafu. Would an actor know that by making "an error" at a given point in time, there would be a deterministic window of time in the future where Firefox users worldwide would be affected by the consequences.

As much as I love my tinfoil hat, I can't see any upside for mozilla in this? If it's to get people to opt in to "studies", they already have most people sending them telemetry, apparently, so this would just be to get stragglers? Seems like a really expensive way to do it.

Re: Update Regarding Add-Ons in Firefox

#418

Earlier quoted context omitted.

No, just this one because it took me more than 5 minutes to not find a working fix, and this was such a massive fuck-up that I don't feel like sticking around. I appreciate the condescension of both your comment and the person I initially replied to, but I honestly see your comments as saying, in more words, "Fuck the user." And that's fine, but why don't you just say it? Go ahead and type it, I want you to type what…

No, we’re not flagging you for your use of swear words; we’re flagging you for your lack of construction to the conversation. You clearly are not interested in having a conversation

Mmhmm.

“Everyone who disagrees with me is an emotional idiot!”

“Hey I just uninstalled Firefox.”

“Flag him!”

I await your apology.

Re: Update Regarding Add-Ons in Firefox

#419
post #365

Earlier quoted context omitted.

Hahahah look at all the Firefox fanboys coming out of the woodwork to try intellectual bullying because they're mad I admitted to uninstalling a web browser.

Or maybe they take offence at your overall tone? You're clearly not interested in being constructive. This kind of toxicity is exactly why many of us have "uninstalled" Reddit and the like. Please refrain from bringing that toxicity to HN.

“Many commenters have spent their Saturday morning pushing a narrative that appeals to emotion.”

“Toxicity.”

Goes both ways.

Re: Update Regarding Add-Ons in Firefox

#420
post #411

Earlier quoted context omitted.

> it’s a good thing they had a system in place that could deliver the quick fix No, it's not. "Studies" is not a security-related mechanism and it didn't exist in the past, when fixes were rolled out very quickly anyway for security reasons. "Studies" should not be relied on to be a fix-delivery mechanism, because it just isn't. This is not even about privacy, it's simple good engineering sense.

It seems like your objection to the Normandy system is that the UX surrounding it includes the word “Studies”. I am grateful they chose in this instance to prioritize repairing addons worldwide over the confusion that word has caused you and potentially others. I assume, having seen this and other such comments delivered with outrage rather than thankfulness today, that they will re-evaluate the UX surrounding the No…

It's not about designation, it's about control. If Mozilla really cares about trust, they shouldn't mix their update delivery system, which should care for timely security-related material, with general telemetry, data-gathering, and experiments.

I use FF because I care about principles. Otherwise I might as well just let myself be exploited by Google, MS, Apple and friends.

Post reply on HN