Live data from Hacker News

Firefox 66.0.4 is out, fixes disabled add-ons

ftp.mozilla.org

81–90 of 392 posts

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#81

Earlier quoted context omitted.

Yes, running experiments on unknowning and unconsenting users is unethical, especially when the metrics being optimized for usually aren't in the users' best interests. The widespread acceptance for this behaviour could definitely be classified as brain damage.

I think this can be compared to McDonald's slightly altering the recipe of something for part of the country. I don't find that unethical at all, and frankly the things we put in our body are a lot more personal than which web browser we use.

Yes, but it isn't (well should not be if they want to stay within the law) adding completely random drugs an garbage to the food. It may be seeking cheaper recipes with no sales losses, better recipes to improve sales, or something else, but it all has to be within the context of proper regulation, i.e.,, FDA. (we can argue elsewhere about the effectiveness of that system).

This unlimited testing can easily be seeking to better maximize psychological exploits with no regulation.

So, yes, I'm happy to see someone putting in a bit of control.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#83
I was already a bit mad at them for removing RSS support and claiming their proprietary service that's built in is an alternative, now their proprietary service keeps working (presumably, I didn't use it but it's not an addon so I doubt it's signed the same way) and I can't use the RSS addon.

I know this was a mistake, but I can't help but be mad that their proprietary built in stuff effectively gets a free pass and special treatment and meanwhile I can't use RSS and all my containers were deleted (those didn't come back after the study was pushed either).

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#84
post #69

I don't understand why renewing the certificate wouldn't fix the issue ? How does the 66.0.4 fix the problem exactly ?

It's a signing certificate that is built into the browser to verify add-ons, not a normal TLS certificate that they can just update on a web server. The change basically just imports the new certificate into the database: https://hg.mozilla.org/releases/mozilla-release/rev/848b1502...

> It's a signing certificate that is built into the browser to verify add-ons, not a normal TLS certificate that they can just update on a web server.

Ah, so that's why. Thanks.

What was the signing certificate validity period ?

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#85

What about older versions? Does this mean that older versions of firefox can never be used with addons (even matching older versions) anymore?

A fix for the ESR is coming, are there any other supported old versions of firefox out there?

If you're using an unsupported version, then it's probably safe to assume you won't get a fix.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#86

Earlier quoted context omitted.

Yes, running experiments on unknowning and unconsenting users is unethical, especially when the metrics being optimized for usually aren't in the users' best interests. The widespread acceptance for this behaviour could definitely be classified as brain damage.

I think this can be compared to McDonald's slightly altering the recipe of something for part of the country. I don't find that unethical at all, and frankly the things we put in our body are a lot more personal than which web browser we use.

That is dismissive of how much value people place on their selves and digital aspects thereof. My identity, private conversations, and sexuality are infinitely more personal than the food I consume.

I agree that it’s appropriate to A/B test changes, within reasonable bounds. I wish the debate would focus more on what the reasonable bounds are to each objector.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#87
post #69

Earlier quoted context omitted.

It's a signing certificate that is built into the browser to verify add-ons, not a normal TLS certificate that they can just update on a web server. The change basically just imports the new certificate into the database: https://hg.mozilla.org/releases/mozilla-release/rev/848b1502...

> It's a signing certificate that is built into the browser to verify add-ons, not a normal TLS certificate that they can just update on a web server. Ah, so that's why. Thanks. What was the signing certificate validity period ?

Two years, iirc.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#89

Earlier quoted context omitted.

> especially when the metrics being optimized for usually aren't in the users' best interests I don't think so. Mozilla is not google, and apart from the mr. Robot error, that they apologized for, I am sure Mozilla is using it for making the browser better, and not to use you for targeted ads like the other browser maker does.

When has Chrome used A/B testing for ad targeting in the past? Can you link to an example?

Google Chrome uses the RLZ tracking identifier for some installations.

"RLZ gives us the ability to accurately measure the success of marketing promotions and distribution partnerships in order to meet our contractual and financial obligations."

https://blog.chromium.org/2010/06/in-open-for-rlz.html

Post reply on HN