Live data from Hacker News

Promoted Add-ons Pilot

blog.mozilla.org

111–120 of 138 posts

Re: Promoted Add-ons Pilot

#111
post #83

Earlier quoted context omitted.

Open source extensions already wait weeks or, more often, months to be reviewed and have that scary warning removed. As this program is planned, any commercial or other well-funded extensions will be jumping the queue ahead of them. That seems strictly worse, unless they also pay to play.

Well the Mozilla add-on website maybe isn't the only way to distribute webextensions. Mozilla already hosts and lists the add-ons for free. It seems only normal it warns users that no verification has been made as they might assume since it's on an official website. Extensions may be hosted elsewhere and reviewed by online communities too. For example, the Krabby extension that add Kakoune keybindings to web navigati…

Well the Mozilla add-on website maybe isn't the only way to distribute webextensions.

It is now. All add-ons must be signed by Mozilla. There's a development mode, but test add-ons disappear when the browser exits.

Re: Promoted Add-ons Pilot

#112

Mozilla has been recommending a copy-cat extension for ~3 years, despite reports from users and developers. https://twitter.com/Pythux/status/1154403982342852609 https://twitter.com/gorhill/status/1165747661691064322 https://github.com/mozilla/addons/issues/1078 This is an unpaid recommendation. Why would I trust Mozilla now that they’re getting paid?

Is there anything inherently wrong with recommending a "copycat" extension? As long as it complies with the license, why is the fact is has copied an issue? If it is useful for users and passes Mozilla's criteria why should they not recommend it?

Re: Promoted Add-ons Pilot

#113

I bet they're going to make bribing Mozilla a condition to get on the whitelist for mobile Firefox. Which explains why it exists.

It's hardly a bribe though, is it?

The allowlist exists so it can guarantee users install add-ons which work, and don't break their browser. Both reviewing and adding support for required APIs costs money.

Re: Promoted Add-ons Pilot

#114
post #80

Earlier quoted context omitted.

Meanwhile, commercially owned extensions which are terrible for privacy and security, like Grammarly and Honey, are going to get promoted by Mozilla. The open-source projects with no income are the ones getting hurt.

How are the Grammarly[1] or Honey[2] addons terrible for security? I can guess why you say they're terrible for privacy, but they both mention what data they share on the addon page. So it seems not so much that they are violating users privacy, but that you think people should be more concerned with the amount of privacy they give up. For the record, I am pro-privacy, and would never want to use addons like these th…

Unless I’m mistaken, Grammarly processes everything you type on their servers. It’s an internet-enabled keylogger.

Re: Promoted Add-ons Pilot

#115

I bet they're going to make bribing Mozilla a condition to get on the whitelist for mobile Firefox. Which explains why it exists.

It's hardly a bribe though, is it? The allowlist exists so it can guarantee users install add-ons which work, and don't break their browser. Both reviewing and adding support for required APIs costs money.

Not putting artificial restrictions into the browser is free.

Re: Promoted Add-ons Pilot

#116

Earlier quoted context omitted.

It's hardly a bribe though, is it? The allowlist exists so it can guarantee users install add-ons which work, and don't break their browser. Both reviewing and adding support for required APIs costs money.

Not putting artificial restrictions into the browser is free.

It's really not. I work on Firefox. Just yesterday I spent some time helping a user debug an issue they had, and it turned out to be caused by them flipping a hidden pref in about:config. This is not uncommon, it takes up my time and my colleagues' time, which costs money.

Re: Promoted Add-ons Pilot

#117
post #97

Earlier quoted context omitted.

The only thing that a banner "by scrolling down you opt in to something" means according to GDPR is that the people who wrote that banner are liars. Quoting GDPR definitions (Art 4.12), '‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes [..]'. If the site owner wants to assert that the user provided consent, it's up to them to demonstrate…

I'm not saying it's a good way to do this. But they clearly state so. 'By scrolling, you are agreeing to use of cookies for marketing ' . They give you a good,easy way to opt out too.

https://ico.org.uk/for-organisations/guide-to-data-protectio...

> You may not rely on silence, inactivity, default settings, pre-ticked boxes or your general terms and conditions, or seek to take advantage of inertia, inattention or default bias in any other way. All of these methods also involve ambiguity – and for consent to be valid it must be both unambiguous and affirmative. It must be clear that the individual deliberately and actively chose to consent

Re: Promoted Add-ons Pilot

#118
post #80

Earlier quoted context omitted.

How are the Grammarly[1] or Honey[2] addons terrible for security? I can guess why you say they're terrible for privacy, but they both mention what data they share on the addon page. So it seems not so much that they are violating users privacy, but that you think people should be more concerned with the amount of privacy they give up. For the record, I am pro-privacy, and would never want to use addons like these th…

Unless I’m mistaken, Grammarly processes everything you type on their servers. It’s an internet-enabled keylogger.

If that is true, then I would hope that they fail the verification review, despite having paid a fee.

"Developers will have all new versions of their add-on reviewed for security and policy compliance. If the add-on passes, it will receive a Verified badge"

Re: Promoted Add-ons Pilot

#119
post #97

Earlier quoted context omitted.

The only thing that a banner "by scrolling down you opt in to something" means according to GDPR is that the people who wrote that banner are liars. Quoting GDPR definitions (Art 4.12), '‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes [..]'. If the site owner wants to assert that the user provided consent, it's up to them to demonstrate…

I'm not saying it's a good way to do this. But they clearly state so. 'By scrolling, you are agreeing to use of cookies for marketing ' . They give you a good,easy way to opt out too.

A good way to do what? Clearly stating something does not make it true, because, to make it really clear, by reading this you definitely agree that you owe me $100.

The GDPR approach is that processing personal data by companies is prohibited by default, unless they can point out one of the specific GDPR subsections that permits that particular purpose of processing. They are not allowed to use my personal data for marketing unless specific conditions are met. Scrolling past a statement 'By scrolling, you are agreeing to use of cookies for marketing' does not meet these specific conditions, no matter how clearly its said, so the banner legally makes no difference whatsoever, it does not mean that I'm agreeing to anything, it's exactly as if it wasn't there, and that clear statement is simply a lie.

And the "good,easy way to opt out" does not matter, after the opt-out it's just as illegal for them to use data as before the opt-out, since I did not opt-in. If they're using my data without an intentional opt-in, then they're untrustworthy cheaters anyway, there's no reason to try to opt-out of something that I didn't opt-in to, this should be handled by the regulator who will be able to audit them to verify if they have actually stopped using the data.

Furthermore, if had opted in, the legal requirement (Article 7.3) is "It shall be as easy to withdraw as to give consent." So if opting in happens on the main page by scrolling but opting out happens in a settings menu requiring two clicks, then that may be good but it's not good enough, because it's not as easy as it was to opt in.

Re: Promoted Add-ons Pilot

#120

I bet they're going to make bribing Mozilla a condition to get on the whitelist for mobile Firefox. Which explains why it exists.

It's hardly a bribe though, is it? The allowlist exists so it can guarantee users install add-ons which work, and don't break their browser. Both reviewing and adding support for required APIs costs money.

bribe: noun

Something offered to induce another to do something.

Post reply on HN