Live data from Hacker News

Firefox add-on with 7m downloads secretly tracks your browsing history

iwtf.net

1–10 of 58 posts

Re: Firefox add-on with 7m downloads secretly tracks your browsing history

#4
post #3

The lesson here: don't install shady addons, just as you aren't installing every damn toolbar out there. Also, this is enough to sue, isn't it?

Rather depressingly, this wasn't so much a shady add-on, as one that was meant to have been vetted by Mozilla.

From the Mozilla Add-Ons FAQ @ https://addons.mozilla.org/en-US/firefox/faq

Are add-ons safe to install? Unless clearly marked otherwise, add-ons available from this gallery have been checked and approved by Mozilla's team of editors and are safe to install. We recommend that you only install approved add-ons. If you wish to install unapproved add-ons or add-ons from third-party websites, use caution as these add-ons may harm your computer or violate your privacy. Learn more about our approval process

Re: Firefox add-on with 7m downloads secretly tracks your browsing history

#6
Like Apple products, Firefox branded itself as malware proof.

---

http://web.archive.org/web/20041127034451/http://www.mozilla...

"“Beware of spyware. If you can, use the Firefox browser.” - USA Today"

"Privacy and Security

Built with your security in mind, Firefox keeps your computer safe from malicious spyware by not loading harmful ActiveX controls. A comprehensive set of privacy tools keep your online activity your business."

---

While that's technically correct - Firefox couldn't (can't?) load ActiveX controls, therefore it could't load harmful ActiveX controls - the Firefox extensions system has permitted installation of executable code for a long time, if not since its inception. Since that's what ActiveX is, more or less, Firefox has never been any more secure in that respect than e.g. Internet Explorer.

Like Apple products, as Firefox becomes more popular (and therefore a jucier attack target) there will be more malware that targets it.

Re: Firefox add-on with 7m downloads secretly tracks your browsing history

#7
post #6

Like Apple products, Firefox branded itself as malware proof. --- http://web.archive.org/web/20041127034451/http://www.mozilla... "“Beware of spyware. If you can, use the Firefox browser.” - USA Today" "Privacy and Security Built with your security in mind, Firefox keeps your computer safe from malicious spyware by not loading harmful ActiveX controls. A comprehensive set of privacy tools keep your online activity yo…

Are you blaming Mozilla/Firefox for every possible 3rd party misuse of their software?

Re: Firefox add-on with 7m downloads secretly tracks your browsing history

#8
post #6

Like Apple products, Firefox branded itself as malware proof. --- http://web.archive.org/web/20041127034451/http://www.mozilla... "“Beware of spyware. If you can, use the Firefox browser.” - USA Today" "Privacy and Security Built with your security in mind, Firefox keeps your computer safe from malicious spyware by not loading harmful ActiveX controls. A comprehensive set of privacy tools keep your online activity yo…

The difference being that you have to decide to install this harmful extension. ActiveX just gets loaded during regular browsing.

Re: Firefox add-on with 7m downloads secretly tracks your browsing history

#9
"This add-on has been preliminarily reviewed by Mozilla."

What that entails:

"When performing a preliminary review, editors will review the source code for security issues and major policy violations, but will not install the add-on to test functionality in most cases. Preliminary review will be granted unless a security vulnerability or major policy violation is discovered."

From: https://addons.mozilla.org/en-US/developers/docs/policies/re...

Extensions marked 'experimental' are not fully reviewed. Which is why they probably left this plugin marked as 'experimental'.

You can't blame the users since they are installing from a Mozilla page and trusting the brand. I hope this triggers a review of those procedures at Mozilla, since I would consider sending back every site you visit a 'major policy violation'. Very scary.

Edit: they may also want to change the 'experimental' policy and set a time limit to how long an extension can remain experimental, and not list them in the default directory unless users (more advanced users) specifically seek out experimental extensions

Post reply on HN