Live data from Hacker News

Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

support.mozilla.org

211–220 of 537 posts

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#212

If they state as an explicit principle that no addons/studies are actually enabled unless the user opted in, then I’m going to give them the benefit of the doubt that if that happened to users that did not opt in, it was a terrible mistake (I.e a bug). I can tolerate bugs, much more than I can tolerate sneaky app behavior. But I hope the statement about explicit opt-in will be repeated, and this will be explained. At…

I haven’t understood whether this thing is completely inert or actually does anything without opt in.

If it is downloaded and listed without opt-in, but only actually invoked after opt-in, then I’ll call it acceptable (not great, but not terrible either)

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#213
post #16
post #10

Earlier quoted context omitted.

I don't think that makes it better. Knowing that there's a way to get an addon installed invisibly is going to be more justification for paranoia.

You can disable these studies under Options | Privacy and Security

Preferences/Options -> Privacy and Security -> Allow Firefox to install and run studies

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#215
post #190
post #181

Earlier quoted context omitted.

Speaking for myself here, but I'm not concerned that Mozilla might push malware into Firefox installations. I'm concerned about the lack of judgement in pushing an extension with a vague, scary-sounding name and description simply for a cross-marketing tie-in, and I'm worried that it could have damaged the trust ordinary users have in Firefox.

> I'm not concerned that Mozilla might push malware into Firefox installations Nobody is concerned about that, in my opinion. I'm concerned someone will push malware through Mozilla into Firefox installations. Pushing addon installs should not be possible at all.

They can also push new browser releases though. They are also auto-installed by default.

The exception is that an addon can do slightly less damage than a compromised browser itself.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#216

Earlier quoted context omitted.

Are you switching to Chrome, the browser that sends your every keystroke back to HQ?

Google does a lot of things but they've never betrayed my trust by installing an extension in conjunction with a third party without telling me. Google does track a lot of my data but they provide useful services in exchange, and in addition they make it pretty easy to see what data they have on me. Also Google's data is its competitive advantage so our interest in protecting my data from 3rd parties is aligned. In s…

> but they're pretty transparent about it

They may be transparent about the fact that they're tracking you, but not about what they're tracking or when they're tracking it. And there's no way for you to find out because the vast majority of their software is not open source.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#217
post #64

Earlier quoted context omitted.

There almost certainly is not a way to invisibly install add-ons, unless you are part of Mozilla, and, you know, making Firefox. If paranoia is your thing, it might be worth considering that Mozilla can do anything it wants inside Firefox core, all of it is "invisible" to you.

And this is the point where even the most Mozilla-supporting users move away. For me, this is it, I’m going to Chromium. Fuck this shit, in the past months we had CliqZ https://news.ycombinator.com/item?id=15421708 , we had Mozilla adding new telemetry, we had Mozilla force-enable toolkit.telemetry.enabled, we had Mozilla say that, if you download Nightly, that is considered opt-in to tracking, we had Mozilla put Goo…

Great points, thanks for compiling these..

I was using firefox because I don't trust google. ;(

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#218
post #204
post #190

Earlier quoted context omitted.

> I'm not concerned that Mozilla might push malware into Firefox installations Nobody is concerned about that, in my opinion. I'm concerned someone will push malware through Mozilla into Firefox installations. Pushing addon installs should not be possible at all.

I'm concerned about Mozilla pushing software written by the Mr Robot marketing department.

Is the plugin opensource, where can we vet it? I can't find it on github or anything like I can with the other plugins I use

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#219

Many people seem to be shocked because Mozilla installed an add-on automatically. In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all? The main question is what behavior is being introduced. I haven't researched deeply, but apparently the ad…

This is being added to the browser, outside the realm of security updates, through what is supposed to be a UX improvement program, for commercial purposes. It's written by a commercial company that produces advertisement content. It's not clear this code is audited. Sorry, but I'm uninstalling firefox. They have broken the basic trust I have in them as a user to not push arbitrary code to my machine against my inter…

> It's written by a commercial company that produces advertisement content. It's not clear this code is audited.

Do you have any evidence of this?

Assuming their normal processes for SHIELD studies were followed, a _lot_ of different people have to review the plugin before it gets approved: https://wiki.mozilla.org/Firefox/Shield/Shield_Studies#Who_A...

Edit: Also, the contributors list on the plugin's GitHub repo lists exclusively Mozilla employees: https://github.com/gregglind/addon-wr/graphs/contributors

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#220
post #181

Many people seem to be shocked because Mozilla installed an add-on automatically. In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all? The main question is what behavior is being introduced. I haven't researched deeply, but apparently the ad…

Speaking for myself here, but I'm not concerned that Mozilla might push malware into Firefox installations. I'm concerned about the lack of judgement in pushing an extension with a vague, scary-sounding name and description simply for a cross-marketing tie-in, and I'm worried that it could have damaged the trust ordinary users have in Firefox.

I'm worried my work Security/IT department will see it, freak out, and blanket ban Firefox on all machines for 6 months.
Post reply on HN