Live data from Hacker News

Mozilla pulls Bypass Paywalls from Firefox add-ons store

github.com

241–250 of 288 posts

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#241
post #90

I've never understood how paywall bypass addons can be considered ethical. Even if you hate paywalls, it's the publisher's decision to use them. If I were to take a newspaper from a news stand without paying because there's an article I want to read but I don't want to pay, is that much different? I'm honestly asking what the justification is for people who use these addons. Do you not consider it unethical or do you…

Just to give one example where I consider it ethical: the WSJ doesn't paywall articles if they originate from FB and it's simple to simulate this link. These bypasses aren't "hacking" the sites in any normal sense. They are using publisher-created methods of accessing articles that any person could do if they had enough time and knowledge of the particular side channel. In short, unless the bypass is truly hacking th…

Did you just essentially argue that it is ethical because it is easy?

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#242

This would not be an issue at all if Firefox had not jumped the shark in version 37 by implementing anti-user features like requiring Mozilla approval (signed) to run add-ons.

The idea is to protect users, not hurt them in any way. Anyone can sign and run their own add-ons, or offer those add-ons for others to use. The only thing being restricted now is who can distribute their addons via addons.mozilla.org, which seems more than fair.

I can download an arbitrary exe file and run it with a few clicks. It can do anything, install rootkit in my BIOS and of course completely replace Firefox.exe or anything else. What's the reasoning to forbid me to download and run addon? I can already shot myself, very easily. Additional protection does not do any good, only harms users.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#243

Boy, ungoogled chrome and brave are looking mighty appeasing at the moment. Im not sure how long I can continue to support mozilla.. Why do they keep doing these things? They can't just be satisfied with what they were? Profit over all, always and forever.

In your mind, how is this decision one that was made to increase profit?

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#244
post #232

Earlier quoted context omitted.

> The execution is harmful to users Do you have a source for that? Moz has a ton of data about how harmful to users it was to have an ecosystem full of trashy spam extensions. The leap from "this solution has some downsides" to "this solution's downsides outweigh its upsides" is skipping the most important part of the question.

> Moz has a ton of data about how harmful to users it was to have an ecosystem full of trashy spam extensions. I wish that this data were available somewhere—not this specific data, but in general. Mozilla's response to community push-back is always "trust us, the data show that this is what's best". If you trust them already, then that might be good enough; but, when this is always their first, and often their only,…

That's fair, but I want to highlight the world of difference between "dubious behavior" and "it would be nice if we had your data to check your conclusions." I'm not with Mozilla, but when I've been in a similar position, it's deeply frustrating to read stuff like this on the internet. (So the healthy thing is really to just stop reading it, which is a shame.)

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#245
post #103

HN mods: title is incorrect and misleading, should at least read "Bypass Paywalls add-on removed from Firefox add-ons store". The use of "Mozilla" in the title has caused a lot of confusion in this thread from people who haven't clicked through the link.

Distinction without a difference, IMO. Mozilla has chosen to require this level of curation on Firefox against all complaints in the name of "safety", so they can also take the heat when their process results in an outcome like this. Their browser, their addon site, their decision, their fault.

The idea that AMO shouldn't be curated is baffling. Browser extensions are the biggest malware vector since email attachments named `importantstuff.txt.exe`. The title saying that Mozilla "pulled" this extension is not merely incorrect, it is blatant misinformation.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#246
post #208

Earlier quoted context omitted.

1. So you have the set of people who would be much better off in a “walled garden”, in my experience that is almost everyone. 2. You have the set of people who can compile the code from source and who want to get outside of the wall. 3. You have the set of people who want to get out of the wall but don’t have the technical expertise to know the dangers of doing so. 4. You have people who have the technical expertise…

Perhaps, they forced them to do that in the middle of their workday in order to get their UX back. Imagine if your computer crashed and when it restarted it came with the mouse drivers disabled and you had to use the arrows to move the mouse around, and you were reassured you could sign up for WDN to restore use of the mouse. And I don’t think expecting the user to personally recompile for every update is reasonable,…

The same users who have complete “control of thier computer” who don’t know what they are doing is what causes all of the crapware, malware, ransomware on many Windows based PCs.

I’m all for platforms being in a wall gardener by default where you have to jump through a few hoops to unlock an “advanced mode”.

And signing up for WDN (Windows Developer Network?) hopefully you would get signed drivers.

You can’t imagine the number of times my mom has done the perfectly reasonable thing of searching for Windows printer drivers on Google and ended up installing crapware from a third party site instead of getting the official driver. Signing requirements from MS would hopefully alleviate that and let advanced users try to figure out how to load unsigned drivers.

(Also tangentially, why are printer drivers still a thing on Windows anyway? Anyone who connects a Mac, iPad, or iPhone to my home network - if I give them access to the non-guest network - automatically can print.)

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#247
post #43
post #22

Earlier quoted context omitted.

I wonder who's more unethical: The guy who comes in, smashes your stuff and leaves or the guy who comes in, smashes your stuff and leaves a check for you at his place. I bet that's a common battle ground between consequentialists and idealists. Fun aside, I don't think the comparison holds up very well. I don't think that anyone has a right to execute code on my devices just because I'm browsing a website. In this co…

If you consider the page code, you requested it and it’s bundled in there. Same with CSS and JS used for features. In that case, you requested the page and allowed them to.

I requested _this_ page, then requested the CSS/JS. I then blocked future requests.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#248

Earlier quoted context omitted.

The idea is to protect users, not hurt them in any way. Anyone can sign and run their own add-ons, or offer those add-ons for others to use. The only thing being restricted now is who can distribute their addons via addons.mozilla.org, which seems more than fair.

If it was just distribution through the add-on app store, that would be one thing. As of Firefox 48 however, in stable builds of Firefox, unsigned addons (which haven't gone through Mozilla's review process) cannot be installed. Period. The about:config setting meant to override signature checks (and allow third-party extensions), `xpinstall.signatures.required`, is plainly ignored in stable versions from this point…

You skipped over a part:

> Anyone can sign and run their own add-ons, or offer those add-ons for others to use.

And this is consistent with what Mozilla says here: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Dis...

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#249

Earlier quoted context omitted.

The idea is to protect users, not hurt them in any way. Anyone can sign and run their own add-ons, or offer those add-ons for others to use. The only thing being restricted now is who can distribute their addons via addons.mozilla.org, which seems more than fair.

If it was just distribution through the add-on app store, that would be one thing. As of Firefox 48 however, in stable builds of Firefox, unsigned addons (which haven't gone through Mozilla's review process) cannot be installed. Period. The about:config setting meant to override signature checks (and allow third-party extensions), `xpinstall.signatures.required`, is plainly ignored in stable versions from this point…

Let's dial back on the unwarranted outrage. Mozilla expects that people who develop their own extensions will be using the Developer edition. It also expects that people who aren't especially computer-savvy will be using the stable edition. The people crying foul about requiring signing for add-ons on the stable edition are living in a bubble where they don't realize that most people will completely fail to understand the importance of vetting browser extensions, while also failing to appreciate the potentially disastrous ramifications of installing a malicious extension.

Browser extension malware is a big, big problem in a way that some otherwise tech-savvy people in here apparently don't understand. Why are people so quick to ascribe malice when nobody can come up with even a single potential malicious motive for Mozilla requiring signing of add-ons? There's no profit motive or perverse incentive here. Mozilla doesn't make money from this process. Frankly, they'd make a lot more money if they didn't run AMO at all and didn't bother hiring any stuff to run it and vet extensions.

Re: Mozilla pulls Bypass Paywalls from Firefox add-ons store

#250
post #196

Earlier quoted context omitted.

The idea might be good. The execution is harmful to users, and they refuse to roll it back. That's all that matters. Mozilla has shown this pattern consistently - they have an idea they think will be good for people, and when it ends up being hurtful and damaging not only the core product but the userbase - driving more people to alternate browsers - they steadfastly refuse to see what's going on around them. Frankly…

> The idea might be good. The execution is harmful to users, and they refuse to roll it back. Howso? I've been using FF forever and I didn't notice this change…

The fact that this benign comment is so downvoted says a lot about the sort of people who are brigading this thread.
Post reply on HN