Live data from Hacker News

Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

support.mozilla.org

251–260 of 537 posts

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#251
post #222

Earlier quoted context omitted.

This is being added to the browser, outside the realm of security updates, through what is supposed to be a UX improvement program, for commercial purposes. It's written by a commercial company that produces advertisement content. It's not clear this code is audited. Sorry, but I'm uninstalling firefox. They have broken the basic trust I have in them as a user to not push arbitrary code to my machine against my inter…

Have fun in Lynx. that's probably the only browser that wouldn't do something like this. Well maybe Safari, not because Apple wouldn't, but because they just don't care enough about ad revenue. Chrome: They leech everything they can get away with, granted it goes only to Google, but you know it's just to feed their never-ending ad-revenue goal. MS: They bypassed IE only ads, and went on to build ads into the entire O…

Gopher. That was content focused and so inflexible that it was hard to be a dick with it.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#252
post #225

Many people seem to be shocked because Mozilla installed an add-on automatically. In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all? The main question is what behavior is being introduced. I haven't researched deeply, but apparently the ad…

> If someone distrusts their add-ons, why trust their browser at all? "Well, I'm your bank. You already gave me authority to reinvest all your savings. Why are you mad now that I invested everything into bitcoin futures?" What exactly does "trust" mean? We might have given mozilla such a widespread access exactly because we trust them not to abuse it. Stuff like this undermine that trust.

Before, we didn't need to trust them, because we didn't have to. We had all the code, we could verify the code we can read is the code in the binary we use via checksums. Now the code contains the ability to go fetch arbitrary code behind our backs and run it against our will. Firefox is now malware and it's a real damn shame.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#253

Earlier quoted context omitted.

> but the deep Pocket integration was just too offputting You mean the single button that does literally nothing until and unless you click on it?

Add a couple more buttons and hey, you've got a toolbar going. Why can't they just make a web browser that's... just a web browser? Chrome has never had buttons to email pages with gmail, record videos onto YouTube, share pages on G+ etc.

The default new tab in Chrome contains links to all of those things and more.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#254

Earlier quoted context omitted.

The wiki page says that no changes are made until you opt in. Can you tell if you're part of the game? (I assume you'd be able to tell somehow)

I did not recall agreeing to opt-in for the studies and there it is under Privacy & Security as checked. I have the pug experience study active and I don't recall the browser asking about it. From the studies about page linked from about:studies... "When a study is available, you will automatically be enrolled if you meet the criteria. There will be occasions where we might prompt you for participation first." Just s…

It is also active for me, and there is zero chance id ever opt into this garbage.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#255

Earlier quoted context omitted.

This is being added to the browser, outside the realm of security updates, through what is supposed to be a UX improvement program, for commercial purposes. It's written by a commercial company that produces advertisement content. It's not clear this code is audited. Sorry, but I'm uninstalling firefox. They have broken the basic trust I have in them as a user to not push arbitrary code to my machine against my inter…

What browser are you going to use instead?

If you like Firefox but don't trust Mozilla anymore there are plenty of forks to choose from: Waterfox, Pale Moon, Basilisk, GNU IceCat.

Personally I build Firefox from source and maintain a set of patches largely based on these: https://aur.archlinux.org/packages/firefox-esr-privacy/

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#256
post #85

Previously: * https://news.ycombinator.com/item?id=15921134 This is a link to the GitHub issue: * https://github.com/gregglind/addon-wr/issues/36 There are several scary things about this: - Unknown Mozilla developers can distribute addons to users without their permission - Mozilla developers can distribute addons to users without their knowledge - Mozilla developers themselves don't realise the consequences of doin…

I think this was a very bad move, because Mozilla installed adware in all of its browsers. The fact that it was installed through an add on, though, seems irrelevant. Mozilla developers can distribute arbitrary code to all users because they write the browser. The add on just makes this particular bit of code user visible.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#258
post #225

Earlier quoted context omitted.

> If someone distrusts their add-ons, why trust their browser at all? "Well, I'm your bank. You already gave me authority to reinvest all your savings. Why are you mad now that I invested everything into bitcoin futures?" What exactly does "trust" mean? We might have given mozilla such a widespread access exactly because we trust them not to abuse it. Stuff like this undermine that trust.

Maybe not be the best analogy since that is exactly what banks do with your money while it's parked in your savings account - invest it in whatever they feel like. Probably not Bitcoin futures because the bank manager doesn't want to, but there's nothing stopping them from doing exactly that.

No, the bitcoin futures were my point. Of course they can re-invest in principle but the trust is tgat they won't invest them into something that is an obvious risk.

And no, they can't: In many countries there are regulations forbidding high-risk investments with regular savings accounts for exactly that reason.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#259

Earlier quoted context omitted.

I never knowingly opted in to anything and found both the "Studies" section and the "pug-experience" study turned on just now in about:studies. I don't know if it really is meant to be opt-in, but it certainly didn't seem like they've done it correctly.

The wiki page says that no changes are made until you opt in. Can you tell if you're part of the game? (I assume you'd be able to tell somehow)

Most shield studies are opt-out: https://www.jeffersonscher.com/sumo/shield.php (filter by "extensions").

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#260

Many people seem to be shocked because Mozilla installed an add-on automatically. In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all? The main question is what behavior is being introduced. I haven't researched deeply, but apparently the ad…

What it bugs me is not that Mozilla pushed and extension into my/their browser but the behavior of the extension itself. It literally broke some pages, disrupting my use experience more than it was supposed to do (or at least I hope it was not intended). Peoples who complain about Mozilla pushing this just failed to check the basic browser options and should blame themselves instead. Anyway Mozilla seem to have rised quite a lot of attention about the secuirity and the privacy of their own browser with this stunt, so... it was a success, I guess?
Post reply on HN