Live data from Hacker News

Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

support.mozilla.org

261–270 of 537 posts

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#261
post #64

Earlier quoted context omitted.

There almost certainly is not a way to invisibly install add-ons, unless you are part of Mozilla, and, you know, making Firefox. If paranoia is your thing, it might be worth considering that Mozilla can do anything it wants inside Firefox core, all of it is "invisible" to you.

And this is the point where even the most Mozilla-supporting users move away. For me, this is it, I’m going to Chromium. Fuck this shit, in the past months we had CliqZ https://news.ycombinator.com/item?id=15421708 , we had Mozilla adding new telemetry, we had Mozilla force-enable toolkit.telemetry.enabled, we had Mozilla say that, if you download Nightly, that is considered opt-in to tracking, we had Mozilla put Goo…

Regarding telemetry, take a look at the settings in about:config. There are several toolkit.telemetry.Ping settings which are set to true by default. In the spirit of charity I'm going to assume that those phone home pings - on startup, shutdown, update - are not enabled unless telemetry is enabled. But I have not checked...

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#262

This happened to me yesterday, so I looked for it. The Extension actually does nothing, but invert (make them upside down) a few words on specific sites. It's an experiment called "PUG ARG" to check whether page contents sniffing works. Its page doesn't reference any Bugzilla issue or Wiki page, while https://wiki.mozilla.org/Firefox/Shield/Shield_Studies/Queue doesn't list it. The source code references https://supp…

I was fine with the Shield Studies program when I understood it to be a tool for improving the browser. This is clearly an abuse of a development/testing/telemetry tool to deliver an advertisement. Trust is hard to win and easily lost.

Take a look at the existing studies: https://www.jeffersonscher.com/sumo/shield.php

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#263

Earlier quoted context omitted.

> I haven't researched deeply, but apparently the add-on does nothing until the user opts-in on studies. It adds some css to a list of words: https://github.com/gregglind/addon-wr/blob/da464ac8f1c3b0894...

Only if the preference extensions.pug.lookingglass is changed from the default of false. I haven't figured out how that setting is exposed yet. Maybe they expect people to go to about:config and change it? Is there video footage suggesting that in the TV show? https://github.com/gregglind/addon-wr/blob/104-rename-less-v...

From reading the source, that setting is not exposed anywhere; about:config seems to be the only way to turn it on.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#264
post #84

Earlier quoted context omitted.

I agree. I merely challenge the notion that a nonprofit -- which proudly tumpets its benevolence and non-profitness -- should get a free pass for covertly installing advertising arrangements, just because they need to "make money". Their charter and marketing is all about defending the internet from the companies doing shady things to make money, so they can't have their cake and eat it.

There is a difference between a non-profit and a non-for-profit (most health insurance companies are the later; go try and figure that out). Firefox gets most of its donations from corporate sponsors. That's why the default search and switched back and fourth between Yahoo and Google; it's all about the amount of money they contribute for that. I'm not sure, but Pocket might be another example. User contributions are…

Mozilla bought Pocket a while ago.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#266

Many people seem to be shocked because Mozilla installed an add-on automatically. In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all? The main question is what behavior is being introduced. I haven't researched deeply, but apparently the ad…

To some extent, the line between code in the browser core and code in an add-on coming from Mozilla is arbitrary. However, it's a line that Mozilla themselves have drawn. We've been trained to be vigilant when choosing and installing add-ons, to read the list of permissions the add-on is asking for and judge whether we want to take the risk. The implicit messaging to users has been that if you let through a bad add-on that degrades the browser in some way, it's your fault. (Indeed, we're supposed to sympathise with Mozilla when 'badly-written' add-ons slow down the browser and make Mozilla look bad.)

Mozilla have presented "add-ons" as a line where users are supposed to be responsible for what to "trust", over and above the choice to install the browser in the first place. They can expect those users to be watching that line carefully.

(Incidentally, I would still dislike this functionality - moreso even - if it was in the browser core.)

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#267

Many people seem to be shocked because Mozilla installed an add-on automatically. In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all? The main question is what behavior is being introduced. I haven't researched deeply, but apparently the ad…

The major problem is that they installed an add-on without properly communicating what it was. A somewhat smaller problem but still a big problem is that was an utterly frivolous add-on that shouldn't have been pushed to people who didn't explicitly want it. But the biggest problem is that Mozilla seems to have trouble understanding why any of those two would be a problem, I want my browser vendor to be serious and not play silly games that can so easily backfire.

Yeah, add-ons from Mozilla merits the same trust as the browser. But this cuts both ways, this stuff undermines my and probably more people's trust in the browser.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#268

In the Preferences, scroll down to "Data Collection and Use", and disable everything . I know that you only need to need to turn off "install and run studies", but this has now cost Mozilla all telemetry data from me, and I encourage everyone to do the same.

Why can't I see the "install and run studies" option? Is it because I'm using Finnish language Firefox?

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#269

Earlier quoted context omitted.

This is being added to the browser, outside the realm of security updates, through what is supposed to be a UX improvement program, for commercial purposes. It's written by a commercial company that produces advertisement content. It's not clear this code is audited. Sorry, but I'm uninstalling firefox. They have broken the basic trust I have in them as a user to not push arbitrary code to my machine against my inter…

> It's written by a commercial company that produces advertisement content. It's not clear this code is audited. Do you have any evidence of this? Assuming their normal processes for SHIELD studies were followed, a _lot_ of different people have to review the plugin before it gets approved: https://wiki.mozilla.org/Firefox/Shield/Shield_Studies#Who_A... Edit: Also, the contributors list on the plugin's GitHub repo li…

Unfortunately the most important person involved didn't get to review the plugin before it was installed on my computer. Me.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#270
post #220
post #181

Earlier quoted context omitted.

Speaking for myself here, but I'm not concerned that Mozilla might push malware into Firefox installations. I'm concerned about the lack of judgement in pushing an extension with a vague, scary-sounding name and description simply for a cross-marketing tie-in, and I'm worried that it could have damaged the trust ordinary users have in Firefox.

I'm worried my work Security/IT department will see it, freak out, and blanket ban Firefox on all machines for 6 months.

your work security team loves mr robot, it will be fine...
Post reply on HN