Live data from Hacker News

Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

support.mozilla.org

271–280 of 537 posts

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#271
post #97

Earlier quoted context omitted.

> you also need to explicitly opt-in Wrong, as far as I see: Looking in my about:config, I see app.shield.optoutstudies.enabled=true browser.onboarding.shieldstudy.enabled=true enabled by default . The settings that I've changed from the default are shown in bold. These aren't bold. Those are the defaults. Everybody can check. That means that the user must actively take steps to disable them, if he knows that they ex…

Are you sure that's what those config options do? I tried looking them up, but they don't seem to be listed in Mozilla's config documentation: http://kb.mozillazine.org/About:config_entries According to the Wiki page I linked in my previous comment, global settings shouldn't even matter in this case; since each SHIELD study must be opted into on an individual basis. (Or at least, that's how it's _supposed_ to work.)…

Your link in edit part is the answer to your question before the edit:

https://normandy.readthedocs.io/en/latest/user/actions/opt-o...

"opt-out-study: Install a Study Add-on Without Prompting

The opt-out-study action installs an add-on, typically one that implements a feature experiment by changing Firefox and measuring how it affects the user."

They are obviously the topic of:

app.shield.optoutstudies.enabled=true

That I mentioned.

I see a lot of commenters trying to excuse them. The problem is, people allowed the "studies" because Mozilla claimed that they are "measuring" whatever "to make Firefox better." They never told anybody that they are selling the "studies" functionality which silently installs ("opt-out" not opt in!) to the advertisers.

I don't know how anybody can defend such an approach.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#272
post #204

Earlier quoted context omitted.

I'm concerned about Mozilla pushing software written by the Mr Robot marketing department.

I'm not entirely comfortable with how this all went, but it's at least worth noting that the add-on was written entirely by Mozilla engineers.

This is the opposite of comforting

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#273
post #233

Earlier quoted context omitted.

>Hopefully, it's a bug, and that addon wasn't intended to be installed (much less active) universally like it is. hey look, a voice of reason! seriously. Mozilla is a company that has a long track record of dedication to openness and the free and open internet this isnt Google, facebook, etc let's all take a step back and give them a little benefit of the doubt here, until we get some facts on what happened. for ever…

>>Hopefully, it's a bug, and that addon wasn't intended to be installed (much less active) universally like it is. >hey look, a voice of reason! Where's official statement saying it's a bug and it will be disabled ASAP? All I see is Mozilla workers here trying to justity the "bug".

I'm not happy with how this rolled out, and I'm not here to justify it.

I wasn't involved in its development, so I can't speak to its origin or the decision to use Shield for distribution, but I can gather feedback and answer technical questions about Firefox and the add-on.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#274

While I agree that releasing this as an undocumented extension was a poor PR move, in practical terms, I don’t see how this is any more insidious than the ‘no internet’ dinosaur jumping game built in to chrome. Both are first-party. The difference seems to be that the dinosaur game keeps you entertained, where as this hopes to promote awareness of privacy/security.

The dinosaur was not placed there by a movie studio to promote a random.movie.

Neither was the Looking Glass extension.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#275

Many people seem to be shocked because Mozilla installed an add-on automatically. In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all? The main question is what behavior is being introduced. I haven't researched deeply, but apparently the ad…

[deleted]

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#276

I actually discovered this because my browser would not stop running at 100% cpu utilization about 3 days ago, not doing anything, just sitting at Google.com with one tab open. It freaked me out because I couldn't find any documentation on the extension. Once removed Firefox was running fine again. I guess I'm relieved to know it wasn't some malware or something more sketchy, but I am wondering what it was doing pegg…

Whatever you experienced is very unlikely to be caused by this add-on. The add-on only initializes if you manually dig into about:config and enable `extensions.pug.lookingglass`. Otherwise, it just starts up once at browser launch, checks that preference, and shuts itself down. (https://github.com/gregglind/addon-wr/blob/59659431fd2a75c33...)

If you're able to consistently reproduce the issue, please let me know.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#277
post #225

Earlier quoted context omitted.

> If someone distrusts their add-ons, why trust their browser at all? "Well, I'm your bank. You already gave me authority to reinvest all your savings. Why are you mad now that I invested everything into bitcoin futures?" What exactly does "trust" mean? We might have given mozilla such a widespread access exactly because we trust them not to abuse it. Stuff like this undermine that trust.

Before, we didn't need to trust them, because we didn't have to. We had all the code, we could verify the code we can read is the code in the binary we use via checksums. Now the code contains the ability to go fetch arbitrary code behind our backs and run it against our will. Firefox is now malware and it's a real damn shame.

> Now the code contains the ability to go fetch arbitrary code behind our backs and run it against our will.

How is that not what automatic updates are?

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#278

Many people seem to be shocked because Mozilla installed an add-on automatically. In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all? The main question is what behavior is being introduced. I haven't researched deeply, but apparently the ad…

> In my opinion, it doesn't really matter since the code is coming from Mozilla - they're building the whole browser, so they could introduce functionality anywhere. If someone distrusts their add-ons, why trust their browser at all?

An appropriate response here would be to decide that you no longer trust their browser at all.

It's hard to quantify trust exactly. I'm fine with trusting the partly-closed-source Google Chrome build, including the proprietary Chromecast, Hangouts, etc., plugins, because I believe that the people writing them are generally reasonable. I don't have a good formal proof that they're generally reasonable people, and I never will - that's why it's trust. If they start installing marketing gimmicks, certainly they have the technical ability to do that, but I will lose my trust that they're reasonable people.

Here's an analogy: I trust a small number of my friends with keys to my apartment because I think they'll make reasonable use of that access. If they decide to show up at 3 AM with a keg and three tubas without telling (let alone asking) in advance, I technically have no grounds to complain that they abused their access - but I'll certainly not be calling them friends any more.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#279
post #222

Earlier quoted context omitted.

This is being added to the browser, outside the realm of security updates, through what is supposed to be a UX improvement program, for commercial purposes. It's written by a commercial company that produces advertisement content. It's not clear this code is audited. Sorry, but I'm uninstalling firefox. They have broken the basic trust I have in them as a user to not push arbitrary code to my machine against my inter…

Have fun in Lynx. that's probably the only browser that wouldn't do something like this. Well maybe Safari, not because Apple wouldn't, but because they just don't care enough about ad revenue. Chrome: They leech everything they can get away with, granted it goes only to Google, but you know it's just to feed their never-ending ad-revenue goal. MS: They bypassed IE only ads, and went on to build ads into the entire O…

I'm running Firefox via Debian, and I intend to continue running Firefox via Debian - I trust that the outcry in the Debian community would be so huge if the Firefox maintainer (or any other maintainer) allowed this sort of code from upstream through.

Re: Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser

#280

Earlier quoted context omitted.

Before, we didn't need to trust them, because we didn't have to. We had all the code, we could verify the code we can read is the code in the binary we use via checksums. Now the code contains the ability to go fetch arbitrary code behind our backs and run it against our will. Firefox is now malware and it's a real damn shame.

> Now the code contains the ability to go fetch arbitrary code behind our backs and run it against our will. How is that not what automatic updates are?

Right. I trust my browser vendor to send me automatic updates without me reviewing because I believe that's net good for my security. I'd prefer to live in a world where I don't have to question that.
Post reply on HN