Live data from Hacker News

Leaving Mozilla

blog.unitedheroes.net

341–346 of 346 posts

Re: Leaving Mozilla

#341

Earlier quoted context omitted.

They are already doing that with a literal fork of Firefox OS. Look up KaiOS.

That is not ambitious enough.

Making almost 20 million a year is pretty good considering that their only product is a maintained FirefoxOS fork licensed to run on budget phones.

Re: Leaving Mozilla

#342

Earlier quoted context omitted.

Websites themselves are a much larger threat than extensions - should your ideal browser remove support for them as well?

This is incredibly untrue. Many extensions can see and modify everything you see on any other site. Installing a browser extension is best described as installing a rootkit in your browser.

If you look at actual negative consequences to users from extensions and websites I'm pretty sure the latter will win by a long shot. And you need extensions to protect yourself from malicious websites.

And of course extensions get access to websites, just like the browser. That's what "extension" means. As much as Google, Mozilla, Microsoft and Apple want you to believe otherwise they are not the only ones that can be trusted with that access.

Re: Leaving Mozilla

#343

Earlier quoted context omitted.

Not so sure about R* https://www.dexerto.com/gta/fired-gta-6-devs-speak-out-about...

Oh that’s too bad. They had a good run at least.

Sadly they’ve demonstrated a decades-running pattern of promising to do better and then just doing exactly what they did before. I don’t support their games anymore at this point.

Re: Leaving Mozilla

#344
post #191

Firefox leadership had a recovery the time when Brendan Eich was CEO, then he was kicked out. since then it has been downhill since.

Eich was CEO for 11 days. You’re wildly misremembering how much of an impact he had in that post.

I was a real founder (not retconned fake founder). My contributions were almost entirely before taking the CEO job, of course.

https://news.ycombinator.com/item?id=44544226

"Lots of decline after I left, but I'll take some blame for decline before I quit, if you credit me for all the growth from inception."

Re: Leaving Mozilla

#345

Earlier quoted context omitted.

I don't believe that for one second, and neither should you. Every single CEO who gets fired is made to "voluntarily" resign.

You weren’t there.

Were you? I have no idea who you are, but the only "other C-level position" was an unspecified throwaway line from Reid Hoffman, who didn't have authority to create any such "Chief of Special Projects" position anyway. The CEO makes the C-level org chart; the new CEO after me was waiting in the wings but in no position to make promises.

You seem awfully eager to assert something false, possibly out of bad conscience. No one involved in my departure had a good solution for my staying at Mozilla, including me.

Re: Leaving Mozilla

#346
post #179

Earlier quoted context omitted.

It doesn't seem a coincidence that it started to go down hill after they removed an engineer from CEO (Brendan Eich), and replaced him with a marketing dude, then a lawyer lady, and now an MBA bro.

That engineer went on to create Brave, a browser that pays you Monopoly money for watching ads, injected affiliate links, installed their commercial VPN without asking, and leaked DNS traffic when using Tor in its "privacy" mode. I'd say Mozilla dodged a bullet there.

Brave engineer here.

> "Monopoly money for watching ads"

What does Firefox pay you for piping your keystrokes off to Google? BAT is a reward for your attention; far better arrangement and exchange than what has existed up to this point. It's not perfect, but what's your solution?

> "injected affiliate links"

You seem to be a little free and loose with _facts_. Rather than exchange your data for revenue, Brave explores revenue streams which won't keep us up at night. One such consideration was affiliate links. We had a couple (quite literally a couple/few), that would appear when you typed certain crypto-related keywords into the address bar. When suggestions were offered, so too would be our affiliate option.

This solution presented a means by which users could support Brave without involving their data. Unfortunately, a UI/UX bug caused the affiliate option to appear even for a fully-qualified domain, which meant a user who quickly typed a URL for which we offered an affiliate link and mashed Enter, could unintentionally have selected the affiliate option. That isn't _injection_.

The issue was identified pretty quickly, and a patch was sent out. Guess how much Brave made from the buggy behavior before it was patched? I'll help you: $0.

You can read more at https://brave.com/blog/referral-codes-in-suggested-sites/, though I must warn you ahead of time that it isn't as exciting or shocking as you might have liked.

You know what would be SHOCKING though? Imagine if Mozilla had tried to do something quite similar. Oh, wait… https://www.malwarebytes.com/blog/news/2021/10/firefox-revea....

> "installed their commercial VPN without asking"

This one is actually somewhat true. We did indeed ship an inert service for some Windows users. The goal was to have the VPN option be immediately available to users who wished to purchase it, as a means of supporting Brave. Details are in the GitHub issue: https://github.com/brave/brave-browser/issues/33726.

> "and leaked DNS traffic when using Tor in its 'privacy' mode."

Oh, this is one of my favorites. It's a classic story with depth, misdirection, unexpected side-effects of decisions made years in between, and more! This one is the type of thing I would have expected to read about in _Joel on Software_ many years ago.

So, we shipped a browser with a "privacy" mode, much like everybody else. But, we weren't fans of the common approach used by Chrome, Firefox, Edge, and others. Their approach doesn't really make you _incognito_, or _private_; it just creates an ephemeral account locally and basically does some file-system cleanup. We wanted something stronger!

As fans of the Tor project, we opted to bake-in support for Tor as an optional enhancement to private tabs. This would give you one extra, super-thick layer of incognito-ness. Tor Private Tabs were shipped back in mid 2018, and the next couple of years were pretty awesome. Brave users who enabled optional Tor support enjoyed a superior experience to that found in other popular browsers.

Years later—as the tracker wars waged on—some data-harvesters got the idea that they could evade detection by way of CNAMEs, giving them first-party privileges. So in late 2020, Brave shipped CNAME decloaking, unmasking more trackers than Mystery Inc., and dramatically expanding the privacy moat.

But the story wouldn't be all that exciting if it didn't have a twist, right!? Brave's new CNAME-decloaking didn't consider the Tor scenario, and performed DNS lookups outside of an existing proxy!

While the combination of these features didn't make Brave as porous as ordinary "incognito mode", it did punch an embarrassing hole in the Tor boundary: page traffic still went through Tor, but CNAME adblocking DNS lookups accidentally went out through the user's normal DNS path.

For that narrow slice of activity, Brave drifted uncomfortably close to what Mozilla calls "private browsing": https://support.mozilla.org/en-US/kb/common-myths-about-priv... ("Private browsing [in Firefox] doesn't hide your activity from your ISP, mask your IP address or location, or stop websites from identifying or tracking you…)

> "I'd say Mozilla dodged a bullet there."

Let's check in again in another 5 years ;)

Post reply on HN