Live data from Hacker News

Firefox 66.0.4 is out, fixes disabled add-ons

ftp.mozilla.org

61–70 of 392 posts

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#62

Earlier quoted context omitted.

So when deploying changes it should just go to every single user with no incremental rollout?

Yes. The testing should be done on users that opt in (likely less than 0.1% but that should be OK if it's done properly) and it should be rolled out by releasing an update to everyone. These so-called "best practices" often aren't.

I don't see the purpose. There seems to be an assumption that A/B testing is inherently bad, therefor should be opt-in.

A/B testing is necessary for stable rollouts, that much seems self evident.

So what is the evidence that A/B testing is harmful to users?

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#63

What about older versions? Does this mean that older versions of firefox can never be used with addons (even matching older versions) anymore?

Good question. Looks like they do have a release for 60 (the current ESR): https://archive.mozilla.org/pub/firefox/releases/60.6.2esr/

Just export the key from a current version and import it into the old version. Worked for me.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#64

Earlier quoted context omitted.

Having a capability for widespread A/B testing is brain-damage?

Yes, running experiments on unknowning and unconsenting users is unethical, especially when the metrics being optimized for usually aren't in the users' best interests. The widespread acceptance for this behaviour could definitely be classified as brain damage.

I think this can be compared to McDonald's slightly altering the recipe of something for part of the country. I don't find that unethical at all, and frankly the things we put in our body are a lot more personal than which web browser we use.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#65
post #3

A good outcome of this certificate fiasco is that many firefox users learned about the "studies" and "Normandy" brain-damage and promptly disabled them.

Having a capability for widespread A/B testing is brain-damage?

It's just the usual tug of war between developers and users for control of the computer.

A completely careful open source project would normally leave such controversial things off by default, and moz which leans corporate will go part of the way towards enabling such features. I don't mind their compromise, they do good.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#66
post #43
post #41

No release for android yet, at least not on [1], where I am getting the apk files from. As of now, latest release uploaded there is 66.0.2 from March. [1]: https://archive.mozilla.org/pub/mobile/releases/ EDIT it's up: https://archive.mozilla.org/pub/mobile/releases/66.0.4/

Well, at least you didn't get hit with 66.0.3.

What did 66.0.3 break?

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#67
post #44

I am not interested in finding out what they'll break next unless I want to participate in their Normandy botnet. Goodbye, Mozilla.

So... Hello, Google?

A large part of the problem is that too many people are happy with not having a choice anymore.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#68

Earlier quoted context omitted.

AFAICT still no update out for the android version either

Installing the hotfix package directly worked on Firefox for Android for me. https://storage.googleapis.com/moz-fx-normandy-prod-addons/e...

This is how I fixed it too

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#69

I don't understand why renewing the certificate wouldn't fix the issue ? How does the 66.0.4 fix the problem exactly ?

It's a signing certificate that is built into the browser to verify add-ons, not a normal TLS certificate that they can just update on a web server.

The change basically just imports the new certificate into the database: https://hg.mozilla.org/releases/mozilla-release/rev/848b1502...

Post reply on HN