Firefox Now Offers a More Private Browsing Experience
blog.mozilla.org
blog.mozilla.org
And links to lists of what is blocked: https://wiki.mozilla.org/Security/Tracking_protection#Lists
I'm curious to know what the in-the-wild breakage rate for FF's blocking feature is. I use Ghostery myself and I find that maybe 1 in 100 are broken. I feel like that could be 1 in 1000 if blockers implemented a Google Analytics stub -- by far the most commonly required script for things to work.
In the situations I've seen, the issue was using GA without first checking it loaded correctly. Defensively coding third party requests, let alone all requests, should be second nature.
It raises two questions for me:
1. Is there some code out there being copied everywhere which assumes GA will always load?
2. How do I make sure this is never an issue in my projects?
I don't think (1) is an actual problem, and I don't know of any options for (2).
Bandwidth throttling doesn't directly help, although it may make it obvious which third-party scripts block the render of the page (which often seems related).
Ideally you would have good test coverage on the loaded page, and then randomly block requests to see what breaks. Mark resources as either hard or soft dependencies, make sure soft dependencies never break the page/functionality of the app, and make sure loss of a hard dependency degrades nicely.
Edit: I should also add, my most memorable run in with this bug was with a very well known application, and they were very quick to fix it once reported. I was surprised none of the internal devs had run into the problem, as I assumed most would run a blocker, but it may have been an early access release...
Now, you could argue that requests can legitimately fail at any time, and it's best to handle it. OK, as a lazy/efficient dev willing to entertain that, I'll design my page to put up a modal alert saying "There was an error loading this page. Click OK to refresh." if anything fails to load. Now my error-handling job is done, but privacy-conscious users will still be mad at me, demanding that I gracefully degrade for every combination of request-blocking (or in GP's case, request-tampering!) they can dream up.
Again, I'm sympathetic as a user, and I've even experienced broken pages due to Ghostery, but as a developer it's hard to blame them.
[0] And AFAIK have no hard dependencies on third-party scripts like GA.
As a dev, it's nice that I can track what my users are doing with GA, but I would rather my users be able to use my application. This is definitely a 'soft' dependency because I do not have a hard requirement to use its functionality. If a critical piece of my application (a 'hard' dependency) fails to load then that is a bigger problem.
I don't think we have to degrade gracefully for every possible failure, but failing to render anything is a really bad failure mode. Your lazy/efficient dev is actually just providing a good user experience; if something bad has gone wrong, let the user know so they can refresh etc.
The thing about third-party scripts is that you have no control over them at all. By their nature, you can't even bundle them (that is a workaround for some options though)!
If your users are deploying your web-app behind the firewall, and outbound requests are blocked, if you don't handle these requests failing then the entire app becomes unusable regardless of if they use ad blocking or not.
I found this searching for "google analytics stub": http://ejohn.org/blog/fixing-google-analytics-for-ghostery/ . Supposedly Ghostery was already stubbing it in 2013. They might be missing some stubs for certain scripts though, because I've had something break 6-8 weeks ago, and it worked when I disabled Ghostery and refreshed.
ghostery and friends tend to break stuff more often.
But yours and my general anecdotal experiences aren't useful. There are hundreds of millions of Firefox users; we [EDIT: i.e., you and I] could have great or horrible experiences and they would indicate nothing. Perhaps if we could point to specific bugs our posts would be substantive, though still probably not of much consequence. We need data.
For instance, somebody just landed a pretty tricky bit of code to fix a severe incremental GC performance fault he'd been experiencing with a lot of tabs open (disclaimer: I reviewed the patch): https://bugzilla.mozilla.org/show_bug.cgi?id=1214961
I moved to Firefox a while back in futile protest at the big G ... but I've come to truly appreciate it.
It's the much better browser. Not sure where Chrome is nowadays but I remember it looked clean, and was like lightning at the beginning. Crapware now (or when I left it).
Appreciate these moves. Long live the fox.
* Although we're currently running an A/B test to measure performance differences with e10s enabled and disabled, so you might fall into the disabled cohort when you run Dev Edition. This experiment is scheduled to end in a few days.
Nit: you mean (js-based) addons/extensions, not (binary) plugins.
1) The greatest challenge for Tracking Protection seems to me to be not technical, but strategic: How do you protect users from tracking without creating a backlash from the tracking industry and their customers (the whole Internet economy built on tracking) that will make the outcome worse or no better, and after an expensive battle. As an extreme example, if the next release of Firefox cut off tracking for all its users then I think there would be a war, including possibly lawsuits and an arms race between trackers and tracking protection. The users would be no better off (or worse off) and it would consume Mozilla's resources.
2) How do they plan to protect the great majority of users who lack the knowledge and skill to understand tracking protection? Remember that most users barely know they are being tracked, much less what that means or how it's done. Many users I deal with don't know the URL field from the search box on their home page; they don't understand what a web browser, web page, or remote server are, much less their components, requests, JavaScript, etc. They lack even the framework to begin understanding tracking. Most other end users I know would be overwhelmed by the concept and extra hassle to load a page. Also, how will most users understand why the webpage is malfunctioning, of all the possible reasons, and what to do about it? Maybe they'll think Firefox is simply broken. Maybe this is why Tracking Protection is available only in Private Browsing right now, and hidden behind a small, somewhat obscure icon (if I understand correctly); maybe that's a way of limiting it to more technically skilled users. Providing tracking protection to technical users has been done, via Ghostery, Disconnect, etc. I'd like to see it become available to everyone else. (That's not a criticism of Mozilla - this is a great, precedent-setting step forward, establishing that major browser vendors might block tracking and act in user interests over industry's, and hopefully creating some competition in that area.)
Maybe the first step is to raise awareness of tracking and the idea that users benefit from and should have the option for privacy, which can be done by simply telling users about Tracking Protection when they open Firefox after the update, whether or not they actually use it.
I don't see this as a concern for Mozilla. Google/Apple/Microsoft and their respective browsers sure, but the point of Firefox is to provide a browser whose goals align with the user. The industry's goals here have never aligned with users and it's about time (many, many years too late) that a major browser vendor ships this as part of the browser rather than an addon.
They make a lot of money from people who rely on advertising like Yahoo and Yandex.
Pure speculation though.
For example, if you're trying to sell tickets to your ski resort, it wouldn't necessarily hurt your bargaining position to burn down gyms, bicycle shops, and other places that command your prospective customers' time and money.
I'd like to see a comprehensive effort to prevent fingerprinting without having to resort to simply blocking the canvas element altogether.
[1] https://addons.mozilla.org/en-US/firefox/addon/canvasblocker...
[1] https://addons.mozilla.org/en-US/firefox/addon/tree-style-ta...
Between firing the CEO over someone making noise in social media and planning to make Tree Style Tabs etc impossible by breaking the API and not replacing it with a usable one I'm, if not out, at least looking for good alternatives.
Edit: the sad thing being that I have been a Firefox user since the first time I got my hands on it and never looked back after the two first addon competitions where brilliant stuff like Scrapbook was created. Basically it is another league than any other browsers addons for now.
If you're using a general purpose blocker (uBlock, uMatrix, PoliceMan, AdBlock, etc, even NoScript), it makes sense to actually disable the internal blocker (less hooks/rules to parse), as FF's list is not even remotely comparable to what you get by subscribing to a couple of community-maintained ones, plus there's no convenient way to tweak the rules (something that other addons excel at).
FF internal tracking protection is somewhat nice for the casual user, and it's going to stir some extra polemics about content blocking (which I consider a positive thing), but it's nowhere as effective as the others. I fear it's also going to be circumvented more quickly, promoting more inline JS, supercookies and fingerprinting techniques.
Overall, it's not something that I would have included in FF from a purely pragmatical perspective. It's just opening Mozilla to direct liability, while not providing anything for the privacy conscious person.
I would guess that there are many people who use Private Browsing mode that don't understand or use security addons. This change may not help many Hacker News users, almost all of whom do understand and can easily use the addons, but we are only a tiny fraction of the Internet.
That will help us figure out what broke and fix it.
sort of hoping other similar things like hello do that too. thats how id like firefox to be, as a user. would be even better if default off at install ;-) (albeit id probably enable hello, its just nice to not be forced-in for such features)
https://mail.mozilla.org/pipermail/gofaster/2015-November/00...
But true enough, you can spend some time and check that it's unlikely to be executed, unless there's some hidden malicious obfuscated code sneaked under the hood. And discovery of such code would be a giant scandal, so it's unlikely there'd be some - it just won't worth it. Anyway, such analysis would take some time and skill. It's not really possible to just open Firefox source code and immediately understand what's going on. And I was commenting on the general nature of Firefox, not this particular button.
To be precise, though, static analysis can only confirm that there are no obvious direct references to the specific code parts outside of certain areas. Given that in a language like JS such references are surely not the only way how execution can get there, the task is not really trivial.
Then we have no argument there. I thought you were commenting on the general nature of the Pocket feature, which is also probably complicated given it's its own separate thing, and my reply was just echoing that you only need to understand and audit the layer that talks to the black box. In this case, a button response handler.
I found https://hg.mozilla.org/mozilla-central/file/tip/browser/comp... within 5 minutes of looking. It's very readable, I spent another 5-10 minutes reading it. This is the first time in memory I've looked at Firefox's code, so I didn't even know where to find it, though I'm sure I've browsed bits of the codebase before for some reason. I first browsed to their files, went to 'browser', and since we're talking about the button I thought 'components' was a good next choice, and hey, a pocket directory. Lucky? Maybe. Reading through the component tells me the initial claim of nothing important happening until you click the button seems accurate, except that functions are exposed publicly so other bits of Firefox could probably get at them without user interaction, and when you do click on it (L165) it'll prompt you to sign up at about:pocket-signup before doing anything. If I wanted to get rid of this, googling seems to say you can override default components with some extra effort. I build Firefox from source (Gentoo) so it would be simpler to just add a patch to the build process that removes the whole directory and deletes the dir line from moz.build.
This is just static human analysis, it didn't take much time or skill. But static analysis isn't the only thing you can do, as I initially said "verify". Active verification by monitoring and alerting works great, and if you can do rebuilds like you can with Firefox then you have even greater control. If I were particularly concerned about something happening without my knowledge (with or without the button) I'd use what I learned from reading the code to monitor my network for outreaches to pocket's website. Of course I can't be fully certain some other code doesn't send all my visited sites to some other IP (or maybe an IRC server) that is then harvested by pocket asynchronously... But as you say, it's very unlikely for such malicious and underhanded code to be there.
git discern intentIt compromises Mozilla's claims that they still put users' interests first. Furthermore, they insist that these promoted tiles is something that people want, whereby it absolutely bloody obvious that nobody, except for Mozilla, wants this junk. These tiles basically show that Mozilla can act against users' interests and in a blatantly disingenuous manner. This in turn makes you question the rest of their efforts that are branded as pro-user.
More info: https://support.mozilla.org/en-US/kb/about-tiles-new-tab?red...
There are other concerns, though. Did you know that when you type in sync passphrase (if you dare to use sync, of course) - the one that Mozilla is supposed to never have any access to - you're actually fetching a piece of HTML+JS from Mozilla's servers and letting that code process it? That's a privacy/security concern that really bothers me.
No personally identifiable data leaves your machine, AFAIK. It's actually an innovative way to provide advertising, necessary to fund many things today, while maintaining privacy. Unfortunately there is a lot of misinformation about it and knee-jerk responses to any advertising.
So, as I get it (I haven't read code for this part of Firefox) it sends some counters about how tiles perform. The data is weakly personally identifiable - in a sense that sender's IP address is logged.
Whatever, I disabled those tiles because I just didn't fancy the selection - but it doesn't bother me (personally, other opinions may vary) if browser would eventually ping Mozilla back telling that I had clicked few tiles.
WHAT DATA IS BEING COLLECTED AND WHY?
To deliver content, Firefox downloads all possible Tiles for your location and/or language and determines for itself what to display. Data is only collected to report on the performance of Tiles in Firefox. No data is collected to deliver the New Tab experience.
To report on the performance of these Tiles, Firefox reports back to Mozilla:
* Geo/Locale
* How many times a Tile is:
-- Displayed
-- Pinned
-- Clicked on
-- Blocked
The data is stored on a restricted access server for a maximum of 7 days, and then the IP address (the only data that would associate the Tile with an individual) is removed.
--------------
WHERE DOES MY DATA GO/GET SHARED?
Data is transmitted directly to Mozilla and only aggregate data is stored on Mozilla servers. Mozilla is sharing aggregate numbers with partners on the number of impressions, clicks, pins, and hides their own content received. The little data that suggested sites reports goes to a restricted access server located in the USA. This data is stripped of IP addresses within 7 days, meaning that no one can be identified. We retain this data for a maximum of 13 months.
Any data that is to be shared with a partner is this aggregated data on the number of impressions, clicks, pins, and hides their own content received.
How do you suggest they continue to exist, if not partnering with Pocket / Yahoo / etc?
https://www.reddit.com/r/firefox/comments/38aorv/psa_mozilla...
Case in point: This entire thread.
Hell, I use one-tab on Chrome, but pocket is just a usability disaster. If I can barely bring myself to use it, imagine the rest :/
Hint: none of them have signed bundling deals.
Note that I'm no fan of the Pocket integration at all - to my knowledge there isn't even any sort of bundling deal or other kind of monetisation involved. I don't understand why Mozilla does this.
You are welcome to draw your own conclusions about the viability of constructing a modern browser engine on donated time from a handful of Facebook and Netflix engineers.
I do, of course, realise that FB and Netflix very much have an interest in the web platform, and could undoubtedly influence it more if they were willing to contribute code. That said, it's probably worthwhile to point out to those who don't know that both FB and Netflix are W3C members, and have several people who contribute heavily to specs.
Just look at GnuPG, OpenSSH, or OpenBSD. These are projects that produce some really essential infrastructure that runs the modern web. This software has been in use at companies like Amazon, Facebook, Google, IBM, etc for decades. They have received almost no support whatsover. Werner Koch (of GPG fame) was so broke and desperate that he considered getting a corporate job. Theo de Raadt tried to get support from any of the hardware vendors that used OpenSSH in their products. He eventually got a laptop from IBM after pestering them for a year. I doubt busybox or mksh get much in the way of support from Google or Android hardware manufacturers.
I would hazard a guess that Firefox is better-funded than most open source "infrastructure" products.
Mozilla wanted to ship a WebRTC implementation, but it's not much use having webcam and microphone input unless you can send them to other people, and in this age of NAT and firewalls, that needs a rendezvous server. Mozilla had already had fruitful business interactions with Telefonica with FirefoxOS, and a telco seems like a reasonable choice for hosting a long-uptime network service...
In exchange for donating server hosting, Telefonica gets to display their logo in the Hello UI. I don't know if they also shelled out money in addition to hosting a service, but 80% of Hello's code is Firefox platform stuff (VP8 encoding and decoding, etc.) not Telefonica stuff.
Unfortunately, in the real world they end up doing things like pocket in order to survive.
Are you worried that data will go to Pocket even if you don't log in?
This statement is utterly wrong. Pocket has 14,000,000 users. Firefox has between 125,000,000 and 150,000,000 users. Assuming every single Pocket user is also a Firefox user, you're now optimizing for 10% of your users. This is clearly stupid.
It's also incorrect to claim that parsing and loading an addon would increase startup time. It's already loading the Pocket button; moving that code into an addon would not affect startup time at all. What it would do is allow users to disable or remove the Pocket integration -- which of course Pocket is paying Mozilla to prevent.
Don't pretend this is a technical decision. It is a business transaction.
edit: to -> too
It’s as if my browser had a copy of Wolfenstein3D integrated.
Funny easteregg, but just a waste of development and testing time, and a waste of storage space.
Every line of code costs time and money in testing.
And here it costs me time every few days to fix new issues that were introduced when the code changed, to update my .patch, reapply it, recompile, repackage. Every few days. All the time.
And when the regression with Gtk3.14 -> 3.18 regarding Drag-and-Drop is still not fixed, but they have time and money to implement, test and bugfix this, sorry, but then I am seriously out of options for running a stable, customizable no-bullshit browser.
Currently it’s fixable by downgrading Gtk, but at the moment there is no fix in Nightly either yet.
Because I have enough of Firefox Stable with just recommended settings completely hanging up or crashing every time it encounters flash or similar things.
Dunno why your Firefox is crashing every time it encounters Flash or similar media, but I can assure you that's not a common experience. Maybe try enabling click-to-play?
Wow this is some level of entitlement I have rarely seen before.
You have the option to contribute. You're not the only one who doesn't want pocket.
Is it going to get accepted into Firefox? No. Just like the last 5 times people tried to do this.
What I currently do is constantly keeping my patch up to date and recompiling Firefox for my Desktop and Laptop (ARCH and Kubuntu) every night based on the current source from the latest trunk release.
But it’s not nearly worth the effort to do this when the browser could easily accept one of the many patches people have written by now to get rid of pocket as part of the system and to move it into an addon.
Same with the ad-ridden new tab page. Put that stuff into an addon and allow me to uninstall it.
Expose the EME DRM feature as plugin on the plugins page, and allow me to uninstall it (I do not know if this is yet the case, I haven’t checked).
I don’t want to have to maintain a huge patchset just to run my browser.
I already have to hack-fix bugs like the before mentioned drag-and-drop bug myself (or downgrade to Gtk3.14).
Mozilla is being especially hypocritical with the integration of these features. During their previous projects (e.g. Australis) Mozilla pushed a lot of previously-integrated features into extensions. This caused problems for a LOT of people, but I reluctantly supported it because a minimal core with most features as plugins is generally a good design. For them to turn around an integrate a plugin that baits people into using spyware is outrageous - and somewhat suspicious.
That button needs to be removed because it's an attractive nuisance[2].
[1] http://www.gnu.org/philosophy/who-does-that-server-really-se...
[2] https://en.wikipedia.org/wiki/Attractive_nuisance_doctrine
Bah. It's basically a lightweight extension, and will soon get packaged as one. It's not integrated into the core, which means the main anti-bloat principles are still upheld.
And it's not like it hides the process of making an account. If you want to sync things, you need a server. Not suspicious.
So why not use about:reader and Firefox Sync?
If it's in the default UI it's not disabled, disabled means you have to take steps outside the expected workflow to enable it.
Dramatisation follows ...
"Oh, this rock I put in the middle of the floor, don't worry it's disabled; if you don't kick it or fall on it then it can't hurt you. Sure, putting it there makes you likely to trip on it; requires you to move it if you don't want to.
What's that? The company name on the side, oh that's just the company that asked us to put the rock here. Yeah, we're totally honouring our roots and keeping with minimalism aren't we!
No, no, it's not an advert - many of our users like having this rock here.
Next week we're going to scatter marbles on the floor, each one says 'drink more Koke', aren't we just being awesome.
Ha, do you remember when you had to choose for yourself which junk to clutter your office up with."
If they are not careful, they are going to run Mozilla into the ground.
(I don't need answers directly, but perhaps a FAQ would help. ...)
1) It's good to see threads managed more agressively; thanks. I can think of another benefit from higher quality discussions: I see a few Mozillians here and of course they aren't the only vendors to participate; perhaps more would come and be more engaged if there was less nonsense. And that would attract more people who are interested in valuable, informative interaction, which would attract more vendors, which would ... etc.
2) "marked it off-topic": What does this mean in practice?
3) While the issue with Eich is off-topic, so is the issue with Pocket and many other threads and subthreads. I don't understand the distinction, unless that the former is more inflamatory, more outdated, and more tired. Yawn.
Re #3: we marked that subthread off-topic because a user emailed to complain about it. Didn't see the other ones.
General note: we started doing this as an experiment and it's clear by now that it has improved thread quality, so we're probably going to write code to support it, and let the community mostly manage it, probably by generalizing the flagging mechanism.
What do you consider bloat here? The 'Hello' button/promotion? Or the full WebRTC stack?
And how can you decide that efforts spent to build FxOS are 'wasted'?
It's not as he was CEO of LGBT organization or he was running for a public office. Mozilla is not a political organization, his opinions in this matter should make no difference whatsoever.
This move was basically infringing on rights to have his personal beliefs.
How would it looks like if it was the reverse? Someone pro LGBT made a contribution against prop 8 and then was told 6 years later that his personal values did not match the company's even though the company has nothing to do with LGBT and his opinion has no impact.
This move was is simply discrimination. It should matter whether he is republican or democrat, christian/muslim/atheist or fire worshiper, whether he's pro guns or against. Mozilla is a technology company, neither of that should matter in what they do.
As someone who cares about politics, I would be furious if my employer told me that my personal beliefs are wrong. That infringes on my rights as a citizen and voter.
Now, I do admit that I didn't like the whole 'we dug up this stuff in his past' part of the story. Nor the pitchfork wielding crowds on the net. I, personally, would've considered him misguided and stuck in the past in this regard, but I wasn't calling for (or expecting) consequences. Mozilla decided (or was pressured) to distance itself from the person and his statements. That might be correct or might be unfair, depending on your stance.
But it's not about free speech.
What I mean is that by telling me that my vote or contribution toward specific cause is not aligned with company's goals essentially forces me to vote in a specific way which does affect my freedom of speech.
If Mozilla would be an LGBT organization and I joined and was told that my contribution don't agree with company's values. Then I'm totally at fault and should look for job somewhere else if this matter to me, but company like Mozilla has no obvious political affiliations and in fact they should not have any.
People have freedom of speech, not freedom from consequences.
This definition of a "right" is so loose as to be basically meaningless. Accordingly, I have the freedom to murder anyone, just not the freedom from its consequences. People in North Korea are free to speak whatever they want, but aren't free to remain living if the government doesn't like what they said.
If you make the other cliched argument that the first amendment only applies to government suppression of speech, that's true, but the US Constitution doesn't have a monopoly on what "freedom of expression" means. It's only a legal lower bound, and in one country.
They don't say that though. The problem wasn't that he did something, the problem is that what he did prevented him from performing his role as CEO. And CEO is not just another employee. They are the public face of the company. They are the leader. And I don't think you'll find anyone that would argue that when he was made CEO, there was a backlash which caused problems both internally and externally for his role as CEO.
And that's why the board and he decided he would not be able to fill the role of CEO and he stepped down. Not because of his political affiliations, but because he couldn't fulfill the role they needed him to fulfill.
This action of Mozilla's doesn't peal back the first amendment. But it does chill the free exchange of ideas. That's what the first amendment was for. Shouldn't we be concerned when someone finds a way around the safeguards we put in place to protect free society?
Let's not mince words here. This was never about "speech", this was about action, and his complete unwillingness to own up to that action. For a CEO, that's a pretty big failure of leadership.
Technically, in California, they can't if the statements are part of the political process. Or at least they will get a pretty nominal fine if they do. See http://www.leginfo.ca.gov/cgi-bin/displaycode?section=lab&gr...
Your two examples, of course, are not political activity per se, so wouldn't fall under these regulations.
Mozilla is explicitly political. That's like their entire shtick: they want a more open web that respects user freedom and privacy. That's a political stance.
And Mozilla has LGBT employees. They'd like leadership that isn't going to make them feel unwelcome.
Everyone has a right to believe whatever they want. Nobody has a right to be CEO of Mozilla.
Mozilla does, however, have the right to choose their CEO.
Do I have my facts wrong?
Is there something that makes Eich's situation different than Catmull's?
If I understood the difference I feel like I'd be more enlightened.
1. Pixar is a private for-profit company, while Mozilla is at least in part a political nonprofit. For obvious reasons, people are more concerned about the political positions in such a case.
2. I suspect that many people would find the act of donating to a religious body, which holds a wide-ranging diversity of opinions on many subject (not all of which an individual may agree with) as distinct from the explicit act of making a donation for one specific political aim.
There are in California, actually. See California labor code sections 1101-1102 http://www.leginfo.ca.gov/cgi-bin/displaycode?section=lab&gr... , which say:
1101: No employer shall make, adopt, or enforce any rule, regulation, or policy (a) Forbidding or preventing employees from engaging or participating in politics or from becoming candidates for public office. b) Controlling or directing, or tending to control or direct the political activities or affiliations of employees.
1102: No employer shall coerce or influence or attempt to coerce or influence his employees through or by means of threat of discharge or loss of employment to adopt or follow or refrain from adopting or following any particular course or line of political action or political activity.
etc. So in California (where Mozilla is headquartered and where Brendan lives) it is in fact illegal to fire someone for a political donation they make.
Now the actual punishment is a slap on the wrist in practice (see section 1103; it's a $5k maximum fine for the corporation if the employer is a corporation).
Also, I don't know much about the CA law you quote, though I wonder whether it prohibits political discrimination in the _hiring_ of employees at all. Section 1102 definitely prohibits firing based on political activity. I don't see anything that says you can't discriminate on a political basis in _hiring_. Perhaps that is in a different section. I tend to think, e.g., that the Democratic Party organization would not be forced to consider hiring Republicans equally with Democrats, not sure how that's dealt with.
Your "basically demoting" story is a new one. What's your source on that?
I'm just going by media reports and the answers the Mozilla leadership gave at the time. It was clear the pressure was on and without you stepping out voluntarily (which was the right gesture, from all points of view), something would have happened which would have damaged the project more -- in that sense, it would have been at odd with the project's aims. I expect you share the same view, or you wouldn't have stepped down in the first place.
I was just pointing out that you weren't fired and you likely would have not been fired in any case; at worst, you would have been moved to a different role; hence "demoted", since most people see the CEO as the pinnacle of a pyramid.
Would you agree that this is a fairer representation of the historical truth, from your point of view, than "Eich was fired"?
/be
You and Mozilla both claim you were not fired and that you chose to step down. Had there not been political pressure from a certain group, would you still have stepped down?
When people hear about your story - it sounds more like being smoked out of your own house. A group wants you ousted due to a donation they disagree with and will be disruptive, give bad PR, or straight up quit developing for Mozilla until and unless you leave. At that point it is within Mozilla's and your best interests for you to step down.
So if you stepped down for entirely unrelated reasons than the rabble rabble going on by a certain group of people - why then? I don't think I've ever seen that answered.
And if you did step down because of the rabble rabble going on - that is what so many people have a problem with. Even if you necessarily don't.
What is the difference between lynch-mobbing someone because they don't support {fill in your individual preferences or proclivities} and lynch-mobbing someone because they do support {fill in your individual preferences or proclivities}. There is absolutely nothing different than the perspective. Everyone should have the right to express their opinions, even if you don't like them and they are not your favorite thing (to invoke Louis CK) and then a conversation may lead to a debate and that is how better ideas come about.
The process that society is going through right now is really nothing but a hardening of positions, a "liberal" form of tyranny if you will; the overbearing imposition of a particular perspective upon others. Ironically, that is the very thing the "liberal" side claims is done by the "right/conservatives".
What the current state of civilization in the west shares is an apparent inherent stupidity and irrationality that is quite stunning. Up is right, left is forward, down is blue, billion dollar valuations for what is essentially marketing middle-ware, people maintain their own personal state surveillance dossiers on themselves. It's like the world has gone god damn ape shit mad.
But what a private foundation and/or company promotes or demotes isn't up to its members?
Sounds like a double standard to me.
[1] - https://news.ycombinator.com/item?id=10097630
Deleted comment
Saying "X" usually means "Y" is not proof that it means such in this case.
"We first added Private Browsing to Firefox to give you control over your privacy locally by not saving your browser history and cookies when you close a private window. However, when you browse the Web, you can unknowingly share information about yourself with third parties that are separate from the site you’re actually visiting, even in Private Browsing mode on any browser. Until today.
Private Browsing with Tracking Protection in Firefox for Windows, Mac, Android and Linux actively blocks content like ads, analytics trackers and social share buttons that may record your behavior without your knowledge across sites."
I really wish Mozilla would get back to promoting the add-ons model that once made Firefox so attractive, and prioritising flexibility and stability accordingly. Some of the other features they've added directly might be useful, but the price of the constant change is too high, and in just about every case I can think of the add-ons community already had good, working solutions.
uBlock Origin is apparently now the blessed alternative and is OK for blocking most ads, but I immediately found a few potential tracking issues with its default lists, and its UI is awful.
Ghostery also isn't blocking various trackers effectively now, even though its UI still claims it has detected and blocked them. I can't 100% guarantee that's FF42 if Ghostery also updated its lists at almost exactly the same time, but that's when I saw things like Facebook Connect start hitting FB servers even though it's supposedly blocked.
This is almost a brand new machine, BTW, which just happened to update FF and lead to changes in the plug-ins a few days after initial set-up. There's relatively little chance of odd things going on or historical baggage distorting these results.
Bottom line: The day I bought the machine and installed FF and my usual set up add-ons, my browsing experience was fine, and then a few days later FF updated to 42, and my browsing experience immediately sucked.
I am curious: what are these "few potential tracking issues" specifically?
Whatever default lists uBO is using, unlike with ABE (which is essentially ABP filtering engine), users have the last words in what is blocked:
- The `important` filter option can be used to override exception filters.[1]
- Dynamic filtering override all static filters.[2] For example, you do not need a special filter list to block Facebook everywhere, it's a matter of a few point-and-click to block it everywhere without any way for any static filter to counter it.[3]
* * *
[1] https://github.com/gorhill/uBlock/wiki/Static-filter-syntax#...
[2] https://github.com/gorhill/uBlock/wiki/Overview-of-uBlock's-...
[3] https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-to...
It's certainly possible to customise uBlock Origin to prevent these things. However, I couldn't immediately see any of the other suggested lists that would have blocked some of these potential privacy/tracking issues either, which suggests that not only do I need to manually block them if I want to stop the tracking, I also need to manually update those lists.
In contrast, with a couple of fire-and-forget plug-ins I've been installing as standard for years until recent FF updates broke them, I very rarely had to customise anything manually. They just worked as standard, and I trusted them to keep working and never noticed any significant problems, until now.
Fanboy's Anti-ThirdpartySocial is right there in the list of lists, under the Social header.
> In contrast, with a couple of fire-and-forget plug-ins I've been installing as standard for years until recent FF updates broke them
Ok, my answer was meant to address your point that uBO was no replacement for ABE, as you stated "uBlock Origin is apparently now the blessed alternative [to ABE]".
And it doesn't block any of the things I mentioned. The domain connect.facebook.com isn't in there, for example, and I ran into a page running a script from there within five minutes of switching to the new plug-ins.
Ok, my answer was meant to address your point that uBO was no replacement for ABE
Sorry, I'm not sure where I said anything like that. I explicitly noted that uBO was apparently being promoted as the successor to ABE, as you seem to have noticed. I just also noted that the plug-ins I've got running now aren't as good in some respects as the ones that worked just fine for a long time until recent FF changes.
"Anti-ThirdpartySocial" aka "Anti-Facebook List" list https://www.fanboy.co.nz/fanboy-antifacebook.txt
> ||connect.facebook.com^$third-party,domain=~facebook.net|~fb.com
> ||connect.facebook.net^$third-party,domain=~facebook.com|~fb.com
> ||facebook.com/connect/$third-party
Is that not what you are looking for?
I misunderstood before and at the time I read "Fanboy's Anti-ThirdpartySocial" as "Fanboy’s Social Blocking List" not "Anti-ThirdpartySocial (see warning inside list)", perhaps because the latter sometimes seems to change its name to "Anti-Facebook List" for reasons I haven't identified. The former does block numerous Facebook addresses, just not that one.
I'm not sure any of this really invalidates my original point, though. Two weeks ago my Firefox had a couple of privacy/blocker extensions installed, and with no real configuration beyond ticking the "everything" boxes in the Ghostery wizard, they blocked pretty much everything that bothered me. Today, with FF42, neither of them works any more.
Apparently the new version involves figuring out which of the almost 50 lists that are suggested but not active by default in uBlock Origin are needed to get a reasonable level of blocking. I dare say almost no-one is actually going to get that right reliably even if they want to. And while I might have guessed to just activate everything under the social heading to block Facebook Connect (at least if I'd realised something related to Facebook wasn't already blocked by default), I have no idea which of those lists to even check to see if I can disable the various web font resources that involve tracking.
Here (my emphasis):
> Adblock Edge was discontinued a little while back [...] uBlock Origin is apparently now the blessed alternative [...] but I immediately found a few potential tracking issues with its default lists [...]
"but", implying Adblock Edge somehow did not have the "few potential tracking issues" you said you found in uBO.
Hope it's clear.
> Since some Web pages may appear broken when elements that track behavior are blocked, we’ve made it easy to turn off Tracking Protection in Private Browsing for a particular site using the Control Center.
Whitelisting a whole site because it "appears broken" is a pretty weak approach, and clearly incentivizes "brokenness". I notice the spies (google etc.) are more intelligent and creative than the defenders of privacy.
We need a browser that can make such sites work - for the user. Without leaking any cross-site information. This involves rewriting URLs and cookies, or "mixmastering" identifiers across a cloud of users.
>Today we’re also releasing new visual editing tools in Firefox Developer Edition including Animation Tools that work the same way animators think.
To me this sounds like fiddling while Rome burns. Typical of their track record of wasting energy on irrelevant projects instead of making a great browser.
I don't think you're being fair. I'm seeing a lot of improvements from Firefox, outside of their vastly improved developer tools and tracking prevention.
* They've been working on multi-process Firefox,
enabled in developer edition [1]
* They've been beating Chrome's JS Engine in the
benchmarks (not to mention IE) [2]
* They've been implementing more and more of HTML5, about
81% of the way there according to [3]
* Firefox supports more ES6 features than Chrome [4]
I guess I'm seeing a lot of good progress coming from the Firefox team.[1] - https://developer.mozilla.org/en-US/Firefox/Multiprocess_Fir...
[2] - http://arewefastyet.com/