sort of hoping other similar things like hello do that too. thats how id like firefox to be, as a user. would be even better if default off at install ;-) (albeit id probably enable hello, its just nice to not be forced-in for such features)
https://mail.mozilla.org/pipermail/gofaster/2015-November/00...
But true enough, you can spend some time and check that it's unlikely to be executed, unless there's some hidden malicious obfuscated code sneaked under the hood. And discovery of such code would be a giant scandal, so it's unlikely there'd be some - it just won't worth it. Anyway, such analysis would take some time and skill. It's not really possible to just open Firefox source code and immediately understand what's going on. And I was commenting on the general nature of Firefox, not this particular button.
To be precise, though, static analysis can only confirm that there are no obvious direct references to the specific code parts outside of certain areas. Given that in a language like JS such references are surely not the only way how execution can get there, the task is not really trivial.
Then we have no argument there. I thought you were commenting on the general nature of the Pocket feature, which is also probably complicated given it's its own separate thing, and my reply was just echoing that you only need to understand and audit the layer that talks to the black box. In this case, a button response handler.
I found https://hg.mozilla.org/mozilla-central/file/tip/browser/comp... within 5 minutes of looking. It's very readable, I spent another 5-10 minutes reading it. This is the first time in memory I've looked at Firefox's code, so I didn't even know where to find it, though I'm sure I've browsed bits of the codebase before for some reason. I first browsed to their files, went to 'browser', and since we're talking about the button I thought 'components' was a good next choice, and hey, a pocket directory. Lucky? Maybe. Reading through the component tells me the initial claim of nothing important happening until you click the button seems accurate, except that functions are exposed publicly so other bits of Firefox could probably get at them without user interaction, and when you do click on it (L165) it'll prompt you to sign up at about:pocket-signup before doing anything. If I wanted to get rid of this, googling seems to say you can override default components with some extra effort. I build Firefox from source (Gentoo) so it would be simpler to just add a patch to the build process that removes the whole directory and deletes the dir line from moz.build.
This is just static human analysis, it didn't take much time or skill. But static analysis isn't the only thing you can do, as I initially said "verify". Active verification by monitoring and alerting works great, and if you can do rebuilds like you can with Firefox then you have even greater control. If I were particularly concerned about something happening without my knowledge (with or without the button) I'd use what I learned from reading the code to monitor my network for outreaches to pocket's website. Of course I can't be fully certain some other code doesn't send all my visited sites to some other IP (or maybe an IRC server) that is then harvested by pocket asynchronously... But as you say, it's very unlikely for such malicious and underhanded code to be there.
git discern intentIt compromises Mozilla's claims that they still put users' interests first. Furthermore, they insist that these promoted tiles is something that people want, whereby it absolutely bloody obvious that nobody, except for Mozilla, wants this junk. These tiles basically show that Mozilla can act against users' interests and in a blatantly disingenuous manner. This in turn makes you question the rest of their efforts that are branded as pro-user.
More info: https://support.mozilla.org/en-US/kb/about-tiles-new-tab?red...
There are other concerns, though. Did you know that when you type in sync passphrase (if you dare to use sync, of course) - the one that Mozilla is supposed to never have any access to - you're actually fetching a piece of HTML+JS from Mozilla's servers and letting that code process it? That's a privacy/security concern that really bothers me.
No personally identifiable data leaves your machine, AFAIK. It's actually an innovative way to provide advertising, necessary to fund many things today, while maintaining privacy. Unfortunately there is a lot of misinformation about it and knee-jerk responses to any advertising.
So, as I get it (I haven't read code for this part of Firefox) it sends some counters about how tiles perform. The data is weakly personally identifiable - in a sense that sender's IP address is logged.
Whatever, I disabled those tiles because I just didn't fancy the selection - but it doesn't bother me (personally, other opinions may vary) if browser would eventually ping Mozilla back telling that I had clicked few tiles.
WHAT DATA IS BEING COLLECTED AND WHY?
To deliver content, Firefox downloads all possible Tiles for your location and/or language and determines for itself what to display. Data is only collected to report on the performance of Tiles in Firefox. No data is collected to deliver the New Tab experience.
To report on the performance of these Tiles, Firefox reports back to Mozilla:
* Geo/Locale
* How many times a Tile is:
-- Displayed
-- Pinned
-- Clicked on
-- Blocked
The data is stored on a restricted access server for a maximum of 7 days, and then the IP address (the only data that would associate the Tile with an individual) is removed.
--------------
WHERE DOES MY DATA GO/GET SHARED?
Data is transmitted directly to Mozilla and only aggregate data is stored on Mozilla servers. Mozilla is sharing aggregate numbers with partners on the number of impressions, clicks, pins, and hides their own content received. The little data that suggested sites reports goes to a restricted access server located in the USA. This data is stripped of IP addresses within 7 days, meaning that no one can be identified. We retain this data for a maximum of 13 months.
Any data that is to be shared with a partner is this aggregated data on the number of impressions, clicks, pins, and hides their own content received.
How do you suggest they continue to exist, if not partnering with Pocket / Yahoo / etc?
Unfortunately, in the real world they end up doing things like pocket in order to survive.
Are you worried that data will go to Pocket even if you don't log in?
Mozilla is being especially hypocritical with the integration of these features. During their previous projects (e.g. Australis) Mozilla pushed a lot of previously-integrated features into extensions. This caused problems for a LOT of people, but I reluctantly supported it because a minimal core with most features as plugins is generally a good design. For them to turn around an integrate a plugin that baits people into using spyware is outrageous - and somewhat suspicious.
That button needs to be removed because it's an attractive nuisance[2].
[1] http://www.gnu.org/philosophy/who-does-that-server-really-se...
[2] https://en.wikipedia.org/wiki/Attractive_nuisance_doctrine
Bah. It's basically a lightweight extension, and will soon get packaged as one. It's not integrated into the core, which means the main anti-bloat principles are still upheld.
And it's not like it hides the process of making an account. If you want to sync things, you need a server. Not suspicious.
So why not use about:reader and Firefox Sync?
It’s as if my browser had a copy of Wolfenstein3D integrated.
Funny easteregg, but just a waste of development and testing time, and a waste of storage space.
Every line of code costs time and money in testing.
And here it costs me time every few days to fix new issues that were introduced when the code changed, to update my .patch, reapply it, recompile, repackage. Every few days. All the time.
And when the regression with Gtk3.14 -> 3.18 regarding Drag-and-Drop is still not fixed, but they have time and money to implement, test and bugfix this, sorry, but then I am seriously out of options for running a stable, customizable no-bullshit browser.
Wow this is some level of entitlement I have rarely seen before.
You have the option to contribute. You're not the only one who doesn't want pocket.
Is it going to get accepted into Firefox? No. Just like the last 5 times people tried to do this.
What I currently do is constantly keeping my patch up to date and recompiling Firefox for my Desktop and Laptop (ARCH and Kubuntu) every night based on the current source from the latest trunk release.
But it’s not nearly worth the effort to do this when the browser could easily accept one of the many patches people have written by now to get rid of pocket as part of the system and to move it into an addon.
Same with the ad-ridden new tab page. Put that stuff into an addon and allow me to uninstall it.
Expose the EME DRM feature as plugin on the plugins page, and allow me to uninstall it (I do not know if this is yet the case, I haven’t checked).
I don’t want to have to maintain a huge patchset just to run my browser.
I already have to hack-fix bugs like the before mentioned drag-and-drop bug myself (or downgrade to Gtk3.14).
Currently it’s fixable by downgrading Gtk, but at the moment there is no fix in Nightly either yet.
Because I have enough of Firefox Stable with just recommended settings completely hanging up or crashing every time it encounters flash or similar things.
Dunno why your Firefox is crashing every time it encounters Flash or similar media, but I can assure you that's not a common experience. Maybe try enabling click-to-play?
edit: to -> too
This statement is utterly wrong. Pocket has 14,000,000 users. Firefox has between 125,000,000 and 150,000,000 users. Assuming every single Pocket user is also a Firefox user, you're now optimizing for 10% of your users. This is clearly stupid.
It's also incorrect to claim that parsing and loading an addon would increase startup time. It's already loading the Pocket button; moving that code into an addon would not affect startup time at all. What it would do is allow users to disable or remove the Pocket integration -- which of course Pocket is paying Mozilla to prevent.
Don't pretend this is a technical decision. It is a business transaction.
If it's in the default UI it's not disabled, disabled means you have to take steps outside the expected workflow to enable it.
Dramatisation follows ...
"Oh, this rock I put in the middle of the floor, don't worry it's disabled; if you don't kick it or fall on it then it can't hurt you. Sure, putting it there makes you likely to trip on it; requires you to move it if you don't want to.
What's that? The company name on the side, oh that's just the company that asked us to put the rock here. Yeah, we're totally honouring our roots and keeping with minimalism aren't we!
No, no, it's not an advert - many of our users like having this rock here.
Next week we're going to scatter marbles on the floor, each one says 'drink more Koke', aren't we just being awesome.
Ha, do you remember when you had to choose for yourself which junk to clutter your office up with."
Hint: none of them have signed bundling deals.
Note that I'm no fan of the Pocket integration at all - to my knowledge there isn't even any sort of bundling deal or other kind of monetisation involved. I don't understand why Mozilla does this.
You are welcome to draw your own conclusions about the viability of constructing a modern browser engine on donated time from a handful of Facebook and Netflix engineers.
I do, of course, realise that FB and Netflix very much have an interest in the web platform, and could undoubtedly influence it more if they were willing to contribute code. That said, it's probably worthwhile to point out to those who don't know that both FB and Netflix are W3C members, and have several people who contribute heavily to specs.
Just look at GnuPG, OpenSSH, or OpenBSD. These are projects that produce some really essential infrastructure that runs the modern web. This software has been in use at companies like Amazon, Facebook, Google, IBM, etc for decades. They have received almost no support whatsover. Werner Koch (of GPG fame) was so broke and desperate that he considered getting a corporate job. Theo de Raadt tried to get support from any of the hardware vendors that used OpenSSH in their products. He eventually got a laptop from IBM after pestering them for a year. I doubt busybox or mksh get much in the way of support from Google or Android hardware manufacturers.
I would hazard a guess that Firefox is better-funded than most open source "infrastructure" products.
Mozilla wanted to ship a WebRTC implementation, but it's not much use having webcam and microphone input unless you can send them to other people, and in this age of NAT and firewalls, that needs a rendezvous server. Mozilla had already had fruitful business interactions with Telefonica with FirefoxOS, and a telco seems like a reasonable choice for hosting a long-uptime network service...
In exchange for donating server hosting, Telefonica gets to display their logo in the Hello UI. I don't know if they also shelled out money in addition to hosting a service, but 80% of Hello's code is Firefox platform stuff (VP8 encoding and decoding, etc.) not Telefonica stuff.
https://www.reddit.com/r/firefox/comments/38aorv/psa_mozilla...
Case in point: This entire thread.
Hell, I use one-tab on Chrome, but pocket is just a usability disaster. If I can barely bring myself to use it, imagine the rest :/