I really wish it shouldn't have existed, and instead Mozilla would've focused on providing an API to build a synchronization service upon. And then, whatever - their services could've been an pre-bundled extension.
2. I believe all of those SaaSes (i.e. Firefox Screenshots, too) shouldn't belong to the browser's core. Those could be distributed as pre-bundled extensions (which they actually are, but in a special way), but not as a part of the browser itself.
This is highly opinionated, though. I just feel that rather than a browser, Firefox is becoming something like a service platform. I don't like it for the same reasons I tend to value self-hosting over the dependence on others' services, and Free Software over non-free options. I recognize others may feel very differently and possibly even welcome that.
---
[1] Authentication pages are still served from network, so if you use it - you trust Mozilla to not steal (or, better say, not be forced to steal) your password and the encryption keys. The protocol is stable for quite a while so I really don't know why they're still not fixing this.
[2] I wrote an alternative self-hosted Accounts & Sync implementation, so while I'm biased I sort of know what I'm talking about here. Four different authentication protocols (BrowserID, Hawk, OAuth2 and JWT), multiple non-standard HTTP headers, and the whole system just reeks of the NIH syndrome.
Isn't it? Wasn't this the crux of the whole dev team controversy/split years ago?
(This is all sounding like rehashed news to me, but I admit I don't go out of my way to keep up with browser community drama, so someone correct me if I'm wrong.)
Did you open-sourced your alternative self-hosted Accounts & Sync implementation?
Still, here it is: https://gitlab.com/drdaeman/firesync
Development is very sporadic, though - you can see it in commit history. And some parts of code feel dirty (in particular, I've made a bad design decision when trying to avoid implementing full-fledged OAuth2).
The repo lacks few things:
1) Notes about patched PyBrowserID. It's in the repo, and you can check the Dockerfile, but not in README.
2) Instructions on installing Kinto - another piece that is used to sync WebExtension settings[1]. It became mandatory with 57, without it sync fails and doesn't update "last synced" date (used to work in 56 and below). I'll add some instructions later, when I'll find time to do so.
----
[1] BTW, this means that everyone who runs self-hosted Sync but not Accounts (relying on Mozilla tokens instead) are now storing parts of their data on Mozilla servers. I don't think this was ever announced, I've only learned about Kinto when my Firefoxes started to log errors in the browser console. If you self-host Sync-only and think you may be affected - check `webextensions.storage.sync.serverURL` value.
Even if they don't use resources when not being actively used (no way to test since there is no way to remove them), they increase attack surface and clutter UI.
But your OS does come with lots of packages and features you may not use.
Sure does. And I can remove them if I want to. I can apt-get remove libc6 if I really really want to and I accept the consequences. I can't remove non-essential parts of the Firefox, though.
Delete /usr/lib/firefox/browser/features/firefox@getpocket.com.xpi (or - better - rebuild the .deb package to not include this file) and the Pocket will be gone. Same for screenshots@mozilla.org.xpi.
Sync and DevTools are tightly integrated, though. I'd really really wish it would be realistically possible to remove Sync and replace it with something else.
There are users who value OSes for being absolutely minimal, so they can install only the stuff they want.
There are users who build their OSes from scratch, compiling each piece from source, fine-tuning every option they want to touch, manually defining every aspect of their system.
None of those approaches are wrong. And each of users may voice their discontent if things are not the way they prefer them to be (and that's good).