So who is telling the truth?
The one thing I know is that I am writing from a Firefox right now and don't see headers, inversions etc. at all. The examples given in the article should have all been inverted, right?
So who is telling the truth?
The one thing I know is that I am writing from a Firefox right now and don't see headers, inversions etc. at all. The examples given in the article should have all been inverted, right?
[0] https://www.reddit.com/r/programming/comments/7k8pf7/firefox...
the use, as far as I know, has always been to disable broken features in older versions of users that do not update. pretty ok and necessary.
but this makes me think they are using it to a/b test or capacity plan for marketing campaigns now :(
There is NEVER a ethical reason for a dark update channel to exist. Altering the functionality of installed software without consent or notification is an act of sabotage, even when done by the vendor. If you want to disable broken features you prompt the user to have them disabled. Worst case (say something that allows malware to propagate or puts them or others at active risk) you disable it and display a message telling exactly what has happened.
I completely disagree this need to be hidden from the end user, it should be FULLY and COMPLETELY transparent what is being disabled, added, or changed. There should be an "about/system-extension" page where a person could go and see everything that is doing or has done, and even optionally disable it if they desire.
I've only seen people that saw the addon being installed unexpectedly.
That doesn't lead to thinking any sites have been hacked.
And, for good measure, here's an official quote confirming that we're pulling the add-on from Firefox: https://gizmodo.com/after-blowback-firefox-will-move-mr-robo...
It's great that it was pulled, but what about removing the ability to silently install add-ons? Give up the power to make this mistake in the future if you want forgiveness.
Although different, this too brushes off this one instance as a mistake, and entirely disregards the rest of the article, not even trying to address or explain the rest of Mozilla's recent borderline malicious behavior.
A serious fork is long overdue, if only it didn't take a corporation as big as Mozilla to undo their bad deeds.
I still want a justification of the cliqz thing, sure, but I don't demand it in relation to this.
Even if the add-on is "enabled," it's doesn't initialize itself unless a specific about:config value is also manually flipped
Attack surface 101 / reason nobody else does this
"It involved sideloading a sketchy browser extension which will invert text that matches a list of Mr. Robot-related keywords like “fsociety”, “robot”, “undo”, and “fuck”, and does a number of other things like adding an HTTP header to certain sites you visit."
Only if HN is on the list of "certain sites". It's also irrelevant because the extension offers me no value so Mozilla was not acting in my best interest.
But still, the fact that the extension was not active unless you mess around in about:config is a crucial fact, which should not have been omitted in an highly critical article, specially if they use words like "Mozilla, you fucked up bad, and you still haven’t apologised. The study is still active and ongoing".
I feel misinformed by that article, to say the less.
If that is the case (I'm not saying it's not, just that I don't know)... why did the extension even need to exist? Presumably "certain sites" are partner sites participating in the promotion. If they are participating and (I assume) they control their own content, why didn't they just invert those words or whatever else they wanted to do with the content when they served it?
I'm very confused about why this needed to roll out as a browser extension at all.
So presumably it was implemented as a browser extension so game players would be able to find the browser extension, which would give them hints about what to do next.