But pushing it out broadly, even in an inert state, was not good.
I can assure you that there's an active internal discussion to that effect. I'm hopeful that we'll learn from this.
But pushing it out broadly, even in an inert state, was not good.
I can assure you that there's an active internal discussion to that effect. I'm hopeful that we'll learn from this.
I don't understand why you believe that, especially when it's not an "easter egg" but actually an ad.
When's the last time I upgraded my linux kernel and it came bundled with an "easter egg" kmod, loaded by default, which made lightsaber noises if I wrote 1 to /sys/class/ad/starwars/enabled? Would you think that's appropriate?
You're developing a web browser, a critical piece of software. Almost an OS within an OS these days. You got rid of "cookies are delicious delicacies"[1] (an actual easter egg) because you deemed that the joke wasn't worth obfuscating an important piece of information. 15 years later you're adding stealthy extensions that look like backdoors. What changed?
I can assure you, people who want novelty extensions know where to find them.
I think you agree:
> But pushing it out broadly, even in an inert state, was not good.
The folks behind this presumably wanted this experience to be seamless, and were also trying to keep it under wraps to preserve the surprise factor. This meant that they bypassed the usual processes by which Firefox engineers would have had the opportunity to (a) raise concerns about the deployment approach, and (b) suggest other mechanisms that would have achieved the desired experience while keeping deployment appropriately scoped.
It's really heartbreaking that it ended up this way. The marketing team was trying to think outside the box to bring new users to Firefox, which is crucial if Quantum is to succeed. Surprises and stealth are the bread and butter of marketing, but they didn't think through the dangers of applying those things to engineering. Moreover, the very nature of surprise and stealth meant that they missed the chance for internal feedback before it went live.
A lot of us inside Mozilla are hurting right now. We poured our lives into Quantum for two years for the long-shot dream of giving Firefox a fresh start and saving the web from monopoly. It's frustrating to feel that all our hard-earned goodwill might be squandered by a few people and a botched marketing stunt. But the people behind that stunt were only trying to help, and I'm sure they feel especially terrible right now too.
Mozilla will learn from this. But the mistakes here are probably less sinister than they may appear, and it would be sad if they caused our most closely-aligned users to switch to Chrome.
i would have been happy to write this one off, but the ship has all but sailed. the ice is so thin that you guys are one PR disaster away from a mass exodus of people who trust you.
if mozilla learned anything from the Pocket disaster, it would have immediately made it a removable addon and genuinely apologized. instead, there it is in my toolbar on nightly. i know you guys bought them, but that's a solution that only addresses the privacy aspect - you went from nonremovable Pocket to nonremovable Mozilla/Pocket.
every misstep that has happened with "enhancing the user experience" is an affront to the brilliant engineering you guys are doing. you're literally shedding user-engineers - not unlike yourselves - over these user choice, bundling/marketing double-speak, viralgrab and privacy fiascos.
i'm reasonable. i understood the DRM situation. the content providers make the rules and the consumers make the choices based on where they can consume the content. many people went apeshit with ideology. but mozilla is in full control of everything that is going on right now.
> This meant that they bypassed the usual processes by which Firefox engineers would have had the opportunity to (a) raise concerns about the deployment approach, and (b) suggest other mechanisms that would have achieved the desired experience while keeping deployment appropriately scoped.
i don't know what's worse, that users don't know what's going on, or that the engineers don't. here's an apt description for this: rgba(0,0,0,1)
rather than being delighted to discover features i didn't know where in there, i'm now horrified to discover them. i'm becoming mozilla's unwitting social testing platform and this is unacceptable. it is not what i signed up for with firefox 1.5. there's a reason that Tor's browser is firefox; i think this reason is ripe for re-evaluation.
mozilla is long overdue for automated regression tests of their core values.
plz don't take this comment personally. i have huge respect for the work you do. it's a shame the engineers are not in control of their destiny; they rarely are.
https://en.wikipedia.org/wiki/Controlled_flight_into_terrain
That doesn't make any sense--if it's an ad for Firefox, why is it in Firefox, which is presumably already being used by the target audience? It should be in some other site or software set up by the Mr Robot production company which directed people to Firefox, no?
If I understand correctly, at some point when following the breadcrumbs the user is given the opportunity to opt in to the game. I think everyone now agrees that this opt-in step should have triggered the download and installation of the add-on, rather than the activation of a dormant add-on that was deployed to every single Firefox user.
Are those responsible for this stunt still employed at mozilla? If so, you can say goodbye to trust of most of the technically aware world. I cannot recommend Firefox while idiotic stunts like this are institutionally viable - have you got the message?
I humbly suggest that your message might be a little harsh and unforgiving. Is there anything I can say which will change your mind? Kindness has a place in the world. Please help me preserve it.
This scares me an many others quite a lot.
Thanks for listening.
But who actually wants it? Who wants a fundamental part of their daily work suddenly manipulated by somebody else at a whim?
What if Ford decided it would force-push add a cool "Star Wars" tie in to its cars (no pun intended on "force push")? That's a mission-critical part of my life, I drive my kids in it. Don't mess with my car over-the-air without telling me, I don't care if it's all fun and games to you, to me it's my life.
Same for my browser. It's not a toy I use for fun. It's how I see my medical records, pay bills, transport extremely sensitive and confidential information... I don't want anyone to suddenly push "cool fun easter eggs" to it, under any circumstance.
FWIW, Tesla includes easter eggs in its cars. You need to go out of your way to use them, and they're pretty much hidden unless you go looking for them, and they keep adding more via OTA updates.
If your question is "Who are easter eggs made for?" then the answer is "the people that care to go looking for them." The difference between a Tesla easter egg (which are almost entirely regarded as delightful) and this easter egg is that this easter egg was poorly executed.
A Tesla easter egg is silly and whimsical. This easter egg parodied something that's potentially threatening. And hell, Firefox has had easter eggs since its first release; go visit `about:mozilla` in your address bar. Saying easter eggs are bad outright is silly, but they should be done in a way that isn't concerning to users.
I don't own a Tesla but I assume a key difference is that the easter eggs exist solely to delight the user whereas this was more of a partnership designed to make Mozilla money.
Hah, good one.
Thanks for that warning. I was considering buying one, but now I'm certain that I won't.
In the part you quoted they were just pointing out that an optional extension is the correct place to implement this sort of thing. I am sure that if they had just posted this as a separate extension from day one then the target audience of Mr Robot fans would have had fun with the ARG and everyone else would be totally unnafected.
That aren't Callahad's words. Here I quote him exactly:
"Looking Glass is a really cool idea for users who want it. But pushing it out broadly, even in an inert state, was not good."
Note, not even "bad." Just "not good." And far from "terrible, terrible."
EDIT:
> The core idea (deploy an easter egg via an add-on) seems pretty reasonable.
no, no it doesn't. especially not when done silently, without confirmation and modifies headers and content on pages i visit.
in what alternate universe is this "reasonable"?
"reasonable" would be to push it to a tile on the new tab page.
EDIT 2: Mr Robot is the exact type of sensationalized shit i want to keep out of my tools.
As to your edit, I absolutely agree. That's what I meant when I said pushing the add-on was not good. I was only suggesting that an add-on is a reasonable place to implement an easter egg, since it's separate from the core browser code. Distributing that add-on is a different matter, and I personally disagree with what happened there.
It was not a common add-on but an ad disguised as a "study." The question is still: why?
Why did that marketing team need that treatment instead of giving to the interested users a link to the normal add on? What was the actually planned scenario? Was it planned that that "study" (the studies are apparently officially "a way of making more informed product decisions based on actual user needs") uses some functionality not available to the normal add-ons? Was it that the normal add-ons wouldn't have access to the API that the "study" would use but that is forbidden to the normal add-ons since v57?
"The addon is actually deployed as an embedded WebExtension, which is subtly different. It has a 40-line legacy XUL/XPCOM bootstrapper controlling whether the WebExtension part of it runs. The legacy code actually could upload your hard drive and isn't bound by any of the WebExtension restrictions. We know it doesn't do anything harmful, but it could have done so.
The WebExtension itself also has <all_urls> and webRequest permissions, granting it the ability to sniff the content and headers of every page."
(Source: https://www.reddit.com/r/talesfromtechsupport/comments/7k7wu... )
The question is still: what was the goal?
That's not okay.
Pretty much every site on the internet does that.
Why are we spending 500 replies and all this developer time on an issue that if done by, say google on their home page, would be considered at best a fun little doodle at worst business as usual?
To add insult to injury I don't see an apology or anything similar from Mozilla (or callahad here on hn) that would show me they understand the extent of this issue - how badly they f* up on how many occasions.
It's ironic, right when browser can finally stand next to Chrome in terms of performance...
If this code had been in core-Firefox, we'd never have noticed it. Counter-intuitively, maybe it wouldn't have felt as invasive, because I know that Mozilla controls core-Firefox, not me. (And I choose to defer to their judgement, because my other options are to defer to Google or Apple.)
The code is available. I'm pretty sure the tor project would have noticed it.
I do not expect advertisements from my web browser - and I don't think that's an unreasonable line to draw.
There is some degree of deceit present here which bothers me. They pushed out this advertisement through user studies, a feature that ostensibly exists and is designed to improve Firefox. I take issue with it instead serving as a backdoor silently install an advertisement.
If I personally saw this in my add-on page without any knowledge of what it was, I would be alarmed. My first thought would be that my computer had been somehow compromised.
I'm also slightly sympathetic to the idea that these user studies / telemetry can be used to improve FF. By abusing the feature, they encourage people to disable it, which harms Firefox if you take the position that the data gained by telemetry is useful. I certainly no longer have it turned on.
I've seen people link to anecdotes about the user study feature being reenabled after an update was downloaded. All I'll say here is that this is not cool if true.
And really, at the end of the day, why should I put up with any form of advertisements in my actual browser software? Good alternatives exist that don't have advertisements. Advertisements embedded in the product is a huge part of the reason why I switched away from Windows 10 to Linux.
To me, it's a worrying trend between this, Cliqz, the initial integration of pocket, and the the advertisements on the default new tab page.
I'm not particularly sympathetic to the idea that Mozilla needs to pull these kind of anti-user stunts in order to function. We're talking about a foundation that saw revenue of 421 million US Dollars in 2015 and 520 million in 2016.[0]
[0] - https://www.ghacks.net/2017/12/02/mozillas-revenue-increased...
Count me in here... I was opposed to this feature and commented about making it Opt-in when it was introduced, however I did leave it enabled on a few of my systems believing it would only be used to improve the technology of the browser.
It is now (or will be soon) disabled on every system I manage...
Good Job Mozilla...
... your computer was compromised.
I think we should all expect a full accounting from Mozilla on their actions and what data and information was acquired by them or a 3rd party as a result of the 'study' as well as what steps they will take to prevent this from happening again (now that they have a proof of concept (MVP?) surely another 3rd party can plant their own easter eggs in the future.
No, it doesn't do that until you explicitly activate it.
The "pretty reasonable" core idea is just having that flag available in about:config or on the addons website or similar.
- - -
for other reasons I wanna comment on the "seems pretty reasonable" bit
"In this day and age" what with fear and stuff being a main chunk of news , perhaps using a webext (which can really only modify a page to do any tricky cool stuff) is a bad thing?
(especially when it plays off of the pre-existing FUD by referencing hacking n' stuff!, but not my point)
same for any unexpected icons appearing in the toolbars! People are being told to be weary when using their browsers: look out for signs the pages might be fake or messed with, look out for unexplained installation of programs and addons, being hammered in from every secure site!
Its worrying that, I know it would fuck with my parents pretty bad WHEN it would be enabled, because there isn't much point in developing something for it to not be enabled! Especially when money is probably on the table, when higher ups probably rammed this through normal steps designed to prevent this sort of stuff (again)
I need something to give my parents, something that is ethical, something that cares about them, and something that works: chrome still works better for them, and mozilla seems really really keen on blurring the lines for the other ones (I know I know, it requires users to opt into shield studies etc, but man, I had a talk with my ma, "do you wanna contribute back to mozilla in this way?", please don't punish us for asking other less-techy people that.)
If you guys need easter eggs, probably keep them off to the side, in the settings or about sections
Freudian typo.
Erm no. I don't use a browser to have fun. I certainly don't want any surprises, and coming from Firefox/Mozilla this is very, very disappointing. How can we trust you guys to do the right thing from now on?
> How can we trust you guys to do the right thing from now on?
The same way you can continue to trust the GNU/Linux system which contains easter eggs.
Easter-eggs, to me, means something like "press a key combination, get a list of developers" or "go through the levels in a fast time, unlock a secret level" or "on march 14th there's a message about Pi day". It doesn't mean "if you change xyz settings, we'll sell some control to your system to a third party for our profit".
By which you mean, not at all, I assume.
This is not an easter Egg, I wish people would stop calling it that.
This is a Paid Advertisement, injected with out my permission into my software. AKA Malware or Adware.
Companies pay thousands of dollars a year to prevent that type of software from being loaded on their system.
Firefox DOES NOT have a long history of being a distributor or malware or adware...
Easter Eggs are funny things that Dev put into code that make people chuckle but have no impact on the actual software
To call this a "Easter egg" is naive and ignorant. This is a Paid Promotional Advertisement of a Large Commercial project not an Easter egg
(the upsidedownternet is over 10 years old at this point - http://www.ex-parrot.com/pete/upside-down-ternet.html is from at least 2006 - awkward out of touch big company advertising isn't fun)
He explains that including that addon for everyone by default is NOT OK. What he means by the first sentence is that using addon for easters eggs is OK (but users need to install it themselfs).
Whenever a story like this happens, I'm left wondering who came up with those ideas and who okayed them. From my perspective, anyone who thinks those things (as they were implemented) were justified is not suited to make decisions in a project like Firefox, period.
Another comment in this thread asked what will be done to make sure something like this doesn't ever happen again. I am aware that probably, nobody here can answer that question. But in essence, this is the thing Mozilla should be considering and communicating clearly in the near future.
I don't see how "push" is even useful here. It's ARG content; teasing players into actively seeking out content is the bread and butter of ARGs. While it's certainly part of the premise that they exist as a sort of overlay on top of reality, well-run ones usually have a clear concept of which media are "in-game" to discourage people getting off into the weeds of fan-made content and unintended red herrings. The game is typically not meant to leak into unrelated media (such as the add-ons tab of Firefox on my company-issued laptop). Good examples of wider distribution for the initial round of hints to advertise the existence of an ARG include the "corruption" in a Halo 2 trailer (I Love Bees) and the heat-sensitive ink on the Nine Inch Nails Year Zero CD.
> I can assure you that there's an active internal discussion to that effect. I'm hopeful that we'll learn from this.
Here's one thing that somebody at Mozilla ought to learn (though I worry that the people who most need to learn this are going to be above the fray of the internal discussion): This was absolutely not a mere PR misstep, as the current non-apologies from official channels suggest. The primary problem now isn't that users misunderstood what Looking Glass is, it's that Mozilla management misunderstands what Looking Glass represents. If the Mozilla brand stands for anything at all, it stands for the mission of building the future of the web on behalf of the full spectrum of end users and developers instead of parochial and shortsighted corporate interests. The fact that Looking Glass was deployed in this way, with any internal alarm over it clearly either absent or overruled until after the fact, sends the opposite message. That message was further reinforced by the "clarifications" issued in response to the backlash.
Right now, I feel like any apology is likely to ring hollow. All indications so far are that upper management badly wants this sort of thing and that there will just be another flavor of it next year, as though it's just a matter of tweaking the recipe until they find a version of the pill that people will swallow.
I really love the work you guys do, but I feel like it's being undermined by exactly the sort of thing Mozilla is supposed to be the antidote to. I imagine many Mozillans feel the same way. So what the heck is going on?
It's fine if you believe this, but it means I'm not using your browser. I switched to Safari today.
Also, as others pointed out, this sentence you quote (probably) isn't as bad as your interpretation (I think I interpreted as you did, too, on first read). If you want an easter egg in your browser, and you install an add-on to get it, what's bad about that? The interpretation that "add-on" means "installed by default by Mozilla" seems off compared to what was said elsewhere here (though as it happens, this add-on was installed by default, hence the interpretation that this was okay... but read on, and clearly callahad is saying that it wasn't okay to install by default).
I think the statement is poorly worded, but with the larger context, I'll give Mozilla a chance here... or else I'll use a browser that I think is more privacy conscious and that is more likely to listen to its users, not a browser that I think is less privacy conscious and less likely to listen to its users.
There were very disappointing answers by mozilla employees on r/firefox.
Consider for a moment what you think the lesson is.
Now that you have it...
(have it? great)
... is it different from the lesson when Pocket was made part of the browser?
What % of your users did you think you would frighten -- I guess it was acceptably low?
Yes, deploying an easter egg via an add-on is pretty reasonable, hell if it's out of the way enough even in the core browser. But Mozilla didn't deploy an easter egg: they deployed an advertisement.
I am stunned. I need to think about it for a few days, but this, to me is enough of a reason to stop using FF. Force feeding users this way is not even Chrome-style; it is early Internet Explorer like behavior.
Dan is saying "Easter egg yay, auto-include in browser nay".
Let me clarify: I do not want Easter eggs in my browser. At all. If you have to insert it, doing it via an add on is better than via core capability (I guess), but either way it is a very bad idea. And I think (correct me if I am wrong) that it is not "auto include nay". It is rather "Easter egg yay, auto-include yay, auto-activate nay".
At best an Easter egg is some useless junk and at worst it is a possible backdoor which can be activated by mistake on the developer side (as happened) or by a user fat fingering some input.
Sadly, I do not trust Mozilla anymore. It is just another evil empire competing to capture any user information it can. Any time there is another non-removable "feature" added I could bet 10:1 that the goal is to try putting yet another hook into the user and "good news: we are enhancing user experience again" is a clumsy PR. My 2c.
So don't install the addon. Why is everyone missing Dan's point? He's saying the current method (Available on AMO, you can install it if you want it) is what it should have been from the start.
BTW, they didn't get paid for this.