Lots of people here additionally are up in arms their incredibly specific workflow was upheaveled by a movement to webextensions planned like 2 years in advance. Browser engines don’t have the luxury of being vim and supporting every environment and config.
So it is naive to hold a Non-Profit to their foundational mission statement and goal? Their Manfeisto?
Mozilla is not, or rather used to not be, just a For-Profit Software firm making a browser. They were a Non-Profit Foundation started to advance ideological and philosophical ideas, namely Open Web Standards and Access for all.
It seems like you are perfectly find with Losing the Mozilla Foundation, and replacing it with Mozilla Corporation the software developers that make a commercial browser.
Maybe FireFox 60 should just go closed source and charge $40 a download
And I suspect this is where we completely differ - because while Mozilla has made some mistakes, I am not nearly as enraged as some of the other commenters I've seen have been.
I think Mozilla has been doing a great job, with a few notable hiccups.
Then what the hell did I donate money to them for? I thought their whole thing was they were for "people, not profit." I don't want my technology to make money off of me in any way I'm not aware of.
If you rule out Firefox, there's hardly any viable option for a modern, feature-complete and freedom-respecting browser. Chromium is OK, but those suspicious blobs don't look very appealing.
For me the most shocking part is that the FSF has a Firefox ESR fork, IceCat, which is hardly maintained and goes 2 versions behind mainline. They don't even bother patching CVEs...
Maybe their incredibly specific workflow involves a piece of multi-million dollar equipment and updating to a new API involves reflashing its firmware for some crazy reason. (alternately, 100 $200 pieces of equipment in hard-to-reach places that must be manually reflashed.)
2 years may be roughly the maximum attention span of a software project, but 5 years seems like a better number for bedrock systems like web browser.
I don't mean to trivialize what goes into Firefox, just that backwards compatibility is a big deal and most software companies don't take it seriously enough.
Really, the point of WebExtensions is to establish a well-defined, maintainable API set that can be kept backwards-compatible going forward. Swaths of legacy extensions were already breaking with every release as internal APIs changed. The old system made the e10s (multiprocess) roll-out inordinately more painful and slower than it would have been with WebExtensions, for example.
They're up in arms because of an upheaval which prevents anyone from restoring their workflow: the new extensions API simply does not allow the extensibility the new extensions API allowed. Some of the changes are arbitrary (e.g. it's not possible to rebind C-n).
The move to Quantum is awesome, but the permanent loss of functionality is not.
Likewise, the security reversion in the Sync protocol is another unforced error.
The change to the Sync security model happened in response to years of user feedback about the usability of the system as it was.
They should have improved default usability while still preserving their previously-unmatched security level. Yes, the old system didn't do what novices expected, and yes they should have gotten a default system which would. But experts should still be able to use a truly-secure system.
It's currently impossible to use the Sync system securely: even if one ran one's own Accounts server remotely, then an attacker would still be able to inject malicious JavaScript into the signin page. Accounts should never have been usable from within a web page; they should always have been isolated to the browser chrome.
This is yet again a too-simplistic view of things that seems very common with Americans.
Some big companies do unethical things, and you translate that to "all big companies hate consumers and want to eat their children"
Safari is pretty good at privacy protection. Apple doesn't really have an interest in collecting your data and they have a history of implementing features improving privacy (cross-site tracking protection, build-in adblock API, etc.).
The problem is that Safari is only available to the wealthiest in the world.
“”” WebKit is a cross-platform web browser engine. On iOS and macOS, it powers Safari, Mail, iBooks, and many other applications. “””
Midori is also based on WebKit: http://midori-browser.org
AFAIK Safari does not provide more privacy protections than WebKit.
“””In the recent history of management ideas, few have had a more profound — or pernicious — effect than the one that says corporations should be run in a manner that “maximizes shareholder value.””””
https://www.washingtonpost.com/news/wonk/wp/2013/09/09/how-t...
http://mashable.com/2014/02/28/apple-ceo-tim-cook-climate-ch...
At this point Mozilla has to prove to us that they are worthy of our usage
So I think the project is relatively healthy, and in any case, still miles and miles ahead in terms of worthiness than every other major browser out there.
When people say the Mr. Robot thing was a violation of privacy, I believe this is ultimately where they are coming from.
Pocket and Looking Glass should have been regular add-ons available for people who want them (I’m an avid Pocket user and have had a paid sub with them in the past). Even with the Yahoo search deal, it would have been nice to have the first start go through a wizard that lets you choose Yahoo (as a default option), Google, Bing, or whatever else...though I guess they likely wouldn’t have been able to score as much funding from that arrangement (but that’s just an assumption).
I’m very happy that Mozilla exists and have some friends who have worked there, but I can’t say that 100% of their decisions value users and privacy above all else.
A third party company (funded by venture capital) created something called "Pocket", which allowed you to save any article you were reading to their service. Pocket had an extension that you could choose to download & enable on your Firefox browser.
For apparently no reason at all, in June 2015, Mozilla integrated the proprietary Pocket into their open source browser, not just as an optional extension but as part of the default installation. The only way to disable Pocket was to go into "about:config", as the option was not available in the "Extensions" toolbar. (Later, Mozilla Corporation purchased the company Pocket, though at the time Pocket was introduced as an inextricable part of Firefox, Pocket was a separate company.)
The Mr. Robot addon had some similarities with the Pocket fiasco:
1. it was pushed to users without their knowledge or consent
2. it was integration of a plugin for a private company into an open-source project
3. it was a decision by marketing, and not development
I am not quite sure how or when we can begin to trust Mozilla Firefox, and what they would need to do to regain that trust.
This isn't exactly correct. The Pocket integration did absolutely nothing at all until and unless you tried to use it. So by "disabling" it from about:config all you did was to remove the icon.
Buying Pocket signalled that if you can take the right Mozillan to lunch, you can get an early exit. That did not solve the problem.
It's still impossible to remove Pocket.
they solved the privacy concern in a very awkward manner (via acquisition) but not the user choice concern. it is impossible to believe that pocket is so integrated into the codebase that it cannot live as a removable addon. it was an addonafter all. fwiw, firefox sync should also be a removable addon.
i am fine with mozilla installing these as removable addons at major version upgrades. i am not fine with silently side-loading and permanent non-removable integration. i need my tools to be secure, reliable and predictable.
And it's on about:blank just like when Chrome started capping up the blank page. I had to install a script to load an actual blank HTML page because about:blank isn't blank.
It's very chatty, annoyingly. Captive portal check on all requests that has to be disabled in about:config and a laundry list more. That config is scarily full of remote and telemetry based URLs also, but at least they are co figurable I guess.
An open source browser that just does what you want and no more seems like a dying hope.
Regarding the I robot thing, I must be living under a rock, had not heard of it before today. Storm in a glass of water.
Mozilla acquired Pocket in February: https://blog.mozilla.org/blog/2017/02/27/mozilla-acquires-po...
All you had to do was remove it from the toolbar. Pocket is/was lazily loaded, it doesn't do anything if you're not using it.
Are all these people sticking with Chrome because Mozilla is not holding up to its values really think Google is better at taking care of our freedom?!
> Not only are these experiments enabled by default, but updates have been known to re-enable it if you turn it off.
Chrome has some troubling defaults but Google never decided to flip the default search engine or turn on any phone-home feature once it has been turned off. Even though they had/have the power to do so, they know people won't trust Chrome if they ever tried to do that. In my book that's more trustworthy than a vendor that decides to use updates to surreptitiously enable features that users disabled.
And for some dissidents or researchers those defaults could be life or career ending.
I also had the Shield stuff turned off (my choice), and it hasn't been reverted, nor did the Mr. Robot extension ever show up. I agree, though, that that was a Bad Idea.
I would also argue that "just being better than X" was shown not to be effective in the last US Presidential election.
They're missteps, not trust breakers. Quantum was a massive step in the right direction. The Mr. Robot Easter Egg was non-malicious poor execution. I don't think it's a free pass to just contextualize how small their missteps have been in the grand scheme of things.
The reason the response seems outsized is because of the breach of trust involved, much more so than the technical impacts.
Quantum is great, and I just like a lot of the UX decisions Firefox makes. But a major reason for my support of Mozilla is their stated mission. And regularly making bumbling moves that overtly compromise that stated mission makes you start to question their commitment to it. Is it really their mission, or is it just a thing it is good for them to keep saying? POSIWID and all that.
Mozilla became a shady character. It engages in "it depends on a meaning of the word 'is'" speak.
Here's how Mozilla can get back into my graces - it needs to publicly FIRE whoever approved it and whoever advocated for this project.
You do? Okay, I don't. Please, show me exactly how Google uses data they collect from their users. Every usage. Not just a few. And no "but they say they can use it for whatever they want!" - then we can talk about transparency.
Mozilla is pretending to be a health store. But we are starting to see that they are also peddling drugs. Not Google drugs - drugs with security and drugs with delivery system and drugs that we are pretty sure how they work - but some other drugs, from shady producers using shady means.
Mr. Robot.
Google tells me - "Dude, for providing me your information you get gooodieeeees!"
Mozilla tells me - "We respect your privacy. "
In a micro-font : "except when we do things that you should not be concerned about"
and what other uses?
The really annoying ads which auto-play videos, block content, etc., tend to be served by companies who aren't taking the long view --- which is why Chrome is going to be adding adblocking for those ads that are ultra-annyoing early next year.
There's a pretty big difference between "using your information for marketing", and "marketing your information to advertisers". The second implies that your private information is getting divulged for a price, and that's simply not true.
If I narrowly target an ad and then I know you saw it, I now know all those things about you.
So, yes, they do not literally sell your information, there is one level of indirection there. And the amount of information that data brokers get their hands on tells me that it is very likely people are exporting this information regularly.
If you don't like Google, you can always use Chromium or Brave. I trust them not to run marketing campaigns inside my browser.
Do you also trust them not to listen to your mic? I think debian had to have a discussion with them about that.
Having a Mozilla option is good, but when Mozilla screws up it needs to get a clear indication that it did. I think folks saying "down with Mozilla" do not really mean this 100%; but they do want Mozilla to know that it seriously screwed up in their view. And we should not treat it as a shrinking violet -- it is not a tiny startup; it is a large corporation with funding in hundreds of millions.
> It only needs to be better than Google.
This, IMO, is setting the bar way too low. It should aim to do what the users want and consumer technology easily allows. If there is a big gap between those we should encourage new entrants, not entrench Mozilla as "the" alternative to pick-your-evil. My 2c.
Its ironic seeing a company making questionable decisions being reported by someone getting paid for questionable reporting.
Mozilla has a very unique problem. It's most ardent and loyal users are technically savvy. They expect a high quality, privacy-respecting, ad-free product.
But, here's the catch, they will not pay for it. How does Mozilla survive?
Google finances Chrome through its Search/Ad business. Safari and IE costs are bundled in the cost of the devices/OS they are on.
How should Mozilla survive? Should they go the shareware route and have a paid copy for 20$ ?
They have to make money somehow.
Software freedom (the freedom to run, inspect, share, and modify published computer software) means we don't need to trust Mozilla's free software because we have permission to inspect the code to see what the software does, change the code if we don't like what the software does, distribute the improved software (or a verbatim copy at our choice) even commercially, and run the software anytime we wish for any reason. These principles place us in control of our computers to the extent we're willing and able to put in the work. We can even hire other people to do this work if we don't do the work ourselves.
Lunduke complained about incorporation and non-profit status but never articulated an argument explaining how these things are a problem. Around 7m53s he said this "doesn't make them [Mozilla] untrustworthy" leaving me wondering why this was brought up in the first place. He consistently mispronounced the word "Mozilla" as "Motzilla" (there's no "t" in their name), and directly contradicted his own thesis (around 6m30s) in neighboring sentences: "This is not an opinion on my part. I guess that my opinion is that they're not trustworthy based on these facts...". He did that again in his own ignorance of the terms "foundation" and "corporation" around 7m where he seemed to have a problem with the difference between what he read into the terms he didn't define versus what he described to be the case (thus vaguely complaining that Mozilla made money and published free software for hire). I think it comes down to not having a good argument to raise in the first place but feeling a need to say something about a situation he found irksome. But I think his disorganized view built on a non-issue is typical of the published reaction to this situation.
This entire kerfuffle comes off to me as manufacturing a controversy out of very little. The main beneficiaries of this indignance are the software proprietors -- organizations that make nonfree browsers you can't trust because you never really know what they're doing when those programs run.
It's telling that vanishingly little of the commentary on this situation brings people to understand what software freedom is or how its practical consequences read directly on this situation by explaining how the other programs to do the same job (mostly nonfree user-subjugating programs) are not alternatives at all because they don't respect a user's software freedom. It's not clear how this issue with Looking Glass (the Firefox add-on in question) rises to something more serious than a bungled PR effort and poor communication from Mozilla. Source code analysis shows that Looking Glass did nothing unless activated and that add-on was off by default; hardly something to get so worked up over and largely a purposefully-missed opportunity to teach people about software freedom.
There's no reason to limit this examination to web browsers. Justifying use of any nonfree browser in light of security problems hinges on trusting the proprietor (which you should never do) precisely because those programs are nonfree. Users don't have other information on which to make an informed decision and the information they have is inadequate to make an informed decision. These browsers are also published by known NSA partners. There's no good reason to defend switching to any nonfree program to do any job, particularly if you're going to have a discussion centered on privacy and security.
I see the lacking discussion on this topic as a consequence of pushing for "open source" instead of insisting on software freedom. Open source development methodology was founded to separate the ethics-based principles on which the free software movement is based (the free software movement is a social movement) from the practical outcome of software freedom -- lots of useful software -- while talking chiefly to businesses about the gratis programming labor those businesses can use. This approach purposefully skips past an ethical understanding of how to treat people with regard to computers. This approach requires talking at length about this situation without drawing users' attention to what software freedom is or how it matters. But there's no substance in that approach so proponents raise ill-formed non-issues (with a heavy dose of entitlement ("Mozilla has to prove to us that they are worthy of our usage") to make it seem like Mozilla has become a persistent problem instead of seeing a long-time free software publisher make a relatively minor communication mistake that posed no threat to Firefox users. Quite the contrary is the case: we can and should continue to run and build new programs on Mozilla's free software just as we do with any other free software. Thanking them for their work and not taking an entitled attitude is also right and proper.
When quantum came out I switched to dev edition to try it out, but I've had nothing but trouble. Page loads of local unbuilt code are 2-3x slower than chrome. Tabs crash with alarming regularity, especially after the most recent update. There is still no way to inspect websocket frames. Form inputs are black text on dark background with the dark theme of developer edition.
At least I can get CSS source maps working, which seems to be impossible in chrome these days. But really that's the only plus for a lot of negatives. I'd love to be using firefox instead of chrome, but after this most recent update I get several tab crashes a day and I've finally given up as it's become a hindrance to productivity. I wish it weren't so.
Something similar that noone has complained about are the Android version names which are promotional tie-ins: Kit Kat and Oreo. Mozilla's biggest screw up IMO was failing to disclose properly what was going on.
From what I recall, it wasn't paid-for either.
> we developed an unpaid collaboration to engage our users and viewers of the show in a new way
Source: https://blog.mozilla.org/firefox/update-looking-glass-add/
Hackers gonna hack. In the “let’s build cool stuff because we can” way.
It was absolutely the wrong thing to do, but it's not like they stood nothing to gain from it.
That was not the only issue
1. Failure to Disclose it before distribution
2. Failure to Properly name or provide any support context to the Add In.
3. Using the "Studies" System designed to improve the technology and advance the web browser for this Adware "Easter egg" not really an Easter egg addin
4. Failure to Publicly Comment about it until a full 72 hours after concerns were raised
5. Deleting and Hiding Bug Reports about the Addin in Bugzilla
6. Failure to adequately respond, apologize, or explain why and how the Studies system was used to distribute this Adware, There blog post so far is woefully inadequate.
7. Failure to disclose what steps are being taken immediately to ensure the Studies system is not abused in this manner in the future
Should I go on? There were many many many failures here, which are compounded by the many other failures Mozilla has had over the last few years.
Debian had to raise a storm over it and turned into a compile-time only option to not get the microphone listening plugin on your chromium install.
I support Mozilla on Ideological grounds and it is said they are dropping their Ideology in favor of a pure commercial company.
But every one of these things seems like legit issues that I'd like to see made an anomaly, and it's conceivable that if Mozilla isn't able to make it crystal clear that they know how to make things go that way, Chrome might well be the right choice.
Mischievous easter eggs don't really belong in commercial software anymore (with very careful exception) but the allure still exists. I can't fault the dev team too harshly for this lapse of judgement, especially since it sounds from their blog post that they've taken the backlash to heart.
It was just weird and it freaked me out until I heard everyone else was losing their mind over it. I just really don't get what they were thinking.