Retrospective: Looking Glass
blog.mozilla.org
blog.mozilla.org
But as I said, Mozilla were very up-front with the plans. They weren't with Looking Glass.
Setting the extensions.pocket.enabled variable to false will disable the addon. That's all there is to it.
I'd love to know who, the people, is making these decisions?
I switched to Vivaldi, which is a Chromium with high levels of customization, including a vertical tab bar.
What.
I'd really love to know how you came to this conclusion.
You have no idea what you are talking about. Quantum is a name for a variety of technologies in Firefox, all of which have a shared goal of speeding the browser up. None of them have anything to do with telemetry.
Also, Looking Glass collected no data. It says it right there in the article.
You already mentioned the Pocket fiasco. I could've sworn they also once bundled a non-Free plugin for enhanced disabled access. They dragged their feet for years fixing a serious privacy issue regarding IndexedDB https://superuser.com/a/1250955/867963
Less scandalously, they use a non-standard licence for no clear reason.
The technical progress in Firefox has been great, but the history of mismanagement is awful. But I'm still using Firefox, for what that's worth.
What are you talking about? Who defines "standard" for licenses?
It's listed in the OpenSource.org list of approved OS licenses: https://opensource.org/licenses
Your link is about writing your own open source license, not about which licenses are standard. Nowhere in that blog is any mention of Mozilla. I am not sure what you are trying to say by linking to it.
Wikipedia tells me it's a copyleft licence, but one that's 'weaker' than the GPL.
It seems A/B testing provides clear numbers on what's most popular, but you can't quantify what's right.
I'm a firm believer that you should never ask your user to make a decision or look over their shoulder. Not once ever. You should listen to their complaints and ideas when they come to you, then build your strategy on that. Be reactive, not prescriptive. That empowers the user, shows respect and results in a satisfactory product that benefits the user which after all is the end game.
Telemetry invades the user's privacy. Feedback does not empower the user because the user expects a reaction from it which is unlikely. A/B testing results in churn for the user which does not show respect, merely that they are a test subject.
Microsoft as a fine example could learn a lot from listening to their users rather than steamroll ahead based on collected telemetry and feedback data.
A fine example: People didn't want UWP/metro and still don't today. I have yet to meet one person who uses that side of windows 10. They wanted shit that worked, was faster and kept out of their way and didn't wreck the workflow that they had invested years in learning or had someone experienced close at hand to help them with it. 90% of the userbase just installs chrome and does everything in there as well so that stuff just gets in the way.
I was going to say, "I do!", but then I realized that no, actually, I don't. I mean, I have a Win10 tablet PC which I often use in tablet mode, and I appreciate the Windows 10 UX. But what I most appreciate about that UX is... how well it works with regular Windows applications!
Because it turns out UWP/metro is just too dumb an interface. It's Android/iOS-level dumb (just with less apps). I'm split about Microsoft right now. On the one hand, I just don't understand why they're on the "dumb down everything" bandwagon. On the other hand, as long as they still support normal Windows interface and applications, I want to support them and wish them best, because Windows 10 is literally, honest-to-God, the best system for tablets that currently exists. Period. I don't want to have to move back to Android.
Even when I use my Surface, I rarely end up using the UWP apps because, as said, they're dumb. Even the Microsoft ones feel half-baked and lacking. I think Microsoft should have dumped more money into Research and tried to find a novel method for automatically handling different UI sizes without dumbing down the UI.
I like the idea of the Store, too, but I think instead of forcing all apps to this new interface, they could have created a new package format, like Mac's _.app_ directories, to allow one-click install distributions of classic Windows applications.
I’ve recently been feeling the same but couldn’t articulate it as well as you have.
This is one thing that the biggest open source projects seem to get wrong more often than right (trying to be all things to all people, all of the time). Management by consensus usually yields mediocre results in the commercial space, too. The BDFL model is a great compromise. Everyone gets a say, but not the final say, and there’s a consistent vision driving the project.
When projects get very popular, it’s hard to say “no” and keep that vision focussed. This seems to come more naturally to proprietary projects, at times resulting in a better overall experience for the narrower subset of users served.
Plugin based architectures tend to work well under such governance, as then the contributors are more insulated from each other and interfere less frequently.
No single governance mechanism is so much better that the others need to go away. Not every project should have community governance, not every project should have a BDFL. Not every project should even take outside contributions -- personal projects (especially licensed under CC0) can offer great value to the wider world without having to placate opinionated contributors.
But it's a pretty blurry line, isn't it? You give permission to install Firefox, and it's somewhat arbitrary is a specific code is "part of Firefox" or "part of an extension" when that extension is shipped with Firefox by default.
(In this case, the specific code wasn't even executed unless the user flipped a switch in about:config. The problematic part was something being listed among your extensions that you couldn't make sense of as a user.)
Release Notes of a new version is a good place to place that bundle. People concerned with security do set aside time for such task.
Any competent manager should be able to tell the difference between "functionality directly related to what users expect of a browser" and "code that we have installed on their machines without their knowledge, primarily motivated by our interests rather than theirs".
This is not about the specific implementation of such decisions, such as whether including it as "part of" or "extension to". That's a pointless distinction - also something any competent manager in the tech sector should be aware of.
It did not do anything, unless you manually switched on an about:config value. And if you did, then all it did, was flip some random words on webpages upside down.
No, I don't like it either to have eastereggs in my software that wasn't just put there for the fun of it, and rather was also motivated to some degree by a continued commercial relationship. But if this commercially motivated easter egg helps to gather more money to improve the software, which itself is non-commercial, and is as harmless as Looking Glass, then I do not see a problem with that.
And let me repeat that, if it is as harmless as Looking Glass. I do not see a reason to categorically exclude any sort of commercially motivated thing from the browser. Even including some actual ads would in my opinion not be unthinkable, given that they get enough money for it and have effective ways to do good with that money, while especially also taking into account that users will get pissed off by it and leave the browser, effectively slimming the ability of Mozilla to do good.
If you take everything into account, you can be morally on the good side without having to resort to never doing things from certain categories.
Easter eggs started at a time when software and games were shipped on cartridges, disks, or other media. If there was extra room available, it didn't affect the user experience to include them (performance was always very much in mind back then).
Today, however, we see a couple of changes:
First, apps and games are mostly downloaded. Easter eggs take up additional space, slowing down your download in the best case, and eating away at data caps in the worst cases. So you're already doing something that is somewhat hostile to the user.
Second, both Mozilla and Google position their browsers as fast and lightweight. Does including Easter eggs actually help further either of those claims? Most likely not. One Easter egg might not really impact performance at all, but at what point does it become a problem? There are probably different teams working on the browser, and if each of them are adding Easter eggs, how long before those start to affect performance, whether because it's cruft or because many users are on older systems that don't have as much memory as the typical developer is used to?
This at least bears consideration.
- What does it do?
- Is it needed for core functionality or optional?
- How do you switch it off/on?
- Does it transmit any data, and if so, which one and how do I control the data flow?
- Who are the developers and is the code open source or is it proprietary?
- What are the default settings and why?
If it's optional, then it's an extension. If it's on by default, I better get a very good reason for it (e.g. that it ostensibly enhances security). All of the above questions need to be answered before I install it, i.e., the information needs to be freely available and easy to find on web pages, release notes, Readme, etc. If something is added in an update or upgrade, I need to be informed and given a choice about it.
There's a fine line between "Easter Egg" and "within of 3 months we've installed without user approval CliqZ's tracking, added Google Analytics to the about:addons Discovery menu, and added some easter eggs". This is how you lose all trust.
This particular one didn't get complains because of a combination of reasons like:
- It is completely off-line (hell, it's only available on the "you're off-line" screen, where there isn't much else you can do with a browser).
- It's off by default (you need to be on a proper screen).
- It's a small and self-contained game. Doesn't impact anything else beyond a small area on the tab, which makes it just a step up from an animated GIF.
- It's just a joke, it isn't tied to any commercial franchise or brand, nor does it promote any ideology or organization.
- People expect less user-fairness from Google than from Mozilla.
Ultimately, the line is fuzzy, but Chrome's dinosaur is clearly more like an Easter egg, and Mozilla's Looking Glass is clearly more like a very specific extension/feature.
This is an interesting point - I guess the blowback would also have been far less intense had it been a reference to e.g. Big Buck Bunny rather than Mr. Robot.
@MoCo, you might think the (marketing) key for the (economic viability in the) future is privacy. I tend to agree. Currently, privacy has to be enforced because people are not in control. For everyone to be able to choose a satisfying level of privacy, we need tools we can control and education (poke @MoFo).
IMHO, what we (power?) users (influencers?) need is control. Hence the problem with the recent lack of support of legacy addons. While we can understand it from a security/privacy/technical point of view, it nevertheless goes in the wrong direction WRT control (shaping your tool for a specific usage).
That's a shame that you, we, can't imagine something better and make it available.
I agree. It's all about control. Which is why I rant so often about modern UI/UX/software design trends - they're all about disenfranchising users! The amount of control the users have over their software is being actively reduced everywhere.
No one, especially Mozilla, should never ever decide for us what we need.
You don't see the problem here, no, you plan on doing this again. With the only change being that you will try to answer a specific question.
You could not have mitigated the uproar by "trying to answer a specific question" and "appropriately naming the 'study'". The biggest issue is that you are unable to realize that.
[0] https://blog.mozilla.org/firefox/update-looking-glass-add/[1] https://blog.mozilla.org/blog/2017/02/27/mozilla-acquires-po...
Pocket, Hello/Telefonica, Pocket again (or was it Hello, my recollection is hazy, they forced the icons back for users who's removed them), Mr Robot, ...
I apologise if it causes some harm that I have imperfect recollection.
Not what I was arguing. The purpose of my post was helping out recollecting the mistakes Mozilla made. I don't remember the Hello issue. You're also forgetting the Cliqz debacle. Sure, it was German-specific, but still.
I don't think it is fine, and it is good Mozilla is being criticised. However, the alternatives are arguably much worse.
>An ‘experiment’ that does not capture any data is not an experiment at all.
>In retrospect, not capturing data was a strong indicator that this was not a good SHIELD study candidate, so we’re making sure we’re going to specifically evaluate future studies
So a commercial add on that _does_ collect data is ok?
That’s not how I read it. What they’re saying here is “the fact that it didn’t try to answer a question is a red flag unto itself”. If it had tried to answer a question, it would’ve collected data, and the usual privacy process would’ve kicked in hard: is this an appropriate question to ask, are the changes narrowly tailored to ask that question, are we handling the data appropriately? On those counts, a version of Looking Glass that collects data would never have rolled out. Instead, by not collecting data, they found themselves answering an overly narrow question: does this impact user privacy? No, it does not!
Naming really was adding more fuel to the fire though. It’s a fine line between a surprise/Easter egg and being outright deceitful, and the cock up with the SHIELD test burnt through all the goodwill they might have here.
What makes them out of touch is that these were apparently the only criteria that needed to be met. As opposed to, say, "how would people feel if we took our software, which occupies a space in their workflow that demands a lot of trust, and auto-updated it with a marketing campaign for a TV show?"
I mean, if they wanted to answer the question "how many of our users like Big Bird?", and they crafted a pop-up survey to be delivered through this mechanism that did not impact user privacy, would that get the green light?
It's not just about respecting user privacy and safeguarding data, it's about adhering to expectations. The fact that there was apparently not a single human in the loop with the power to stop this from rolling out that recognized this is concerning, and the fact that there's no mention of it in this blog post is doubly so. What people want to hear is not just "we will safeguard your data", it's "we will never waste your time or introduce any kind of risk by pushing things like marketing campaigns into your trusted software."
My point is precisely that, in going the SHIELD route, they selected for people who would ask that narrow question, because that's what they're usually concerned with, rather than the bigger questions they should've been asking.
Come up with an idea of "browser neutrality".
And what should be their source of funding?
Has the idea that Mozilla won't survive without advertising income been substantiated somewhere? (This ad was unpaid, though.)
So I agree that it was not neutral, because there was more of a barrier to other advertisers than to Mr. Roboto. The right thing would be to have hosted the addon on addons.mozilla.org, same as for anyone else.
But it's not a dramatically uneven playing field, given that an open conduit does exist and the reception of any actual advertising was opt-in. (I'm not saying it was ok; it wasn't. But it's not as black and white as you are saying.)
I'm not sure they could have done anything more short of going back in time and reversing their stupid decision.
It's important not to forgive Mozilla, and to constantly remind them of CliqZ, the tracking in Firefox Focus (also using Google Analytics) and about:addons Discovery page, and of Mr Robot.
Only then, maybe, will they learn something from this. For now, it looks like they don't give a shit.
The arguments will be over whether sufficient contrition has been shown and whether someone needs to be placed in the stocks.
It was a bad, bad mistake. I think they've learned their lesson.
So simple. So obvious. So necessary, if you value privacy.
Yet they have not acknowledged the mistake or shown any signs of willing to listen to the complaints - their entire explanation is about something else that people weren't even aware of!
Given the level of feedback and the intelligence of the recipients, this is unlikely to be a mistake or a coincidence. It is reasonable to conclude they fully intend to repeat this behaviour in future.
As is I trust they won't use SHIELD next time (and have opted back into their studies based on the policy change), but my expectation is that next time they want to ship some garbage like that they'll use some other channel and marketing have probably already identified it.
People who don't get why it is important are leading Mozilla into the grave, no matter what expertise and experience in other areas they have. Unfortunately, the world has never seen a bureaucrat who resigns on his own will.
The people responsible don't even understand the multi-layeredness of the fuck-up (because they don't understand the core problem). a) There is a silently installed unwanted code. b) There is a little known backdoor in Firefox that installed the code. (And that makes manual confirmation of regular updates a security circus that simply cheats the user.) Sure, they can say it is only used to satisfy a specific set of developers' needs, but c) It has already been abused! d) To everyone's amusement, Mozilla happens to bother itself with that baloney (“…instead of working”, many will add). e) No one at Mozilla prevented that from happening (or was able to, or was aware of it). f) That all makes the crack between Mozilla's declarations and Mozilla's reality shine bright. Now if someone at Mozilla decides to come up with the times and sell user browsing history (“non-personalized”, as they say), will I be able to find solace in another couple of PR bullshit blog posts?
If some engineers were Mr Robot fans and decided to implement the same functionality, it would have been forgotten in a couple of days. Easter egg, mildly amusing, go on. But a company that shows its absolute incompetence that way is not a pleasurable sight.
Maybe the internal document covers all of this, but this blog-post summary does not. And what is included here does not bring me great confidence.
Firstly, this summary indicates they were far too narrowly focused in their assessment, talking only about the Mr Robot promotion's compatibility with the purpose and restrictions of the SHIELD tool. And I suspect that maybe internally the story now is that some marketing staff misused the SHIELD approval process to get this plugin around other more robust processes.
But the intricacies of which particular avenue within Firefox or Mozilla this occurred through is a backwards view of the problem. Users aren't upset that the SHIELD tool was misused to push an ad on unsuspecting and confused users. They're upset that _Firefox_ was misused to push an ad on unsuspecting and confused users. The problem here is the entire idea of a "TV show tie-in" to Firefox.
And lastly, the action items here are pretty pathetic, and fail to address users' concerns (not a surprise since users' concerns are never explicitly recognized in the post, either). Yes, SHIELD studies should be actual studies; and yes, SHIELD studies should be clearly named; and yes, it's bad that the SHIELD program was used to ship a commercial. But never once does this post promise that Mozilla will take a broader view of the actual needs and desires of their users, or that they will correct their internal mindset that led to anyone thinking this tie-in was ever remotely a good idea.
But regarding 'Can you imagine getting this kind of transparency and humility from Google or Apple?' I think Apple's response to the the battery debacle (the software update was installed with good intentions, but with insufficient explanation) is similar and in response to similar reputational damage.
On Maps: https://www.apple.com/ca/letter-from-tim-cook-on-maps/
On "batterygate": https://www.apple.com/iphone-battery-and-performance/
On customer service in China: https://support.apple.com/zh-cn/warranties (In Chinese)
Might become a problem too. Who is responsible? We all are!
In this case, I continued to read, and it did improve; but those couple of errors at the start damaged it.
(Since I’m mentioning such errors, two more jumped out as I skimmed the article: the text which is linked in `[set of principles t]hat `, and the space in `wiki ,`.)
People may not like to hear these things, but I assert their veracity and importance nonetheless.
Please don't comment about the voting on comments.
The marketing people writing this stuff (I assume) really don't get it, do they?