Dear Mozilla, please stop spamming
palant.de
palant.de
If you configure Firefox to not automatically update, and then use, say, a package manager to update it, automatic updates will get re-enabled.
That isn't what the bug report says - package managers don't use the Firefox installer. Are you talking about a real bug (if so, is it logged?), or are you spreading FUD?
After a certain point, plausible deniability isn't plausible anymore.
They are doing it on purpose.
Thanks, MoFoCo.
The creators probably had good intentions, but Recommended by Pocket seems almost like a dark pattern.
(And here's a popular preconfigured user.js https://github.com/pyllyukko/user.js )
The other config settings I'm going to be less charitable about considering there would be no rational reason for an update to ever change those values.
Some of the comments here remind me of when my users think everything is deliberately implemented and if something doesn't work perfectly, it's because I'm incompetent/malicious and designed it that way when it's just a bug or oversight.
But anyway, "optout" ought to take priority IMHO.
But that doesn't explain how or when it was set.
I don’t see how signing someone up to a newsletter is a security vulnerability.
What is it with all Firefox/Mozilla hating as of late? They don't seem to be able to do anything right in the eyes of some people, and seem to be held to a ridiculously high standard (far higher than anyone else).
While I generally think there's lots of overblown criticism of Mozilla and that Mozilla is still far ahead of the others in these regards overall, it's worrysome that they get basics like this wrong.
Firefox remains configurable and privacy-enabling to a large extent, but it is becoming harder and harder, especially for non-technical folks, to realize that default Firefox settings are not necessarily user or privacy friendly. See the ruckus last year about defaulting to Cloudflare's DNS servers.
and performance, and memory use, and UI.
Something went wrong and the author (that's the ABP-creator, right?) is just making a mountain out of a molehill.
Reports like this spamming thing confirms my lack of trust was on point. :)
The least resource-intensive way to provide attack-resistance near the level provided by Google's Chrome team would probably be to notify the user when a vulnerability is disclosed so that the user can either switch to Chrome or restrict their browsing to safe sites till the binary provider can get a security update out.
I know of no one doing that or providing timely security updates however except Google, possibly Opera, possibly Brave and probably some day soon Microsoft.
It's a honest question. I understand you'd say that about Chrome, but I thought that Chromium being open source it isn't exactly in the same bag.
The also have a guide for enhancing privacy in Firefox
Do you block ads without the publisher's consent? If so, you are in a much more morally precarious situation.
I mean no offense by this but I consider myself a privacy wonk and that website is a bit too tin foil hat even for me.
I think we're in a bad way as far as choices go for browsers these days, but Firefox seems like the best of a bad situation to me. If people are still concerned, they should take a look at the changes made to Firefox for the Tor browser.
Edit: I know it's chromium-based, but still wondering!
I've also started to make use of text browsers. Links and Links2 are two that I use. Links2 is a nice halfway option as it will support images too.
I find them great for websites where I want to read info, but the interface is ironically designed to make that harder than it should be. News sites are a perfect example. Text browsers turn them from bloated billboards back into a readable format.
The hell of it is that with the way ad tech has eaten the web, I'm not sure they're wrong.
https://www.mozillapulse.org/profile/410
New Knowledge is the organization that setup a fake Russian botnet, and then tried to push a narrative about how the Republican candidate in an Alabama Senate race was being assisted by this "Russian election interference"... anybody involved with that organization is a scumbag - it has zero redeeming qualities. Renee has been making the rounds lately on Youtube, informing everyone about how much of a threat these operations are (not her organizations fabricated ops, the totally real ones). I haven't yet found the prime mover in this, but her activities are well aligned with those of the DoD ratcheting up the scaremongering about the (according to them) active Chinese operations against the US population. So there is a pretty strong push for further internet lockdown measures being made right now by these people - and Mozilla is associated. At this point I would not be at all surprised to hear Mozilla announce RealID browser integration.
At least one person from New Knowledge was involved in a small experiment designed to explore how the sorts of tactics used by the Russians worked, which attempted to convince Republicans that Mr. Moore was receiving Russian help, but it was designed to be too small to actually affect the outcome of the election (as the goal was to explore how the tactics worked, not to produce any effect). This is a little shady, but as long as it didn't actually affect the outcome I see no harm in a group of people trying to better understand how the Russian social media tactics work.
If you can't see something very wrong with this, well you'll be just fine in cold-war 2.0 - we can pick up where we left off in government experimentation on an unwitting public. MKULTRA 2 electricboogaloo. I'm sure its been a while since we updated our nuclear/biological/chemical weapons models... so long as it doesn't affect the public by a statistically significant amount - we should be fine to resume the 1970s practice of releasing airborne pathogens over major American population centers, doubling the number of deaths in the elderly.
From reading the article, the group's¹ objective wasn't to deceive voters, it was to research how these tactics worked. Are you suggesting that a single $100k research project was sufficient to alter the course of an election with a $51M advertising budget? As near as I can tell, that's just how the right-wing media is trying to spin it. Certainly if I were to actually try and alter the outcome of an election like this, I'd expect to be spending a lot more than $100k to do so.
That said, I find it hard to believe you're arguing in good faith when you're drawing parallels between a limited spread of misinformation centered around a single event with literally murdering people.
¹Which seems to have involved at least one New Knowledge member but it seems wasn't actually run by New Knowledge.
"The report does not say whether the project purchased the Russian bot Twitter accounts that suddenly began to follow Mr. Moore. But it takes credit for “radicalizing Democrats with a Russian bot scandal” and points to stories on the phenomenon in the mainstream media. “Roy Moore flooded with fake Russian Twitter followers,” reported The New York Post."
Deception.
> Which seems to have involved at least one New Knowledge member but it seems wasn't actually run by New Knowledge.
Reid Hoffman, the billionaire funding AET wrote an apology. What does he have to apologize for? Well he paid AET $750k, AET paid New Knowledge at least $100k of that to run this disinformation campaign. So you can knock it off with the "at least one member... seems wasn't run by New Knowledge..." Obviously my patience has run thin on this - it has been proven that Morgan is a liar and that New Knowledge was deeply involved.
https://medium.com/@reidhoffman/truth-and-politics-1a532bc6c...
As I said, they've change their story more than once. When Morgan was pressed on the leaked internal report's clearly political goals, he said that "it didn't ring a bell".
Oh, and go check out their release of the report they provided the Senate Select Committee on Intelligence in December. What, you didn't know that this politically motivated organization with an agenda was asked to inform the Senate about Russian interference in US election? Yeah, they were - and did, in December. Checkout the timestamp on that pdf - not December... weird...
> That said, I find it hard to believe you're arguing in good faith when you're drawing parallels between a limited spread of misinformation centered around a single event with literally murdering people.
When you say "limited spread" do you actually mean "completely unrestrained"? And no. I find it hard to believe that you don't see the parallels between the justifications for unethical experimentation conducted on an unwitting population during the cold war, and the rationalization you've provided in this thread. It has nothing to do with deaths, it has everything to do with the ethics and the non-zero cost to individuals. In the cold war a statistically insignificant portion of the population involuntarily paid a heavy price, in this "experiment" (it wasn't, the leak shows it was a political action) a statistically insignificant portion of the population was convinced that their president was a traitorous Russian agent and driven mad with impotent rage.
They were researching a tactic already used in the wild that involves deception, yes. But the end goal of the experiment wasn't to deceive voters, which is what you claimed. The goal was to learn about how this tactic, a tactic that involves deception, works, presumably to help identify and combat it in the future.
> What, you didn't know that this politically motivated organization with an agenda was asked to inform the Senate about Russian interference in US election?
So what you're saying is an organization doing research into Russian interference was asked to inform the Senate about Russian interference? When you put it like that, it sounds like they have an excellent reason to conduct this sort of research.
> When you say "limited spread" do you actually mean "completely unrestrained"?
No I don't, which is why I didn't say that.
In any case, it sounds like this discussion has run its course.
No, it's not okay to 'experiment' with effecting the outcome of an election, even if they say it did not effect the outcome.
I did say it was a bit shady, but I'm not really sure how to do this sort of research in a way that doesn't potentially affect the real world, because the whole point is to see how this sort of thing affects real people. Doing it in simulation doesn't help because that only tests your simulation.
I'm taking it as a given that this kind of research is important to be able to identify and combat actual interference of this kind from malicious entities in the future.
It's just not okay for so many reasons.
OK, so I just did this, and I don't really see what the issue is. Looking at Wireshark, I see requests for:
* detectportal.firefox.com, which is used to detect whether you're connected to a captive portal network and need to sign in before you can connect to the internet. As far as I'm aware, no personal information is transmitted as part of this request, and there's apparently a pref to disable it [0]
* A couple of requests for OCSP certificate validation [1], which seems like a useful feature, and is also pretty easy to disable if you really don't want it.
* A request to download.mozilla.org and another one to download.cdn.mozilla.net, which looks like it's checking whether an update is available.
I don't really see a problem with any of these?
[0] https://bugzilla.mozilla.org/show_bug.cgi?id=1307867 [1] https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...
You seriously don't have an issue with being fingerprinted and tracked every single time you open an application on your computer?
The point is that there should be zero. I should not have a single outgoing network request triggered by opening a web browser to a blank page until interacting in some way. The fact that we've lost this as a standard is terrifying to me.
I think you're looking in the wrong direction. Try the closed-source (or partial closed source) operating systems you interact with on a daily basis: Windows, Android, macOS, iOS- that's where you'll find the "fingerprinted and tracked every single time you open" sort of thing you speak of. :)
Just to point out, that "the whole point of Firefox" is to make the network requests I want.
eg from my perspective it's a tool like (say) cURL that has a specific purpose.
It's a subtle difference, but an important one. :)
I'm mainly just replying to the poster that attempted to say that since Firefox already makes network requests, ~anything should be ok.
My guess is that Firefox will not try to check for updates or other things if it notices that the detectportal-request was not successful (i.e. the user is not logged into the hotel-wifi or something like this yet).
So... guessing here, that particular request would be checking if the domain for the Firefox update check itself has a valid cert.
If that's not what it's checking, hmmm...
And you can prove this how?
All I'm saying is think twice before blindly trusting a tech company, because Mozilla is no longer the fun and friendly company we once knew. They are very much a rank and file data mining company now, generating tons of cash, and being infiltrated by CEO and marketing types.
Captive portal popup seems like an obvious UX improvement for 99% of people. I wonder how many people on HN even know how to trigger it if the browser didn't try to do it for you.
Update checking and over the air updates make obvious sense to me given that my mother and girlfriend will click "Remind me tomorrow" for years on the macOS update popup, and there's nothing user-friendly about making it so easy for users use old browser versions.
The rare user can turn both off if they want, so what's the big deal?
For anyone wondering: Just try and open literally any http page (note: no s). I use groklaw.net.
There's still neverssl.com, but with the most popular pages using HSTS like Google Facebook and Reddit, captive portal detection is essential for your average user.
Although I wish the IETF would make a standard for doing this at the network level as part of DHCP rather than the current ridiculousness we have. Captive portals are just the buggiest shit.
This is a delightfully concise summary of Mozilla today. I was a Mozilla contributor in the "scrappy" years and became one of those listed on /about/owners.html. But Mozilla today is basically unrecognizable. A few years ago, even after I'd stopped contributing, it made me sick to my stomach to think about where things have gone, but I can process it better nowadays.
Mozilla's done worse than what's written in OP, but the absolute worst they can do is continue getting people to believe they're the same scrappy organization fighting for good.
If you believe in the Mozilla mission, then use Firefox, I guess, because there's not really a better option. (Although I suppose a WebKit-based browser should be an acceptable equivalent.) But please don't give Mozilla any money or tell people that Mozilla is their friend. It sort of tarnishes how things were around the time when you could say that and it was actually true all the way through.