Firefox Preview/GeckoView Add-Ons Support
blog.mozilla.org
blog.mozilla.org
That's a generous way to describe it. I'd describe it as "invaders inside the Trojan horse".
Please don't kill my JS blocker, Firefox.
Edit: Is my experience unusual? News websites that are normally encrusted with ads (e.g. using Firefox for Android without any add-ons) turn refreshingly ad-free in Firefox Preview.
I mostly use ublock origin to block ads in search, YouTube, Instagram, Facebook or Reddit. AFAIK none of those are blocked by the current Firefox tracking protection.
I guess my browsing habits are unusual, since the only website among these I've visited since switching to Firefox Preview is Reddit.
Second, it's called Preview for a reason. Support for add-ons is currently being implemented, so if you install Firefox Preview on an Android device right now, you won't be able to use uBlock Origin yet.
Third, the built-in tracking protection blocks most ads (at least on websites I frequent EDIT: which do not include Google or Facebook etc.), so you can already try it out if you just want to see fewer ads and don't absolutely need uBlock Origin.
But this was deprecated a few months ago in favor of a new browser, still early in development, that has no extension support. Previous HN outrage: [2]
At the time I don't think they had any timeline for adding extension support, but now it sounds like major extensions could be supported within the next 9 months.
[1] https://play.google.com/store/apps/details?id=org.mozilla.fi...
It would be really sad if they really did deprecated it without providing a proper replacement first - eq. comparable addon support & other things the current Firefox on Android can do.
Uh, no? Firefox Preview will eventually become the new version of Firefox for Mobile. That doesn't mean the current Firefox stopped getting updates.
My biggest issue with it ? When at the top of the page, dragging from top to bottom doesn't trigger a refresh of the page like in other browsers and many apps. I know it's a very petty complaint, but somehow it's major for me.
Still staying with it though, adblocking is even more mandatory on mobile than on desktop ...
Minor aside, they don't seem to support the <meta name="theme-color" content="#000000"> to colour the address bar.
Do you consider that a bug or a feature? :) Some people wouldn't want the website to mess with their app UI. I can file a Firefox Preview bug report.
Sometimes it takes a surprising amount of time to copy these nice designs. :)
I'm not totally sold on the URL bar being at the bottom, and I kind of miss the support for CSS theme-color, but I can see myself switching at some point.
I still quite like Firefox Preview though. I'm not quite sure what you mean by CSS theme-color, but if that refers to preferes-color-scheme: dark, then as far as I can see it supports that? DuckDuckGo is dark for me.
Isn't the existing Android browser built on top of Firefox's own mobile browser engine? Or am I reading this wrong?
GeckoView view = findViewById(R.id.geckoview);
GeckoSession session = new GeckoSession();
GeckoRuntime runtime = GeckoRuntime.create(this);
session.open(runtime);
view.setSession(session);
session.loadUri("about:buildconfig");
[0] https://mozilla.github.io/geckoview/One advantage of using GeckoView in your app instead of WebView is that you know exactly which Gecko engine version and features are available; you don't have to support old random WebView versions across different Android devices and OS versions.
Is this similar to how each Electron app uses a bundled version of Chromium (which takes up disk space), as opposed to web apps which have to run in whatever Chrome version (or other browser) the user has installed?
Firefox Focus on Android is quite a large app (132MB installed on my phone), even though on my phone, it uses either Chrome or WebView (bundled Gecko is disabled).
At the moment, yes. In Android 10, Chrome and WebView are sharing common code (a feature Google calls "Trichrome"), even though they are separate downloads, so perhaps there is a way for GeckoView apps to share one GeckoView in the future.
https://www.xda-developers.com/google-chrome-no-longer-webvi...
> Firefox Focus on Android is quite a large app (132MB installed on my phone), even though on my phone, it uses either Chrome or WebView (bundled Gecko is disabled).
Some Firefox Focus users were still getting WebView as part of an A/B test comparing GeckoView to WebView. As of the latest release (Focus 8.0.23), everyone should be getting GeckoView.
The Firefox Focus APK (with GeckoView) download size is about 38MB, but the uncompressed footprint is larger.
Oh you're right.
Not exactly; GeckoView is a clean interface for embedding Gecko in Android applications.
It's a shame it's going to be months until they get there, but hopefully I can continue with the current Firefox on Mobile until then.
An immediate concern is that the privacy settings are either dumbed-down, or else altogether missing. I'm noticing a trend in Firefox across the various devices and versions:
* FIREFOX FOR DESKTOP - The "settings" section allows you to block trackers, 3rd-party cookies, and fingerprinting.
* FIREFOX FOR ANDROID - The "settings" section allows you to block trackers and 3rd-party cookies. Fingerprint protection is possible, but hidden. You have to go to "about:config" and know how to enable it manually.
* FIREFOX PREVIEW FOR ANDROID - The "settings" section appears to be built for my Mom. It has a toggle for blocking trackers, and that's it.
Are more granular (or at least visible and understandable) privacy settings coming in future releases, or is this just the UX direction? Why is Mozilla making it so much harder to enable desktop-class protections on mobile devices?
Yes, that release is imminent. Preview will include all of those settings. You can try them right now by downloading Firefox Preview Nightly.
After looking at github, I understood that Fenix won't support Firefox Sync for syncing login and passwords, but will rely on Firefox Lockwise, and is the way forward. It this correct ?
edit : added a precision regarding firefox sync for passwords
(Disclosure: I work at Mozilla but not on Fenix)
Based on my user experience Fenix (Firefox Preview) supports Firefox Sync in terms of bookmarks. I believe history and other data is also synchronized, but I haven't had occasion to test it thoroughly. In my opinion claim that "Fenix won't support Firefox Sync" is a bit too far [0]. I noticed the login/password sync feature has not been implemented yet [1]. I suppose it will might materialize soon, because lack of it could be a huge mistake in terms of usability.
[0]: https://github.com/mozilla-mobile/fenix/issues?q=firefox+syn...
1) The code base is not production ready yet, and they don't want an issue to come up which leaks users passwords
2) (More likely) They intend to add support for LockBox, their extension that replaces mediocre password support with a full-fledged password manager. And they need the Add-On support before they can include that.
So most probably you'll see this along with add-on support come in the next few months
It seems Lockwise can not work on pre Oreo android devices, so in the end, Fenix will get password sync natively as well, and this is a work in progress.
edit: It's supposed to do that automatically, if it doesn't - I think you could report an issue.
Lack of add-ons and lack of user specified search engines is a must have to me...
Anyway, I'm thankful for leaving a comment.
At the same time, all Addons I've installed right now require "Access your data for all websites", making absolute trust in the developer / reviewer necessary.
Corrections welcome — I've probably missed something somewhere.
Give this addon a try (on desktop or mobile Fennec only, obviously): Dark Background and Light Text [0]
[0] https://addons.mozilla.org/en-US/firefox/addon/dark-backgrou...
What else are you asking for?
This site is full of threads talking about how friends, family, and coworkers’ browsers are riddled with badware that was installed behind their backs.
Not even Google is this heavy-handed, they allow installing local extensions in Chrome after users enable an option, although a warning is shown on browser restarts about the presence of external extensions, which can be dismissed.
Why not have sensible defaults, then educate and warn users about certain actions, instead of treating them like cattle?
And has been pointed out in most of these threads, the reason for not allowing people to circumvent some things is because that also allows malicious software to circumvent it.
Extensions loaded in about:debugging are not persistent, they are removed at the end of the browsing session.
> And has been pointed out in most of these threads, the reason for not allowing people to circumvent some things is because that also allows malicious software to circumvent it.
Yes, and the discussion mostly ends after people point out that malware if free to circumvent extension signing in any number of ways when it has root access on the device.
The threat model is flawed, or at the very least they're placing minimal security benefits above important user liberties.
Forcing extension signing by default is a great initiative, but we must be given ways to override defaults, guarded by administrative access and appropiate warnings, and be able to install local extensions in the browser we love, and that is the release version of Firefox.
But that's a big if. Extensions can be installed without root access, and can wreck a lot of havoc. I'd also dare to state the the organisation with the best insight into the extent of security benefits is the organisation that has data on the number and nature of exploits, i.e. Mozilla.
> we must be given ways to override defaults, guarded by administrative access and appropiate warnings, and be able to install local extensions
Guarded by administrative access sounds reasonable, and I think that's even already possible with Firefox ESR? I'd also consider an unbranded version of Firefox equal to the branded one, with the unbrandedness being an "appropriate warning". It does need to support auto-updating first, though.
Malware extensions is a real problem that affects literally millions more people than people who want to use the standard Firefox release with an unsigned extension.
And it's such a lazy thing to say "oh they can just replace the Firefox binary" when that's clearly a significantly more complex task than just writing an extension.
What's so secret about your extension code that you want to be able to distribute it to users without getting it reviewed by Mozilla?
You posted on that Bugzilla post but gave no details as to what your use case is.
Also why can't a user take the code for your extension, create an account on the add-on marketplace and privately get it signed for themselves. It's a multistep process but works.
Though its worth noting that we do not need reasons to expect our privacy being respected. And this issue is not just about me and my needs, but about user liberties, so please refrain from making it personal.
> Also why can't a user take the code for your extension, create an account on the add-on marketplace and privately get it signed for themselves. It's a multistep process but works.
No, it does not work, as the maintainer of Page Translator can attest.
https://github.com/jeremiahlee/page-translator/issues/26
This change is hostile to users and concentrates power in the hands of the browser vendor. Consider that they are making third-party extension stores impossible.
Ouch. I'm generally in favour of having add-ons signed, but I do have an extension that injects an external script into the browser and web pages - for a completely non-nefarious use case.
I do understand the security risk and why they'd block it, but I'm not looking forward to the day my extension is no longer flying under the radar and gets pulled.
Edit: Of note is that the Chrome web-store does allow my extension, but requires a multi-week review every time I upload a new version. Somehow they're fine with the remote code, even though it could change after their review.
Given that the leadership of the Mozilla Corporation is completely useless, users have the responsibility to raise these issues so we can push them to fix them.
It would be more productive to allow others to learn about the issue and give us a chance to have a public discourse about it, where technical details can be explained and their threat model shared, and possibly allow for feedback by the community to shape the final implementation.
This continues the long trend of browsers not trusting the underlying OS to actually protect users from soft-malware.
I feel like the people we consider ”regular users” to be really different.
Like we’re talking about a subset of the population that want’s to install their own private extensions or sideload someone else’s but doesn’t understand how to uninstall the release version and install the developer edition when prompoted.
It's also possible to make this setting configurable only from the browser UI, where you get a chance to educate and properly warn your users.
They also want to restrict the config option on Linux, where the adware problem you describe is not really present.