Promoted Add-ons Pilot
blog.mozilla.org
blog.mozilla.org
I wrote back to Mozilla: "This is an old add-on. I just want to get rid of the warning label. How much will that cost me?"
I feel like I'm asking the extortionist goon how much it's going to cost me to not be beaten up.
The open-source projects with no income are the ones getting hurt.
I can guess why you say they're terrible for privacy, but they both mention what data they share on the addon page. So it seems not so much that they are violating users privacy, but that you think people should be more concerned with the amount of privacy they give up.
For the record, I am pro-privacy, and would never want to use addons like these that send my browsing and other data to a third-party. And I know the vast majority of people don't read privacy statements and might not fully realize the amount of privacy they're giving up. But that's a much bigger problem than Mozilla giving these addons that openly collect this data a Verified tag. Also, the tag will ostensibly indicate some level of verification that the addon isn't doing anything sneaky (on the client side), so it's not "just" promotion, according to the announcement. If you don't believe Mozilla is going to do that verification well/honestly, that's a different discussion.
Regarding open-source projects, I share your concern, but would be interested to see some evidence that they will be hurt by this.
[1] https://addons.mozilla.org/en-US/firefox/addon/grammarly-1/
It is now. All add-ons must be signed by Mozilla. There's a development mode, but test add-ons disappear when the browser exits.
"Developers will have all new versions of their add-on reviewed for security and policy compliance. If the add-on passes, it will receive a Verified badge"
> Additionally, we collect payment information if you choose to use our Premium services, and we automatically collect technical information, including log data and usage information, for legitimate business interests, such as improving our product and providing customer support.
You can bet that means they're building a credit profile of people and likely selling the information.
> We may share any of the information that we collect through the add-on with our third-party service providers in order to provide you with services, as required by law, to protect our rights or the rights of others, with your consent, or as otherwise legally permitted.
I'd really like to call out the "or as otherwise legally permitted at the end" which means essentially says that the previous list of things is a bullshit hand-picked subset of the set "legally permitted to perform." When I change it to:
> We may share any of the information that we collect through the add-on with our third-party service providers as legally permitted.
It all feels a bit different; which is to say, unless the law says its explicitly illegal for us to share information we collect, we can and will share it. For something that literally monitors everything you write/think, your payment information (probably invoices/site/etc), and then shares it with anyone the fucking please... I'm gonna say that's a big "terrible for security" from me, dawg.
Where I live it's illegal to walk around with a beer/booze in public. But whenever I want to drink a beer in public, I just walk around with it like any other drink. My behavior looks so normal, people just assume it's not a beer, helping me out even more is the fact is "it's illegal" so people's good intentions/will further push the idea out of mind "I don't want to think they're breaking the law, they don't look like they would."
I would say after reading what's literally on the page and thinking about it: the Grammarly extension authors are pretty proudly walking around with a beer right now...
Mozilla being like the friend who invites someone to your home to help tighten up some loose wobblywomps on the porch; but that person then drinks your beer, drinks their beer, goes through your fridge eats what they want, starts making their own batch of beer at your house, and then finally partially adjusts your wobblywomps. Departing, the drunken fat stranger looks to you and says "it was great doing business with you and I be back everyday this week to tighten your wobblywomps."
Huh? That seems like a bit of a leap
I mean you could try to do a web of trust kinda thing but you would still end up paying someone.
I get where you’re coming from that they could just not have the scary warning but the fact that it’s hosted on Mozilla’s site without a warning already lends a lot of legitimacy to what should be seen as “some random person’s add on.”
It's like putting a sign in front of a retail store that says "make sure you trust the proprietor before patronizing this store" -- it's not saying anything that isn't true, but it's also going to be a direct cause of fewer people patronizing the store, even if the proprietor is trustworthy.
If the sign then only comes down by paying money to the party who put up the sign, well, now it's a racket.
I've got two extensions which I'm really fond of: "I don't care about cookies" (1), and its paid version "No thanks" (2). The creator, Daniel, lives in Croatia and thus they won't be able to join this program. I hope the country limitation is lifted soon.
1) https://addons.mozilla.org/en-US/firefox/addon/i-dont-care-a...
> You (or your company) must be based in the United States, Canada, New Zealand, Australia, the United Kingdom, Malaysia, or Singapore, because once the pilot ends, we can only accept payment from these countries. (If you’re interested in participating but live outside these regions, please sign up to join the waitlist. We’re currently looking into how we can expand to more countries.)
Specifically note the last sentence.
Go to the home page and click the 'AdBlock Plus' link to add to uBlock Origin - https://www.i-dont-care-about-cookies.eu/
1 less addon with access to all sites you visit.
To remove cookie banners permanently on lesser known sites, follow this 30 second guide by the dev - https://www.youtube.com/watch?v=8TvCGWwQr5o
it's not enabled by default
I maintain both the "I don't care about cookies" and the premium "No, thanks" extension and the filter list. All by myself, for the last 8-9 years. Please don't write stuff you didn't recheck first.
While the list is a cool addition for those who can't install the extension, it really can't do much when cookie policy needs to be accepted for the website to work properly. The extension accepts policies automatically when it's needed.
Cheers, Daniel
You can do those with uBlock Origin, but users don't want to mess with extensions and want extensions to work out of the box, so they install many extensions leading to malware and privacy issues.
Ublock origin is the one to use, and is maintained by the original creator.
I'd link to sources, but it's too easy for me to cherry pick... I'd recommend looking around to see if what you find corroborates with what I've stated.
> By using it, you explicitly allow websites to do whatever they want with cookies they set on your computer (which they mostly do anyway, whether you allow them or not).
Taking GDPR into account, this seems wrong, since GDPR enforces opt-in, not opt-out. Therefore, a notification only gives you an opportunity to opt in and blocking the notification should leave the website with no permissions.
Sites like Facebook and Ghacks automatically opt you in if you start scrolling down, because they said they would do this in the banner they show. You didn't read it, because you were blocking it with the extension.
The dev is just trying to save himself from silly lawsuits.
Quoting GDPR definitions (Art 4.12), '‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes [..]'.
If the site owner wants to assert that the user provided consent, it's up to them to demonstrate that they fulfilled all these criteria. If they assert that a particular action (e.g. scrolling in this case) indicates consent, then they have the burden of proof to convince the regulator or the court that the action was unambiguous, that it's clear that reasonable people would only take that action with the intent to opt-in, and not because of some unrelated reason such as wanting to read the content below. The legality of various opt-in 'dark patterns' has been tested in EU courts already before GDPR, and it's not considered legally valid if it systematically misrepresents the actual user intent and wishes.
The appropriateness of any technical measure can be trivially tested with a user survey - get 100 random people to use the site for 5 minutes, and after the "opt in" action is completed, ask them whether they know that they "opted in", whether they know to what they opted in, and whether they really intended to opt in or not - and if not, then your method for "collecting consent" does not work and the things you recorded - actions, clicks, even physical signatures in a 'meatspace' setting - do not give you any legal permission whatsoever, they're meaningless.
The one thing they can do with that banner and scrolling is to cover their information requirements, where they have the right to do some thing even if the user disagrees (much less opts in), but they are required to notify the users that they are doing that thing. But there it makes all sense that the user can choose to delete that banner if they want to, it's like the notifications in supermarkets that they have cameras - they're required to display them, but the users don't need to read them if they don't care.
The law is pretty clear, nobody should be surprised that their banners are non-compliant.
They give you a good,easy way to opt out too.
The GDPR approach is that processing personal data by companies is prohibited by default, unless they can point out one of the specific GDPR subsections that permits that particular purpose of processing. They are not allowed to use my personal data for marketing unless specific conditions are met. Scrolling past a statement 'By scrolling, you are agreeing to use of cookies for marketing' does not meet these specific conditions, no matter how clearly its said, so the banner legally makes no difference whatsoever, it does not mean that I'm agreeing to anything, it's exactly as if it wasn't there, and that clear statement is simply a lie.
And the "good,easy way to opt out" does not matter, after the opt-out it's just as illegal for them to use data as before the opt-out, since I did not opt-in. If they're using my data without an intentional opt-in, then they're untrustworthy cheaters anyway, there's no reason to try to opt-out of something that I didn't opt-in to, this should be handled by the regulator who will be able to audit them to verify if they have actually stopped using the data.
Furthermore, if had opted in, the legal requirement (Article 7.3) is "It shall be as easy to withdraw as to give consent." So if opting in happens on the main page by scrolling but opting out happens in a settings menu requiring two clicks, then that may be good but it's not good enough, because it's not as easy as it was to opt in.
> You may not rely on silence, inactivity, default settings, pre-ticked boxes or your general terms and conditions, or seek to take advantage of inertia, inattention or default bias in any other way. All of these methods also involve ambiguity – and for consent to be valid it must be both unambiguous and affirmative. It must be clear that the individual deliberately and actively chose to consent
Do you have a source on this? I'm pretty certain this right is not dependent on reading the banner nor even the existence of a banner.
Considering the relatively small market share of FF, I feel like the amount of companies that would pay for review could be pretty small (<= 1000).
The ad model also creates an awkward conflict of interest: the add-ons most willing to pay good good money for placement are probably ones that you shouldn't install and Firefox should not promote. Think tracking, ads, .... Or commercial ad blockers trying to always appear above Ublock Origin.
It will be detrimental to open source/hobby add-ons in general, unless Mozilla includes those in the review program for free.
Overall, I can't see how this will bring in any considerable amount of revenue, not even considering the labour cost of manual review. At least while keeping shady actors out.
I can imagine this just to be an effort to balance out the costs of curating the store, while still bringing in a bit of additional money.
I'm tentatively supportive, assuming they provide free reviews for non-commercial open source extensions and are strict with the promotions they allow.
The whole point is for people to pay to have their add-on manually vetted by Firefox staff to verify that it meets the recommendation standards. As the article says, this process is repeated regularly to account for updates.
> I'm tentatively supportive, IF they provide free reviews for non-commercial open source extensions and are strict with the promotions they allow. No mention of this in the announcement though...
This is already how it works, every recommended add-on has been manually reviewed. The article says that they will use this to expand the reviewing process, not to replace it. They also say, "During the pilot program, these services will be provided to a small number of participants without cost." The extent of the two promotional "levels" are clearly outlined as well.
This is just a way for companies to get their add-ons on the fast track to wide adoption by having them reviewed for policy compliance and, if they choose to pay more, added to a promotional section to increase visibility. The Twitter-style hot take to find a flaw right away is not warranted.
On the other hand, it also provides an opportunity to have a trusted addon ecosystem. If the price is reasonable, popular free addons can collect it through donations, and in exchange, users can be sure that the addons were actually reviewed (hopefully thoroughly and by humans, i.e. with a much lower "oops bad thing slipped through" rate than addon stores that rely mostly on automation).
Could even be a great way to generate revenue. Have two versions of the addon. One is free. One costs $1/year but is reviewed. Same addon. I know which one I'd pick (for myself and all relatives). Mozilla and the addon dev can split the revenue 50:50.
Having mozilla people review your add on so that they officially say it is « safe » from tracking, malware, privacy intrusion, etc.
I don't see how any amount of explanation and good intention can outweigh a fundamental conflict of interest.
FF's market share may be tiny, but these ~5% still translate to ~200 million users.
edit: That was before the discontinueing support of XUL-based extensions. I can't imagine there are more webex-based now. Except when adding the endless persona/colorscheme stuff which adds no real functionality, only changing some looks.
Or, they count the symlinks, instead of the original file.
The fact that Mozilla will only promote/market extensions which have been reviewed by humans for security and privacy issues is a big step up over pretty much everyone else.
https://twitter.com/Pythux/status/1154403982342852609
https://twitter.com/gorhill/status/1165747661691064322
https://github.com/mozilla/addons/issues/1078
This is an unpaid recommendation. Why would I trust Mozilla now that they’re getting paid?
If this isn't reviewing, what is? It makes it seem like this new program is less about actually reviewing (which they already do) and more about pushing for advertising revenue. That's a fair thing to do, but it's weird to frame it as if reviewing isn't already happening.
1: https://addons.mozilla.org/en-US/firefox/addon/beelinereader...
If what we've experienced isn't considered a strict review, I'd hate to see what the next level looks like.
If eventually some kind of payments would be possible, Forefox could transform into a kind of platform and bring completely new possibilities.
Just saying this might only be a first step. Tipping their toes, see what is possible. Might work out differently. Or not at all, or the same ;-)
Now, it also means Mozilla is in the enviable position of offering ads to Firefox users which can not be blocked by Firefox ad blocking extensions.
Put another way, if you want to browse AMO ad free, you will need to use a different browser.
The allowlist exists so it can guarantee users install add-ons which work, and don't break their browser. Both reviewing and adding support for required APIs costs money.
As for support, a) we'd like to support all of our users, and b) it often takes a lot of support time until you establish that an add-on or hidden preference is responsible.
Such as?
> a) we'd like to support all of our users
Only what the users would like matters. Giving them the choice between being installing what they want and getting support is strictly better than a forced whitelist.
> b) it often takes a lot of support time until you establish that an add-on or hidden preference is responsible.
Then check for that first.
For extensions, as I understand it not all the APIs are implemented yet for geckoview. Not my area though so can't provide more details. For about:config, again lots of the preferences don't make sense for geckoview, or can even break it completely.
> Giving them the choice between being installing what they want and getting support is strictly better than a forced whitelist.
For you perhaps. But for many users having a working browser is more important. Users don't deliberately break their browsers, yet it happens all of the time. I believe (and I'm speaking for just myself here, not Mozilla) that finding a balance between allowing users to install/tweak many things whilst ensuring a usable browser is better.
> Then check for that first.
Sure we could immediately check if users have any addons or prefs set, and just ignore them if so. But that would let many genuine bugs slip through, not to mention not be very nice to those people.
Something offered to induce another to do something.
This is very unfortunate. I'm not liking how the future is looking here. Fired a bunch of people, then announce a partnership with Google, and now this.
I am not seeing the big concern around promoting paid ads on the add on site assuming they are clearly marked as such.
That’s how they’ve made money since the beginning except it was ads on all searches, and it was google doing the infrastructure work for them.
Step 2: budget problem is solved.
Really? Was that necessary?
Please explain. Your comment is very negative with 0 reasoning.
Make adblock be a first class feature that you enabled/whitelist in the main browser option screen.
I'm not yet a taxpayer, but I'm not looking forward to having my money be wasted on yet another "service" that neither I nor most people would choose to benefit from. I'll wager the postal service is an example of waste of public funds that translates well across borders.
Evidence that open source leads to better software abounds. I don't think one could say the same about state-funded anything unless one lives in that fictitious country called Finland.
Mozilla should've always been structured as a co-op.
really bummed about the whole thing.
> Mozilla should've always been structured as a co-op. Please fork their software and start one. If you are successful, I will say I always believed in you, if not, I will say that you should've always been structured as a social purpose corporation
If you forked Firefox and made unambiguous improvements, Mozilla would presumably incorporate them, because why wouldn't they? Then everybody would get your improvements from firefox.com instead of notfirefox.com because that's what they're familiar with, and with Mozilla's default search instead of yours, so they still get all the money.
Just commenting on the fact that the way the organization was setup was bad for Firefox as the product.
[1] https://www.mozilla.org/en-US/foundation/annualreport/2018/
There's a reason there's now so few independent browser engines.
We can't have it both ways.
But browser makers can pick and choose what they want to implement. And we end users can pick the browers we like.
Unfortunately that doesn't actually work like that in practice. We don't get to pick all of the websites we use and we certainly don't get to pick which APIs their developers use to make them. This in turn limits both your freedom to choose the browser you want and the browser vendor's freedom to choose what to implement.
As fun as it is to blame Google for the fall of the open Web, a big part of the blame lies with the developers that use those APIs without regard for their status.