Update on Firefox Send and Firefox Notes
blog.mozilla.org
blog.mozilla.org
I've built `ffsend` as CLI tool for Send to securely share files from the command line. It has been a great success! Thanks Mozilla, for building and providing this amazing service!
For the interested: https://github.com/timvisee/ffsend
I'm currently hosting a public Send instance myself to ffsend keep working. Let's see how long I can keep this going (and funded).
It runs Send in Docker. I set up this configuration for it: https://github.com/timvisee/send-docker-compose
If someone sends an encrypted email containing illegal content, is email then considered harmful?
You design a system that gives you (the hoster) zero ability to inspect, modify, block, censor, restrict any of your users' content and in doing so you're allowed to abdicate all responsibility for how the system is used because you're literally incapable of controlling it. Pure infrastructure with none of the messy real-world bits.
I've thought about it though, but haven't settled on anything yet. I can't inspect files. I'll add an abuse report notice soon, abuse@ is already live. I'll attempt to manually review cases. That doesn't prevent illegal sharing, but I think that's the best I can do. If things get out of hand, I might take the instance down. I don't want to support hosting illegal stuff.
A newer Send version (yet to deploy) also shows a clear warning, and requires users to tick a confirmation box, when downloading through the webpage. I hope that helps preventing malware installations.
Between the short TTL and E2E encryption, I'm struggling to think of any legal obligations you would have in most western jurisdictions. Perhaps logging in some places? Even the DMCA permits more than 24 hours to respond to a takedown notice.
First transfer.sh and now Firefox Send are closed. What service should I trust to send file quickly and securely.
I just rent a VPS, temporarily host the file on there, and give whoever it is a link.
Edit: If my threat model were to include protecting the contents of the file from the VPS provider I would probably encrypt it client side with GPG or something similar.
You can still use ffsend for now, it still works and uses the Send instance I'm hosting (send dot vis dot ee). Some generous users started sponsoring me through GitHub, so that'll definitely help keep it alive longer.
I haven't found a great alternative myself yet.
There is also a Golang port: https://github.com/psanford/wormhole-william
Mozilla VPN seems to be just rebranded resell of Mullavad VPN with Mozilla Goodies.
Mozilla Monitor seems to use https://haveibeenpwned.com/ (also as seen in Firefox desktop)
Mozilla Firefox Private Network looks like another Cloudflare Warp's rebrand (with litte good additions maybe?) seeing that it uses Cloudflare .
Mozilla Firefox is also losing it's usershare and Management division may force in future to ditch Gecko and adopt Webkit/Blink in the hope that it could bring more userbase (just my thought) to lessen maintainance and focus on revenue.
If it brings revenue for them doing this,then it is absolutely good for them , but we are slowly loosing the Original Mozilla as Company based on Philosophy.
Browsers would be forked then. But,maintainance and adding features require lot of effort which is almost impractical by single dev/group without much funding in the world of ever changing large web.
And I dont see any of your comment about diverging into other product market a bad thing at all.
Mozillas initially incredible partnership with Google, from which they earn the vast majority of their income, essentially turned toxic once Google started experimenting with Chrome. On that day Google’s favourite browser to support shifted from Firefox to Chrome.
Being financially reliant on your main competitor is a deeply troubling and dysfunctional position to be in.
Regardless of how good it started, its time to move on.
Maybe Mozilla should also look into reducing leadership compensation or at least have it reflect the performance of the company.
I have no insider knowledge of how well it’s been managed so I’ll leave that to other commentators.
However I’d say that their vision for openness is part of their curse.
Google in developing Chrome are not held to the same community expectations.
It’s expensive to build and maintain a modern day browser and the competitors have deep pockets to the extent of it being worth completing even at a loss due to the benefits of controlling the platform (being the browser platform).
Mozilla have to extract value somewhere. But where should it be?
I think the challenge is to reframe that Mozilla are maintaining an open commons that all are welcome to visit for free without access fees while also metaphorically “selling cool drinks nearby for a price”.
If the community won’t let them charge for anything they do, and claim “extraction/extraction!” with every move they are destined to go under.
I think the most useful framing for Mozilla fans is:
What here should be part of our global commons and needs to be freely available and what would I/we be willing to pay Mozilla for that extends or compliments these core offerings?
Google was forced to do it by themselves.
>If the community won’t let them charge for anything they do, and claim “extraction/extraction!” with every move they are destined to go under.
I dont ever see that from Mozilla community. No one is bashing them for starting side business or charging for something other than the Browser. The problem is none of their side project were successful in business terms.
This seems like an inherent problem with sufficiently large companies; the more areas the expand into, the harder it is not to compete.
They laid off most people working on Servo, so the adoption of WebKit/Blink seems rather likely.
The Gecko team was mostly spared from the layoffs. There is no intention to cease Gecko development.
> Servo is an attempt to rebuild the Web browser from the ground up on modern hardware, rethinking old assumptions along the way.
2) It was an attempt to rebuild a browser engine up from the ground up on modern hardware - and large parts of that work landed in Firefox.
I've tracked their progress for quite some time. There was never a concrete plan to replace the DOM handling components of Gecko with the DOM handling components of Servo.
Saying "large parts of that work landed in Firefox" is misleading. A browser engine is a huge thing, and most of Servo is not in Firefox. If you just want to replace a few parts, creating an entirely new engine from scratch is far from the most efficient way.
Why does this matter? Well, because decisions have consequences. Way back in 2013, they were feeling pressure from Chrome, and decided the best way to compete was to rewrite the browser engine (in a brand new language to boot). The original engine stagnated, and here we are 7 years later. What a colossal failure.
Here is a quote from the Servo wiki from 2014, which is the earliest snapshot present in the WaybackMachine archives.
>Servo is explicitly not aiming to create a full Web browser (except for demonstration and experimentation purposes). Rather it is focused on creating a solid, embeddable engine. Although Servo is a research project, it is designed to be "productizable"—the code that we write should be of high enough quality that it could eventually be shipped to users.
https://web.archive.org/web/20140718030420/https://github.co...
The words "Firefox" or "Gecko" do not appear a single time in the blog post you cited originally. This is because there were no plans to replace Gecko with Servo at that point in time. They did plan for that possibility, and it was probably a minor goal, but the primary goal was research, as they stated in both the blog post and the wiki entry. They were hoping that they could replace parts of Gecko, I'm sure, but it was never a given.
In your quote, they didn't want to create a full browser, but they did want to create a full engine. And it was designed to be "productizable." I think it supports what I'm saying.
Servo was the last big plan from Mozilla to turn things around. Since then, we've just gotten Pocket, random bundled add-ons, etc. It seems like they are mostly just content to slide into irrelevance. And I am very sad about that. I do honestly wish Servo had succeeded, although I thought it was pretty obvious it wasn't going to.
Also, while I'm airing grievances, I think it's very likely that having a few big chunks of Firefox/Gecko be written in Rust is going to be a maintenance burden that will slow down development even more. Now that Mozilla has laid off the Rust and Servo people, what are they going to do?
>If you're working on Servo, you can be much more strict about what hardware combinations you support and what kind of content renders well. Look, there's a reason that the lineage of all widespread web engines go back 20+ years: it's much easier to incrementally improve that engine while ensuring that you're not breaking anything than it is to start over from scratch.
>I would also like to point out that you don't have to take my word for it: It has taken at least 3 years (probably closer to 4 years) to get WebRender ported over to Gecko from Servo and get it running well enough to the point that we can start saying that it will likely reach 100% deployment within months instead of years.
>My point is that, while Servo was great for demonstrating new ideas and producing eye-popping demos, it was not going to replace Gecko anytime soon, regardless of what those few Servo developers thought. In all the time I've worked at Mozilla, I have never once heard anybody in charge of Firefox say that we were going to do a wholesale swap out of Gecko with Servo.
https://web.archive.org/web/20200815135321/https://tildes.ne...
We might be arguing past each other. He says this:
> Unfortunately a narrative kind of built up around all this stuff that Gecko developers were a bunch of bumbling idiots who were just maintaining a bunch of outdated bloatware, while the Servo project was where all the action was.
This is precisely my complaint. Firefox really did need some sort of strong direction to save it, and Servo was all they came up with. I don't think it was just a few self-important Servo devs, I think (at least part of) management was in on it too. In fact, the blog post above was signed by Brendan Eich, which I find really disappointing (I thought he, at least, was smarter than that...).
Anyway, once Servo sucked all the other oxygen out of the room, Firefox was really doomed. Now Servo is dead and we have... a few incremental improvements to Gecko to show for it. I definitely feel bad for the guys working on Gecko the whole time. That said, they could've came up with some "response" to Servo, but they didn't.
Contrast a Blink-based FF, which would basically just be Brave.
People largely don't choose firefox over non-degoogled chrome today. All browsers on iOS are reskinned safari with different accounts for synced bookmarks and tabs, and yet people choose to use different iOS browsers for various reasons, the browser's engine not among them.
It pains me to think about, but from a realpolitik perspective it makes zero sense for Mozilla not to slap an orange fox on chromium and call it a day,
Although I suopose there is still manifest v3...
I fear that if Firefox switched to webkit or blink, they might lose a significant number of existing users without a clear way to win back more.
The system has worked great for decades. Data is automatically gathered via a hardware datalogger accessory that has a ethernet interface. Is there any google product with anything close to that useful lifespan?
If Google can do it why can’t we?
>And this is why we all should have shouted louder when Google set this precedent five years ago.
Do you also shout loud when Microsoft set a precedent for shutting down products and services? Of course you don't. You just confine your rage to Google. Let's have a look at all of the products and services Microsoft has cancelled:
Let that sink in next time you do a drive by on a Google related topic and post one of those lame "I wonder when it will be cancelled" worthless posts.
I mean, that list has MS-DOS. To which we still have backwards compatibility. And it's twice as old as Google.
Also, tone.
Relentlessly. If you get me talking about MS you won’t be able to get me to shut up.
They’re a bully who was never broken and that just invites more bullies.
Whatever tiny power I have to prevent another Microsoft from ever happening again, I will happily use it, and proactively. I think you’ll find that some of the “unfair” venom FB, Google and Amazon get is from people who feel the same way. Take them down a notch while they’re still in arm’s reach.
a) I pay for. An amount of /money/, both service and I can sustain with, or
b) I host myself.
Looking for some help if anyone can, :)
- https://github.com/femto-apps/web-file-uploader
The old copy (https://femto.pw/) has been used over 100 million times and sent over 13PB of data!
Out of curiosity, how do you deal with all that bandwidth? Are you self-hosted?
We have 5gbps of bandwidth and 12TB of storage that I've dedicated to the service (costing me ~£30/mo, so a fairly trivial sum).
I'm hoping that if we ever exceed 12TB / 5gbps, others will similarly host their own versions of the application. I've heard of half a dozen people already who have just decided to host their own.
I assume you're using hardware you own and the thirty pounds are just networking costs?
Some people over here are dying to start paying for Firefox.
(Mozilla donations go to the much smaller non-profit part of Mozilla and are unrelated to Firefox.)
Now, whether Firefox NEEDS 500M per year is a different matter, but the whole idea of 'some people want to pay for Firefox' seems rather naive as a suggestion for how Firefox can be viable without Google.
Don't hide behind the fact. Tell the fact in the title.
I interpret this news as "it's not coming back".
No need for interpretation, they state it flat out:
"In the intervening period [since the temporary shutdown], as we weighed the cost of our overall portfolio and strategic focus, we've made the decision not to relaunch the service."
All those side projects is the reason while Firefox is dying. They completely ignored their core product: they made a worse copy of Chrome that killed all extensions.
But instead of focusing on their core product, like 50 people dealt with Firefox and 950 did various side projects that nobody used.
I get it, hard projects are hard. But it doesnt help that nobody is interested in Firefox development and most people focus on useless side projects used to boost their CV.
I personally have had great, highly individualized, product-market fit with a two year old beta android app out of Mozilla Indonesia of all places [1]. It provides on device unbelievable OCR search for my massive screenshot inventory unique to my personal workflow and it just works.
I have no idea of its future in the new Mozilla but will keep using it until it dosen't work anymore and then find another way.
[1] https://mozilla-next.com/eng/firefox_screenshotgo_beta#first...
Super neat service, makes total sense in Mozilla’s portfolio but I don’t see it as a natural part of the browser.
Now that we'll be maintaining our own fork (https://github.com/plyint/send), if anyone has any thoughts on features or fixes you'd like added I'd love to hear from you. Just send us a message from our website (https://plyint.com), open a github issue or contact me through my HN profile. I can't promise will implement it, but we'll definitely give it a serious look.
As a developer, I am already aware of similar open-source packages like magic-wormhole. The code/tools themselves don't solve the problem, though. I had my non-techincal mom exchange sensitive documents through Send but I'm never going to get her to use magic wormhole, and self-hosting is too much hassle for one-off documents.
I'm aware of dropbox etc but if my both me and my mom don't already use them, there's friction to create an account and pay.
I'm not sure whether there's a business model for a standalone hosted version if Mozilla themselves couldn't make it work (and I presume they gave it thorough thought)
Why not add a Report button and start charging for the service?
Having a consumer download a sketchy file from what should be a trusted service (it's firefox! they're the good guys!) is not good for your company image, either.
And unfortunately, charging for a service is no guarantee that these issues will go away. I have seen fraud links from many b2b services presumably caused by credential misuse. If you operate a file sharing service, please be sure that there is a way to report a file either on the download page or on the contact us page. I'm the guy with too much time on his hands and actually follows up on reported phish emails and I've seen many services with no reporting mechanisms. Also, give your customers their own subdomain so I can selectively allow them in the palo alto.
I just don't understand this kind of logic. I can send mail bombs with the trusted postal service and people will open them. Does anyone blame the postal service?
Yes?
Do you think the USPS does nothing to detect bombs in the mail?
You can’t earn trust by saying “that’s not my problem.”
Which they also scan for?
The USPS does try to keep the mail safe, and generally does a good job.
Mozilla cannot make the same guarantees about Send so they shut it down.
Well, and with encryption the files going through mozilla are always properly sealed and they can only rely on external indicators such as reports or IP blacklists. So they're doing no worse than USPS.
https://www.cidrap.umn.edu/news-perspective/2003/06/postal-s...
Your framing suggests that Firefox Send was a 'public utility', held to the same standard as a power company or a gas company, required to provide service to all who seek it. Firefox Send was not a 'public utility', though, and so it need not be temporary to shut it down in the face of attackers. Apparently the Firefox group decided to make it permanent.
What if Gmail was shutdown without notice tomorrow? Would any lawsuit have standing if refunds were issued that same day? Would free users have any recourse whatsoever? It isn't a public utility, right?
A few months months ago I would have argued that there were clear non-monetary motivations behind Mozilla and Firefox. I don't think that is as true today.
Now to lose "Pocket" and bring back a bookmarks toolbar that lets you find things locally.
Which is honestly super depressing so I will applaud any attempt they make at an actual sustainable income stream.
I hate to say it, but that killer app could be ... a directory. A more portal like, tree like way to browse the web. Search has become so unruly. A person new to the web sits at a blank search box, and it might be hard to learn all the great places there are to visit. With the paradox of choice, people get so overwhelmed they just fall back to infinite feeds because browsing is so endlessly open ended. Everyone needs a "start page" of some sort, and I wouldnt mind if the msn's and drudge reports of the world had some nice fresh competition.
Shopping leading you to wirecutter type things, in a slowly refined way. Recipes organized in a mildly coherent way. Crafts, ways to find local home contractors. Wikis of the best way to browse the web. Best practices for life. Promote financial literacy, web surfing literacy, comparison shopping literacy, seo avoidance literacy. Make it easier to navigate the plague the modern web has become, and get people directly to useful things. In a way, designed with purpose and experience in mind.
In the "This is why we can't have nice things category" it's sad to see yet another encrypted file-sharing service that is inevitably shut down when someone starts abusing it to host malware or child porn.
Well, maybe lockwise might be ok, but I already have a password manager.
The moral panic almost inevitably tilts the scales towards [insert technology name] not working for anyone, rather than allowing bad guys use it publicly. So bad guys use it privately, and good guys... well, they can also use it privately, if they are tech-savvy enough. Otherwise, tough luck.
It’s not really a moral panic so much as it’s damaging to Mozilla’s reputation.
It doesn't matter whether the response is due to a moral panic or an attempt to protect their reputation. The end result is the same - reduced public availability of <insert technology here> while the bad guys generally continue using it the same as before.
Until trust is solved, running and using such a service remains problematic. It needs not be solved via content inspection, though; if I could verify the sender, I won't care about phishing links (and such links would cease to be useful for scammers and disappear). But this is a separate significant undertaking.
Sigh.
I see you worked on Send, and am surprised that you'd comment on here in such fashion about the decision-making to not charge for Send.
No file size limit.
Downside is that the sender, or someone else who has completed the torrent download, must keep the page (or their WebTorrent client) running for the share link to work.
A couple of good options.
Was there any angle at play other than releasing it? It was a great feature and even a small fee would've been more viable than freemium only.
I like Firefox, but I worry about the direction the Mozilla Foundation are taking. At least it's Free Software.
WebWormhole: WebRTC encryption, direct data transfer, large file support, browser and command line. Looks more versatile than the others. Has not undergone security review yet.
https://github.com/saljam/webwormhole
Magic Wormhole: Data relay required (public relay is often slow), mainly command line.
https://github.com/warner/magic-wormhole
https://magic-wormhole.readthedocs.io/
croc: End-to-end encryption, data relay required (I think), command line only.
https://github.com/schollz/croc
https://schollz.com/blog/croc6/
File Pizza: WebTorrent, seems to load entire file into RAM, browser only.
https://github.com/kern/filepizza
Snapdrop: WebRTC encryption, local sharing only (I think), browser only.
> While saying goodbye is never easy, this decision allows us to sharpen our focus on experiences like Mozilla VPN, Firefox Monitor, and Firefox Private Network.
Since Edge is basically Chrome with Microsoft's telemetry baked in that means that your browser choices will either be the one made directly by an ad company or Chrome repackaged by some other company that just wants to pipe the browser telemetry back into their already egregious OS telemetry pipeline.
It is definitely time for a fork or a fresh start with actual privacy, security and simplicity in mind.
Imho all solutions which require a webserver somewhere are doomed to fail at some point, or as in this case can be discontinued.
P2P tools should be client only with no servers at all to survive time and provide independency. Tools on their own don't matter either, but protocols like BitTorrent do.
Popup on the website
> This project repository has no relation with the service at https://transfer.sh that's managed by https://storj.io. So far we cannot address any issue related to the service at https://transfer.sh.
But the popup on transfer.sh suggests emailing hello@dutchcoders.io.
Listen to the developers and implement API. Firefox web API implementation is so far behind from Chrome. It is saddening.
Sell and bring values to developers. They are your most likely customers, not the general public.
Isn't it absurdly incompetent of them not to foresee this?