Our Year in Review: How we’ve kept Firefox working for you in 2020
blog.mozilla.org
blog.mozilla.org
This is being done with the best of intentions but browsers scaremongering over HTTP sites as if they are dangerous is a bad thing. There is more to the web than commercial transactions!
Human people cannot feasibly be cert authorities. Only corporations can. When browsers will only display sites that are authorized by corporations we're eventually going to be in big trouble. Yes, LetsEncrypt is a benevolent corporation, yes there are even options beyond LE, but as we know from the dot org fiasco as long as there is potential money to be made these benevolent dictorships will eventually go very bad. And that's ignoring all centralization making a very juicy target for government censorship.
Encrypt, yes. But also allow plaintext. The potential for a down-grade attack on a "secure" site is worth far less to the world than being able to communicate person to person without a corporate intermediary approving every bit.
There is absolutely no reason not to have your site functioning over HTTPs these days, except negligence.
With Firefox for Android, it doesn't permit you to connect a machine on your own LAN, even if you try to add an exception.
With stock browser it does.
I'm sure there are better ways to serve a file between machine and phone, but that python snippet was my easiest goto.
No more
Works without a problem (I just tried python -m SimpleHTTPServer). You just have to type out the http://-part explicitly. Wow that would be annoying if they dropped http completly.
I just actually use synced storage (Synology Drive from a Synology NAS), so I would probably use a Dropbox like service for that functionality.
There's an app called droid transfer that basically does what you did with python (setup a server and have a simple download client), and there's also wireless ADB (which will require you to use the USB cable for the initial setup)
how would that be any better?
HTTPS is not just confidentiality - security is confidentiality, integrity and availability.
However, there's no way to ensure the files we download are created by who they say they are. A domain for example can change hands and existing links say on HN can be loaded with unexpected, potentially malicious, content. Same for hacked servers.
IMO we need some form standard page signing to enforce actual integrity of information, not just transport. I made a proof-of-concept Web Extension to show how that might be possible using PGP [1]. Of course PGP has its own issues but it's just an experiment.
This is the same argument technique being used when people say, "Oh, but you can MITM HTTP!" Yes, a target attack of something beyond your webserver is bad. But it applies to HTTP and HTTPS.
[0] https://letsencrypt.org/2020/02/19/multi-perspective-validat...
2. You're overthinking this. I'm not talking about hijacking established sessions. I'm talking about never letting the authentic session start in the first place.
As soon as the attacker controls the DNS resolver it doesn't matter what security you have in place. The bank and the LE servers and all that can be perfectly secure. But if the client is going to the wrong IPs they never will interact with them. They'll only interact with the perfectly valid HTTPS hosts the attacker sets up.
If we're talking about SSL Stripping, then 1. we're back to you needing to control the network, so apparently my goalposts are exactly in the right place, 2. that is at best partially effective (AFAIK, requires the victim to start from a non-HTTPS page, so again, we really want 100% of sites on HTTPS), and 3. that works specifically by getting the victim back onto insecure HTTP, so if you need that then it's proof of the effectiveness of HTTPS.
I am giving examples of how that class of attacks is not mitigated by HTTPS.
I am not talking about SSL stripping. I am talking about not even letting the client talk to the remote host because in the scenario where you MITM you have control of the network.
You could redirect the user to a HTTP site, but 1. that can be defeated by adding the domain to hsts preload list 2. This isn't replacing content of HTTPS site, but replacing HTTPS site with a HTTP one.
To actually pull your attack off, you'd need to add your own root certificate to the client device (which means you either tricked the super into doing it and could've as well tricked them into letting you take control of their device anyway, or actually had control of their device - in both cases MITM is pointless at that point), or trick a CA into issuing you a certificate for a domain you don't own/steal a CA's private keys - both of which are things that can easily kill a CA (see DigiNotar, which stopped existing same month the security breach was reported), and therefore obviously aren't easy to pull off.
Besides installing a Let's Encrypt cert is straightforward these days.
Someone not attesting the validity of the data served from their site is, effectively, lying if they provide a cert.
Why? HTTPS is an open protocol anyone can implement.
Aside from that, what is the purpose of this comment supposed to be? (The general tone reads as if its meant to refute the parent; did you intend it to be a reply to chrisseaton instead—and thus a defense of the HTTPS-complicates-things position?)
That's correct, some CAs issue certificates for public IPs. You're never ever going to get a cert for a private IP, since these are not globally unique.
(In any case, I'm totally mystified about why my own comment that includes that link and corrects the untrue statement about it not being possible possible to get certificates for IPs was deemed to offend someone's sensibilities. Surely the offense, if there is one, is in the comment that makes an outright, verifiably untrue claim?)
I wasn’t refuting jackewiehose‘s comment about HTTPS hassles. I was just sharing a specific example of a hassle.
One interesting find was that close to 100% of all email tracking links are still on HTTP. None of the major email providers support HTTPS easily for those.
Likewise they removed support for unsigned add-ons. So you can't just write a small private add-on without sending them your private(!) code. Who needs freedom when you are so well "protected" :-(
OTOH localhost is finally exempt from the "not https" warning.
https is helpful but also a tool for more centralized control.
- Laying off 25% of their engineers
- Investing in a 400% increase in leadership salaries and bonuses during record-low market share
- Adding more advertising to an end-user application
- Sending all of your browsing history to Cloudflare
- Launching a VPN grift which sends all of your data to another third-party (and charges you for the pleasure)
- Terminated Firefox Send and Firefox Notes
- Failed to open source Pocket, 3 years since their promise to
- Removing browser features (tab groups) by factoring them out into extensions, then
- Breaking the extension API such that such extensions are no longer possible, then
- Say you'll add new extension APIs to allow such features but actually don't implement anything for several years (https://wiki.mozilla.org/WebExtensions/TabHiding / https://bugzilla.mozilla.org/show_bug.cgi?id=1332447)
- Separately, break all extensions on the mobile version of firefox and then decree that the only extensions allowed on mobile must be specifically whitelisted by Mozilla
https://blog.mozilla.org/addons/2020/09/29/expanded-extensio...
That was done after much screaming, and there are no plans to ever bring that out of Nightly.
(I'm not saying that is part of the deal but I don't know what more Google could realistically hope for...)
Again, not something I actually believe, but the presented position is at least internally consistent/valid.
And the elephant in the room is the tiny and ever-shrinking user base. Not only do they fail to confront this single, existentially threatening fact, but they don't even bring it up.
It's like the titanic captain listing all the features which will keep you comfortable for the second half of the voyage.
The world would be better if firefox could succeed, but it's increasingly difficult to even imagine what this would look like, or how it could come to pass.
That concerns me on a technical level; Mozilla-the-organisation now has control over the tiles on the default New Tab page which people are accustomed to using as bookmarks.
It's feasible that a bad actor could use that vector to replace valid URLs with nefarious ones as part of targeted phishing.
The Mullvad (VPN) thing is completely optional and you have to opt in by paying money. You are not required to use a VPN. I'm not sure why anyone is even remotely upset by this at all. What's the issue? Honestly, I don't understand.
Both these companies have good track records. I'm not sure what the issue is here. #2 seems to be my only concern.
Source? The last financial release detailed 2018, one year after Mozilla's highest revenue year. Additionally, their CEO resigned and I doubt Baker got a raise at all, certainly not for more than Chris Beard's salary.
The data is only as recent as 2018, indeed, but I don't have any reason to suspect that they've corrected course. It's an especially bad look when they're also laying off large swaths of their staff.
Also, that huge spike on the chart was roughly $4.5 million of the over $100 million in increased revenue.
... after spending years saying that the relationship with Google regarding search royalties was a serendipitous one that involved getting paid for a decision that was the right thing for users whether money was changing hands or not, and that the default search engine spot wasn't actually for sell.
That lie is not unlike their carefully crafted PR statements that were intended to mislead people about the financial arrangement regarding the Pocket partnership. Those efforts turned out to be so successful that they hoodwinked many of Mozilla Corporation's own employees—who interpreted the statements to mean that there was no financial incentive, just as it was intended to be interpreted by the general public. Then those employees began showing up on places like HN and started saying explicitly that there was no money changing hands, even though that's not what the PR statements ever said and reality actually differed.
What? The default search engine is unambiguously for sale, that's what Google (and other companies depending on your country) are buying. And it was the right decision to sell it to the highest bidder to fund development, when Yahoo bid more than Google they sold it to Yahoo.
I genuinely have no idea what point you are trying to make.
The point, as already stated, is that people who were official mouthpieces for Mozilla said for years that the default search engine simply wasn't up for sale to just whomever would pay for it. That it pointed to Google because Google's search engine was the best search engine for Firefox's users. Just like Google was the default search engine before Mozilla ever signed a deal. Just like Wikipedia was added to the searchbar without anyone paying to make it happen. That any royalties were icing on the cake. (See "serendipitous" in the previous comment). What's hard to understand about this or the earlier comment?
This is untrue. They openly stated they sold it to Google in 2008, and in 2011 a bidding war between Google, Microsoft, and Yahoo saw the price triple from 100 million to 300 million.[1]
Maybe at some point following a contract they had a generic "Google was the best choice" PR statement, but they've never hid that it was up for sale to whoever wanted it or that it made up most of their budget.
And even if they did say the royalties were icing on the cake, what would be wrong with then changing their policy to generate as much money for development as possible?
http://allthingsd.com/20111222/google-will-pay-mozilla-almos...
The staff. The staff, who were subsequently fired.
While I won't claim the leadership has been truly outstanding, I think the extreme criticism of their salary is unwarranted.
The only bad thing about the layoffs is that Mozilla leadership was shitty enough to do it during the middle of a pandemic. At this point though, keep it coming. It's been a bittersweet experience watching the tide turn against Mozilla over the last year, as the popular perception of it has only just now begun to align with how unworthy of an organization it has been for years already.
On the up side, it remembers where you were and returns there when it wakes up again. Still less bad than Chrome.
When it pops up two (count 'em, 2) dialog boxes announcing it has crashed and would you like to have it re-started, that seems pretty unambiguous. It happens about every day, lately, often when I click the "new tab" button.
If Firefox need to cut costs to survive, this is part of keeping Firefox working for us.
> - Sending all of your browsing history to Cloudflare
Are you referring to DNS over HTTPS? That's not all my browsing history, though it is still more than I want going to CloudFlare.
See also:
>Investing in a 400% increase in leadership salaries and bonuses during record-low market share
Please get your shit together, Mozilla. But it seems like their model for the future is to sell worse versions of 3rd party services with their logo ...
A little bit of reasonable descent could give Mozilla a lot of authenticity, but they seem incapable of that level of humility.
Occasionally I see private blog/reddit/tweeter posts from employees, but never in an official manner, and always with a hint of trepidation that they could be fired for speaking out.
[0] - https://foundation.mozilla.org/en/blog/fellow-research-decen...
[1] - https://foundation.mozilla.org/en/campaigns/regrets-reporter...
Would you really be OK with donating to a cause whose major service is their most visible one and for your money to instead go into mostly, completely different things? I'm not and therefore I won't donate to Mozilla. I donated to other projects with clear goals, limited scope and visible results - there are quite a few of those. If the firefox team decided to split from Mozilla or a team decided to build a browser upon a new browser engine (like quantum or whatever that new rust browser engine is), I'd be glad to donate directly to the project.
Mozilla leadership has proven that they are too scatterbrained and insensitive to reality to be trusted with donations. Their priorities aren't aligned with the ones stated by the org. I try my best not to give money to people like that.
I honestly don't know if how much each 1$ donated to the Mozilla Foundation contributes to Firefox development, if at all.