Firefox 3rd Party Installer Campaign – Mozilla Community Portal
community.mozilla.org
community.mozilla.org
> Your report will help us identify the attributes and traits of third-party websites that offer Firefox download outside our official source, so we can work with them towards better distribution practices – eventually, leading to better security, privacy, and user experience for Firefox users.
It's also possible that what they really mean is that they're going to go after these providers for trademark violations [0] like what happened with Debian [1].
I'd love to be in a world where I can trust Mozilla to generally do the right and honest thing, but I'm having a hard time imagining what other form this "work[ing] with them" could take, and it makes me very uncomfortable that they're not forthright about the details of their plan when asking users to help them identify targets.
[0] https://www.mozilla.org/en-US/foundation/trademarks/policy/
[1] https://en.m.wikipedia.org/w/index.php?title=Debian%E2%80%93...
That people's instinctive response to pretty much anything coming from the big players is mistrust and backlash is entirely understandable. It's the result of learning from experience. On the whole, the industry has burned a significant amount of trust and benefit of the doubt.
https://www.theregister.com/2024/06/18/mozilla_buys_anonym_b...
So, yep, my trust has gone to zero. It doesn't seem difficult to not become an ad company, but money corrupts.
Are they
1. Gods who simply ship bug free code and can't understand why mortals like us need telemetry to do the same.
2. Non-software people who've never shipped software to devices they don't control, just posting on HN for fun.
Valuing privacy, I can understand, I'm on board with that. It's when they take it to extreme, weird lengths, where they say that telemetry could allow the VSCode team at Microsoft to deanonymise them and then ... what exactly? It's gotten to a point where software like VSCode can't even be discussed on HN without the entire thread just being about telemetry.
> 1. Gods who simply ship bug free code and can't understand why mortals like us need telemetry to do the same.
> 2. Non-software people who've never shipped software to devices they don't control, just posting on HN for fun.
I'm a user who thinks internal testing and user bug reports is good enough and doesn't like my computer telling other people how I use it. Doubly so when its software that explicitly bills itself as caring about privacy.
What people don't like is that lots of modern tech employees apparently don't understand consent, and just assume it's okay to spy on you and take whatever personal data they want.
It is very hard to beat ninite.com for installing everything at once on a new pc.
Something that's been on my mind in terms of user reporting is while firefox puts a large emphasis on privacy, what proportion of the userbase conceal their user agent and disable/minimize telemetry
And for that matter Action1 is likely better if I am doing this on a regular basis.
Honestly Microsoft's biggest miss is not having a GUI for it. (The Windows Store does act as a software source for it, but the primary software source is separate and much larger without the Windows Store overhang.)
If they implemented 1. An Apt like interface (it's kinda not amazing as is) and 2. a GUI, it could see mass adoption overnight. As long as they don't fuck it up or be overbearing on who gets to be included. And no paid software should be listed by default; at least not without a trial and a warning that it's paid software.
This is directed at predatory SEO sites that unofficially bundle Firefox installers with adware for example.
Does anyone know where they get this data from?
about:telemetry#environment-data-tab_partner
[1] https://www.reddit.com/r/sysadmin/comments/b2j16p/til_chromi...
This data comes from attribution data (https://firefox-source-docs.mozilla.org/browser/components/a...) and the installation ping (https://firefox-source-docs.mozilla.org/toolkit/components/t...).
Most of the Firefox installers/packages for Windows & macOS on https://archive.mozilla.org/ have a sentinel value for attribution data that indicates "this is a build that Mozilla produced and uploaded to archive.mozilla.org", and is considered to be from a known source. (Anyone that downloads directly from archive and redistributes will maintain this data and also be considered known.)
Downloads that flow through www.mozilla.org and meet certain conditions (most notably, Do Not Track being disabled) will have this data overwritten at download time with UTM parameter information (see the first link above). These are considered to be from a known source as well (our own website!).
I'm not an _expert_ on the analysis side of this data, but I believe that install pings that don't contain attribution data are considered "unknown". (There may be other cases that end up in the "unknown" bucket as well - I honestly don't know.) On Windows, there's a _shockingly_ high percentage of installs that fall into this bucket.
Or, at the very least, don't do the same stupid crap every other site does, aka: sniff my geo-ip and then opaquely serve me a specialized build without my knowledge. Just another thing on the list of reasons why i don't bother being a Firefox advocate anymore. There's so many basics not accounted for.
> A: On Windows, when you open the downloaded .exe file, you’ll see a pop-up with a “Verified publisher” name. If “Mozilla corporation” is the publisher you have an official installer, else it’s not.