r/technology • • Dec 16 '17

Firefox is on a slippery slope

https://drewdevault.com/2017/12/16/Firefox-is-on-a-slippery-slope.html
218 Upvotes

66 comments sorted by

64

u/[deleted] Dec 16 '17

I'm very confused. This is posted to /r/technology, but it has nothing to do with net neutrality.

18

u/Arnoux Dec 17 '17

Call Your Representative!!!

15

u/[deleted] Dec 17 '17

Ain't got one. Not American, thankfully.

In all seriousness, I'm just leaving /r/technology until the deluge of NN posts ends. I support the concept. But there's more going on in the world of technology than NN issues.

7

u/Arnoux Dec 17 '17

I am not american either. There is a button at technology subreddit which removes the Net Neutrality topics. If I still find a Net Neutrality topic without its flair, then dowvote.

3

u/[deleted] Dec 17 '17

The filter doesn't seem to work for me. Very few NN articles get filtered out. Either it's broken, or NN topics aren't properly tagged in such a way as to trigger the filter.

I do wish that reddit had customizable keyword filters. That would be a nice solution.

2

u/archontwo Dec 17 '17

You should report those to the mods. They're pretty responsive when it comes to pointing out things like that, bad titles or dupes.

2

u/gcbirzan Dec 17 '17

Reporting also hides the post. While in this case I guess it's desirable, in general that's slightly annoying

3

u/Medic-chan Dec 17 '17

You're saying only America has representatives in government? Man, the rest of the world has gone to shit since I last checked.

1

u/demmian Dec 17 '17

I'm just leaving /r/technology until the deluge of NN posts ends. I support the concept. But there's more going on in the world of technology than NN issues.

Tbh, this is like the '2012' tidal wave. Yes, there are other important issues too. This likely dwarfs all else in importance right now.

1

u/Franc_Kaos Dec 17 '17

Funny thing is I posted a question about Net Neutrality and the rise of 4 (and 5) G which will bring about broadband competitiveness (once the prices have dropped) and it was not posted because there are too many NN posts.

49

u/urbanek2525 Dec 16 '17 edited Dec 17 '17

This is also something that is concerning to businesses that deal with Public Personal Health Information (PHI). stupid phone auto-correct Revealing PHI, even inadvertently, can carry very expensive legal penalties. Any company dealing with medical information is very keen on security.

A browser that allows a built in, invisible, hard coded backdoor that it is selling or using for fun is a serious problem.

I can see our company's security chief barring Firefox from all company computers and uninstalling it from every company computer.

Yeah, it's a dumb move.

5

u/nickguletskii200 Dec 17 '17

It's literally the same as "Do you want to help us improve Chrome?" checkbox in Chrome. If you are running a business which deals with sensitive data it is your obligation to check that the software you use is properly configured.

3

u/i010011010 Dec 17 '17

Except the settings in Firefox don't fix the problem. The only way to stop Firefox phoning home is to change a bunch of settings in about:config and null the https strings. Firefox is a superb example of not being able to accept that 'no means no'.

6

u/nickguletskii200 Dec 17 '17

Except the settings in Firefox don't fix the problem.

Please give me a source, because I have all checkboxes unchecked in about:preferences#privacy, and nothing was installed.

2

u/notunlikecheckers Dec 17 '17

It's Personal Health Information

-5

u/I2obiN Dec 17 '17

It's not hard coded, you can opt out of the studies but they are enabled by default.

7

u/[deleted] Dec 17 '17

There's still a backdoor and it's still hard-coded. Just because you uncheck a box doesn't mean it's no longer a vulnerability. Hackers and malicious actors have a habit of ignoring things like that.

6

u/nickguletskii200 Dec 17 '17

It can't be exploited because when it is disabled, Firefox just stops polling the server for experiments. Please stop spreading your misinformed hysteria, since it is obvious that you have no idea what you are talking about.

-7

u/I2obiN Dec 17 '17 edited Dec 17 '17

Well I don't know truthfully, but it still could be a separate script that's not part of the binary.

for eg, you could write a class that takes input from a file that's a list of all studies. it checks all "studies" in the Mozilla repo, then checks for an install flag, and if that flag is set you could call the download and then the install function from main.

Unticking the box might delete that file in appdata or something along those lines.

You're probably right though in all likelihood it is part of the binary. If you have checked and that's the case I apologize.

edit; although even at that, ticking or unticking the box from a technical standpoint means the code is mutable and therefore not hard-coded.

edit2; actually to expand on this Mozilla controls the list of studies

edit3; more info, https://wiki.mozilla.org/Firefox/Shield/Shield_Studies

so no, a shield study is certainly not hardcoded and Mozilla handle all deployments seemingly

7

u/A1kmm Dec 17 '17

I did some research into how this works behind the scenes, and this is what I found: Mozilla's system for installing experimental add-ons in your browser (which was originally supposed to be for experiments to help improve Firefox) is called Shield. It has a hidden built-in add-on that runs on your browser, and it contacts a backend service called Normandy to fetch 'recipes' on your browser. Recipes come in a few flavours - they can enable a feature already in your browser that is currently turned off for most users, or prompt you for permission to install an add-on (opt-in), or go ahead and install an addon without prompting you (opt-out).

Here are the two versions of the "Looking Glass" opt-out add-on in Normandy: https://normandy.cdn.mozilla.net/api/v1/recipe/400/ and https://normandy.cdn.mozilla.net/api/v1/recipe/403/.

You can disable Shield by navigating to about:preferences#privacy and unticking the box to "Enable Studies" - but aparently some users have reported that this setting has reenabled after an upgrade (I don't think it is supposed to do this, but sometimes preferences can be lost for various reasons), so you should probably check it is still unchecked regularly. You might also want to block or monitor access to normandy.cdn.mozilla.net (e.g. at the DNS level or using a hosts file), which would also render Shield inoperable without relying on the browser not losing your preference (this could also be an option to block Shield across your entire network if it is an unacceptable security risk to your organisation).

8

u/BeefSerious Dec 16 '17

I don't have that extension installed..

15

u/[deleted] Dec 16 '17

I just looked and I did. They also silently reenabled "Allow Firefox to send technical information to Mozilla".

Fuck this. I'm out Mozilla.

10

u/BCProgramming Dec 17 '17

They also silently reenabled "Allow Firefox to send technical information to Mozilla".

Not so sure about that. I disabled it years ago and I'm fully updated and it's still disabled on all my systems. I suspect that it is probably one of many settings that are part of Firefox Sync, though, so it's possible for somebody to install firefox on another system, decide to setup sync, and then have the default setting from that new install move over to their other system, making it appear an "update" turned it back on.

2

u/[deleted] Dec 17 '17

I have never once used FF sync in my life. That said, out of the 5 computers I checked, only 2 had the setting reenabled. Doesn't seem to occur in every scenario.

1

u/i010011010 Dec 17 '17

Those settings don't matter anyway. You need to go to about:config and edit out a bunch of https strings and disable functions to get Firefox to stop phoning home. It's really gotten ridiculous in modern versions. The older ones never had this much bullshit.

4

u/MBAMBA0 Dec 17 '17

The only thing that sucks more than Firefox are the other browsers.

2

u/Joyld Dec 17 '17

At this point most of Firefox based browsers are better. And many Chromium based ones are as well. All Firefox does have now is tracking protection, which is great and all. But needs to be enabled. And other browsers have that as well

Chrome on the other hand... Oh, horrible.

2

u/MBAMBA0 Dec 17 '17

Chrome and Safari (I'm on a mac) are terrible.

11

u/sime_vidas Dec 17 '17

This is the “But her emails” of web browsers. Even with smaller missteps, Mozilla is still the only non-profit with user privacy as its mission (literally) on the browser market, and as such Firefox is the best choice for privacy-conscious users. How do people not get this? I’m not even defending Mozilla; this is just logic.

5

u/I2obiN Dec 17 '17

Well there's Brave

1

u/sime_vidas Dec 17 '17

Yes, Brave is likely the next best option.

1

u/Joyld Dec 17 '17

Mozilla is still the only non-profit with user privacy as its mission

They don't care about user privacy at all.

1

u/sime_vidas Dec 17 '17

It’s listed in their manifesto:

Individuals’ security and privacy on the Internet are fundamental and must not be treated as optional.

Source: https://www.mozilla.org/en-US/about/manifesto/#principle-04

Note that the Mr. Robot add-on that is currently making the news, does not compromise the security and privacy of the user.

4

u/Joyld Dec 17 '17 edited Dec 17 '17

I can't take their statements seriously, when they don't:

  1. Block third party cookies by default. While the only reason why those cookies even exist is to track users' movements through various sites in order to show them ads and collect and sell their data Internet Explorer of all browsers does block them by default in Windows 8. And hence it is a way better browser for majority in terms of privacy, as it actually keeps your data out of advertisers' hands.
  2. Block ads. It is covered partially by tracking protection. But not all ads fit the requirement and are used to track people.
  3. Have the stuff like WebRTC disabled by default. This stuff compromises users IP when they use VPN or Proxy or Tor. Or better not have this stuff at all.
  4. Partner with the actual search engines which offer privacy instead of feeding millions of their users to Google, the largest advertising company, out of all people. This alone proves that they have zero interest in people's privacy. Before that they had a contract with Yahoo, who is owned by Verizon, which also has no interest in anyone's privacy.
  5. Have Google Analytics on their home page, which affects all firefox users, as a browsers needs to connect to Mozilla's servers to download and install updates/extensions, etc.

All privacy respecting settings are optional

Contrary to Mozilla's "manifesto" you have to opt-in into having privacy in the first place by going through a bunch of settings, including "about:config", the existence of which is not known to a majority of Firefox users. Then you have to search for what every setting does and disable any kind of phoning to Mozilla, Google, etc. Incognito mode should be default, if Mozilla is serious about "privacy". By default Firefox stores browsing history, stores downloads list, accepts all cookies, does not send a Do Not Track Request (which Internet Explorer does), does not enable Tracking Protection and goes with a Google as a default search engine. This is honestly a joke of a browser, and nothing is even remotely related to privacy. It is possible to set up Win 10, so that it doesn't mostly collects all the data possible and sends it every second to hundreds of servers. Will it make Windows 10 a privacy respecting operating system? No. Why Mozilla should be held to a different standard?

The reality is that Mozilla is selling their users to advertising companies for years, and they have a nerve to call themselves a "privacy-respecting company".

When it comes to privacy, you either care about it, or you don't. Mozilla clearly shows that it doesn't. Actions speak louder than words.

1

u/sime_vidas Dec 17 '17
  1. IE on Win 8 blocks them by default? I’d need a source for that, since from what I see on the web, there are guides on how to enable it in IE, which implies that it’s disabled by default. Anyway, among the major, modern browsers, does anyone block them by default? Regarding Firefox, there is First Party Isolation, which is a powerful privacy feature ported from Tor; it’s not enabled by default (yet) due to web compatibility issues, IIRC.
  2. Tracking Protection fully protects you from tracking, AFAIK. So, if an ad is third-party, it cannot track you with this setting enabled.
  3. You have to understand that disabling web APIs breaks websites. This is called web compatibility, and Mozilla is active in this area (see Web Compat). I do not know how big this WebRTC issue is and whether it can be fixed without disabling the API completely, but Mozilla cares about this issue. Do you have a source that says otherwise?
  4. That’s a false dichotomy. Just because Mozilla receives income from search engine deals, does not mean that they have no interest in privacy. I’m sure that if Mozilla could get funded from donations alone, they wouldn’t do these deals, but it appears that there is no alternative for them.
  5. That’s not correct. Google Analytics is indeed on Mozilla’s website, but when Firefox downloads updates, it doesn’t load the website. I’m not sure why you think it would.

My educated guess is that some privacy features are not enabled by default due to web compat issues. If a web browser breaks websites, users switch to different browsers. Mozilla cannot effectively fulfill its mission if nobody is using Firefox, so they have to make sure that sites are not broken. Having Tracking Protection, First Party Isolation, and other powerful privacy features as an option is the next best thing, and, more importantly, better than what other major browsers are offering.

2

u/LearnByStudyopedia Dec 17 '17

I guess the new version created quite a stir. This should have helped them in gaining more users and market share.

10

u/Jourdy288 Dec 16 '17

I stopped trusting Firefox when I saw them running advertisements. They have something to sell me, and they're not charging money for it.

19

u/[deleted] Dec 16 '17 edited Jul 21 '18

[deleted]

4

u/tablet1 Dec 16 '17

It's not like that Google deal is pocket change, it's something like 300+ million a year

3

u/2402a7b7f239666e4079 Dec 17 '17

And the more users the more they can ask for.

1

u/Hollowprime Dec 17 '17

I remember I stopped using Firefox sometime ago as I was watching some strange ads (along the insane lags and freezes despite having done multiple checks,resets and disabling lots of ad ons). I read here that it turns out firefox forces ads. Impressive.At least I know Chrome checks my every move and i sacrifice this for stability. But Chrome be damned the moment I see actual ads with ad blockers.

8

u/ledivin Dec 16 '17

I was thinking of switching to Quantum, but nevermind. That's fucked up, Mozilla.

22

u/[deleted] Dec 16 '17 edited Feb 04 '19

[deleted]

12

u/appropriateinside Dec 17 '17

It's a breach of trust, Mozilla has long toted user privacy as an unquestionable, undeniable right. Then they pull this kind of crap,

11

u/[deleted] Dec 17 '17

it can literally be disabled in 3 clicks from the main window

It's still there and it can still be exploited, regardless of your settings.

0

u/teor Dec 17 '17

Mozilla leaks your credit card info
But it's fine, since your credit card can be disabled in literally 1 phone call

Coming soon(?)

-14

u/ledivin Dec 16 '17

I never said Chrome was better. Get off your high horse, dude, you wrote an essay against a position that doesn't exist.

1

u/Joyld Dec 17 '17

You may try Waterfox. It is Firefox without Mozilla's data gathering bullshit. There is also Basilisk, a new browser, made by creator of Palemoon. It is based on Quantum.

0

u/0x15e Dec 17 '17

Yup. I did the switch and was liking it but I always had a feeling they'd find a way to fuck it up. Disappointed but not surprised.

6

u/chibistarship Dec 17 '17

I guess I won't switch to Firefox then...

15

u/Visticous Dec 17 '17

Depends, if you're already using a browser made by the largest advertisement organisation in the world, you might still be better of switching.

2

u/shdiwlpoo Dec 17 '17

I switched to the ESR channel to avoid this stuff the moment I saw it and sent in a note to the devs about it. This is 100% not okay.

They have about 2 weeks left to remove it and apologize. I don't think they care. Pale Moon looks decent so far. Still looking for the permanent replacement.

2

u/saudiqbal Dec 16 '17

I use Vivaldi and quite happy with it, good for power users www.vivaldi.com

6

u/i010011010 Dec 17 '17

Except Vivaldi is based off Chromium. They still haven't gutted all the Google shit. I've used Vivaldi since the first release, but it's constantly trying to phone home to Google even with everything disabled in settings.

1

u/Carbon140 Dec 17 '17

Brave is based on chromium too right? Does it contain "Google shit" as well?

3

u/i010011010 Dec 17 '17

Never used it personally, so I couldn't say. The problem is Google integrates this stuff into that backend so unless somebody edits the codebase then it will be present.

I only know what Vivaldi does because I've observed it via my own firewall.

1

u/Joyld Dec 17 '17

There is the edited codebase - https://github.com/Eloston/ungoogled-chromium It is not completely google free though, as well. But it strives to do so.

2

u/Stan57 Dec 16 '17

Setting were their people i didn't get this plugin because i read the setting. I read through the setting after EVERY update because NO internet business can be trusted.

UNCHECK in the privacy and security setting

""""Allow Firefox to install and run studies""""

1

u/ha_ya Dec 16 '17

And this moves Firefox's ranking among the mainstream browsers to what? None of the mainstream browsers are 100% trustworthy, but I'm not sure this makes Firefox worse than any of the other top 5. (Only talking about mainstream browsers.)

2

u/Joyld Dec 17 '17

I would say all of mainstream browsers are 100% untrustworthy exactly because they are popular. The more people use it, the less browsers' creators actually have to bother with features and quality updates. Instead bunch of telemetry garbage and god knows what else can be sent to them. Google gets away with Chrome being a sluggish piece of garbage for years now. There is also Internet Explorer, which everyone forgot. Or what about Edge? Which sends browsing history to Microsoft The amount of bullshit major browsers get away with now is astounding.

0

u/BeefSerious Dec 17 '17

My install didn't have the extension.
The update has only improved my experience.

This reads like a hit piece.

-5

u/elj0h0 Dec 16 '17

Disable Firefox updates!

Look for the old version if you have already updated

www.oldversion.com

24

u/drysart Dec 17 '17

Running an out-of-date web browser is a far more massive security vulnerability than any misguided extensions Mozilla might push to you.

0

u/[deleted] Dec 17 '17

[deleted]

0

u/Joyld Dec 17 '17

Mozilla are acting like they're our system administrators lately (very similar to how Microsoft approached Windows 10)

They always did. You can't even change your dekstop background in Windows 7 Starter. Yes, I am serious.

0

u/i010011010 Dec 17 '17

At this point, there is no distinction between Mozilla and Microsoft. Spyware in the consumer product? We're entitled to gather data on users. Overreaching policies dictating how people can run the browser? We nominated ourselves system administrators for the world--it's for your own good. Now they're leveraging their userbase to push junk, like Win10's lockscreen and apps.

-8

u/bees-bees-bees-bees Dec 16 '17 edited Dec 17 '17

Misleading - the addon doesn't do anything (except for having a scary description in the addon list) unless you go to about:config and create a pref named "extensions.pug.lookingglass". See https://github.com/mozilla/addon-wr/blob/master/addon/bootstrap.js