Slashdot Mirror


Mozilla Slipped a 'Mr. Robot'-Promo Plugin Into Firefox and Users Are Pissed (gizmodo.com)

MarcAuslander shares a report from Gizmodo: Mozilla sneaked a browser plugin that promotes Mr. Robot into Firefox -- and managed to piss off a bunch of its privacy-conscious users in the process. The extension, called Looking Glass, is intended to promote an augmented reality game to "further your immersion into the Mr. Robot universe," according to Mozilla. It was automatically added to Firefox users' browsers this week with no explanation except the cryptic message, "MY REALITY IS JUST DIFFERENT THAN YOURS," prompting users to worry on Reddit that they'd been hit with spyware. Without an explanation included with the extension, users were left digging around in the code for Looking Glass to find answers. Looking Glass was updated for some users today with a description that explains the connection to Mr. Robot and lets users know that the extension won't activate without explicit opt-in.

Mozilla justified its decision to include the extension because Mr. Robot promotes user privacy. "The Mr. Robot series centers around the theme of online privacy and security," the company said in an explanation of the mysterious extension. "One of the 10 guiding principles of Mozilla's mission is that individuals' security and privacy on the internet are fundamental and must not be treated as optional. The more people know about what information they are sharing online, the more they can protect their privacy."

34 of 307 comments (clear)

  1. One step forward, two back by grasshoppa · · Score: 4, Insightful

    If they were trying to win back Chrome users, this is a pretty effective way to sabotage their efforts.

    I hope they were paid a shitload of cash for this little stun, because it's gonna cost them.

    --
    Mod me down with all of your hatred and your journey towards the dark side will be complete!
    1. Re:One step forward, two back by Dutch+Gun · · Score: 5, Insightful

      “Firefox worked with the Mr. Robot team to create a custom experience that would surprise and delight fans of the show and our users. It’s especially important to call out that this collaboration does not compromise our principles or values regarding privacy. The experience does not collect or share any data,” Jascha Kaykas-Wolff, chief marketing officer of Mozilla, said in a statement to Gizmodo. “The experience was kept under wraps to be introduced at the conclusion of the season of Mr. Robot. We gave Mr. Robot fans a unique mystery to solve to deepen their connection and engagement with the show and is only available in Firefox.”

      So, no apologies for those of us who spotted it, freaked out, and spent a bunch of time trying to figure out WTF this was, and if it was malicious or not.

      Seriously, on what planet do you essentially prank all your users with a stunt like this? I was actually pretty happy with Firefox after the Quantum update, as it went better than I was expecting. After that, I immediately turned off telemetry and experiments, because they've now abused my trust with this stunt.

      And now comes this statement, doubling down on their incredibly poor judgment. This is the last straw for me. If Mozilla had been the least bit contrite, I might have forgiven this. I've been using Firefox almost since it's inception 15 years ago. That ends today.

      --
      Irony: Agile development has too much intertia to be abandoned now.
    2. Re:One step forward, two back by TuringTest · · Score: 3, Insightful

      > After that, I immediately turned off telemetry and experiments, because they've now abused my trust with this stunt.

      If you had those turned on, how is this an abuse of your trust? You had given them permission to do anything with your browser. If you don't want anti-privacy measures in Firefox, don't turn them on.

      --
      Singularity: a belief in the "God" idea with the "demiurge" relation inverted.
    3. Re: One step forward, two back by sacrilicious · · Score: 2, Funny

      I don't find NPR any more credible (or less prone to propaganda) than Faux News, or any other tabloid.

      Yeah! And Roy Moore rocks! And Trump Rulez!!!! LIbral Media can suck my dickzzzzzz!!!!! Did I get that right, homeboy?

      --
      - First they ignore you, then they laugh at you, then ???, then profit.
  2. Re:When browsers jump the shark by Lisandro · · Score: 5, Funny

    "The Mr. Robot series centers around the theme of online privacy and security. One of the 10 guiding principles of Mozilla’s mission is that individuals’ security and privacy on the internet are fundamental and must not be treated as optional."

    So yeah, let surreptitiously install plugins on everyone's browsers.

  3. Does the plugin actually *do* anything? by gman003 · · Score: 4, Interesting

    So I disabled the addon as soon as I read the article, and I am legit mad that Mozilla would do this, but... what does the addon actually do? I didn't notice any difference before disabling it, and I've dug through all the links and nobody seems to be saying what it does.

    Even if it was just a blank addon, no effect other than putting what's essentially an ad into my addon list (pun unintended), that would be bad, but it would be less bad than if it actually disrupted the browser in some way.

    Mozilla's half-assed apology seems to indicate the addon only starts doing things once you "opt-in", with no mention of how or where one would do that. Which is probably the least evil way you could do this, I'll admit.

    1. Re:Does the plugin actually *do* anything? by bigdavex · · Score: 5, Funny

      The plugin downloads U2 albums.

      --
      -Dave
    2. Re:Does the plugin actually *do* anything? by unrtst · · Score: 3, Informative

      According to https://github.com/mozilla/add..., it does:

      * sends header "X-1057" to sites
      * if the page contains certain strings, it flips those strings upside down for 2-6 seconds and then reverts to normal (ex. "privacy" and "control"). It'll also put an on hover box on them with a link.

      Dunno if that's really the right plugin, test plan, or full list of what it does, but it was linked from the parents link, which was waaaay more to read than the above two bullet points. If someone sees the above and knows them to be wrong, please reply and correct me.

    3. Re:Does the plugin actually *do* anything? by Mal-2 · · Score: 4, Funny

      The plugin downloads U2 albums.

      With or without you.

      --
      How is the Riemann zeta function like Trump rallies? Both have an endless number of trivial zeros.
  4. Never seen it... by Kernel+Krumpit · · Score: 2

    Thanks for all the Headzup but I've never seen it in my Add-ons. And it's still not there in v. 57.0.2 64-Bit. Is this maybe just a US thing?

    --
    May the lies we live by make us strong, healthy, happy and wise - Kurt Vonnegut.
    1. Re:Never seen it... by Dutch+Gun · · Score: 4, Informative

      If you hadn't enabled telemetry and studies, you wouldn't see it. Also, given that it's some sort of marketing tie-in to Mr. Robot, it might very well be US only.

      --
      Irony: Agile development has too much intertia to be abandoned now.
  5. What Config Key Do I Disable/Delete? by ewhac · · Score: 4, Interesting
    So if Mozilla can remotely jam new extensions in to my browser without so much as a dialog, that means malicious actors with even fewer scruples will be able to do it in about a week. Short of firewalling all of mozilla.org, how do I turn this shit off?

    (I wonder if this has anything to do with the weird XSS blocking dialog NoScript threw three times earlier today. It was blocking an XSS attempt between two domains, neither of which was open in any browser tab at the time.)

    1. Re:What Config Key Do I Disable/Delete? by Dutch+Gun · · Score: 4, Informative

      Presumably only Mozilla has access to this sort of system. But then again, that's just an assumption of mine.

      You can turn this off in the Privacy section: "Allow Firefox to send technical and interaction data to Mozilla", and under that "Allow Firefox to install and run studies".

      It's the latter one that allows those experimental add-ons to be added and run. I had those both enabled, because I thought that Mozilla would be responsible in how it used them. Obviously, I was mistaken. So, at the very least disable the latter if you don't want more mysterious add-ons showing up. As soon as you uncheck that box, the add-on disappears.

      --
      Irony: Agile development has too much intertia to be abandoned now.
    2. Re:What Config Key Do I Disable/Delete? by Anonymous Coward · · Score: 2, Insightful

      (Sorry, can't logon from AC on this machine)

      I really don't mind phoning home anymore since literally everything does it. At least Chrome provides useful reasons for being online like url auto completion and integration with my google cloud stuff like remembering my bookmarks.

      What I REALLY FIND OFFENSIVE is when products (whoever they are, Google, Mozilla, Apple, whatever) install things without telling me, ESPECIALLY if they're written by a third party. I may trust Google, or Mozilla, but that doesn't mean I magically trust whatever third party they whored themselves out to.

      It may be an illusion that we control our PCs anymore. But any actor that intentionally violates that illusion (like Apple downloading a free U2 album to your phone) feels like a violation. It's like someone walked into your home while you were asleep and baked you a cake. "Hey, you've got a free cake! Why aren't you happy?" ... "Because you came in without asking while I was asleep!" and then these companies are asking us, "Don't you trust me?"

  6. Auto-update abuse by duke_cheetah2003 · · Score: 2

    You know it's crap like this that encourages end-users to find ways to block auto-updates, because of abusive use of it.

    Need to reel that BS in, it's not a good idea, auto-updates should be a good thing. Don't be muddying the waters any further, it's getting pretty obnoxious as it is.

  7. Re:When browsers jump the shark by KiloByte · · Score: 5, Informative

    Don't forget disabling all existing privacy extensions. Oh, and mails you get from Mozilla are pure gold: "Keep trackers off your trail" blah blah "evade tracking technology" blah blah "https://click.e.mozilla.org/?qs=e7bb0dcf14b1013fca3820..."

    --
    The creatures outside looked from Alt-Right to Antifa; but already it was impossible to say which was which.
  8. Re:"privacy-conscious users" by sgage · · Score: 2

    This, this, a thousand times this.

    Nobody cares about privacy, or really even about security, as long as they get their new fresh modern stuff.

    The dream of the web died years ago, and the dream of personal computing is dying right now before our very eyes.

    It was inevitable. There is nothing that the corporate shitheads can't co-opt, corrupt, and ruin - the genius of Capitalism at work.

    Oh well, it was fun there for a while...

  9. Re: When browsers jump the shark by Anonymous Coward · · Score: 5, Insightful

    Mozilla has no business installing add-ons without user consent, especially when it's done quietly in the background. This is the type of behavior that one would expect from malware, and it may well be illegal. I am seriously considering filing a lawsuit against the Mozilla Foundation under the Computer Fraud and Abuse Act.

  10. Re:The final straw. by sgage · · Score: 2

    Chrome? Chrome?! Out of the frying pan, into the fire. I will not have anything to do with any Google product whatsoever.

  11. Firefox Studies by zenbi · · Score: 5, Informative

    The extension was able to be installed if you had the "Firefox Studies" checkbox selected. To prevent Firefox Studies from installing extensions on your behalf:

    • Navigate to: "about:preferences#privacy"
    • Scroll down to the "Firefox Data Collection and Use" section
    • Uncheck the "Allow Firefox to install and run studies" checkbox (and the others, if you wish)
  12. Re:When browsers jump the shark by rudy_wayne · · Score: 2

    Mozilla justified its decision to include the extension because Mr. Robot promotes user privacy.

    Bullshit. They did it because they got paid by the producers of that TV show to do it. This is what happens when a company is totally dependent on advertising for their revenue.

  13. Disable Firefox "shield" studies. by fahrbot-bot · · Score: 3, Informative

    A little Googling leads me to think the Looking Glass add-on was installed via the Firefox built-in Shield Recipe Client Feature, also described here: Firefox/Shield/Shield Studies, which is documented as:

    Shield is a Firefox user testing platform for proposed, new and existing features and ideas.

    Shield Studies is a function of the Shield project that prompts a random population of users to help us try out new products, features, and ideas.

    I have this disabled via the following pref.js settings:

    // Disable Shield Recipe Client
    user_pref("app.shield.optoutstudies.enabled", false);
    user_pref("extensions.shield-recipe-client.enabled", false);

    --
    It must have been something you assimilated. . . .
  14. Re: When browsers jump the shark by retchdog · · Score: 2, Insightful

    well, yeah, of course they can be. i'm just wondering what you're going to show them as damages.

    --
    "They were pure niggers." – Noam Chomsky
  15. Re: When browsers jump the shark by omnichad · · Score: 2

    So if it was just a browser update with the same code it's fine, but as an add-on it's illegal. Sure...

    Look, the outcry is real and fair. But let's not call it illegal, because it's their software and you clicked to agree to updates.

  16. Re:When browsers jump the shark by rtb61 · · Score: 2

    Mozilla also have a pretty bad reputation for forcing stuff on people, a real clique arrogance. Your tabs, screw you, we want they where we want they, bugger your choice. Same as for appearance, like the old look, meh, we don't, new millennium style, don't like use IE suckers. They can be pretty bloody rude and like a lot of these types or orgs, a particular crowd worms they way in and it is all about serving their ego and fuck everyone else. Mozzilla certainly ain't what it used to be and it stinks of Google actively working to fuck up firefox in order to drive users to super invasive chrome, the chrome plated versions of Windows anal probe 10. The stink of the big shit at 'Alphabet' is string in this action, designed to damage Mozzilla's reputation and win a monopoly for chrome.

    --
    Chaos - everything, everywhere, everywhen
  17. Re: When browsers jump the shark by ShanghaiBill · · Score: 2

    I believe Mozilla probably can be sued under the CFAA.

    Anyone can be sued for anything. But you aren't going to do it. If you were someone actually capable of preparing and filing a lawsuit, you wouldn't be anonymously blabbing about it on Slashdot.

    Litigating a case like this could easily cost $100k. Justice isn't cheap. I doubt if you, personally, could show more than $1 in damages.

  18. Re: When browsers jump the shark by mikael · · Score: 4, Informative

    It seems to be a trend. I installed Chrome on a Linux partition and almost immediately, Yahoo tried to install their plugin into that browser.

    Not forgetting Canonical's spyware which sent your local search queries for command options to their servers. It's anonymized they claim - well it isn't if your ISP decides to do a man-in-the-middle attack and deep packet inspection with your data.

    http://www.omgubuntu.co.uk/201...

    --
    Vintage computer adverts: http://www.vintageadbrowser.com/computers-and-software-ads
  19. Re:When browsers jump the shark by Anonymous Coward · · Score: 2, Informative

    To move tabs, I created the directory c:\Users\(username)\AppData\Roaming\Mozilla\Firefox\Profiles\(yourprofile).default\chrome and then put a file named userChrome.css in it with this content. Note the 1,2,3 order you can modify to change where tabs, etc. are at the top of Firefox 57. The order below is for navigation bar, bookmarks, then tabs:
    /* Tab bar below navigation & bookmarks toolbars */

    #nav-bar{
      -moz-box-ordinal-group: 1;
      border-top-width: 0;
    }

    #PersonalToolbar {
      -moz-box-ordinal-group: 2;
    }

    #TabsToolbar {
      -moz-box-ordinal-group: 3;
    }

    #main-windows[windowtype="navigator:browser"] {
    background-color: transparent;
    }

    /* 2/1/3 - bookmarks, controls, tabs */

    /* 1/2/3 - controls, bookmarks, tabs */

  20. well here goes my karma.... by iwbcman · · Score: 3, Interesting

    Sorry folks, but Slashdot just revealed it's true colors. The chorus of OMG! WTF! down with Mozilla, witnessed in this thread is, sadly, proof that the Slashdot audience has become those who the hackers of yore were hacking against. Is there not an ounce of rebellious spirit left on this site? Whether you like the show, Mr. Robot, or not, I just can't fathom the reaction here.

    For those those who say this is the last straw for Mozilla-good riddance, don't let the door hit your ass on the way out.

    Look there are lots of things I could complain about regarding Firefox, but a chance wanderer coming to Slashdot would think this site is full of nothing but chrome shills and misanthropes who actually *hate* Free software. What made this site so interesting in days long ago was the tension between the rebellious spirit of Free Software and those who made their living working for the man or trying to make a living selling proprietary software. Nowadays corporate shills and libtards reign supreme on this site and the very notion that technology can actually be a source of societal change is completely and utterly lost.

    Well duh maybe that's why most here don't even get what Mozilla is, what it represents and how much it actually changed the world around us.

    But oh my God they rendered my extension useless, oh my God one of my 80 tabs is leaking memory, or Oh my God it takes a full 1.7 seconds to launch on a modern computer.

    Oh well I guess I am just a fanboy, forgot to check the mail and get my check for promoting not only Firefox but Mozilla as a an organization, foundation and corporation. Am I the only idiot here who jumped for joy back in January of 1998 when the mozilla source code was made free and downloaded it just so I could see the code?

    My guess is that anywhere from %30-50 of all currently existing jobs in software development wouldn't even exist without Free Software, and Mozilla did more to promote and garner mainstream acceptance of Free Software than the GNU movement ever dreamt of. In all likelihood there would be no Google, Facebook, Twitter, Amazon etc. without the courage and commitment that founded Mozilla. Alas without Richard Stallman and the GNU movement there probably would never have been a Mozilla.

    Long live Mozilla

    1. Re:well here goes my karma.... by 110010001000 · · Score: 3, Informative

      You are an idiot. Just because they use a Open Source business model doesn't mean they shouldn't be chastised for pushing advertisements in our face. This extension isn't even Open Source. Yes, they are pushing CLOSED SOURCE software to your machine without you knowing about it.

  21. Re:When browsers jump the shark by jellomizer · · Score: 4, Insightful

    I want a browser to be fast, secure and protect my privacy. I don’t want it to tell me what I should watch or think.
    I may want Firefox for reasons different then the organization goals. I don’t appreciate getting stuff pushed on me.

    --
    If something is so important that you feel the need to post it on the internet... It probably isn't that important.
  22. Re:"privacy-conscious users" by Anonymous+Brave+Guy · · Score: 4, Insightful

    Things are changing so fast and so broadly that the only way to keep up is to make that trade off.

    What an odd thing to write. We used to compensate people who provided new things we liked to have by paying them.

    The reason privacy is dying is because invading privacy has become profitable, and that in turn is because it provided a way to monetize people using a service or enjoying some digital content online without them having to do anything or even necessarily realising what was going on.

    Google and Facebook, with their culture of spying-for-ads, and Apple, with its app store culture of software-costing-$3-is-expensive, have much to answer for.

    --
    If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
  23. Re:No. by Rakarra · · Score: 2

    And the males there would be too excited.

    I guess that's one way to defeat those sorts of guys.
    When a pervert masturbates at you, acting offended is what they want. Instead, masturbate back! It will freak them out and ruin their fun.

  24. Screw "experiences." Fix the bugs first. by imjustabigcat · · Score: 2

    I am sick of having "experiences" pushed in my face by marketing drones who think I need to know what's "cool" or "interesting." The "experience" I'm really interested in is a browser that functions properly, doesn't crash, supports standards, and which doesn't eat all of the available memory or CPU. I'm even willing to PAY for something like that. If the management team at the Mozilla Foundation has time and resources to surreptitiously load unwanted extensions hyping some television show on the browser, they sure as hell have the time and resources to fix some of the more egregious and annoying bugs.

    I sure hope Firefox isn't about to plummet into "form over function" irrelevancy like Skype recently did ("The most expressive Skype ever!"). Bugger "expressive" or "experience"...just make the damned thing work properly.