Bonum Certa Men Certa

Mozilla Firefox Takes Another Step in the Direction of Being Malware With “Firefox Suggest”

Guest post by Ryan, reprinted with permission from the original

Opening: Yesterday I was surfing the web when I found out that LKML.org, a centralized place to see what’s going on in Linux kernel development, was attempting to load an ad script from a company called “BuySellAds dot com”.

When I investigated the company in more detail, I found that there was an entire page where they plot with some of the titans of the web industry to track and psychologically manipulate people.



One such partnership was Brave. Apparently, this company is pushing Brave’s “ethical ads” from behind the scenes, and another was Mozilla.



"One such partnership was Brave. Apparently, this company is pushing Brave’s “ethical ads” from behind the scenes, and another was Mozilla."It said that they feed ads into “Pocket”, which is where the “Sponsored Content” (including from Big Oil companies like Exxon) keep popping up in the Firefox New Tab page, and now in your address bar if you live in the US (under the guise of Firefox Suggest).



Well, what I suggest is that Mozilla CEO Mitchell Baker does with Firefox Suggest and Pocket is probably anatomically impossible, but that’s outside the scope of this post.



It sickens me, that a great piece of software that I used from its inception in 2002 (pre-releases), and even before that (as Mozilla Suite, and before Mozilla, as the proprietary Netscape suite) has gone and done this as a cash grab on the way down.



Each release, there’s more stuff to turn off, and you have to remember to do all of that every time you install it somewhere.



"Each release, there’s more stuff to turn off, and you have to remember to do all of that every time you install it somewhere."There’s like 5 different settings (something like that) to fully disable DRM and keep it from coming back on or demanding it. That’s pretty bad when many of the sites using it are using it not for DRM, but as a fingerprinting attack.



Firefox ceased being Free and Open Source Software when distributed according to the Mozilla Trademark policies long ago, when they enabled Google DRM by default and pestered the user if they turned it off and then didn’t do some “about:config fu” to make sure it stayed off and disappeared from the GUI, but with Cloudflare DNS (a privacy hazard that OpenBSD patched to turn off!), Pocket’s Sponsored Crap, and Firefox Suggest, Firefox has not only straddled the line of what I consider to be “malware”, but has finally crossed it.



Perhaps there’s something very wrong with Debian for not going back to calling it “IceWeasel” and patching this stuff out of the source code so that it can’t come on. They are now in abeyance of their Debian Free Software Guidelines all so they can ship malware and call it Firefox.



You can perhaps forgive, under these circumstances, that some GNU/Linux distributions are throwing in the towel with Firefox, which doesn’t perform very well and uses gobs and gobs of RAM to perform the tasks, and are shipping some other browser.



Linux Mint spins are even putting in Vivaldi. And, if you frame it as a choice between Vivaldi and Firefox, I’d say Firefox is even worse than Vivaldi at this point, though Vivaldi doesn’t pretend to be open source like Firefox does, and they don’t beg for donations while they sell you down the river to adtechs like Mozilla does.



"Firefox ceased being Free and Open Source Software when distributed according to the Mozilla Trademark policies long ago, when they enabled Google DRM by default and pestered the user if they turned it off and then didn’t do some “about:config fu” to make sure it stayed off and disappeared from the GUI, but with Cloudflare DNS (a privacy hazard that OpenBSD patched to turn off!), Pocket’s Sponsored Crap, and Firefox Suggest, Firefox has not only straddled the line of what I consider to be “malware”, but has finally crossed it."What Mozilla fails to understand, obviously, is that by pissing off users into leaving, they not only have less who will stay and drive “ad hits” for them, but they’ll see a further collapse in their search royalty value to Google, and incoming revenue will fall faster than had they just left it alone.



Furthermore, by letting this incompetent twit remain as CEO and firing the engineers while leaving a “Global Chief Diversity Officer” and other dead weight so that they can be a political party, development of the browser’s underpinnings lags while they fritter away valuable capital towards these nutjobs.



Well, enough was enough so….



I finally figured out the dependency matrix to get Debian to allow me to apt purge firefox-esr from my Debian 11 system without trying to take out GNOME metapackages and the X server.



It turns out that I had to give up on using the GNOME Web flatpak from FlatHub, because it collides with the Stable version from Debian. So I backed that out, and deleted its settings and cache under the .var folder hierarchy, and put the epiphany-browser package back in.



"...on a clean install, Firefox Suggest is on by default and doesn’t even ask whether the user wants ads or a keylogger malware in their address bar."As long as that’s there, and those internationalization and LibreOffice Help Packs and foreign spell checkers and such that I removed the other day are gone, you can remove firefox-esr and the system won’t complain that you need a web browser.



It seems that Apt only wants to remove the gnome metapackages and xorg (Jean-Baptist…Emanuel….Zorg! Sorry.) if epiphany-browser is not already installed. If it is, it’ll shut up and let you get rid of Firefox.



Now you can also reclaim some disk space by removing .mozilla and all of the .mozilla and .firefox stuff under your Home folder (it’s all hidden but unhiding it with Ctrl+H and then using the finder is easy enough). In my case, I don’t use Thunderbird either, so I got rid of its stuff and now it’s just GNOME Web and Evolution.



Mozilla lies and says Firefox Suggest is off by default and that it is opt-in.



In the Bleeping Computer article about Firefox Suggest, which also notes Firefox’s dwindling market share (they went from being almost half of all web users at their peak to being only slightly more popular than Vivaldi, and still falling), they say that in their own tests and user reports, on a clean install, Firefox Suggest is on by default and doesn’t even ask whether the user wants ads or a keylogger malware in their address bar.



I installed the Firefox 93 Flatpak to find out myself. Mozilla even builds it and uploads the builds to Flathub, so they are official. Firefox Suggest was on by default, no message asking me if I wanted it.



When Ubuntu briefly implemented a keylogger that sent your Shell searches to Amazon in their now-abandoned Unity Shell, Richard Stallman called Ubuntu malware.



In its default configuration, Firefox not only sends everything you type into the address bar to Google (even though you can turn that off and split searches into a different box), but also to Mozilla, and Mozilla’s advertisers. This is certainly malware.



"How is it that Debian says the firmware to run my wifi, SSD, and graphics chip isn’t allowed (in the official image, which will lead some people to think Debian is broken and not bother figuring out why….while others have to know there’s a real installer that has firmware that is semi-hidden) but Widevine DRM blobs and a malicious keylogger in Firefox are fine?"How much longer will “Free” operating systems like Debian continue ignoring their own Free Software Guidelines to package this? It already had a grabber that’s on by default to download Google DRM blobs, and now this.



It’s bad enough that Fedora chucked its own Free Software policy out the door when IBM took them over, and started pushing Zoom, Microsoft Teams, and Microsoft Edge.



How is it that Debian says the firmware to run my wifi, SSD, and graphics chip isn’t allowed (in the official image, which will lead some people to think Debian is broken and not bother figuring out why….while others have to know there’s a real installer that has firmware that is semi-hidden) but Widevine DRM blobs and a malicious keylogger in Firefox are fine?



Sounds like someone at Debian should explain this.



As an aside, Mozilla is also considering changing the default search engine to Bing.



Every few years, they come in and decide which crappy privacy-violating mess with worse search results than Google to switch all their users to as part of a cynical ploy to ultimately get Google back to the table for more money.



Microsoft has never offered any browser vendor more money than Google, which is why Google is the default search engine on almost every browser, and the iPhone/Safari, even though Apple pretends they’re bitter enemies (over 60% of Apple iOS apps have Google tracking libraries in them).



I’m not a big fan of Google, but Bing is much worse. Instead of Google violating your privacy, it will be Microsoft, and then the search results often won’t even be usable.



When will Mozilla learn to stop manipulating its remaining users? Never?



Recent Techrights' Posts

Throwing Away "Old" Computers (Mozilla and Other Climate Deniers)
Mozilla is not leftist
Further Media Cut-downs
media reporting about the media being cut
Gemini Links 09/09/2025: Moon Eclipse and ROOPHLOCH Reports
Links for the day
Official SUSE Blog Still Uses LLM Slop (Bots) to Make Fake Articles (Marketing)
The company is all about sound bites
Companies Realise That Slop Doesn't Work as Advertised, Accordingly Dump It
"Hype dims as a country-wide survey of US corporations shows a sudden drop-off in AI use among firms with more than 250 employees."
Microsoft-Funded Lawsuits Against Critics of UEFI 'Secure Boot'
Remember that no company (or law firm) ever survives collaborations with Microsoft
 
Blaming Everything on China
TikTok works for China. GAFAM works for fascists.
People Get Tired of "Hey Hi" (AI), Unlike the Subservient Money-Obsessed Media That Gets Paid to Pretend This Bubble Still Matters
"crash will be way bigger than dot.com burst in 90s. and that was Internet, actually transformative technology, not this expensive AI toy with direct dependency on the energy input which is not scalable"
Brett Wilson LLP Accepts That the Serial Strangler From Microsoft Filed a Case That Also Implicates My Wife (Everything is Connected)
They used to pretend that there were two separate cases
10 Reasons to Disable (or Enable) UEFI Secure Boot
Tomorrow the "trusted corporation" Microsoft will see a certificate expire
Gemini Links 10/09/2025: Hospital and Large Feeds
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 09, 2025
IRC logs for Tuesday, September 09, 2025
The Bluewashing of Red Hat is Being Completed, Many Staff Understand They'll be Made Redundant
Jim AllowHurst (Whitehurst) is meanwhile promoting Microsoft's agenda from within other companies
statCounter Sees GNU/Linux Exceeding 10% in Bulgaria This Month
What can Microsoft still do to stop GNU/Linux?
Dark Patterns
Microsoft saying "security" is like a Convicted Felon in the White House saying "law and order".
It's Almost Fall (Autumn)
To "Facebook prison" you are bound
Bruce Schneier About "Secure Boot"
Bruce Schneier isn't a fan of "Secure Boot"
Links 09/09/2025: Microsoft Mass Layoffs Again and "RTO" (Timed Like It Serves as a Distraction From the Mass Layoffs)
Links for the day
RMS Told Microsoft to Stop 'Secure Boot' (He Even Went There to Say That), But They Didn't Listen
Dr. Stallman (RMS) assumed that speaking to sociopaths would work
What Richard Stallman Told Me About 'Secure' Boot in 2012
"if the user doesn't control the keys, then it's a kind of shackle"
Those Who Helped Microsoft Weaponise "Secure Boot" Against GNU/Linux and BSDs Are Fleeing
Microsofters doing what they do best: they evade accountability
Simple is Better, Simplicity is Power
That is "the advantage of having commodity GNU/Linux systems," an associate notes
Much Ado About Nonsense
Microsoft Lunduke is still all dramatisation and sensationalism
Current Events in France
It needs to dump Microsoft and other GAFAM (US) giants, move to Free software
Links 09/09/2025: US-Korea Tensions and Meta Whistleblowers
Links for the day
Links 09/09/2025: “Torrents of Hate” and Political Crisis in France
Links for the day
Gemini Links 09/09/2025: "Dedigitizing" and Forgejo on FreeBSD
Links for the day
Google News (Not Just Google Search) Lets Itself by Gamed by One Slopfarm - to the Point Almost Half of "Linux" News is Bot-Produced Plagiarism (LLM Slop With Slop Images)
That says a lot about what Google thinks of quality, even in Google News
Bill Gates-Funded Media Inadvertently Refutes the Microsoft Lie That in 2025 Microsoft Had Just Two Waves of Layoffs
There were about 12 rounds of layoffs so far in 2025
From theregister.co.uk to theregister.com (US) to The Register MS (Run by Microsoft Operatives) and theregister.ai
The best way to break this racket (or cycle of hype and harm) is to break the chains of funding
Open Source Initiative (OSI) Culture of Censorship Necessitates More Speech
The OSI bans dissent or people who merely point out that the OSI is abusive
How to Reach Us Discreetly (Other Than Encrypted E-mail)
We're still managing to maintain a 100% source protection record. We soon turn 19.
LLMs Are Vastly Worse Than a Waste of Energy and the Externalities Are Huge
Worse than just higher power bills for everybody
LLMs Versus Search (Not Replacing Search But Engaging in DDoS Attacks Against Web Sites That Permit Searching)
The state of the Web isn't just bad; it's utterly terrible
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 08, 2025
IRC logs for Monday, September 08, 2025
It's Only the Second Week of September and Already Two Waves of Layoffs at Microsoft, Slopfarms and Microsoft-Funded Sites Spin It as "AI Investments" Rather Than Commercial Failure
A very large third one expected next week
The UEFI 9/11 - Part IX - Shunning Old Computers (in 2023 the Certificate Was Updated/Overridden, Underlying Aim May Be Herding/Forcing People to Get TPM and Other 'Novel' Restrictions)
the "upgrade treadmill"
Rumour: Second Wave of Microsoft Mass Layoffs in September to Commence Third Week of September
That basically answers questions like, "Any specific date or time of the month?"
If Your Machine Still Has "Secure Boot" Enabled, Then Microsoft Has a de Facto Kill Switch (Even If Your Machine Doesn't Have Windows and Never Had Windows)
It is not incorrect to call UEFI 'secure boot' a "kill switch"
Gemini Links 08/09/2025: Reality, ROOPHLOCH 2025, and Writing Another Gemini Client
Links for the day
Updating Firmware is Not the Solution But Only Additional Risk, Disable "Secure Boot" Today
firmware blobs are buggy, secret, impossible to audit, and barely tested
Microsoft Tim's DevClass (Part of The Register MS/Situation Publishing) is Full of Slop
Looking at many sites that are full of slop images is becoming an eye sore and hallmark of text too likely generated by LLMs or 'assisted' (tainted) by them
Microsoft Trying to Fake Demand for Slop. At What Cost?
That's a giant demotion and broken promises
Reddit is Corporate Propaganda
To make matters worse, Reddit ousted many original moderators
Jeff Geerling Shocked to Discover Many Metrics in YouTube Are Fake (His Audience Turns Out to be Much Smaller)
Maybe self-host all videos, don't rely on Google's "FOMO" cheating (addiction based on false assumptions)
Sunlight is the Best Disinfectant and Kryptonite/Garlic to Vampires
Transparency (sometimes described by words like "Sunlight" or "Truth") is paramount
The Register MS Uses Slop in Articles About Slop
we are fairly certain it's slop or CG based on other people's work
Visiting a Web Page or a Public URL Should be Safe, Predictable, and Benign
It's probably too late to "fix" the Web
The Register MS (Situation Publishing) is Paid to Spread Mindless Hype for the "Hey Hi" Ponzi Scheme and That's a Serious Problem
"Sponsored by Zoom."
Links 08/09/2025: Burger King Cracked, Cox v. Sony Analysed
Links for the day
Gemini Links 08/09/2025: Socialist Computer Museum and GAFAM/ByteDance/TikTok-Dominated Net
Links for the day
Links 08/09/2025: Tim Crook Disappoints Apple Faithfuls and Zuckerberg Lies (Financial Fraud) for Cheeto King
Links for the day
EPO Workers Point Out that the EPO is Destroying the Planet Under the Guise of "Hey Hi" (It Also Grants Many Invalid Patents Illegally
On 12 March and 16 June 2025, staff representation met with the administration in the Local Occupational Health, Safety and Ergonomics Committee (LOHSEC) in Munich
Turn Off Microsoft's Restricted Boot ("Secure Boot")
We're still running a series on this issue
Social Control Media Sites Have Become Bot Farms (Not Limited to LLMs and Automation)
linkedin.com was nothing but trouble and losses for Microsoft
Deep in Debt With the Magnitude of Losses Quickly Growing, Microsoft "Open" "Hey Hi" Now Uses Broadcom for Vapourware, Pretending It'll Do OK Next Year
At some stage it'll collapse
You Can Tell Microsoft is in Trouble When Its Own Fans and Staff Blast it
"Microsoft sinks billions into chasing artificial intelligence fads to hype up its share price."
Multiple Undersea Cable Cuts and We're Still OK
Microsoft customers experience problems
Lawyers Who Think They Are Online Assassins Don't Deserve a Licence to Operate
they've become a laughing stock in their "sector"
Microsoft Windows Fell to 3.9% "Market Share" in Bahamas
Based on statCounter
How the European Union (EU) Fell Out of Love With Free/Libre Software
Lots of bribery
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, September 07, 2025
IRC logs for Sunday, September 07, 2025