Bonum Certa Men Certa

Mozilla Has Turned Firefox Into OSPS Consistent With "Attestation" Objectives

posted by Roy Schestowitz on Apr 14, 2024

OSPS is Open Source Proprietary Software (Proprietary in 'Open' Clothing)

Halloween image of witch silhouetted flying in front of full moon with evil pumpkins at base

PART of running this Web site and Gemini capsule involves development and rapid improvement of custom-made software that suits our needs and meets some basic standards. A lot of it is coded in Perl, Python, and Bash. Recently, however, JavaScript too (tr-copy-title-url.xpi).

In the process of doing that we discovered just how locked down Firefox (and its derivatives too) had become. If one develops an extension to Firefox it "has to be installed as a 'temporary extension' because it is not signed at all," as an insider explains. "In Firefox," one must go to "about:debugging#/runtime/this-firefox" and then "Load Temporary Add-on..."

This needs to be done again and again every time Firefox gets (re)started. "The downside to it being unsigned," the insider emphasises, "is that it needs to be reloaded each time the browser is restarted."

This wasn't like that when I developed Firefox extensions nearly 20 years ago. Something has changed, we're not sure when it changed, and this change was likely gradual.

I installed the extension using the steps above and it required the same to be done in LibreWolf, so the artificial restrictions got inherited by the "Libre" 'version'. Great, eh?

So people need to 'sideload' ("sideloading" is a misnomer) their own work, even repeatedly. It cannot be done without so many steps. The insider explains that "restarting Firefox clears the plug-in out of memory, so figuring out how to sign it properly would help with that."

There's an issue with that though. As the insider soon realised, based on the official pages [1, 2], self-signing is forbidden. "As usual for nowadays," the insider says, "self-signing is not allowed. The tedious manual process given initially is the only real option" (for those who update the code frequently and want it to still work).

If one signs or self-signs one's own work, what is the problem? That it might crash everything? There are various ways to undo or remove extensions and "signing" does not in any way assure quality; it makes sense to allow self-signing in many circumstances.

We've attempted to find a workaround, we tried to think more of ways to install the extension fast (without all those laborious steps). We still wonder when these tight restrictions were added and why it happened (or how Mozilla tried to justify/rationalise it).

Mozilla just wants to be in control of everything, even whatever extension the user adds, even if the user himself or herself developed the extension for personal use. This can facilitate censorship of software by Mozilla, as in, you can only do in Firefox what we've approved.

Attestation much? Is this where Mozilla is going? It's a stepping stone towards DRM or at least Tivoisation.

Where was this decision debated? "Gradual steps [were taken] so that the public goes along without complaining," our insider says. As LibreWolf is the same, we can really see how the restrictions get inherited by freer alternatives. Apparently LibreWolf is so secure that the user is wrong to add the user's own code. Or, as the insider puts it: "It's not your computer any more. It's Microsoft via Mozilla via Google. The three collude and conspire to ensure that they have control of the system and not the ostensible owner. Don't look at the DRM hard- coded into Apple's M2, M3, and M4 chips."

I've estimated that it would take ~60 minutes/month (or 12 hours a year) if we need to re-load our extension every time Firefox (or LibreWolf) is restarted. The insider thinks "reloading is an intentional PITA by Mozilla."

"About the only other option would be to make it an official plug-in and downloadable via Mozilla's site. Updating it would be a horrible experience and require lots of time, each update."

Imagine trying to update one's own software and resubmit to Mozilla every small changes for re-signing. Where's the logic in that? What if the code (or extension) isn't of much use to the general public? Or Mozilla turns the coder down? This isn't being done for "security", it's all about control by Mozilla and its masters (GAFAM). One can bet that, like in Windows XP (and later), Mozilla also keeps lists of everything you put in Firefox every time you use it (under the guise of "telemetry" to 'improve' your experience or something).

We've seen similar issues in UEFI 'secure' boot and Certificate Authorities. These facilitate censorship of code or restrictions on site access (i.e. attacks on Freedom of Expression).

The way things work at the moment "is a waste of time," the insider opines. "It is not about "security" as you or I or anyone else thinks of it. It is about control of the machine and wresting that away from the public, without their complaints."

So just remember that Mozilla has turned Firefox into OSPS that refuses to trust you, the user, or obey your will. The word "Firefox" has two Fs, but Mozilla doesn't give a F about your Freedom.

Other Recent Techrights' Posts

IRC Proceedings: Saturday, July 13, 2024
IRC logs for Saturday, July 13, 2024
Julian Assange’s Brother Gabriel Shipton Explains the Logistics of 'Smuggling' Julian Out of the United Kingdom
a lot of new information and prison stories
[Video] Why Wikileaks Publishing War-Related Documents Was Both Important and Justified
It's important to remember the principle which says privacy is for the powerless, whereas the powerful (like those with the power to kill) deserve not privacy but transparency
[Meme] Attacking the "G" in GNOME (Since 2009) Was a Mistake
Spending 50,000 pounds to sue women of racial minority
Difficult Times in GNOME Foundation
GNOME Foundation is in "crisis management" or "face-saving" or "damage control" mode
It Takes No Courage to Become Another Corporate Stooge
transition to spam
Why Techrights Has Just Programmatically Blacklisted ZDNet
Even their "Linux" writers are AWOL
Gemini Links 14/07/2024: The Stress of 24/7 Notifications and FOSS tools for Sipeed Tang Nano 1K
Links for the day
Windows Already Down to 10% in Lao (It was 96% a Decade and a Half Ago), Vista 11 Adoption Has Stalled
And GNU/Linux is topping a 1-year high in Loa
Over at Tux Machines...
GNU/Linux news for the past day
Links 13/07/2024: Patent Trolls in UK Court of Appeal, Eric Schmidt Continues so Show Womanising at Google
Links for the day
Links 13/07/2024: Not Quite Dead Yet After All and Unfederated E-mail
Links for the day
Holly Million, GNOME Foundation departure after Albanian whistleblower revelations
Reprinted with permission from Daniel Pocock
[Meme] Like They Got Rid of Molly (and Now Holly)
Pay over 100,000 dollars a year for someone without any background in tech (to "lead" a tech project)
Microsoft Windows Falls to Almost 10% in Palestine (It Was Measured at 100% Just 15 Years Ago)
quite a big drop
Guardianship of the Licence is Not Enough (the Case of Systemd and Microsoft)
Whether the GPL gets enforced or not, if people adopt lousy software, that will have negative consequences
Speaking Out and Spreading the Message of GNU
Free Software Foundation (FSF) got 112 new members since 2.5 weeks ago
3.5 Years in Gemini
It's important to speak about and spread the word (about software freedom, BSD, GNU/Linux, patents etc.) in a medium that's strategic and growing
[Meme] Whoever in GNOME Decided to Attack the G (GNU), It Was a Foolish Miscalculation
How could they expect any outcome other than GNOME's own collapse?
Windows Down to Unprecedented Low in Czech Republic, Android Rises to New Record
From 98% in July 2009 (15 years ago) Windows is down to all-time low of 38% and well below Android
GNOME Foundation Lost Nearly a Million Dollars in 2 Years, IBM and GAFAM Won't Bail It Out Anymore
Seems like a suicide mission
Google News Has Become a Big Pile of Garbage
The issue predates chatbots, but these SEO tricks were accelerated somewhat by slop
OpenAI and ChatGPT Could Very Well Collapse and Shut Down Later This Year (Huge Losses, Sagging Usage Levels, and Massive Debt)
we illuminate the suppressed observations that Microsoft-sponsored publishers and cheaply-made slop (LLM spew disguised as "news") try to distract from
Links 13/07/2024: TikTok Interferences, YouTube Throttled in Russia
Links for the day
Kathy Lette on Julian Assange Staying at Her Attic, Why His Release Matters So Much, and Jen Robinson Staying Over Yesterday
They talk a lot about politics, but the segment mentions publishers, including Rushdie
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, July 12, 2024
IRC logs for Friday, July 12, 2024
Microsoft Windows Down to a New Low in Canada (Only a Third)
Very steep decline a decade ago
Links 12/07/2024: EU/China Tensions and Ukraine War Updates
Links for the day
EPO Staff Reps: "Until now, Mr Campinos is still leaving the appellants in the dark about the exact content of the opinion of the Appeals Committee on the EPO salary adjustment procedure."
Campinos chooses to lawyer up rather than listen up
EPO Staff Representatives Say It Has Gotten Very Hard to Get Promoted (Forget About Getting Rewarded for Hard Work)
This has long been a problem
[Meme] That Time EPO Workers Were Panicking Because the Elevators Kept Getting Stuck
Many people forgot that
Occupational Health, Safety and Ergonomics Committee (LOHSEC) at the European Patent Office (EPO)
nobody in EPO management ever gets punished for crimes, no matter how severe
[Video] Julian Assange's Brother Gabriel Shipton on How the Convoy to the Airport Was Arranged, Being at the Beach With Julian Assange After Release (He's Doing Well), and How Taylor Swift Has 'Helped' Julian
At the airport he was greeted by many press crews, but they were not there for him. They were there because of Taylor Swift.
[Meme] Financial Disinformation From Chatbots Controlled by the Manipulator (Rigger)
ChatGPT, the media is starting to say you're all hype...
Microsoft is Actually Quite Worthless, Its Valuation is Based on Lies and Consistently Defrauding Shareholders
Microsoft's future is not what Wall Street "tells" us
Links 12/07/2024: Nations That Already Ban TikTok and Russia's 'Shadow War' Online
Links for the day
Gemini Links 12/07/2024: Changing and the WIPO Lunacy
Links for the day
Let's Encrypt Continues to Collapse in Geminispace and That's Good News for Free Speech (Among Other Things)
due to the way modern Web browsers work, many sites have no option but to use Let's Encrypt or pay for some other CA to issue some worthless-but-glorified bytes
Microsoft Falls Below 20% in Montenegro - Plunging to All-Time Low
sharp drop
[Meme] The Free Speech Absolutist From Apartheid South Africa
What will it take for all sensible people to quit X/Twitter?
The Final Demise of Social Control Media May be Upon Us (It Ought to be Collectively Abandoned for Society's Sake)
If it keeps going down, prospects of a turnaround or rebound are slim
Linux is Displacing Microsoft and Replacing Windows in Germany (Android Surge and New Highs for ChromeOS+GNU/Linux in Germany)
Germany is upgrading to GNU/Linux, not to latest Windows
The Latest NDAA Amendment Can (or Should) Allow the United States to Remove Microsoft Even Faster From Its Infrastructure (Which Routinely Gets Cracked Completely by Russia and China, Thanks to Microsoft)
It's time to move!
Reorganising for Better Efficiency and More Publication (Original Material)
XBox "journalism" these days is mostly slop (chatbot spew disguised as news), so studying this matter isn't easy
Software Freedom is Still the FSF
At the moment the best advocacy group for Software Freedom is the FSF
Links 12/07/2024: XBox in Trouble, Crackdowns in UAE
Links for the day
Gemini Links 12/07/2024: Make Tea Not War, Considering Guix
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, July 11, 2024
IRC logs for Thursday, July 11, 2024