PSA (?): just got this popup in Firefox when i was on an amazon product page. looked into it a bit because it seemed weird and it turns out if you click the big “yes, try it” button, you agree to mandatory binding arbitration with Fakespot and you waive your right to bring a class action lawsuit against them. this is awesome thank you so much mozilla very cool

https://queer.party/@m04/112872517189786676

So, Mozilla adds an AI review features for products you view using Firefox. Other than being very useless, it’s T&C are as anti-consumer as it possibly can be. It’s like mozilla saying directly “we don’t care about your privacy”.

    • jet@hackertalks.com
      link
      fedilink
      English
      arrow-up
      101
      ·
      4 months ago

      Yeah, corporate dark patterns really don’t respect consent. When would you like to know more: Now, or Later?

      • Buddahriffic@lemmy.world
        link
        fedilink
        arrow-up
        26
        ·
        4 months ago

        Though I don’t mind the “accept, deny, ask me again later” for when something seems interesting but I don’t want to put the effort into looking into it right at the moment but don’t want to click yes without looking into it.

    • laughterlaughter@lemmy.world
      link
      fedilink
      arrow-up
      17
      ·
      4 months ago

      Best I can do is accepting three options: “Yes,” “No,” and “Remind me later.”

      “Not now” or “No, I don’t want this awesome feature” bullshit infuriates me.

      • 𝕸𝖔𝖘𝖘@infosec.pub
        link
        fedilink
        English
        arrow-up
        8
        ·
        4 months ago

        We had a whole generation of people that were taught that ‘no’ means ‘maybe later’ (the whole point of the ‘no means no’ ads about daterapes), and that same generation is now running these companies. What did we expect to happen?

  • nia_the_cat@lemmy.world
    link
    fedilink
    arrow-up
    129
    ·
    edit-2
    4 months ago

    Hot take and I can guarantee this will be downvoted but I think people are putting way too much blind trust into Mozilla for this. (edit: Apparently not here, pleasantly surprised at that)

    They just purchased an advertising company, they made the T&C waive your right to a class action lawsuit. They keep giving their CEO raises and laying off their workers. Mozilla is actively enshittifying but people don’t react until it’s too late because it’s a boiling frog situation.

    Whether you think the feature is useful or not, Firefox is unfortunately shifting away from being a privacy-focused user-focused browser. The saving grace is that it is open source and forks can be made of it, “Firefox” itself can survive anything as long as there’s enough interest to keep it alive.

    I think that Mozilla does great work, but they’ve lost sight of their goals, and are changing focus. This is not necessarily a bad thing, but this needs to be looked at objectively instead of with brand-loyalty. At the end of the day, they’re just another company with financial interests prioritized over user interests.

    • jet@hackertalks.com
      link
      fedilink
      English
      arrow-up
      55
      ·
      4 months ago

      Ohh, Good point, so the entire trust model is we are trusting Mozilla not to share data with Mozilla, because if Mozilla colludes with Mozilla then there is no privacy here at all.

  • davel [he/him]@lemmy.ml
    link
    fedilink
    English
    arrow-up
    91
    ·
    edit-2
    4 months ago

    Why not just be a web browser and leave stuff like this to browser extensions?
    Oh right, you enshittified yourself.

    Edit to add: Why give them money when they apparently already have too much of it from corporate inputs (most of it from Google)? I think they ask us for donations in order to retain their non-profit image, for PR purposes.

  • ZeroHora@lemmy.ml
    link
    fedilink
    English
    arrow-up
    64
    ·
    4 months ago

    Fakespot is from Mozilla, if you trust Mozilla, why don’t you trust Fakespot?

    And why is it useless? With the amount of fake AI reviews an AI to detect them is not completely useless.

    But the popup is annoying.

    • rtxn@lemmy.world
      link
      fedilink
      English
      arrow-up
      59
      ·
      4 months ago

      People shouldn’t trust Mozilla either. It’s a company that does company things. Just because it’s not as far-gone as Google doesn’t mean it’s incapable.

      • sudo@lemmy.today
        link
        fedilink
        arrow-up
        12
        ·
        4 months ago

        just because its not as far-gone as Google

        The fact that the Mozilla Foundation is non-profit, despite wherever controversy there may be around their decisions of late, is a pretty significant factor.

        • LWD@lemm.ee
          link
          fedilink
          arrow-up
          13
          ·
          4 months ago

          Mozilla Foundation has no members, it’s operated by the for-profit Corporation, and the Corporation is powered by its profit motive.

          • rtxn@lemmy.world
            link
            fedilink
            English
            arrow-up
            8
            ·
            4 months ago

            Even worse, the majority of its revenue comes from Google for making it the default search engine.

      • ZeroHora@lemmy.ml
        link
        fedilink
        English
        arrow-up
        9
        ·
        4 months ago

        I never said they should trust. But if they trust Mozilla with the telemetry/pockets/whatever they put on the browser this one is just like the others.

    • lone_faerie@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      23
      ·
      4 months ago

      Using AI to detect AI is completely useless. It’s been a big issue in academics, where a professor will plug your essay into an AI detector and then you get dinged for plagiarism because your entirely handwritten essay gets marked as AI. It’s just glorified pattern matching, it has no concept of real or fake.

      • Laurentide@pawb.social
        link
        fedilink
        English
        arrow-up
        12
        ·
        4 months ago

        If the AI could really detect any discrepancies between human and AI-generated text, it would stop making them.

    • LWD@lemm.ee
      link
      fedilink
      arrow-up
      22
      ·
      4 months ago

      I trust Mozilla to do what they promise with my private data

    • laughterlaughter@lemmy.world
      link
      fedilink
      arrow-up
      12
      ·
      4 months ago

      And why is it useless?

      It’s not useless. It’s just that it’s bloatware that’s unnecessary for many.

      Like a car with a bright orange “Order Bird Food” button in the middle of the dashboard. If you don’t own any birds, then it sucks.

      • ZeroHora@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 months ago

        Nothing new in the helm of browsers. Pockets is a extension baked into the browser.

        Many browsers have VPN/Ad Block native to the browser. Opera GX have all that bullshit that surprising can deceive a lot of normies to use it.

        Sadly this type of bloat sells as “features” to some people and Mozilla gains users with it. Btw I’m not defending this practice I just seeing for what it is, marketing.

        • laughterlaughter@lemmy.world
          link
          fedilink
          arrow-up
          6
          ·
          4 months ago

          Sure, sure, other browsers do it. But I expected more of Mozilla.

          Pocket was already bad enough, but it was kiiiiinda related to browsing anyway - it was a glorified bookmarking tool. It had a nice purpose too - save pages for online reading - but they seem to have gotten rid of that and I’m mad about it.

  • LWD@lemm.ee
    link
    fedilink
    arrow-up
    43
    ·
    4 months ago

    FakeSpot is a hilarious company run by trend chasers, “crypto enthusiasts and web3 believers.”

    If Mozilla chasing the AI trend isn’t bad enough, and their privacy policy doesn’t hurt your soul, FakeSpot also only works on the biggest and most predatory platforms (Walmart and Amazon).

    • Blisterexe@lemmy.zip
      link
      fedilink
      arrow-up
      30
      ·
      4 months ago

      FakeSpot also only works on the biggest and most predatory platforms (Walmart and Amazon).

      that also happen to be by far the most popular, and also where you are the mos likely to see fake reviews

      • LWD@lemm.ee
        link
        fedilink
        arrow-up
        19
        ·
        4 months ago

        “If the privacy invasion and corporate trend chasing doesn’t hurt your soul”?

        Did you miss the privacy invasion where Mozilla now sells private data to advertising companies directly?

  • Napain@lemmy.ml
    link
    fedilink
    arrow-up
    42
    ·
    4 months ago

    didn’t the Firefox management say they would focus on their core product rather than random little services like this

    • laughterlaughter@lemmy.world
      link
      fedilink
      arrow-up
      8
      ·
      4 months ago

      At this point, I’m glad I switched to Mull on my phone. It took a bit of overcoming the resistance of using Firefox for decades (Stockholm syndrome), but I don’t miss Firefox one bit.

      Now I need to do that on my desktop, but I’m still shopping. Librewolf? Palemoon? Ice Weasel? What are folks here trying out these days?

      • Firestorm Druid@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        ·
        4 months ago

        Isn’t Mull basicslly Firefox since it’s just a Firefox-based fork? The UI seems to be identical to me - don’t notice any other differences on my phone

        • laughterlaughter@lemmy.world
          link
          fedilink
          arrow-up
          9
          ·
          4 months ago

          Yes, it’s Firefox without the bullshit.

          It’s ironic that Firefox started the same way, actually.

          When Netscape open sourced its browser and then fucked it up, some folks took the source code and built “Phoenix,” much, much later becoming Firefox.

        • CileTheSane@lemmy.ca
          link
          fedilink
          arrow-up
          4
          ·
          4 months ago

          Isn’t Mull basicslly Firefox since it’s just a Firefox-based fork?

          I don’t understand why that would be a bad thing. If Firefox starts to enshittify then a fork from before the enshittification is exactly what I want.

          • Firestorm Druid@lemmy.zip
            link
            fedilink
            English
            arrow-up
            6
            ·
            4 months ago

            It’s not - quite the contrary. I was just wondering what the commenter that I replied to meant when they said that it took them some getting used to. For me, it’s just a slight change in design and a different icon

    • Carighan Maconar@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      4 months ago

      Yeah but to be fair they bought this years ago. Just took them forever to integrated. I suspect any changes in direction will truly show in 3-4 years, once the current backlog (no don’t look at my company’s Jira, TYVM! 😑 ) is cleared.

  • thegreenguy@sopuli.xyz
    link
    fedilink
    arrow-up
    29
    ·
    4 months ago

    AI shit alone, I never understood the urge to build a whole OS in the browser. I want my browser to view websites. If I want more, then I can install extensions. I’d rather them release this as some sort of “official” extension. Might switch to LibreWolf (do you have any other suggestions?)

  • iAmTheTot@sh.itjust.works
    link
    fedilink
    arrow-up
    29
    ·
    4 months ago

    I’ve used Firefox since it was released. I will be considering other browsers due to this. I do not want AI in my products.

      • TomMasz@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        4 months ago

        Floorp

        Thanks, these look interesting. I’ve been using Firefox forever for my personal browsing (but Edge for work) and I’d prefer to stay with it if I can.

      • puppy@lemmy.world
        link
        fedilink
        arrow-up
        18
        ·
        4 months ago

        Since Firefox is free and open source, there are many other variations of it built and distributed by the community.

      • iAmTheTot@sh.itjust.works
        link
        fedilink
        arrow-up
        18
        ·
        4 months ago

        Different priorities for different people. The AI is what I really have an issue with right now. I’m sick of it being shoved down everyone’s throats, and I have big ethical concerns about it in general.

  • jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    28
    ·
    edit-2
    4 months ago

    “strategic partnerships”

    https://support.mozilla.org/en-US/kb/review-checker-review-quality

    Protect your privacy

    Firefox is committed to empowering you with information about review reliability while respecting your privacy. We use Oblivious HTTP (OHTTP) for Review Checker.

    When Review Checker is turned on, we use information about the products you visit on Amazon, Best Buy and Walmart to analyze the reviews, but by using OHTTP we ensure Mozilla cannot link you or your device to the products you have viewed. OHTTP uses encryption and a third party intermediary server to offer a technical guarantee that this is the case: all Mozilla learns from this network request is that someone, somewhere, looked at a given product.

    • jet@hackertalks.com
      link
      fedilink
      English
      arrow-up
      28
      ·
      edit-2
      4 months ago

      Here is a talk on OHTTP (OHAI) https://www.youtube.com/watch?v=_HEzpnktAwY

      and a OHTTP recap https://www.youtube.com/watch?v=qjLwo4Ufp8s

      Basically, if you trust the OHTTP Proxy (mozilla) and the OHTTP service provider (fakespot) to not collude, then OHTTP protects your data.

      If you think Mozilla and fakespot might collude, then this doesn’t give you any privacy. (Update - Someone pointed out Mozilla has purchased fakespot, so this comes down to Trusting mozilla with 100% of your data for their privacy promise and OHTTP is totally pointless here)

      Depends on your threat model.

      If they actually cared about privacy they would have the OHTTP model, sure, but also a TOR hidden service endpoint that anyone could use as well ; Removing all the links between the user and the service shouldn’t be a problem, since they are not monitizing user behavior, right? RIGHT?!?!?

      • GenderNeutralBro@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        17
        ·
        edit-2
        4 months ago

        Mozilla says they use a third-party OHTTP intermediary. In the blog post linked above, they name Fastly as their partner. So it’s not as bad as Mozilla + Mozilla-wearing-funny-glasses.

        Personally, I still think this is the wrong approach to privacy, even though I’ve used Fakespot on my own many times over the years. Largely because I don’t think any of this needs to be built into a web browser.

        I would prefer my web browser to minimize information leakage by default, to the greatest degree that it can while still remaining useful as a web browser. Mozilla keeps adding bloat to Firefox, and bloat always comes at a cost. I’d much prefer these to be browser extensions that people can download if they want them, rather than built in by default. The baseline Firefox should be lean. Less “stuff” = smaller attack surface. Simplicity is best.

        I mean, the Fakespot browser extension has existed for a long time, and I’ve never seriously considered installing it. I’d much rather just take an extra three seconds to load their web site and paste in a URL than have it constantly monitoring my activity and doing god-knows-what with it. That way I have better knowledge and control of what is happening with my data. Even if I trust their intentions, I don’t implicitly trust their competence (all software has bugs) and I don’t trust that they will never go rogue in the future.

        And also, I just don’t find this claim all that compelling in principle:

        By processing the data jointly across two independent parties, they ensure neither party holds the information required to reveal sensitive information about someone.

        I mean…sure. That’s fair. Buuuuuut handing half the data to your “partner” doesn’t give me a whole lot of confidence. Especially since literally nobody reads all of the privacy policies they are subject to. See:

        https://www.theatlantic.com/technology/archive/2012/03/reading-the-privacy-policies-you-encounter-in-a-year-would-take-76-work-days/253851/

        https://www.npr.org/sections/alltechconsidered/2012/04/19/150905465/to-read-all-those-web-privacy-policies-just-take-a-month-off-work

        https://www.techradar.com/computing/cyber-security/you-need-a-whole-workweek-every-month-to-read-privacy-policiesand-thats-bad-news

        Minimizing privacy policies should be a high-priority goal for any organization that claims to value privacy.

        Furthermore, how many additional parties have access (legally or otherwise) to both Mozilla and Fastly? 🤷

        • jet@hackertalks.com
          link
          fedilink
          English
          arrow-up
          9
          ·
          4 months ago

          i would like to see mozilla making all of these features as full fledged browser extensions (installed by default, sure why not, but uninstallable at user request)

        • jqubed@lemmy.world
          link
          fedilink
          arrow-up
          7
          ·
          4 months ago

          I remember when Firefox was brand new over 20 years ago and one of the reasons for creating it was the main Mozilla browser had too much feature bloat so it was stripped down to just a browser and if you wanted more features you could add them in as extensions, putting just what you wanted in the browser and leaving out what you didn’t. It was great! Eventually Firefox became more popular so Mozilla switched their efforts to it and they’ve been jamming more things that used to be extensions in as features and bloating it full of features I don’t want. It’s one of the reasons I started using Chrome in the early days of Chrome but then of course that and Google started getting worse so I switched back to Firefox, but it still has its problems.

      • 𝘋𝘪𝘳𝘬@lemmy.ml
        link
        fedilink
        arrow-up
        9
        ·
        4 months ago

        I don’t trust Mozilla one single bit with my data as long as they have an advertising network enabled by default and use pingback telemetry for ALL actions you do in the browser by default that can only be turned off by changing multiple “hidden” about:config settings.

        • jet@hackertalks.com
          link
          fedilink
          English
          arrow-up
          5
          ·
          4 months ago

          It doesn’t, but when modeling threats we have to go be capabilities and not intentions.

          • Vincent@feddit.nl
            link
            fedilink
            arrow-up
            12
            ·
            4 months ago

            If we’re going by capabilities, then your browser maker can already see everything you do in that browser.

    • astro_ray@lemdro.idOP
      link
      fedilink
      English
      arrow-up
      32
      ·
      4 months ago

      If someone wanted it, they could’ve installed the Firefox extension, but now for users who doesn’t want this, they have an intrusive feature that is just a bloat. Also, even if I wanted it, it’s fairly useless unless you live in western countries.

        • Luffy879@lemmy.ml
          link
          fedilink
          arrow-up
          13
          ·
          4 months ago

          Because not many people from somewhere like greece shop on walmart or best buy, and many people who use Firefox also are anti amazon

        • antler@feddit.rocks
          link
          fedilink
          arrow-up
          1
          ·
          4 months ago

          apt remove firefox (or via pacman, windows settings etc)

          Otherwise should be a bunch of flags you can set in about:config

        • astro_ray@lemdro.idOP
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 months ago

          I beluga there is an about:config setting to disable it. You can find more details somewhere in the comments of this post or the original post that I quoted.