155

From the post:

In 2023, a significant portion of Firefox downloads came from unknown sources. We believe many of them came from 3rd party websites that let you download Firefox. While some websites are okay, others can put you at risk of downloading an old version or a build with the wrong locale, leading to security risks, a bad user experience, or even malicious installations.

Help the Firefox team to uncover this mystery by taking part in the Firefox 3rd-party installer campaign 3!

There will be swag, and you’ll be featured in our blog if you manage to report 10 valid reports. So don’t forget to invite your friends too!

Have any questions about this campaign? Join us on Matrix or watch the recording of our community call with Romain Testard, Principal Product Manager at Mozilla.

Please also help spread the word about this campaign by sharing this on your social media.

Keep on rocking the helpful web,

Kiki & Konstantina

top 16 comments
sorted by: hot top controversial new old
[-] boredsquirrel@slrpnk.net 27 points 5 months ago* (last edited 5 months ago)

I wonder of they think of all the Linux installs from the various repos. These are nearly all unmodified and will send data to Mozilla, containing an "unknown" install origin.

  • distro repos
  • flathub
  • fedora flatpaks
  • snap store

These may still pull stuff, not per user but per distro.

[-] umbrella@lemmy.ml 5 points 5 months ago

flatpaks and snaps are official now iirc

[-] boredsquirrel@slrpnk.net 3 points 5 months ago

Yes but I wonder if they already know these origins.

Afaik they determine "installations" not via downloads from their servers, but started FF apps. All have some unique ID stuff and send that to Mozilla

[-] possiblylinux127@lemmy.zip 9 points 5 months ago

"We just need to protect our intellectual property"

Obviously harmful versions of Firefox that do not release the source code are bad but there are probably soft forks.

[-] sugar_in_your_tea@sh.itjust.works 78 points 5 months ago

This isn't about forks, it's about installers that pull directly from Mozilla's servers. This could be installers that bundle malware/adware with it.

If you fork it, you'll be building the source and distributing it yourself. This isn't about that.

[-] RobotToaster@mander.xyz 5 points 5 months ago

It could be "forks" that are just installers packaged with distinct configuration files or add-ons.

[-] sugar_in_your_tea@sh.itjust.works 11 points 5 months ago

Evidence? And if so, I don't think Mozilla cares (e.g. snaps are probably repackaged installers).

If you're renaming things, you're going to recompile to put your branding on it. So things like Mull, Mullvad Browser, Librewolf, etc will all use their own binaries.

[-] boredsquirrel@slrpnk.net 2 points 5 months ago

The flatpak is absolutely not a repackaged installer and I dont think the snap is either.

[-] sugar_in_your_tea@sh.itjust.works 1 points 5 months ago

Cool, I just figured packagers would be lazy and just use upstream builds. That's what I would do.

[-] boredsquirrel@slrpnk.net 3 points 5 months ago

They mostly use mozilla binaries, but download them once and package the install in their own format.

So this will download once instead of thousands of times

[-] possiblylinux127@lemmy.zip 3 points 5 months ago
[-] sugar_in_your_tea@sh.itjust.works 40 points 5 months ago

It's not. It's literally talking about installers, not source forks.

Believe what you want, I guess, but the facts available say otherwise.

[-] hanrahan@slrpnk.net 6 points 5 months ago

Linux version I get from Flatpack

[-] rdri@lemmy.world 6 points 5 months ago

I use the one from portableapps because I can't stand going into appdata every time I need to change something.

[-] Cyberjin@lemmy.world 4 points 5 months ago

I remember that Firefox had unique identifiers when downloading from the website. https://www.ghacks.net/2022/03/17/each-firefox-download-has-a-unique-identifier/ So that's probably how they are tracking everything.

For me I use repos like winget or chocolatey And I guess there are tons of options on Linux.

[-] Andromxda@lemmy.dbzer0.com 2 points 5 months ago

Well, almost every Linux distro includes Firefox. Maybe that's where these downloads are coming from?

this post was submitted on 22 Jun 2024
155 points (100.0% liked)

Firefox

17938 readers
2 users here now

A place to discuss the news and latest developments on the open-source browser Firefox

founded 4 years ago
MODERATORS