Hacker Newsnew | past | comments | ask | show | jobs | submit | more mmsc's commentslogin

https://paulgraham.com/disagree.html

Please consider reading.


It's cool that Mozilla updated https://www.mozilla.org/en-US/security/advisories/mfsa2026-1... because we were all wondering who had found 22 vulnerabilities in a single release (their findings were originally not attributed to anybody.)


Use After Free Use After Free Use After Free Use After Free Use After Free Use After Free Use After Free.

I would be more satisfied if they gave a proper explanation of what these could have lead to rather than being "well maybe 0.001% chance to exploit this". They did vaguely go over how "two" exploits managed to drop a file, but how impactful is that? Dropping a file in abcd with custom contents in some folder relative to the user profile is not that impactful other than corrupting data or poisoning cache, injecting some javascript. Now reading session data from other sites, that I would find interesting.


You should generally assume that in a web browser any memory corruption bug can, when combined with enough other bugs and a lot of clever engineering, be turned into arbitrary code execution on your computer.


The most important bit being the difficulty, AI finding 21 easily exploitable bugs is a lot more interesting than 21 that you need all the planets to align to work.


If you can poison cache, you can probably use that a stepping stone to read session data from other sites.


Looks like a lot of the usual suspects


> Mine also isn't anywhere nearly as confusing as his by default

You can run the following and try it for yourself. Don't forget to highlight some text before right-clicking an image (e.g. https://en.wikipedia.org/wiki/The_World_Factbook)

  TMPPROF="$(mktemp -d /tmp/ff-tmp.XXXXXX)"
  /Applications/Firefox.app/Contents/MacOS/firefox -no-remote -profile "$TMPPROF"


It's gleaned from my locale. .hu is irrelevant; my alternative keyboard on my system is Polish


Interesting. I’ve never been to Poland and yet Polish the default second option in a ton of places for me. No clue why.


You're right, I didn't know about what that "..." meant. It's kind of obvious what I meant though: "I don't know why all of these have ..." I've added that information to the post.

The greyed out options have no point because 99.99% of the links I click are already clean. Like so many of the other privacy enhancing options, just provide an option to "clean links automatically."


Link "cleaning" will sometimes just break a link entirely since it's a heuristic-based thing that removes query parameters that appear to be nonfunctional tracking parameters. Doing it by default would be setting up users for the occasional very bad experience.


Did you really make a blog post to tell the world that you don't know some things? That's not usual. If that is true, the only conclusion is that you should learn those things, and I'm not sure what I am supposed to get from reading it.

I think, or at least the way it reads to me is that you believe Firefox devs are wrong. This is what it looks like you meant. You believe the "..." is wrong to be there, and it should be removed. Which I do not agree with, and in any case we should first consider the "..." conventional meaning and only then we can maybe get to the conclusion that it should be removed. That it should be removed because you don't know why it is there is not reasonable, not to me.

In my humble opinion you should reflect a bit more on what you actually meant to say by this and also other points in the post.

> The greyed out options have no point because 99.99% of the links I click are already clean.

Frankly that's nonsense. They obviously have a point, and the fact you disagree with the point is something completely different. Firefox isn't specifically made for you. I appreciate the greyed out options in general, it helps me know they are there and that they may become available under some conditions.


> Did you really make a blog post to tell the world that you don't know some things? That's not usual

You are focusing on 5 words out of a 1000-word post. Get a grip lol.

In a world of usual, I like to be unusual.


loael


I wonder if Microsoft actually likes running their free email service still. They wiped a ton of old Hotmail and Live.com emails some years ago (and then allowed new people to register those deleted names). I imagine they don't get much out of it anymore.


I wonder how many accounts on other services were then hijacked using "forgot my password" attacks.

UPDATE: After a bit of digging it looks like they started the username recycling policy in 2013, may have quietly stopped doing that in 2018 but formalized no longer doing that in 2021: https://web.archive.org/web/20230627104616/https://www.micro...

"Summary of changes to the Microsoft Services Agreement – June 15, 2021 [...] In the Outlook and Office Services sections, we’ve removed the Outlook.com section to clarify that an email address or username is not recycled into our system or assigned to another user."


It's wild to me they ever started doing this in the first place. And in 2013 no less, it isn't like the hijacking risk was some far off concept at that point.


It's certainly not free to run and maybe it doesn't really make sense for Microsoft to run Outlook.com anymore, except that it's an easy way to motivate people to having a Microsoft account.

Outlook.com certainly has to show up as an expense, one that Microsoft would like to reduce. When you look at what other providers charge for a single email account, it's hard to see Microsoft making money of Outlook.com. There's obviously something to be said for scale, but still, it must cost them something.


> it's an easy way to motivate people to having a Microsoft account.

Can you actually use a non-outlook account for windows? Or are you talking about a different kind of "ms account"?


You can register a (personal, not M365) Microsoft Account without Outlook.com by just supplying a different email address in the signup portion.

Also you can have (or was that had - not sure) a (again personal, not Workspace) Google account without Gmail by using a different email address.


>It's certainly not free to run and maybe it doesn't really make sense for Microsoft to run Outlook.com anymore, except that it's an easy way to motivate people to having a Microsoft account.

it also funnels people into using exchange for work. more like a "marketing expense".


They wiped all the emails from my 25 year old Hotmail account. Pretty weak. I refuse to use Microsoft products except if forced, and do my best to evangelize this position.


Most people will never pay for email service. Which leaves you Google, MS or god forbid your own ISP.


That's because it was generated by an LLM.


I simply cannot believe people in this post are discussing this as anything other than a complete bot job. Pure clanker vomit.


I realize it's been "written" by an LLM, but the content could have been written by someone I know. It's eerie how this person thinks exactly the same way. It's never their fault, always the others', and they are always obviously right and no amount of arguing can change their mind.


"Write an essay about struggling to change a software org that doesn't want to change. Make me the hero. Post it at 1am so it looks like I was up late suffering with the burden of what I know."

This is unfortunately the world we are in now.


This is not a politically correct thing to say but there is a class of neurodiverse software developers who display these characteristics and I suspect the author belongs to this group.

Frankly, reminds me of Michael O'Church


Yes, that's why it's great. They have the best of everything around and have imo perfected it. It's difficult to think of certain foods that are actually unique to any "country", tbh.


In addition to completely disabling AI, I found the following setting extremely convinent to disable in about:config. They clutter up my right-click on a link or on text selection.

  browser.translations.select.enable
  dom.text_fragments.enabled
  privacy.query_stripping.strip_on_share.enabled
  devtools.accessibility.enabled
Now if only I could get rid of "Print selection" and "Services" when right-clicking, too (on MacOS)


Also forgot `browser.ml.chat.menu`, `browser.ml.linkPreview.enabled`. If only there was a way to get rid of "Email image", and "Set image as desktop background".


Try modifying a webpage’s source to open with <html mozdisallowselectionprint>. If that works, you can make that universal using any page-mod plugin (though not necessarily the userstyle CSS-only ones). I’m mobile-only tonight so I can’t test myself, but derived from:

https://searchfox.org/firefox-main/source/layout/printing/ns...


Why would you disable "dom.text_fragments.enabled"? Why "privacy.query_stripping.strip_on_share.enabled"?

The latter, especially, seems helpful.


`dom.text_fragments.enabled` to remove "Copy link to highlight" on right-click. Yes, it can be useful, but I never use it and the very rare occasion of needing to use it when opening a page, I can just search it myself.

`privacy.query_stripping.strip_on_share.enabled` to remove "Copy clean link". I would rather it just did that clean link thing automatically, but I don't actually care about clean links -- it's just annoying having two "copy link" next to each other (especially with one which is greyed out 99% of the time!)


It strips query params used for tracking. Has it never bothered you when you click share on Instagram or YouTube and it inserts a unique-to-you "share ID" in the URL? I was burned by this once, now every time I copy a share URL from a social media platform I first paste it into my text editor and remove all of the privacy invasive tracking cruft.

As an aside I think it's only matter of time before this is done without query params and instead each share link is generated just for you.


You may be interested in the ClearURLs extension: https://addons.mozilla.org/en-US/firefox/addon/clearurls/


I'm also missing:

  dom.text-recognition.enabled
  browser.search.visualSearch.featureGate
  extensions.formautofill.addresses.enabled
  extensions.formautofill.creditCards.enabled
  widget.macos.native-context-menus
The last one removes the "Services" option when right-clicking an image or highlighted text.


I wish we could also disable "Send via email" when right clicking a picture, I constantly misclick and userChrome.css does not work for the context menu on macOS since it's natively rendered...


> userChrome.css does not work for the context menu on macOS

Putting:

#context-sendimage { display:none!important; }

in that file works for me.


Does not work on macOS, it uses native context menus that can't be styled via userChrome.css.


Try disabling widget.macos.native-context-menus


That's what was missing, thank you!


> Does not work on macOS

Yes it does.


See the other comment, you have to disable "widget.macos.native-context-menus".


So was I wrong?


print.enabled should disable all the print stuff.


Thanks! I didn't know that.

I think that's a good workaround, but I'll have to re-enable it when I actually need to print something.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: