Mozilla removes uBlock Origin Lite from Addon store. Developer stops developing Lite for Firefox; "it's worrisome what could happen to uBO in the future." - eviltoast

Mozilla recently removed every version of uBlock Origin Lite from their add-on store except for the oldest version.

Mozilla says a manual review flagged these issues:

Consent, specifically Nonexistent: For add-ons that collect or transmit user data, the user must be informed…

Your add-on contains minified, concatenated or otherwise machine-generated code. You need to provide the original sources…

uBlock Origin’s developer gorhill refutes this with linked evidence.

Contrary to what these emails suggest, the source code files highlighted in the email:

  • Have nothing to do with data collection, there is no such thing anywhere in uBOL
  • There is no minified code in uBOL, and certainly none in the supposed faulty files

Even for people who did not prefer this add-on, the removal could have a chilling effect on uBlock Origin itself.

Incidentally, all the files reported as having issues are exactly the same files being used in uBO for years, and have been used in uBOL as well for over a year with no modification. Given this, it’s worrisome what could happen to uBO in the future.

And gorhill notes uBO Lite had a purpose on Firefox, especially on mobile devices:

[T]here were people who preferred the Lite approach of uBOL, which was designed from the ground up to be an efficient suspendable extension, thus a good match for Firefox for Android.

New releases of uBO Lite do not have a Firefox extension; the last version of this coincides with gorhill’s message. The Firefox addon page for uBO Lite is also gone.

  • zkfcfbzr@lemmy.world
    link
    fedilink
    English
    arrow-up
    44
    ·
    edit-2
    4 months ago

    My own reading of the situation on the developer’s GitHub is unfortunately that the review by Mozilla is indeed completely inaccurate in every way. No way to even read it as a “Each side has their own story” type of thing since they reproduce Mozilla’s emails verbatim. They seem just materially incorrect. The source files referenced by the emails are visible on the same GitHub account, along with their complete histories showing no changes at all - the issues referenced don’t and never did exist.

    The only redeeming thing I can find is that the dev (ambiguously) seems to have never replied to the email from Mozilla about the issues, and so Mozilla was never made aware that there was an issue with the review that needed fixing. They seem to have done this because they perceived the process as hostile and not worth engaging with, which… fair, I guess.

    • FeelzGoodMan420
      link
      fedilink
      English
      arrow-up
      18
      arrow-down
      6
      ·
      4 months ago

      I understand where the dev is coming from but I think he still should have just replied to Mozilla. This is clearly a mistake on their part. The dev just seems pissed off and decided to not reply out of emotion. His call I guess but I don’t agree with that approach.

      • zkfcfbzr@lemmy.world
        link
        fedilink
        English
        arrow-up
        16
        ·
        edit-2
        4 months ago

        I agree that they should have replied, and that replying probably would have even fixed the mistake, but I also can’t find it in me to fault them in this situation. Getting those emails would have been both frustrating and insulting, and one of their messages on the linked GitHub page goes into the various stresses the situation puts them through.

        I don’t agree that there’s enough evidence here to decide Mozilla’s actions were hostile/malicious - maybe if they were given a chance to fix things and still didn’t, but everyone makes mistakes. Incompetent, sure, malicious, not enough evidence.

        • FeelzGoodMan420
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          4 months ago

          Yea I don’t think Mozilla did it maliciously. I think either some dumbass analyst fucked up, or they ran it through AI, and the AI is dogshit and fucked up. Those are my guesses.

          • zkfcfbzr@lemmy.world
            link
            fedilink
            English
            arrow-up
            7
            ·
            4 months ago

            Who knows? The file that got incorrectly marked as collecting or transmitting data was named “googlesyndication_adsbygoogle.js”. I’m sure that’s a very reasonable guess for what a file with that name would do… in most add-ons. But like, obviously not in this one. My best guess is the reviewers have some type of tool that’s intended to help them find issues, it flagged the referenced files, and the reviewer either couldn’t or didn’t properly verify the files were actually issues.

            • FeelzGoodMan420
              link
              fedilink
              English
              arrow-up
              4
              arrow-down
              4
              ·
              4 months ago

              Yea I think it’s an honest mistake. I don’t see this as “hostile” to Gorhill. I have no idea why he thinks this. It’s really weird.

          • kbal@fedia.io
            link
            fedilink
            arrow-up
            4
            ·
            4 months ago

            AI seems like a possibility. I find it slightly easier to believe that someone in management was stupid enough to replace human reviewers with bots than that someone in a position to decide what gets accepted had never heard of UBO and didn’t realize that it’s an important one.

            Either way they really ought to explain themselves.

            • FeelzGoodMan420
              link
              fedilink
              English
              arrow-up
              1
              ·
              4 months ago

              Well Gorhill would need to respond…which he said he won’t do so rip.

              • kbal@fedia.io
                link
                fedilink
                arrow-up
                1
                ·
                4 months ago

                Whether or not Mozilla chooses to issue some kind of meaningful statement about what happened beyond the boilerplate “oops, it was an error” is not up to Gorhill.

                • FeelzGoodMan420
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  4 months ago

                  Well we’ll never know what happened unless he tell them they’re wrong. Of course he can do whatever he wants.

      • LWD@lemm.eeOP
        link
        fedilink
        arrow-up
        10
        arrow-down
        9
        ·
        4 months ago

        Gorhill does not seem like the sort of person to respond to problems by giving Up.

        This is the developer who responded to the creation of Manifest V3 by pioneering a hack-free V3-compliant addon, and ended up making it genuinely compelling.

        • FeelzGoodMan420
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 months ago

          Well he clearly gave up when he won’t even respond to Mozilla. That’s fine, it’s his call. But I personally would at least respond and let Mozilla know it is a mistake. I feel like this can be reaolved fairly quickly?