Re: Helping ensure privacy + security

Chris Peterson <[email protected]> Fri, 6 Nov 2015 10:35:35 -0800
Newsgroups gmane.comp.mozilla.devel.plugins
Message-ID <[email protected]>
On 11/5/15 10:53 PM, Josh wrote:
> So . . . the argument is basically that "some websites might break with this field changed" regardless of how it is changed.
>
> So we can expect the next release of Firefox to prevent users from altering the User Agent string, then? After all, changing that to a different value (or null) can and will break many websites.

Customization of the User Agent string will not be removed because it is 
useful for improving compatibility with some websites and for testing.


> I use this example as an extreme case to show the logically inconsistent stance taken. Users want the ability to limit information or otherwise alter the behavior of their browser. Chris' plugin, the "FireGloves" plugin, and many others do this.
>
> What I am seeing is a lack of a technical argument for why the defeaturing took place. It's simply because one person doesn't think people should do this . . . really? There are thousands of plugin users that disagree.

Please read the rest of this thread. I implemented this feature, so I am 
clearly sympathetic to the privacy aspects. I am also the "one person" 
who removed it. It is an all-around worse solution than disabling 
plugins by default and selectively enabling them for websites you need.

This feature could never be enabled by default because it broke too many 
websites. And there was no value in leaving this code dormant because, 
if someone enabled the pref on their machine, it would break websites.

I have asked for, and no one has yet provided, one example of a website 
that uses an NPAPI plugin successfully when plugin names are hidden.