![]() |
|
#1
|
|||
|
|||
|
I manually updated one machine to 12.0.1 this morning, via Help->About->Check for updates. After restarting I found a new extension called "Test Pilot" had been silently installed without any notice. Based on a quick look, this appears to be a mechanism for automatically retrieving work orders from Mozilla, which are then executed to collect usage data, configuration data, and/or survey type responses. There is a new Tools->Test Pilot menu item which allows you to tweak it a bit. The default appears to be "participate and notify me when the study is ready to submit. At which time you can supposedly review it.
Searches turned up some folks reporting this elsewhere some months ago as well as a comment saying that not everyone would get it at the same time. I'm not yet sure if it was just my lucky day or if it is being dished up to everyone who installed 12.0.1. I updated a second machine while running Wireshark. Again, Test Pilot was silently installed with the same settings. After restarting it established a secure connection with testpilot.mozillalabs.com which I'm not setup to sniff so I don't know if it was just trying to retrieve a work order or whether it was sending home some initial data. A bit later right after some secure communications with addons.mozilla.org then production.mozillamessaging.com, I see something strange. It is Thunderbird issuing a get for -http://www.mozilla.org/thunderbird/legal/privacy/ without a referrer header. I was clicking around the Thunderbird interface at the time and didn't explicitly go there. I don't know what caused that. Sadly and ironically, that privacy page has WebTrends javascript (!) which my Thunderbird... not equipped with the protections that my Firefox is.. seems to have executed thus producing a brief info/ID passing exchange with that firm's servers ![]() |
|
#2
|
|||
|
|||
|
The same happened to me yesterday - silently installed Test Pilot spyware when updating from 11 to 12. I no longer trust Mozilla and I'm looking for alternatives - do you know of any? I need a simple email client where I can code my own extensions. Not only is Mozilla spyware, it is also bloatware.
Ironically, uTorrent 3.1.3 update filled my PC yesterday with Conduit adware as well. Now should I be updating or not? If I don't update I end up with malware like I did about a month ago, when I got Luckisel malware through Thunderbird 3 - how could it be, when there is no scripting etc.? I have an answer for that - Mozilla is a NWO subsidiary after our data. I guess I downgrade to IE4 & Outlook Express and be safe. ![]() Last edited by mun : May 4th, 2012 at 08:21 AM. |
|
#3
|
|||
|
|||
|
Thanks for the info. I don't use it myself, but a relative of mine does and may not be aware of it. I'll have to check it out.
Thanks -edit- There was no such extension, but Thunderbird did have Google Update, Adobe Reader, Java and Silverlight plugins loaded. Why would an e-mail client need to check and load those plugins? ![]() Last edited by m00nbl00d : May 4th, 2012 at 10:07 AM. |
|
#4
|
||||
|
||||
|
Quote:
I have disabled the Test Pilot spyware for the moment (on Firefox) while I decide whether it is a good thing or not. If it helps Mozilla I reckon it's OK. I'm pretty sure you wouldn't get this kind of behaviour with Waterfox & SeaMonkey. If you are running 32 bit, not only is SeaMonkey a viable (Gecko) alternative to Firefox, but with this theme you can even make it look like Firefox. SeaMonkey has an internal mail client not unlike Thunderbird, although I don't use it myself.
__________________
Quis custodiet ipsos custodes? Last edited by Daveski17 : May 4th, 2012 at 10:50 AM. |
|
#5
|
||||
|
||||
|
I am a little confused, I guess. I can't seem to find this on either Firefox or Thunderbird. I have Firefox 12.0 and Thunderbird 12.0.1. Can anyone tell me what I am missing here? Thanks.
__________________
Microsoft Windows 8 Pro x64 Windows Defender MalwareBytes Pro SuperAntiSpyware Pro WinPatrol Plus |
|
#6
|
||||
|
||||
|
Quote:
... just the usual everyone is spying on me all the time.
__________________
One can't be too rich, too thin, or too secure |
|
#7
|
||||
|
||||
|
Quote:
Thanks for reply - I won't worry about it. If they are spying on me, they won't find much of interest, I'm afraid.
__________________
Microsoft Windows 8 Pro x64 Windows Defender MalwareBytes Pro SuperAntiSpyware Pro WinPatrol Plus |
|
#8
|
||||
|
||||
|
Updated Thunderbird from 12.0 to 12.0.1 through internal updater and no "Test Pilot" here
![]()
__________________
It is the Tale, not he who tells it (Stephen King) |
|
#9
|
||||
|
||||
|
I got a bad feeling About This :?
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker "Uncommon sense will increase your privacy; common sense will just make you common." "The Worst Thing in the World is To look and not be able to Help " |
|
#10
|
||||
|
||||
|
Quote:
I have it in Firefox on my Win 7 (64 bit) PC, yet it hasn't manifested on my Vista 32 bit notebook. ![]()
__________________
Quis custodiet ipsos custodes? |
|
#11
|
||||
|
||||
|
Quote:
Everyone is spying on everyone all the time.
__________________
Quis custodiet ipsos custodes? |
|
#12
|
||||
|
||||
|
In Thunderbird, tools, add ons, extensions, remove
|
|
#13
|
||||
|
||||
|
__________________
"Being safe on the internet is a lot like being safe in real life. Always have a back-up plan and be careful where you stick your pointer." -- anonymous (but probably not Anonymous) |
|
#14
|
||||
|
||||
|
Quote:
I'm pretty sure that's it.
__________________
Quis custodiet ipsos custodes? |
|
#15
|
|||
|
|||
|
Quote:
I saw it when installing 12.0, and selected the 'disable' option. After using the internal updater to get 12.0.1, Test Pilot was still disabled. Yet I've now gone ahead and removed it completely anyway. I expect you got a notice about it when installing 12.0 or 12.0.1, you just failed to pay close enough attention. |
|
#16
|
|||
|
|||
|
@acr1965: That is surely it. Although I think the version I received might have been newer. I'm not positive; I uninstalled it from both machines right before I went to bed. Speaking of which, here are some links I could have posted earlier:
http://blog.mozilla.org/thunderbird/...rch-27th-2012/ https://wiki.mozilla.org/Thunderbird:UX:Test_Pilot http://groups.google.com/group/mozil...rch+this+group @Mun: For right now I'm just going to disable Thunderbird and Firefox checking for updates, add some software firewall rules, and switch to offline updates for both and their addons. This is but the latest in a string of things I've seen which make me question some of the developers and decision makers within Mozilla. I think there are many good apples in Mozilla and I don't know how we as users can drive out the bad ones. @ABee: Both machines jumped from 11 whatever to 12.0.1. One is a backup for the other and thus uses a copy of the first one's profile, which may account for why both received Test Pilot at the same time essentially. I don't think I missed anything in the way of notice. I was a bit sleepy, granted, but I was watching that much more carefully the second time. Others have reported silent installation too. |
|
#17
|
||||
|
||||
|
Quote:
Thanks! |
|
#18
|
|||
|
|||
|
Speaking of a being proactive, if you don't have it and don't want it I think adding this preference:
Code:
Edit: I'd have to study some more code to be sure but I'm going to stick with the above. Last edited by TheWindBringeth : May 4th, 2012 at 11:20 PM. |
|
#19
|
||||
|
||||
|
__________________
siljaline MS MVP Alum . MVPS HOSTS . Rename Hosts . ESET for Business . 10 Immutable Laws of Security . System Lookup . ESET Threat Blog . MBAM Last edited by siljaline : May 5th, 2012 at 03:18 AM. |
|
#20
|
||||
|
||||
|
Quote:
No offence meant - but that's insane, IMHO. You should really look at the links presented by siljaline in post #19 before making such grievous decisions. |
|
#21
|
||||
|
||||
|
Quote:
__________________
One can't be too rich, too thin, or too secure |
|
#22
|
||||
|
||||
|
Quote:
Maybe, but the really sad thing is all of the rhetoric emanating from the Nanny Cyber-State Police.
__________________
Quis custodiet ipsos custodes? |
|
#23
|
|||
|
|||
|
Sounds like I'll finally install Evolution for windows.
![]()
__________________
Windows 8 Pro x64 First Line of Defense: Sandboxie for Internet-facing programs, Privatefirewall Hardening: EMET, Early Launch Anti-Malware Enabled Browser: Google Chrome (ScriptNo, Adblock) Scanning: MBAM Pro, Windows Defender |
|
#24
|
||||
|
||||
|
Quote:
Yes, paranoia is all around ... ![]() |
|
#25
|
|||
|
|||
|
Quote:
Apart from that aspect which I expect you have a different opinion on, what do you consider insane and/or grievous about shifting to offline updates? Are you assuming that I will forget or fail to do so on a very regular and very timely basis? That I won't be automating things to the extent possible? I may very well run into technical issues and find it problematic in some way. If that is your point and there is a wall, I'll acknowledge it. If that isn't your point, I don't see how the terms insane and grievous apply. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|