Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > other software & services
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 4th, 2012, 06:04 AM
TheWindBringeth TheWindBringeth is offline
Frequent Poster
 
Join Date: Feb 2012
Posts: 813
Default Thunderbird update silently installs Test Pilot extension

I manually updated one machine to 12.0.1 this morning, via Help->About->Check for updates. After restarting I found a new extension called "Test Pilot" had been silently installed without any notice. Based on a quick look, this appears to be a mechanism for automatically retrieving work orders from Mozilla, which are then executed to collect usage data, configuration data, and/or survey type responses. There is a new Tools->Test Pilot menu item which allows you to tweak it a bit. The default appears to be "participate and notify me when the study is ready to submit. At which time you can supposedly review it.

Searches turned up some folks reporting this elsewhere some months ago as well as a comment saying that not everyone would get it at the same time. I'm not yet sure if it was just my lucky day or if it is being dished up to everyone who installed 12.0.1.

I updated a second machine while running Wireshark. Again, Test Pilot was silently installed with the same settings. After restarting it established a secure connection with testpilot.mozillalabs.com which I'm not setup to sniff so I don't know if it was just trying to retrieve a work order or whether it was sending home some initial data.

A bit later right after some secure communications with addons.mozilla.org then production.mozillamessaging.com, I see something strange. It is Thunderbird issuing a get for -http://www.mozilla.org/thunderbird/legal/privacy/ without a referrer header. I was clicking around the Thunderbird interface at the time and didn't explicitly go there. I don't know what caused that. Sadly and ironically, that privacy page has WebTrends javascript (!) which my Thunderbird... not equipped with the protections that my Firefox is.. seems to have executed thus producing a brief info/ID passing exchange with that firm's servers
  #2  
Old May 4th, 2012, 08:14 AM
mun mun is offline
Infrequent Poster
 
Join Date: May 2012
Posts: 1
Default Re: Thunderbird update silently installs Test Pilot extension

The same happened to me yesterday - silently installed Test Pilot spyware when updating from 11 to 12. I no longer trust Mozilla and I'm looking for alternatives - do you know of any? I need a simple email client where I can code my own extensions. Not only is Mozilla spyware, it is also bloatware.

Ironically, uTorrent 3.1.3 update filled my PC yesterday with Conduit adware as well. Now should I be updating or not?

If I don't update I end up with malware like I did about a month ago, when I got Luckisel malware through Thunderbird 3 - how could it be, when there is no scripting etc.? I have an answer for that - Mozilla is a NWO subsidiary after our data.

I guess I downgrade to IE4 & Outlook Express and be safe.

Last edited by mun : May 4th, 2012 at 08:21 AM.
  #3  
Old May 4th, 2012, 09:59 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,457
Default Re: Thunderbird update silently installs Test Pilot extension

Thanks for the info. I don't use it myself, but a relative of mine does and may not be aware of it. I'll have to check it out.


Thanks

-edit-

There was no such extension, but Thunderbird did have Google Update, Adobe Reader, Java and Silverlight plugins loaded. Why would an e-mail client need to check and load those plugins?

Last edited by m00nbl00d : May 4th, 2012 at 10:07 AM.
  #4  
Old May 4th, 2012, 10:44 AM
Daveski17's Avatar
Daveski17 Daveski17 is offline
Massive Poster
 
Join Date: Nov 2008
Location: Lloegyr
Posts: 5,322
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by mun
The same happened to me yesterday - silently installed Test Pilot spyware when updating from 11 to 12. I no longer trust Mozilla and I'm looking for alternatives - do you know of any?

I have disabled the Test Pilot spyware for the moment (on Firefox) while I decide whether it is a good thing or not. If it helps Mozilla I reckon it's OK.

I'm pretty sure you wouldn't get this kind of behaviour with Waterfox & SeaMonkey.

If you are running 32 bit, not only is SeaMonkey a viable (Gecko) alternative to Firefox, but with this theme you can even make it look like Firefox. SeaMonkey has an internal mail client not unlike Thunderbird, although I don't use it myself.
__________________
Quis custodiet ipsos custodes?

Last edited by Daveski17 : May 4th, 2012 at 10:50 AM.
  #5  
Old May 4th, 2012, 11:29 AM
JohnBurns's Avatar
JohnBurns JohnBurns is offline
Frequent Poster
 
Join Date: Jul 2004
Location: Oklahoma City
Posts: 237
Default Re: Thunderbird update silently installs Test Pilot extension

I am a little confused, I guess. I can't seem to find this on either Firefox or Thunderbird. I have Firefox 12.0 and Thunderbird 12.0.1. Can anyone tell me what I am missing here? Thanks.
__________________
Microsoft Windows 8 Pro x64
Windows Defender
MalwareBytes Pro
SuperAntiSpyware Pro
WinPatrol Plus
  #6  
Old May 4th, 2012, 11:35 AM
vasa1's Avatar
vasa1 vasa1 is offline
Massive Poster
 
Join Date: May 2010
Posts: 3,988
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by JohnBurns
... Can anyone tell me what I am missing here? Thanks.
Nothing much ... just the usual everyone is spying on me all the time.
__________________
One can't be too rich, too thin, or too secure
  #7  
Old May 4th, 2012, 11:36 AM
JohnBurns's Avatar
JohnBurns JohnBurns is offline
Frequent Poster
 
Join Date: Jul 2004
Location: Oklahoma City
Posts: 237
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by vasa1
Nothing much ... just the usual everyone is spying on me all the time.

Thanks for reply - I won't worry about it. If they are spying on me, they won't find much of interest, I'm afraid.
__________________
Microsoft Windows 8 Pro x64
Windows Defender
MalwareBytes Pro
SuperAntiSpyware Pro
WinPatrol Plus
  #8  
Old May 4th, 2012, 11:37 AM
Wallaby's Avatar
Wallaby Wallaby is offline
Regular Poster
 
Join Date: Jan 2011
Posts: 138
Default Re: Thunderbird update silently installs Test Pilot extension

Updated Thunderbird from 12.0 to 12.0.1 through internal updater and no "Test Pilot" here
__________________
It is the Tale, not he who tells it (Stephen King)
  #9  
Old May 4th, 2012, 11:54 AM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: Thunderbird update silently installs Test Pilot extension

I got a bad feeling About This :?
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #10  
Old May 4th, 2012, 12:12 PM
Daveski17's Avatar
Daveski17 Daveski17 is offline
Massive Poster
 
Join Date: Nov 2008
Location: Lloegyr
Posts: 5,322
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by JohnBurns
I am a little confused, I guess. I can't seem to find this on either Firefox or Thunderbird. I have Firefox 12.0 and Thunderbird 12.0.1. Can anyone tell me what I am missing here? Thanks.

I have it in Firefox on my Win 7 (64 bit) PC, yet it hasn't manifested on my Vista 32 bit notebook.
__________________
Quis custodiet ipsos custodes?
  #11  
Old May 4th, 2012, 12:13 PM
Daveski17's Avatar
Daveski17 Daveski17 is offline
Massive Poster
 
Join Date: Nov 2008
Location: Lloegyr
Posts: 5,322
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by vasa1
Nothing much ... just the usual everyone is spying on me all the time.

Everyone is spying on everyone all the time.
__________________
Quis custodiet ipsos custodes?
  #12  
Old May 4th, 2012, 12:22 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,210
Default Re: Thunderbird update silently installs Test Pilot extension

In Thunderbird, tools, add ons, extensions, remove
  #13  
Old May 4th, 2012, 01:34 PM
acr1965's Avatar
acr1965 acr1965 is offline
Massive Poster
 
Join Date: Oct 2006
Posts: 4,432
Default Re: Thunderbird update silently installs Test Pilot extension

Is this it? https://addons.mozilla.org/en-US/fir...on/test-pilot/
__________________
"Being safe on the internet is a lot like being safe in real life. Always have a back-up plan and be careful where you stick your pointer." -- anonymous (but probably not Anonymous)
  #14  
Old May 4th, 2012, 01:39 PM
Daveski17's Avatar
Daveski17 Daveski17 is offline
Massive Poster
 
Join Date: Nov 2008
Location: Lloegyr
Posts: 5,322
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by acr1965

I'm pretty sure that's it.
__________________
Quis custodiet ipsos custodes?
  #15  
Old May 4th, 2012, 02:01 PM
ABee ABee is offline
Frequent Poster
 
Join Date: Jun 2010
Posts: 330
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by TheWindBringeth
I manually updated one machine to 12.0.1 this morning, via Help->About->Check for updates. After restarting I found a new extension called "Test Pilot" had been silently installed without any notice.
Perhaps you missed the notice, or missed it when previously installing 12.0?
I saw it when installing 12.0, and selected the 'disable' option. After using the internal updater to get 12.0.1, Test Pilot was still disabled. Yet I've now gone ahead and removed it completely anyway.

I expect you got a notice about it when installing 12.0 or 12.0.1, you just failed to pay close enough attention.
  #16  
Old May 4th, 2012, 03:00 PM
TheWindBringeth TheWindBringeth is offline
Frequent Poster
 
Join Date: Feb 2012
Posts: 813
Default Re: Thunderbird update silently installs Test Pilot extension

@acr1965: That is surely it. Although I think the version I received might have been newer. I'm not positive; I uninstalled it from both machines right before I went to bed. Speaking of which, here are some links I could have posted earlier:

http://blog.mozilla.org/thunderbird/...rch-27th-2012/

https://wiki.mozilla.org/Thunderbird:UX:Test_Pilot

http://groups.google.com/group/mozil...rch+this+group

@Mun: For right now I'm just going to disable Thunderbird and Firefox checking for updates, add some software firewall rules, and switch to offline updates for both and their addons. This is but the latest in a string of things I've seen which make me question some of the developers and decision makers within Mozilla. I think there are many good apples in Mozilla and I don't know how we as users can drive out the bad ones.

@ABee: Both machines jumped from 11 whatever to 12.0.1. One is a backup for the other and thus uses a copy of the first one's profile, which may account for why both received Test Pilot at the same time essentially. I don't think I missed anything in the way of notice. I was a bit sleepy, granted, but I was watching that much more carefully the second time. Others have reported silent installation too.
  #17  
Old May 4th, 2012, 07:59 PM
majoMo's Avatar
majoMo majoMo is offline
Frequent Poster
 
Join Date: Aug 2007
Posts: 785
Lightbulb Info appreciated!

Quote:
Originally Posted by ronjor
In Thunderbird, tools, add ons, extensions, remove
A proactive and assertive information. Suitable, sharp, useful to users. Positive stance to overcome an emotional negativity negligible.

Thanks!
  #18  
Old May 4th, 2012, 10:35 PM
TheWindBringeth TheWindBringeth is offline
Frequent Poster
 
Join Date: Feb 2012
Posts: 813
Default Re: Thunderbird update silently installs Test Pilot extension

Speaking of a being proactive, if you don't have it and don't want it I think adding this preference:
Code:
extensions.installedDistroAddon.tbtestpilot@labs.mozilla.com = true
will prevent it from being added to your install during future updates. Reference: http://mxr.mozilla.org/comm-release/...vider.jsm#2113

Edit: I'd have to study some more code to be sure but I'm going to stick with the above.

Last edited by TheWindBringeth : May 4th, 2012 at 11:20 PM.
  #19  
Old May 5th, 2012, 02:42 AM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,141
Post Re: Thunderbird update silently installs Test Pilot extension

Also on Google Groups. FAQ's Also Mozilla Wiki Test Pilot

Last edited by siljaline : May 5th, 2012 at 03:18 AM.
  #20  
Old May 5th, 2012, 08:27 AM
tlu's Avatar
tlu tlu is offline
Very Frequent Poster
 
Join Date: Sep 2004
Posts: 2,066
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by TheWindBringeth
For right now I'm just going to disable Thunderbird and Firefox checking for updates, add some software firewall rules, and switch to offline updates for both and their addons.

No offence meant - but that's insane, IMHO. You should really look at the links presented by siljaline in post #19 before making such grievous decisions.
  #21  
Old May 5th, 2012, 09:25 AM
vasa1's Avatar
vasa1 vasa1 is offline
Massive Poster
 
Join Date: May 2010
Posts: 3,988
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by tlu
No offence meant - but that's insane, IMHO. ...
The sad thing is that there are others who'll follow.
__________________
One can't be too rich, too thin, or too secure
  #22  
Old May 5th, 2012, 11:27 AM
Daveski17's Avatar
Daveski17 Daveski17 is offline
Massive Poster
 
Join Date: Nov 2008
Location: Lloegyr
Posts: 5,322
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by vasa1
The sad thing is that there are others who'll follow.

Maybe, but the really sad thing is all of the rhetoric emanating from the Nanny Cyber-State Police.
__________________
Quis custodiet ipsos custodes?
  #23  
Old May 5th, 2012, 12:12 PM
Fox Mulder Fox Mulder is offline
Regular Poster
 
Join Date: Jun 2011
Posts: 182
Default Re: Thunderbird update silently installs Test Pilot extension

Sounds like I'll finally install Evolution for windows.
__________________
Windows 8 Pro x64

First Line of Defense: Sandboxie for Internet-facing programs, Privatefirewall
Hardening: EMET, Early Launch Anti-Malware Enabled
Browser: Google Chrome (ScriptNo, Adblock)
Scanning: MBAM Pro, Windows Defender
  #24  
Old May 5th, 2012, 12:15 PM
tlu's Avatar
tlu tlu is offline
Very Frequent Poster
 
Join Date: Sep 2004
Posts: 2,066
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by vasa1
The sad thing is that there are others who'll follow.

Yes, paranoia is all around ...
  #25  
Old May 5th, 2012, 01:07 PM
TheWindBringeth TheWindBringeth is offline
Frequent Poster
 
Join Date: Feb 2012
Posts: 813
Default Re: Thunderbird update silently installs Test Pilot extension

Quote:
Originally Posted by tlu
No offence meant - but that's insane, IMHO. You should really look at the links presented by siljaline in post #19 before making such grievous decisions.
I would draw your attention to my sentence immediately after what you quoted: "This is but the latest in a string of things I've seen which make me question some of the developers and decision makers within Mozilla.". Yes, I read the material pointed to by siljaline, and other material, and contemplated its design. I don't like it. I certainly don't like the fact that a remotely configured data collection component was silently installed and enabled within the email client I use. An ability to review/approve the final step of phoning home certainly doesn't address all of my concerns. This comes just ten days after getting hit with the silent install and enabling of the new Maintenance Service which has security and will have other implications down the road. Which comes not that long after learning of Mozilla's intent to in the future push Firefox metrics reporting on users on an opt-out basis. I could keep going but I think that is sufficient to prove reasonable my opinion and motive.

Apart from that aspect which I expect you have a different opinion on, what do you consider insane and/or grievous about shifting to offline updates? Are you assuming that I will forget or fail to do so on a very regular and very timely basis? That I won't be automating things to the extent possible? I may very well run into technical issues and find it problematic in some way. If that is your point and there is a wall, I'll acknowledge it. If that isn't your point, I don't see how the terms insane and grievous apply.
 

Wilders Security Forums > Software, Hardware and General Services > other software & services « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:44 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums