Extension Block Request: S3.Translator – s3firefox@translator
Categories
(Toolkit :: Blocklist Policy Requests, task)
Tracking
()
People
(Reporter: grahamperrin, Assigned: Fallen)
Details
Attachments
(2 files)
Extension name | S3.Translator – s3firefox@translator |
Extension versions affected | 6.25 |
Platforms affected | <all platforms> |
Block severity | soft |
Reason
Signed version 6.25 appears to collect statistics after the end user explicitly disables collection.
No surprises:
hxxps://extensionworkshop.com/documentation/publish/add-on-policies/#no-surprises
Data disclosure, collection and management:
hxxps://extensionworkshop.com/documentation/publish/add-on-policies/#data-disclosure-collection-and-management
Extension IDs
s3firefox@translator
Additional Information
hxxp://forums.mozillazine.org/viewtopic.php?p=14851955#p14851955 ▶
hxxps://s3blog.org/download/s3gt/s3translator_firefox.xpi
hxxps://www.s3blog.org/s3gt.html ▶
hxxps://www.s3blog.org/download/s3gt/s3translator_firefox.xpi
Publicly raising the concern:
hxxp://forums.mozillazine.org/viewtopic.php?p=14852362#p14852362
Reporter | ||
Comment 1•4 years ago
|
||
Screen recording: collection of data with version 6.25 of the extension added to home-built Waterfox Classic 2019.12 (20191210201058) on FreeBSD-CURRENT.
Whilst I don't know how to perform a comparable analysis with Firefox Quantum (sorry), I assume that the outcome will be the same.
Reporter | ||
Comment 2•4 years ago
|
||
- legacy HttpFox 0.8.14
- S3.Translator 6.25
- Waterfox Classic 2019.12
(Status-Line) HTTP/1.1 302 Found
Date Thu, 19 Dec 2019 04:08:05 GMT
Server Apache/2.2.15 (CentOS) mod_fcgid/2.3.9 mod_ssl/2.2.15 OpenSSL/1.0.1e-fips
Location https://istat.biz/api?key=5853ecc71178be9962ad851ff3626443c30cd53a&out=https%3A%2F%2Fwww.virustotal.com&uid=o256&format=txt
Cache-Control max-age=25920000
Expires Wed, 14 Oct 2020 04:08:05 GMT
Content-Length 0
Connection close
Content-Type text/plain; charset=UTF-8
Reporter | ||
Comment 3•4 years ago
|
||
Assignee | ||
Comment 4•4 years ago
|
||
I’ve reviewed the add-on and confirmed that it is collecting ancillary user data against our policies.
Assignee | ||
Comment 5•4 years ago
|
||
The block has been pushed.
Reporter | ||
Comment 7•4 years ago
|
||
Thank you.
(In reply to comment #0)
Publicly raising the concern:
http://forums.mozillazine.org/viewtopic.php?p=14852362#p14852362
More, which I don't understand:
- http://forums.mozillazine.org/viewtopic.php?p=14852486#p14852486
- http://forums.mozillazine.org/viewtopic.php?p=14852487#p14852487
Note, that's not an invitation to discuss here in this bug. I hope that the developer (or anyone with an understanding) can explain in mozillaZine forums.
General discussion of add-ons (not specific to S3.Translator):
I completely removed the statistics collection.
Please review the addon (original version : s3google@translator : https://addons.mozilla.org/addon/s3google-translator/ ) and remove it from the blocklist:
https://bugzilla.mozilla.org/show_bug.cgi?id=1602293
Thank you!
s3google@translator
Status: Disabled by Mozilla
Listing visibility: Invisible
Review History: none
Why did you completely remove extension without the possibility of updating and without explaining the reasons?
Description
•