Closed Bug 1605007 Opened 4 years ago Closed 4 years ago

Extension Block Request: S3.Translator – s3firefox@translator

Categories

(Toolkit :: Blocklist Policy Requests, task)

task
Not set
normal

Tracking

()

RESOLVED FIXED

People

(Reporter: grahamperrin, Assigned: Fallen)

Details

Attachments

(2 files)

Extension name S3.Translator – s3firefox@translator
Extension versions affected 6.25
Platforms affected <all platforms>
Block severity soft

Reason

Signed version 6.25 appears to collect statistics after the end user explicitly disables collection.

No surprises:

hxxps://extensionworkshop.com/documentation/publish/add-on-policies/#no-surprises

Data disclosure, collection and management:

hxxps://extensionworkshop.com/documentation/publish/add-on-policies/#data-disclosure-collection-and-management

Extension IDs

s3firefox@translator

Additional Information

hxxp://forums.mozillazine.org/viewtopic.php?p=14851955#p14851955 ▶
hxxps://s3blog.org/download/s3gt/s3translator_firefox.xpi

hxxps://www.s3blog.org/s3gt.html ▶
hxxps://www.s3blog.org/download/s3gt/s3translator_firefox.xpi

Publicly raising the concern:

hxxp://forums.mozillazine.org/viewtopic.php?p=14852362#p14852362

Attached video Screen recording

Screen recording: collection of data with version 6.25 of the extension added to home-built Waterfox Classic 2019.12 (20191210201058) on FreeBSD-CURRENT.

Whilst I don't know how to perform a comparable analysis with Firefox Quantum (sorry), I assume that the outcome will be the same.

Attached image Screenshot
  • legacy HttpFox 0.8.14
  • S3.Translator 6.25
  • Waterfox Classic 2019.12
(Status-Line)	HTTP/1.1 302 Found
Date	Thu, 19 Dec 2019 04:08:05 GMT
Server	Apache/2.2.15 (CentOS) mod_fcgid/2.3.9 mod_ssl/2.2.15 OpenSSL/1.0.1e-fips
Location	https://istat.biz/api?key=5853ecc71178be9962ad851ff3626443c30cd53a&out=https%3A%2F%2Fwww.virustotal.com&uid=o256&format=txt
Cache-Control	max-age=25920000
Expires	Wed, 14 Oct 2020 04:08:05 GMT
Content-Length	0
Connection	close
Content-Type	text/plain; charset=UTF-8

I’ve reviewed the add-on and confirmed that it is collecting ancillary user data against our policies.

Assignee: nobody → philipp
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true

The block has been pushed.

Group: blocklist-requests
Status: ASSIGNED → RESOLVED
Closed: 4 years ago
Resolution: --- → FIXED

Thank you.

(In reply to comment #0)

Publicly raising the concern:

http://forums.mozillazine.org/viewtopic.php?p=14852362#p14852362

More, which I don't understand:

Note, that's not an invitation to discuss here in this bug. I hope that the developer (or anyone with an understanding) can explain in mozillaZine forums.


General discussion of add-ons (not specific to S3.Translator):

I completely removed the statistics collection.
Please review the addon (original version : s3google@translator : https://addons.mozilla.org/addon/s3google-translator/ ) and remove it from the blocklist:
https://bugzilla.mozilla.org/show_bug.cgi?id=1602293
Thank you!

s3google@translator
Status: Disabled by Mozilla
Listing visibility: Invisible
Review History: none

Why did you completely remove extension without the possibility of updating and without explaining the reasons?

You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: