Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Something with a public wiki page describing what it does exactly is hardly a backdoor.

Also here's the code for the server: https://github.com/mozilla/normandy



The wiki entry evidently doesn't describe what it does because according to the wiki entry it allows for the enabling and disabling of preferences. The updating of a certificate is beyond what is described in the wiki.

Mozilla should follow up with a post describing exactly how Normandy works and the full capabilities it gives them.


From what I understand, Normandy is an infrastructure for delivery of some changes to some of Firefox users (or all of them). There are two major use cases: preferences rollout and studies. In the first case default values of preferences get changed (if your pref has non-default value, it won't affect you). In case of studies some piece of code gets delivered and executed, which cat do anything. In this hotfix the study installs add-on, which in turn installs certificate.


[flagged]


Users shouldn't have to search and then be able to understand the code found for such a feature. When a remote capability such as this exists it is Mozilla's responsibility to document how the feature works and the exact capabilities it gives them. Instead of doing so they have produced a wiki entry which appears to falsely describe the capabilities of this remote feature by stating it is used to change default preference values.


Hacker News

I think people here can be expected to read some code if they are interested in how something works.


[flagged]


[flagged]


Please read and follow the site guidelines when commenting here.

https://news.ycombinator.com/newsguidelines.html


All code is available – as a tar.xzipped archive of Firefox source code containing over 150k files and measuring over 1GB in size when unpacked.


grep -iR normandy

I expect code related to normandy to be ~1k LOC in size and probably written in JS. I haven't checked though, because I don't really care today.


And you shouldn't have to care. No one should. The very fact that this exists and that we are expected to trust it is very disappointing.


Open source software can't have a backdoor because the code is available to review.

Got it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: