Serious security / privacy breach in Firefox 36.0
I just updated to Firefox 36.0. I was curious about the new "Hello" feature, so:
1) I clicked "Start a conversation". 2) As soon as it opened, I immediately closed the conversation and deleted it. 3) I also changed my status from the default "Available" to "Do Not Disturb".
About 30 minutes later, my camera turned on! I have no other application that would do this without consent; it has never happened before.
I hate to ditch Firefox, but this breach is too severe to overlook. I imagine it has equal control over the microphone. Embedding third party software with this kind of hardware control seems reckless to me. Firefox Hello...Provided by TokBox, Inc....Powered by Telefonica ?! Did we miss the recent news about Lenovo and Superfish?
I have a lot of respect for Mozilla and all the products it has generated. I await news on this, but not using Firefox in the meantime.
All Replies (9)
Is there a way to completely and permanently remove this new technology from Firefox?
enter about:config into the firefox address bar (confirm the info message in case it shows up) & search for the preference named loop.enabled. double-click it and change its value to false.
philipp said
enter about:config into the firefox address bar (confirm the info message in case it shows up) & search for the preference named loop.enabled. double-click it and change its value to false.
Thanks for that, but it looks a bit generic. What else will this setting affect?
generic or not, this setting will disable firefox hello.
I understand you are saying it will disable Hello. But I was asking if anything else in Firefox might be affected by this config setting.
no, "loop" is the codename for firefox hello - it won't affect anything else...
Mozzilav, did you try restarting Firefox when the camera light came on? That would help to prove if it was Firefox or not.
Obviously Firefox shouldn't be turning the camera on outside of your use of Hello, I'm just trying to track down the issue a bit more.
Do you recall when you started the conversation and you had the conversation window open - did the camera light come on then as well, before you shut the conversation?
Hello Standard8, When I started the Hello conversation, it did not display the small orange box at the top of the screen indicating there was camera activity, and I do not recall seeing the camera light on.
But some time after ending the Hello conversation and deleting it (within 30min or so), the camera definitely turned on. I verified that there was no new or hanging Hello activity. It was a big wtf moment. Killing the firefox.exe process via Task Manager immediately turned the camera off.
Thanks, that's useful information. Would you be prepared to give it a try once more to see if it reproduces in the same way?
Also, can I get a few details of what your operating system is, and what camera/microphones you have connected (or built-in)?