Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Mozilla apologized after Firefox users discovered an unfamiliar Mr. Robot tie-in add-on called Looking Glass had arrived without a clear choice to install it. Mozilla said the add-on was off by default and collected or shared no user data, but acknowledged that users should have been asked before installation. The controversy was about consent and transparency, not a confirmed data-collection incident.

What was Firefox’s Looking Glass add-on?

Looking Glass was a promotional alternate reality game (ARG) created through an unpaid collaboration between Mozilla and the television show Mr. Robot. It was not a conventional Firefox feature test. The add-on could reveal a clue on the show’s puzzle page; when activated, it also briefly inverted selected words related to the show’s themes on websites. Mozilla described the promotion and its effects on December 18, 2017.

The tie-in was designed to preserve the game’s surprise. That choice became part of the problem: an add-on with an obscure name and little explanation looked suspicious to people who had not heard about the promotion.

Why did users object?

Mozilla said a Firefox update had installed Looking Glass for English-speaking users, while leaving the add-on off. Users had not directly chosen to install it, and the name did not clearly identify it as a Mr. Robot promotion. Some questioned whether it was malware: the title of a contemporaneous Mozilla Support thread asked whether “Looking Glass 1.0.3” was an unknown developer add-on or malware. The support thread documents that concern; it is an example of user alarm, not a measure of how widespread it was.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Mozilla’s own December statement recognized the distinction at the heart of the backlash: users could choose whether to activate the game effect, but they had not been given the choice to install the add-on in the first place. Mozilla said it should have asked first. TechCrunch’s contemporaneous report also covered the response and objections.

Was Looking Glass malware, and did it collect data?

The available statements do not establish that Looking Glass was malware. Mozilla described it as a promotional game add-on and said it made no changes unless users explicitly turned it on. Mozilla also said it had no intention or mechanism to collect or share user data, even when enabled. Those are Mozilla’s claims, not an independent audit finding.

Those assurances address what the add-on did and whether it collected data; they do not mean users had opted into its installation. The add-on was already installed before a user could decide whether to activate its effect. That difference explains why a statement that the feature was “opt-in” did not resolve the consent concern.

How did Mozilla respond?

On December 18, 2017, Mozilla apologized, improved the add-on’s description, began moving the promotion to its add-ons site as a regular WebExtension, published its source code, and started an internal review. Mozilla Chief Marketing Officer Jascha Kaykas-Wolff wrote, “We didn’t think hard enough about how our actions would affect the community, and we’re sorry for letting you down.” Mozilla’s statement also acknowledged that users should have had the choice to install it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Web Security Testing Cookbook
  • Used Book in Good Condition

What did Mozilla’s review conclude?

In a January 30, 2018 retrospective, Mozilla said the Looking Glass episode had alarmed some users because the review had focused on privacy and missed the central issue. Mozilla said the promotion did not collect data, so it was not a proper SHIELD experiment. SHIELD was Mozilla’s program for testing changes and experiences with Firefox users; a promotion without a study question did not fit that purpose.

Mozilla also admitted the add-on’s name had been deliberately misleading to protect the ARG’s surprise, despite Mozilla’s own advice to users on recognizing malware. The retrospective said future SHIELD studies needed a specific question, accurate names, and broader review. Mozilla’s January 2018 account sets out those lessons.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the episode shows

  • Installation and activation are different. The add-on was installed through an update, according to Mozilla, but its effects stayed off until a user enabled them.
  • A privacy assurance does not replace consent. Mozilla’s statement that no data was collected or shared did not address why the add-on appeared without a direct installation choice.
  • Trust depends on clear presentation. An unexplained add-on name made a promotional surprise resemble a security problem, even though Mozilla said it was not collecting user data.

Mozilla’s statements and the contemporaneous complaints establish that the episode caused alarm, but they do not provide a reliable count of installations, complaints, or affected users.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.