On-Prem

Personal Tech

Mozilla so sorry for intrusive Firefox VPN popup ad

'We accomplished the exact opposite of what we intended...'


Firefox

Mozilla managed to annoy many Firefox users this week by presenting an unwanted ad for its VPN service, and has since suspended the promotional initiative.

This is the same Mozilla that markets Firefox specifically for the availability of ad blocking extensions, or add-ons. "The average person sees an average of 4,000 ads a day," the org crows on its website. "If you think that’s too many, an ad blocker is your new best friend."

Yet the Mozilla VPN ad presented to Firefox users was immune to ad blocking extensions because it was not part of any web page. Rather it was served through Firefox's user interface, via the browser Messaging System. The ad can be disabled, however, by entering about:config in the Firefox input bar and setting browser.vpn_promo.enabled to false.

Microsoft Edge has tried this tactic as well. It presented what looks like a banner ad for Edge atop a Google Chrome Canary download page, though the ad resided within an adjacent Edge-controlled content area rather than content area used for page rendering.

Mozilla's VPN ad proved to be particularly egregious because it disabled the rest of the Firefox interface until it was dismissed.

This is not the first time Mozilla has annoyed users with unwanted ads. In 2020, Mozilla forced push notifications on Firefox users without permission to promote its blog post about the StopHateForProfit coalition, which tried to pressure Facebook to deal with harmful content. The company faced similar blowback in 2017 for its Mr. Robot promotional add-on.

Mozilla's flirtations with advertising – a way to augment and diversify its revenue beyond search engine deals – date back at least to 2014.

Firefox users voiced their displeasure about the unwelcome VPN ad through online forums like Reddit and Mozilla support pages.

As one user wrote, "I am a developer on an emergency intervention hotline for sexual assault. Firefox is now throwing up pseudo-modal advertisements for its VPN above pages.

"It is absolutely IMPERATIVE that our visitors do not receive these new modal advertisements that Firefox is throwing at them. What can I do to prevent Firefox's new browser-hijacking advertisements from showing up on our hotline pages?"

Ick ... Screenshot of Mozilla Firefox's VPN ad popup

Another user wrote, "The company I work for uses Firefox to view and project web content while filming government meetings, along with a number of critical apps. Modal popups will make it difficult to use in production; there are reports of this crashing the current page and causing issues with multiple monitors. If you add this back, I'll have to deploy a Firefox Enterprise policy to disable this on our entire laptop fleet, which is... annoying."

A bug report was filed about the ad and shortly thereafter Mozilla disabled the promotion.

It appears the ad was being triggered inappropriately due to a time miscalculation error. Mozilla's Messaging System includes code that tries to trigger a message (an ad in this case) when a Firefox user has been idle for 20 or more minutes.

But as Mozilla engineer Shane Hughes describes it, browser's attempt to find how much time has passed since the last user interaction or audio event treats Epochs – time since January 1st, 1970 00:00:00 UTC – as if they were milliseconds.

The Register asked Mozilla to confirm that the errant ad followed from a timing bug and to comment on the company's decision to present such an ad.

A Mozilla spokesperson addressed just our second question.

"We’re continuously working to understand the best ways to communicate with people who use Firefox," a Mozilla spokesperson said in an emailed statement. "Ultimately, we accomplished the exact opposite of what we intended in this experiment and quickly rolled the experience back. We apologize for any confusion or concern." ®

Send us news
29 Comments

Mozilla's midlife crisis has taken it from web pioneer to Google's weird neighbor

Can the sleeping fox ever wake up?

Google's third-party cookie culling to begin in Q1 2024 ... for 1% of Chrome users

And in full swing starting Q3

Buyer's remorse haunts 3 in 5 business software purchases

They never do tell you about the unexpected costs and overly complex implementations

Forcing Apple to allow third-party app stores isn't enough

You're excited about Meta offering iOS apps via Facebook ads? Really?

Online tracking is alive and well in link decoration

The pending death of third-party cookies won't do much for other privacy intrusions

Atlassian users complain of cloud migration dead ends, especially in UK

Lack of local clouds and inflexible offers see users depart. Maybe the new ‘Compass’ developer experience tool will be more to their liking

What's unconstitutional about Google keyword search warrants? Nothing, says Colorado Supreme Court

Arson case produces a very tricky precedent for anyone who values digital privacy

Microsoft starts offering advice in how to code for Arm

In 2027 a quarter of PCs won’t use x86, and Redmond wants its ecosystem ready

Ubuntu unleashes Mantic Minotaur with 23.10 build

The bull has escaped Minos' labyrinth, and El Reg follows the thread

Thousands of Teslas recalled over brake fluid bug

OTA software update to deal with misbehaving sensor

SAP barely moving needle to migrate users off ECC before support ends

Gartner finds only a third are somewhat prepared for S/4HANA transition

EPIC urges watchdog to probe Grindr's data privacy – or alleged lack thereof

Dating app kept sensitive info even after peeps deleted accounts, complaint claims