Feeds

Firefox passive-aggressives adjudicate Nerd Law

Better than a severed horse head

The Power of One Brief: Top reasons to choose HP BladeSystem

NoNoScript

For years, NoScript had been using some tricks to keep Adblock Plus from working on its update landing pages. Palant didn't pay it much mind for some time, until he recently recommended that EasyList explicitly block ads on the NoScript servers. Successive iterations of this blocking rendered the NoScript website useless to Adblock Plus users, to the point where they could not even download NoScript without some serious hunting. Having enough of this passive-aggressive posturing, Maone released a version of NoScript that would interfere with the internals of Adblock Plus to allow ads on the NoScript servers.

What followed was a public airing of grievances that brought in the Mozilla Foundation, who came down on Adblock Plus's side. (Yes, the Mozilla Foundation that's kept afloat by advertising revenue from Google, that Mozilla Foundation). It ended with Maone apologizing for interfering with Adblock Plus and issuing an update to NoScript that un-did his fiddling.

If you step back and look at this, it was not nearly a crisis of the magnitude the internet would have you believe. This slug-fest only affected people who use both Adblock Plus and NoScript. Each of these extensions has about 50 million downloads, and if you assume a really generous amount of overlap and adoption, this amounts to about 18 per cent of Firefox users. Woo, let's alert the BBC.

The real cause of this dispute is something I like to call Nerd Law. Nerd Law is some policy that can only be enforced by a piece of code, a public standard, or terms of service. For example, under no circumstances will a police officer throw you to the ground and introduce you to his friend the Tazer if you crawl a website and disrespect the robots.txt file.

The only way to adjudicate Nerd Law is to write about a transgression on your blog and hope that it gets to the front page of Digg. Nerd Law is the result of the pathological introversion software engineers carry around with them, being too afraid of confrontation after that one time in high school when you stood up to a jock and ended up getting your ass kicked.

If you actually talk to people, network, and make agreements, you'll find that most are reasonable. If Maone had talked with the EasyList maintainer, perhaps he could have convinced them that showing AdSense on the NoScript site wasn't a huge affront to users. After all, if those ads really pissed off a user, he could explicitly block them with Adblock Plus.

If the EasyList maintainer contacted Maone about what implications his explicit blocks on the NoScript site would have, maybe the two of them could have come to a mutually-agreeable solution.

But no. Sadly, software engineers will do what they were raised to do. And while it may be a really big hullabaloo to a very small subset of people who Twitter and blog their every thought as if anybody cared, to the rest of us, it just reaffirms our knowledge that it's easy to exploit your average introvert.

After all, what's he gonna do? Blog about it? ®

Ted Dziuba is a co-founder at Milo.com You can read his regular Reg column, Fail and You, every other Monday.

Seven Steps to Software Security

More from The Register

next story
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
KDE releases ice-cream coloured Plasma 5 just in time for summer
Melty but refreshing - popular rival to Mint's Cinnamon's still a work in progress
NO MORE ALL CAPS and other pleasures of Visual Studio 14
Unpicking a packed preview that breaks down ASP.NET
Cheer up, Nokia fans. It can start making mobes again in 18 months
The real winner of the Nokia sale is *drumroll* ... Nokia
Put down that Oracle database patch: It could cost $23,000 per CPU
On-by-default INMEMORY tech a boon for developers ... as long as they can afford it
Another day, another Firefox: Version 31 is upon us ALREADY
Web devs, Mozilla really wants you to like this one
Google shows off new Chrome OS look
Athena springs full-grown from Chromium project's head
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.