Mathieu Pillard

@dioxmat
186 Followers
139 Following
644 Posts
Vous trouvez que les extensions sont une fonctionnalité indispensable d'un navigateur web moderne ? Nous aussi. L'équipe Add-ons de Mozilla recrute un développeur senior pour bosser sur les APIs WebExtensions et tout ce qui va avec dans Firefox. https://www.mozilla.org/en-US/careers/position/gh/7921746/
Mozilla Careers — Senior Software Engineer, WebExtensions — Open Positions

Mozilla is hiring a Senior Software Engineer, WebExtensions in Remote US, Infrastructure, Firefox, Firefox, Firefox, Ads, Firefox, Core Services, Mozilla.org, Mozilla.org,…

Mozilla
It's been 0 days since Oracle have changed the GPG key they use to sign their MySQL debian repository without an announcement, updating their docs or even publishing the new key on public keyservers. https://bugs.mysql.com/bug.php?id=120305
6 mois après ma chute, petit bilan de ce par quoi je suis passé et de la ou j'en suis https://virgule.net/blog/6_mois_plus_tard.html
6 mois plus tard...

Since everyone is sharing their hot takes about AI I thought I'd chime in.

You're paying AI companies a monthly subscription fee to be fingerprinted like a parolee.

I got bored and ran uBlock across Claude, ChatGPT, and Gemini simultaneously.

Claude:

  • Six parallel telemetry pipelines.
  • A tracking GIF with 40 browser fingerprint data points baked into the URL, routed through a CDN proxy alias specifically to make it harder to block.
  • Intercom running a persistent WebSocket whether you use it or not.
  • Honeycomb distributed tracing on a chat UI because apparently your conversation needs the same observability stack as a payments microservice.

ChatGPT:

  • proxies telemetry through their own backend to hide the Datadog destination URL from blockers.
  • uBlock had to deploy scriptlet injection — actual JS injected into the page to intercept fetch() at the API level — because a network rule wasn't enough.
  • Also ships your usage data to Google Analytics. OpenAI. To Google. You cannot make this up.
  • Also runs a proof-of-work challenge before you're allowed to type anything.

Gemini:

  • play.google.com/log getting hammered with your full session behavior, authenticated with three SAPISIDHASH token variants, piped directly into the Google identity supergraph that correlates everything you've ever done across every Google product since 2004.
  • Also creates a Web App Activity record in your Google account timeline. Also has "ads" in one of the telemetry endpoint subdomains.

When uBlock blocks Gemini's requests, the JS exceptions bubble up and Gemini dutifully tries to POST the error details back to Google. uBlock blocks that too. The error messages contain the internal codenames for every upsell popup that failed to load.

KETCHUP_DISCOVERY_CARD.
MUSTARD_DISCOVERY_CARD.
MAYO_DISCOVERY_CARD.

Google named their subscription upsell popups after condiments and I found out because their error handler snitched on them.

All three of these products cost money.
One of them is also running ad infrastructure.

Touch grass. Install @ublockorigin

#infosec #privacy #selfhosted #foss #surveillance

After more than 10 years, @jazzband is sunsetting.

I started it in 2015 because maintaining Open Source alone was exhausting. The idea was simple: shared access, shared responsibility. It's been an honor to watch it grow: 3,135 members, 84 projects, and a lot of code shipped together.

https://jazzband.co/news/2026/03/14/sunsetting-jazzband

(1/3)

Jazzband - News - Sunsetting Jazzband

Pokémon Go players thought they were catching Pikachus.

They were actually building the nervous system for robot civilization.

500M humans. 30B images. Zero consent forms.

The game was the harvest.
https://www.technologyreview.com/2026/03/10/1134099/how-pokemon-go-is-helping-robots-deliver-pizza-on-time/

How Pokémon Go is giving delivery robots an inch-perfect view of the world

Exclusive: Niantic's AI spinout is training a new world model using 30 billion images of urban landmarks crowdsourced from players.

MIT Technology Review
Ça doit pas être facile de s'appeler Claude et de faire de l'informatique en ce moment…

Aidez-moi à lutter contre les usurpations d'identité sur addons.mozilla.org en participant à mon mini-jeu d'identification d'homoglyphes en JavaScript: https://confusables.virgule.net/ (nom d'utilisateur/mot de passe: ce que vous voulez du moment que c'est pas vide)

Rien à gagner à part ma gratitude, il n'y a pour l'instant pas de fin, mais je vous promet c'est rigolo de découvrir des caractères bizarres (enfin moi je trouve ça addictif en tout cas).