Episode 14
The Future of Trust in the Browser
with Ajit Varma, Head of Firefox at Mozilla
Show Notes
My guest, Ajit Varma, is Head of Firefox at Mozilla, where he leads Firefox strategy and product. He joined Mozilla in late 2024, from Meta, where he worked on monetization and business messaging for WhatsApp. He's also worked at Google and various startups in his 20 years of product leadership in Silicon Valley, and is based in the Bay Area.
We talked about trust as a business strategy — Mozilla's bet that in an era of data harvesting and opaque algorithms, being the browser people can actually verify is worth more than scale. That means no in-house AI model, a choice of LLMs in Firefox, a master switch to turn AI off entirely, and revenue that doesn't depend on watching you.
Ajit covered the nuances of data brokers, prompt injection and the tradeoffs between safety and privacy. From there, what a browser even is once it reads pages and acts on your behalf rather than just fetching them — model choice, shipping deliberately slower than the competition, and the parts nobody has solved yet.
On agents: what consent means when software acts as you and spends your money, his argument that agents could route around the platforms taking a 30% cut, and where the next middleman forms if they do.
And finally, who pays for the open web when agents do the reading — including Mozilla's own advertising business, its privacy-preserving ad infrastructure, and whether people will pay directly for software they trust.
Chapter Timestamps
- 00:00Introduction
- 3:18Mozilla's Mission: The Open Internet and Nonprofit Structure
- 5:11Becoming the Most Trusted Software Company
- 9:51AI as New Gatekeepers and Firefox's Response
- 16:19Privacy, Felt Privacy, and User Awareness
- 19:59AI Agents, Browser Automation, and the Human Element
- 24:02Job Applications, Agent Spam, and Asymmetric Information
- 27:33Advertising, the Open Web, and Data Brokers
- 32:42Firefox's Approach to Ad Blocking and Tracker Transparency
- 43:41Mozilla's Revenue Model and the Google Search Deal
Resources & Links
Transcript
There may be transcription errors: we apologize for those in advance.
Rob: Hi, welcome to Won't Fix. I'm Rob Leathern. My guest today is Ajit Varma. He's Head of Firefox at Mozilla, where he leads Firefox strategy and product. He joined in 2024 from Meta, where he oversaw monetization and business messaging for WhatsApp. Before that he was at Google, working on search and ads quality, Gmail and Calendar. Ajit is based in the Bay Area, although he went to UT Austin, where I am currently.
So — excited for you to hear this conversation, where we get into AI, agents, safety, privacy and a lot more. This is Ajit Varma.
Ajit, thanks for joining us. How are you? It hasn't been that long since we caught up, but it's good to see you.
Ajit: It's good to connect again. And I always appreciate all the support you've given to Mozilla, so happy to chat more.
Rob: I'm a believer in a lot of the principles the foundation and the product stand for, so it's great to be able to talk about some of that and some of the recent changes.
Tell us a bit more about how you got to Mozilla — what was your route in?
Ajit: Sure. I've been at Mozilla a little over a year and a half; it'll be two years in December. For about the first year I led product management, and for the last eight or nine months I've been overseeing the overall Firefox product, including engineering and design.
My background before joining was a pretty typical Silicon Valley one. I worked at big tech companies like Google and Meta, and I worked at startups — whether that was starting my own company or joining companies like Square and Uber when they were still in their startup phase. I've spent a lot of my career on zero-to-one products, or inflection products: how do you create new things?
But over time I started thinking more about the overall impact of the work I've done. That's ultimately what motivates me — am I having a positive impact? Not just the impact of the product, but am I having a strong individual impact?
That led me to ask: what are the companies I believe in, that I think are important for what they do? What would happen if they didn't exist? And do I think there's some personal impact I can have, whether that's helping the organization accomplish something or just pushing teams to do things?
Mozilla and Firefox stood out on that. If I work hard on this and we accomplish what we're trying to accomplish, is it good for the world and good for what I believe is important?
So then it comes down to what Mozilla stands for and what Firefox stands for. Firefox is owned by a nonprofit organization, and that's important, because it means we're not necessarily profit-maximizing. We talk about the double bottom line: we want to create good in the world. For us, that means preserving an open internet that's built for humans and adheres to human values.
The internet is pretty amazing — you can access enormous amounts of content, create direct connections, cut out middlemen. But people don't always realize this wasn't a given. Rewind 25 years and there were gatekeepers. AOL was a gatekeeper. There were bulletin board services. There were so many ways that you bought into an ecosystem when you bought a product. If you were part of the AOL ecosystem, and that was how you accessed the internet, you couldn't really do much else. You used AOL Instant Messenger, AOL social networking, AOL to access information. And then everything became AOL's view of how the world is.
You see similar things happen today with app stores. Apple and Google have very similar policies on what's allowed and what isn't. For a long time crypto wasn't allowed. There are restrictions on what content is permitted. In other countries it's even more extreme — there are strong governmental regulations about what's allowed. Gatekeepers mean single points of control.
So for me, Firefox is about making sure no one has control over something as vital as the internet — that there's competition, that there are different engines. That mission is challenging, and it really excites me. That's ultimately why I'm here.
Rob: You have a new CEO, and I saw his initial letter was about Mozilla becoming the most trusted software company. In this time of AI and agents, the browser has such a pivotal role in how people experience content and interact with other people via different apps and services. Could you tell us more about the trusted software company idea and how you see it developing?
Ajit: For people who aren't familiar, we have a new CEO, Anthony. When he came on board he talked a lot about what distinguishes Mozilla from other companies, and what the area is that we really want to win in. A lot of that was: how do we become the most trusted software company?
A lot of the criticism people have of big tech — or of growth-hacking businesses generally — is that they're often trying to guide people into an experience they otherwise wouldn't want, through dark patterns, deceptiveness, ecosystem lock-in. Those things aren't what's best for a user. They're more along the lines of what's best for a business. And then you think, well, that makes sense — a business is built to maximize shareholder value, not necessarily to create the best experience.
But because we're not a publicly traded company, and because of our foundation and our manifesto, we're in this unique position where we can really lean into trust.
So first: what does trust mean, and then why does it matter? Trust is a lot of things. Would we be okay if everyone knew everything we were doing and why we were doing it? We're open source — look at the code. It's not just what we say, it's provable. It's open. Can we talk to our community about the decisions we're making, even the ones that aren't best for growth, but are best for the overall health of the ecosystem?
Choice matters a lot. A lot of users distrust companies because they feel like they were given promises and over time those promises changed. Or they want choice and they're given false choice: you can sign up to use this product, but you have to give me all your data. Things are hidden deep in terms, and people don't trust companies.
The unfortunate part is that, as long as I've been in tech, I keep thinking this can't happen — and it happens every day. I was reading an article yesterday about how TikTok reportedly ran an experiment where they turned off safety controls, and someone died by suicide as a result**. Those are real things. I would never trust a company that would say, I'm running an experiment to show more depressing content and see how the metrics look.
That's why trust is so important. I think we all came into technology hoping technology could make lives better and more productive, and open up dialogue and conversation. But competition is important to ensure people have choice, which is the only real way to make sure it's a human-built internet and human-built technology.
Rob: It feels a bit like some of the AI companies are becoming another set of gatekeepers to other experiences, just because they've grown so quickly and people are now trusting them. I was talking to someone yesterday about AI psychosis and other things that are obviously very problematic. Or even a lighter form of that — I heard from someone whose partner can't make any decisions without consulting one of these chatbots.
I used to think about this with internet search: if it's not on the first couple of pages of Google or Bing, you'd conclude there's no answer to this question. But no — it might be in the library, it might be somewhere else. So now we're in this weird place where there are some new gatekeepers and some of the old ones remain. How does that affect how you think about the browser and the role of Firefox in the ecosystem?
Ajit: A big challenge with gatekeepers is that you really don't know whether they're aligned with your interests. Maybe at one point the gatekeeper was aligned with your interests and things drifted over time. But the other problem with a gatekeeper is that you don't have a choice. If you want a phone, you're going to be locked into one of two gatekeeping ecosystems. There's no open alternative.
The internet isn't like that, and that's very unique. There aren't a lot of things that are as open. ChatGPT was able to launch a website. Google was able to launch a website. Facebook was able to launch a website. All these things emerged because you could just type in a URL and get to it. Hopefully many more companies emerge because someone has a good idea and wants to get it to people.
When we think about AI, AI has a lot of different values embedded in it — what's the political bent, what's a safe question or not a safe question. It always surprises me when I use AI and it refuses to answer something that isn't even a hard question. It seems factual, but there's a bias, because they're weighing legal restrictions, governmental restrictions, retaliation.
You hear a lot about open models and closed models, but it doesn't matter if gatekeepers control how you access them. If a mobile device can only plug into the AI the OS selected, then it doesn't matter if there are a thousand AIs out there — they're not actually accessible.
So within Firefox, when we think about Smart Windows, when we think about AI: you can use open models, you can use closed models, you can use your local AI model. If you want to use Google search, that's great, but we make it a couple of taps to switch to any other search engine. If you want to change the homepage, you can change the homepage.
A lot of this is saying we don't know what's best for everybody, but we're going to make it easy for people to decide what's best for them. That's how you remove gatekeepers — you limit the ability for us, or any other company, to have control over key entry points.
Rob: So part of how you think about trust is giving people choice and control, and an alternative to some of the ways they've been nudged before.
Ajit: Right. And it's true choice, which means transparency. If you want part of something, it shouldn't be all or nothing. When we launched the AI control switch, which lets you kill all the AI in Firefox, we made it easy to turn translations back on — because a lot of people really want translations. Are we the ones who decide what AI is good or not good? No. We'll make it easy to turn off, but if you want translations, we'll make it easy to turn those back on as well.
Rob: It reminds me a bit of when I worked at Facebook and we were talking about ad review. We used machine learning, and we didn't think anyone would understand what machine learning was — this was five or six-plus years ago — so we said, let's just call it all AI.
I wonder how some of these terms will evolve, because no one's going to say NLP or ML or reinforcement learning. It's all AI now. Bundle it all together.
Ajit: What I'd say is that as we started explaining to people what was happening, we were pretty transparent. We posted on our internal and external forums, but also message boards, Reddit, things like that. And there are a lot of different viewpoints, even among rational people, on what these terms mean. I found myself questioning whether I actually had the same viewpoint I thought we all shared. People mean different things.
That's where dark patterns come in — it's not just what I think a dark pattern is, it's whether you do the user research. So we do a lot of talking to customers, trying to understand our trust score as part of this whole process. Not just, did we do a trust review, but what is our trust score? How do we measure it? How do we ask users whether they trust a decision we're making, and whether they think what's going to happen is what actually happens?
We have some interesting features we're in the middle of launching, and I'd love to share the user research. It's always interesting how different people interpret the same sentence on both ends of the spectrum.
Rob: How actively do you think people are going to manage their privacy profile and their personal data? I say this as someone who has run teams that have done some of these things — I've built ad blocking tools, I've done a bunch of things where I assumed a lot of people would want to interact with ads this way or that way.
One of my product managers said something I remember: ad preferences or ad settings are like rearranging your sock drawer. You just don't want to do it. Why would you?
So how do you think about how active people are in managing their settings, their online profile, how their data is used? Or is it that you give people the choice, but also give them more efficient ways to exercise it?
Ajit: The reality is that very few people ever think about changing their settings. Most people use the default unless there's some obvious moment, or something is prompted to them — do you want this or not? — and then they make a decision.
Moments like a change to terms of use are often when you get a vocal minority who call things out. I dealt with this at WhatsApp, where we changed terms and there was a lot of press because people didn't like parts of it. It actually got rolled back. But if that hadn't happened, most people probably wouldn't have noticed or cared.
So increasingly the question isn't just whether it's in settings, buried somewhere — it's how users are made aware when something is being shared or not shared. An example from Firefox: when you share your location with a site, you may have done that the first time and forgotten, because it's easy to miss. So now we're experimenting with a red location indicator in the address bar any time you're on a site, to really try to let people know.
Another thing I talk to the team about a lot is that it's not just privacy, it's *felt* privacy. If there's privacy but people don't feel it and don't understand it, then when they no longer have that level of privacy, do they understand it's been taken away?
This came up for me recently. I got a message from a friend on WhatsApp a couple of days ago and he said, did you know you're sharing your location on Instagram? I can see where you are and I can see where you live. And I thought — well, I did turn that on about three months ago, because I was experimenting with it, and I completely forgot it was running in the background. I've never had a prompt, never had a notice. I looked, and yes, I had it turned on for everyone to see every single place I was going.
If he hadn't told me, it could have been years, because I don't use that feature at all. I don't think of Instagram as sharing my location on a map that everybody can see, because it's not an obvious part of the product.
Instagram probably wants that data — it can target ads, it can do all sorts of things, so it's incredibly valuable, and it's incentivized not to highlight it to me. Whereas for me as a user, maybe I want it, maybe I don't. But if I've set it and never gone back to that page, maybe you should prompt me: are you sure you want this turned on? We see you're not using this feature at all. Whereas if I *am* using the feature, then there's a rational explanation to keep it on.
Rob: Apple does a medium-okay job of this. They prompt me every now and then — do you still want to give this app full access to all your photos? And sometimes I think, do I? Other times it's the opposite, where I'd rather they didn't ask because I'm fine with it. But I'd default to saying that's a good design principle.
I'm not sure if you've noticed, but it feels like it could probably tell whether you're actually using the feature. I get prompted on Google Maps — do you want to share your location? Yes, I literally use this all the time with my location. Whereas with Instagram I never got prompted by Apple either. Is this an odd thing to be doing in Instagram? I never got asked, so I never thought about it at the OS level or the app level.
Here's an example of something interesting — maybe it's actually not that interesting. I went into Claude Cowork and created a newsletter that pulls from different sources, and I set it up to run every day. This morning I'm sitting in the office and suddenly I'm getting all these notifications asking me to give it permission to go to different websites. And I thought, this is not exactly what I was hoping for when I asked you to build me a daily newsletter about trust and safety, AI and privacy topics.
So maybe that's the segue into how you think about agents, and processes that run and go do things, and how the browser's role is evolving for consumers.
Ajit: We have a feature called Smart Windows where we're starting to think more about how this works.
One part is having the controls you need, because often it's an all-or-nothing thing. If you give Gemini access to Chrome, it has everything in Chrome. Or if you're doing browser activity in Claude Cowork or Codex, it's the opposite — it doesn't have access to any of your history or information.
With Firefox, we've spent quite a bit of effort building something called containers. Containers help you encapsulate things separately: here's your work, here's your personal. So you could say, I want agents to have access to my travel profile, but I don't want them to have access to my banking information.
The challenge is making that understandable. What's a profile versus a container versus a private browsing window? Do you understand what's happening with the difference between sharing your passwords, sharing a cookie, sharing a credential? I don't think anyone has really solved that — not just the technical underpinnings, but how you make it accessible to people. How you get the convenience layer plus the power.
We're staying on the more conservative side. An example is autofilling forms. We've had a lot of debate about whether an agent should be able to do all the steps for you — click next, hit enter. What if it autofilled something wrong? So we're now prompting to say: okay, we'll fill out your passport application, but we're not going to hit the submit button. A human has to hit submit.
Over time that might change. Maybe there are guardrails and MCP servers and enough control. Or maybe AI becomes my true digital twin, where it knows everything about me and what I would do and when I would agree to things. I don't know whether I'm optimistic or pessimistic about that world, but I think you're going to see different people have different levels of acceptance. And especially when you have a platform like a browser or an operating system, you ultimately need to cater to the bulk of people, because I don't think anyone knows what the right optimization is.
Rob: I worry a lot about prompt injection. Some of the examples people share — changing their LinkedIn profile, for instance. When you start a new company you get a lot of LinkedIn spam, it's obviously been scraped. But the person who changed their profile to put in a recipe — you can just tell with some of this stuff.
I had someone send me an email. It was the third email they'd sent. The first two were obviously generated by AI, but the third said something like, I'm actually turning off the agent right now and I'm going to email you for real. And I thought, why would you say that? That just makes you seem worse to me.
Ajit: I always wonder when I get a message how much thought someone actually put into it, or whether it's just an agent.
Rob: I like what you said earlier about the human components. I don't know what the right mental model for this is. In my last conversation I talked a lot about residential proxies and pretending to be different IP addresses. A couple of days ago Alex Stamos posted something about a job application site where applications were coming in from all these different residential IPs and residential ISPs.
Do you have a good mental model for how my agents look to the rest of the world, through the browser or other mechanisms? How should we be thinking about that?
Ajit: There are so many considerations. One is what a user would want to do — what tasks are genuinely beneficial — and what the contract is between the consumer and the site.
Jobs are a good example. I don't think anyone enjoys the job application process. You're searching, you're looking, you're trying to come up with a "why am I a good fit" cover letter. Was that a good use of a human's time? Probably not.
But if a business is then getting 10,000 résumés, that's not going to be fair either, because ultimately they're not going to look at those résumés. And then you get into a legacy-admissions type world, where you only get the job if you know somebody there. That's not fair either.
So if you had complete information on both sides — could you map people in a way that saves everybody time? If you had my work history, my interests, what I'm doing, you could tell me the five jobs I'm most qualified for and tell those same five employers, these are five really good people. It saves everyone time.
But I don't think we're at that equilibrium, because there's an almost asymmetric warfare dynamic. If you can create so much more content, the bottleneck becomes taste and evaluating content.
This goes beyond agents, but the thing that frustrates me — going back to getting an email from an agent — is the waste of time. It puts the burden on you to sort through all of it. I read a lot of documents and think, this was all written by AI, this is a waste of my time, because I could have prompted the AI myself. Now I'm just reviewing something. If I get ten times more things to review, that seems like less value for my time.
And I have a moral thing about it too: I don't want to create a digital twin of myself to go review that work. Then you have agents talking to agents, and where's the humanity? It's just agents and agents talking to each other. That doesn't seem fun to me.
Rob: My one PSA here: I used an AI chatbot to figure out whether any of the people sending me these emails were breaking any laws. Apparently as long as you have your physical address in the email, you're compliant with CAN-SPAM. There are probably exceptions. But if you get one of these unsolicited B2B emails and it doesn't have a physical address, that's something to watch out for.
I think what you're pointing to is a good segue to our favorite topic, which is online advertising. An agent could do a kind of mutual advertising — it's advertising the things it wants, and by extension what I want. The advertiser is advertising some services, and the whole process is matchmaking.
Hopefully we could move to a more efficient matchmaking process, but that may require some level of trust — I have to give my information to my agent, who has to give some subset of it to the advertiser, or there's some other mechanism for that data exchange. And there are a lot of weird incentives there, and all kinds of ways it could be gamed by either side.
So how do you think about advertising, and supporting and paying for the open web?
Ajit: I think advertising is a legitimate monetization method. There are lots of ways advertising can be positive for both sides: here's a product I think you're very interested in, and you have the opportunity to choose it or not.
If the alternative was less targeted ads and ad load went up a lot — this company shows me ten ads instead of one — I'd personally probably take the trade-off. That's a fair exchange of value, and I'd rather be on less ad load, more relevancy. But everyone has different values.
What I really dislike is when people resell the data. I didn't even go to that site, I had nothing to do with it, and then it's sold to a third party, and I go to another site and it starts showing up. I didn't get any value exchange from what I believed the contract to be.
Then you get into the question of whether everything should be paid. That doesn't seem fair either — are you saying people who can't afford it can't access relevant content? There are great sites like Wikipedia that don't have ads and live through a donation model. If everything could live through a Wikipedia-style model, where people self-select and say I'll pay and there are no ads, that would be a great internet. But it's also not practical.
So I wouldn't say this is how it has to be. But I'd hope people are at least transparent, so I can decide whether I want to make the trade-off, and that there's good choice and good openness — that I'm not locked into a single service and I actually have the ability to choose alternatives.
Rob: I wrote something about ten years ago saying AI agents would drastically reduce the size of the advertising market, on the theory that matchmaking would get much better.
What worries me about the current state is that some of these gatekeepers have built insane models that can figure out you want to buy a product before you know it yourself. They're just very good at matching. So right now a lot of the value is being retained by them — they're capturing a lot of the economic surplus.
I worry that it's going to get harder to be an independent publisher online and harder to monetize. I don't think crypto is the answer to the micropayments issue. So I worry about who's going to pay, and how this works when real human traffic may be going down in some places and agents are soaking up cycles trying to find information.
Ajit: I agree with you a lot on that, because so much of the beauty of the internet was the long tail of creators saying, I'm passionate about this topic, let me create a blog about it, an article about it. Lots of things emerged from that — different formats, different styles, different content.
If you ask who's likely to be impacted first, it's probably not the big tech company with huge margins. It's the hobbyist. And if you remove all the hobbyists, do you end up with a monoculture — very similar ways of thinking about things, whatever the algorithm promotes? Then you don't get the crazy ideas, the outlier ideas, the new things that would emerge.
You see this happen under pressure. A lot of people started creating content on Reddit, but Reddit changed its policies and changed the friction, because it has other pressures around monetization. X is another example, where it's oscillated in terms of what it promotes and doesn't promote.
It would be very sad to me if there was no sustainable way for people to create high-quality independent content.
Rob: When you think about what's addressable for Mozilla, and specifically for Firefox, in the ad space — I worked at Google and had some interactions around Privacy Sandbox; I won't go into too much detail — I'm curious how you think about the evolution of ad tracking, which is very browser-dependent.
Ajit: We put a lot of focus on blocking trackers, blocking cookies, private browsing mode, making sure as much information as possible stays on device or is end-to-end encrypted if you're doing something like sync.
But there are challenges with website compatibility. This happens more than people think — if you block everything and you're using blockers, you may have sites that just don't work. So how do you get to a state where it's easy for people to know why something isn't working, and then choose whether to enable it?
We're trying to create more transparency as well. We're blocking trackers, and in our next release we're going to show in the address bar how many trackers we're actually blocking. It's not "I blocked five trackers" — it's hundreds and hundreds of trackers on most sites that end up getting blocked.
Shining a light on it matters. If users went to sites that weren't tracking them and behaved in more privacy-centric ways, then publishers and tech companies would understand that if they want to build a long-term sustainable business, they'll have to adhere to better practices.
But it's hard, because convenience often trumps privacy for a lot of people, or the concepts are just hard to understand. The average person probably won't care. But if enough people do care, you can build a coalition — and that may create governmental pressure, which is probably the more likely path.
You see a lot of laws passed in Europe, some good and some bad. Cookie acceptance is probably the most annoying thing ever, but it's well-intentioned. On the DMA side, there's a lot of good around interoperability to ensure competition. So in theory I can pick a gatekeeper that's more private, because I actually have true choice.
Rob: I've had lots of experience with e-privacy notices, non-compliance with those policies, fines and other things — on the business side, as a competitor. But as a consumer, yes, they're annoying.
Once these things pop up and people start ignoring them, they become a source of annoyance. Or you see "322 different partners" you're agreeing to, and there's no way to sort through it.
Ajit: The browser can actually do things better. Can I set a browser-level setting that tells sites what I want, and it just applies everywhere? But it's tough to get sites to agree. We tried standards like Do Not Track, but there was never any legal muscle behind it, so most sites don't bother honoring it.
And sites now do pretty sophisticated things with fingerprinting, so it's a cat-and-mouse game where we're constantly trying to figure out new ways to prevent it. If there were regulation saying you can't fingerprint a user who told you not to fingerprint them, then it's not a cat-and-mouse game — it's a value we say people want. Give people a nutrition label, and if I don't want parts of it, it automatically removes them.
Rob: I'm curious to see how things go in jurisdictions with more laws around data brokers — California, obviously. You're in California, right?
I'm really curious how the data broker opt-outs go. With any of these things, if the more aggressive jurisdictions have done a thoughtful job of understanding the incentives, that's great. But with the DSA and DMA, some of the ideas are great and the implementation isn't. Do you have thoughts on the data broker side and how that plays out?
Ajit: In a lot of ways it's a very sketchy business. There's so much spinning things up and spinning things down — even if you go after one, another pops up the next day. And it does seem like a lot of scams ultimately happen because of data brokers. There's potentially legitimate value in data brokering too, but my take is that there are a lot more cases people don't like than cases they do.
The flip side is: if you don't allow this, does all the power get consolidated further into big tech? That's what happened with Apple's ATT — app tracking transparency. I think the intent was to have a bigger impact on big tech, but from what I can tell the opposite happened. The big tech companies have so many sources of data that they don't actually need to track — they can still do it. It's the smaller sites and smaller apps where, once they have to prompt, their ROI goes down and they can't really do advertising.
So I haven't thought deeply enough about data brokers, but ultimately it's: how do you give users what they want, while making sure you're not just consolidating more power into closed ecosystems through unintended consequences?
Rob: That's one of the problems — if the gatekeepers can afford more lawyers than anyone else, they're going to be one step ahead.
As you think about the next set of things you and your team are going to focus on, or the things you're interested in watching evolve before deciding what to build — what are some of the themes you're thinking about?
Ajit: Like a lot of tech companies, much of the question is around AI: what's the right integration for AI, what's the right data use, what's the right opt-in versus opt-out?
We're taking a more methodical stance, because we want to ensure users are making clear decisions that are best for them. We've publicly stated that all the AI features are going to be opt-in and users should have clear consent. We're trying to create really clear separation between when you're in AI mode and when you're not, and what the data usage implications are.
Another big thing in the news for browsers is that Chromium has made a lot of changes that disable more powerful ad blockers. uBlock Origin is one of the more powerful ones, and almost 11% of people on Firefox use it. We want to make sure that things which can be described as security challenges are fixed in a privacy-centric way, and that you genuinely address the security concerns too.
Increasingly it comes down to: if your business model diverges from what your users want, are you willing to support what users want? A lot of what we push on is making sure there really is choice. If you want to use an ad blocker, that's great. But at the same time, we're very conscious that we don't want to break the internet and have everyone use an ad blocker. So there are sensitivities about where we stand. We want to make things accessible without pushing one viewpoint or the other, so it's easy for people to get to the state they want.
Rob: As someone who worked on ad blocking — maybe a story for another day — I think giving people choices but also showing them the impact of those choices is interesting. It's kind of the inverse of the tracker numbers you mentioned as a feature.
I always wanted a way to support the open web without having to see ads. It felt like there was a big inefficiency there. I wanted to do ad blocking, but not necessarily take all the money away from independent publishers. There are lots of free-rider problems and other issues that make it difficult to balance.
But fundamentally with ad blocking, my observation is that there's been a big loss of trust because of the nature of display advertising and the incentive to put as many ads and as many trackers on a page as possible. In my most honest moments, I don't know how fixable open web advertising is. We may have to start over on some of it.
Ajit: When Firefox first launched, one of the big reasons it gained traction was that it disabled pop-ups by default. Back then a site would load and throw up many, many ad pop-ups, and people found that super annoying. But it didn't kill all sites — they adapted. Whether they landed in the right spot, I don't know.
There's a balance, and it's not about ads, it's about intrusive ads — ads people don't like. There are many ways to do good ads. How you strike that balance is important. I don't know that we're there yet, but I definitely don't think it's zero ads, and I don't think it's going back to pop-ups. There's some middle ground.
Rob: Well, if you can figure out how to have ads shown to my agents instead of to me, and then have my agents decide which ads actually get shown to me, I think that would be ideal.
Ajit: They're just going to start buying stuff on your behalf. You'll get packages every day.
Rob: Maybe it's: do the fifteen steps of work first, then give me the choices, and I'll say, actually, I do want that thing. It's an idea. Who knows. It'll be interesting to see how it evolves.
A lot of folks would say much of Mozilla's revenue comes from working with Google. My understanding is there's a natural point where that may not continue — or it may, I don't know. Reading what's public, what's your official stance on where that goes, or what the next stage is for the organization?
Ajit: We've been transparent that most of our revenue does come from the search deals we have. For us this is generally a good user experience — people want to make searches, and it's a rev share opportunity. We have a really strong relationship with Google and we value the partnership. Ultimately we think it helps us create a better browser, which creates competition in other places.
Regardless of how things shape up in the future, hopefully there's good competition, so people have choices. Hopefully there are many browsers and many search engines. If users want to use a different search engine, we want to encourage them to use what's best for them.
But to date, a lot of our ability to invest in making a better browser and a better internet has been made possible by this deal. So we hope it continues for a while.
Rob: This has been a lot of fun. I appreciate you taking the time to chat about all of this. Great to see you and catch up.
Ajit: Good to chat. If you have any follow-up questions, let me know — catch up soon.
** Reference: https://mashable.com/tech/tiktok-safety-feature-algorithm-engagement-test (August 5, 2026)