Privacy not included: Holiday gift list for privacy and security
foundation.mozilla.org
foundation.mozilla.org
I doubt they expect this page to be used by many laypeople. Maybe a few techies will toss a link out to their families as a rough crowdsourced assessment of the degree to which some popular devices respect user privacy. The inclusion of several nearly-unknown high-privacy options seems to be a reminder that there are alternatives; probably more difficult to use or less capable, but alternatives to the mainstream data-harvesting devices you see routinely advertised.
I think it's lighthearted fun intended to illustrate Mozilla's mission of being advocates for privacy, to a degree that we have become unfamiliar as a society in the age of everything-as-a-service.
Yeah, there are probably some inaccuracies. But frankly, unless you're selling a device that allows you to run the services on your own host using open source software (the way Mozilla does [1]), it's fair game to say that it's possible you are not sufficiently respecting user privacy. How can we as users be sure if all we can measure is that, indeed, the device sends data off-network to the "cloud?"
If you genuinely respect user privacy, you should allow a user to wholly own the data in the most pure form possible: they never send it to you.
Pressure for companies to go green has worked over time; pressure for companies to go "quiet" -- that is pro-privacy -- could have the same effect.
The page looks to be targeted at consumers, with the 'creepy' meter that changes as you scroll. However the PS4 and Xbox are considered 'A little creepy' and a sous vide cooker is listed as 'Somewhat creepy'.
Despite the arguments made on the respective pages for why they are creepy (generally "Shares your information with 3rd parties for unexpected reasons") I don't think any consumer on the planet is going to consider any of those gifts even slightly creepy.
In my opinion it weakens the argument for the legitimately creepy products when such innocuous things are included in the list.
'has parental controls': can't determine
well, it's a blooming thermostat. You can lock the thing out.
That's more 'parental control' than any standard thermostat.
creepy meter? as a gift for a non-family member? yeah, that's weird.
Without discussing these things, the bar for 'normal' will simply continue moving.
Consider that in 2018 the term 'spyware' has essentially become meaningless because outside of FOSS products for power users and a few systems for enterprise _everything_ is doing it.
I won't buy my family products that spy on them and will recommend them against buying such. They need a moderating influence that understands the issues and doesn't have a vested interest in screwing them over like advertisers do.
Further as you point to, a lot of the "creepiness" factor is a function of the delta between expectations and reality, ie. how surprising it is, and the extent to which it's perceived to be avoidable. That can be different then absolute measures of how objectionable something is. To take your example, an internet connected game console these days has some upfront expectation of data collection by virtue of the profile and social features that are right there front and center. Since it's also generally static in a fixed location and used only for a specific purpose, the surprise factor of most of its privacy issues is inherently lower, and the data collection less passive. A cooking tool though might be a lot more subject to surprise at what it's doing.
This list definitely feels very shallow and disconnected from any deeper reasoning about specific security practices, business models, whether a net connection is actually required or not, etc. It's a popularity poll at best, and the actionable advice is minimal. It's a bit disappointing coming from Mozilla, at least to the extent that it's a wasted opportunity on something that the public is growing more aware of.
> We created this guide to help you buy safe, secure products this holiday season.
Because "we created this poll so you can see what other people think is safe, secure products this holiday season" doesn't sound nearly as good.
So they made a guide, that's really a poll. What do you mean you can have your cake and eat it too?
As an example, Imagine the household that has multiple gmail accounts, multiple android phones, everyone uses google maps, Chrome on every desktop, google for search, they add a Nest thermostat, a few Dropcams, and for good measure they use 8.8.8.8 and 4.4.4.4 for all of their DNS queries.
You can live in nearly the same world with Amazon and others.
Sigh.
[X] Can install extensions without my knowledge or consent that do not explain their functionality, and were added based on pressure from the marketing team. https://news.ycombinator.com/item?id=15956325
Edit: Am I being unfair here?
"This add-on was installed and set to ‘OFF’ and made no changes in the user experience unless it was explicitly turned on by a user, but it was added. Even when turned on no user data was collected or shared."
Edit: Also, the "no data was shared" is a lie or two inches short of one. It injected http headers on requests to NBC sites once activated. No one was logging that?
There is a price to pay to be the "good guy". If Mozilla doesn't want to be good they don't have to be. They don't have to make the mistake Google did.
Thy are listing the PS4 and XBox as a "a little creepy" They are listing Apple iPad, Apple Watch, Apple TV, Apple Air Pods, Roku, ChromeCast, and Kindle as "somewhat creepy".
I am concerned about my privacy and avoid "smart" speakers, appliances, etc, but do not find the devices I listed above "creepy".
The guide says of Fitbit Versa, "Shares your information with 3rd parties for unexpected reasons: yes". This is false.
The rating may just be by vote, but there's no excuse for getting the facts wrong.
> How Information Is Shared
> We do not share your personal information except in the limited circumstances described below.
> For External Processing
> We transfer information to our corporate affiliates, service providers, and other partners (so, basically anybody) who process it for us, based on our instructions, and in compliance with this policy and any other appropriate confidentiality and security measures. These partners provide us with services globally, including for customer support, information technology, payments, sales, marketing, data analysis, research (so we can ad target you), and surveys.
If I buy a gadget to track my personal exercise routine, it is definitely unexpected that my whereabouts are being monitored by advertising companies. Does Apple do the same with their fitness data on the watch?
You're free to speculate on the worst possible implications of their privacy policy too. Here's an excerpt from https://www.apple.com/legal/privacy/en-ww/
Service Providers
Apple shares personal information with companies who provide services such as information processing, extending credit, fulfilling customer orders, delivering products to you, managing and enhancing customer data, providing customer service, assessing your interest in our products and services, and conducting customer research or satisfaction surveys. These companies are obligated to protect your information and may be located wherever Apple operates.
Since the software is proprietary, and you are not making an official announcement on behalf of fitbit, why should we believe you? What you say directly contradicts the privacy policy[0] on your employer's website, which certainly states that they have the freedom to share your information 'with others': "You may also authorize us to share your information with others" and "We transfer information to our corporate affiliates, service providers, and other partners who process it for us"
0. https://www.fitbit.com/legal/privacy-policy#how-info-is-shar...
Providing data to third parties for processing is clearly different (and as an ex-user of one of Fitbit's products I definitely wouldn't have expected that this is the case -- Fitbit's fitness tracking is so core to the company that I wouldn't expect the processing of said data to be outsourced.) Yeah, it's in your privacy policy but that's just a cop-out (by that metric, no product can unexpectedly send data to third-parties).
Here's the whole paragraph:
We transfer information to our corporate affiliates, service providers, and other partners who process it for us, based on our instructions, and in compliance with this policy and any other appropriate confidentiality and security measures. These partners provide us with services globally, including for customer support, information technology, payments, sales, marketing, data analysis, research, and surveys.
Do you have any particular insight as to why Fitbit still doesn't support the Apple Watch at all?
I've made my choice of wearable (mostly due to forgetting to take my Charge HR off when going swimming) and don't particularly want to be in a fitness-tracker-akimbo situation again.
The primary value proposition of the Fitbit app (to me) is the social/competition aspect. MobileTrack clocks in anywhere between 2000-9000 steps/day short compared to my watch or my old Fitbit (as I don't carry my phone everywhere I go).
I guess this might not be totally tangential to the sibling thread that followed, as I guess the reason is my activity data isn't valuable enough to Fitbit as a business, which relies primarily on equipment sales?
Eitherway, I'd love to keep using the Fitbit app. The competitions, the badges, they're all great, and way better than the Apple Watch's social/competition functions. Unfortunately, the rest of the product lineup no longer appeals now that I have the AW.
There is literally no reason a fitness device could not do everything locally.
Would be interested in such a device if they were available.
Most privacy advocates are the strongest enemies of their own causes. They only accept purity and it encourages everyone to ignore them.
1. Anonymous
2. Hard to game
3. User privacy
Pick two!