https://support.mozilla.org/en-US/kb/shield#w_to-opt-out-of-...
https://support.mozilla.org/en-US/kb/shield#w_to-opt-out-of-...
- I had never heard of "Studies" before; which leads to
- I never agreed to be a part of Studies in the first place.
The docs says it must be opted in, so supposedly I have to give consent to it. I don't remember doing so. For all my life, I've always rejected any survey, opt-in request and similar stuff. I do admit there is a small, unlikely chance that I did opt-in. Maybe I misclicked it? Maybe I thought I was rejecting when I was actually agreeing to? Maybe someone else was using my computer and opted-in?
If this is indeed opt-in, and this unlikely scenario did happen, then I apologize for the rant. But I can't remember the prompt at all, and I would never consciously opt-in, hence the feeling of betrayal.
For the record: I now know what Studies are. I acknowledge that companies need to run A/B experiments in order to enhance their products. I just don't want to be opted-in by default.
No need to apologize. It's not really an opt-in if you are certain you would never opt in if you were aware of it, and somehow you accidentally "opted in" anyway.
I'm in the same boat, I would never opt in to any of this stuff. Now I had my "studies" setting turned off, so that's good. But when I looked at about:studies, it seems as though it had been on at some point in time (because it lists a plugin that it used for a study, or something). So I suppose that I actually opted out of this studies thing at some point, meaning it had been turned on without my consent either.
You can actually check what is sent, though there's no option to more finely disable studies requiring, say, cursor, keyboard or tab name monitoring. I haven't seen any such studies though.
The "remote code execution" thing is already there, it is called JavaScript. Almost every browser has it. Add-ons use it all the time.
As for browser code itself, it is open, go read the changelog. If you're extra paranoid, you can build it yourself. Study code is also fully readable.
How is software whose sole purpose is to send my information to a third party not spyware?
>The "remote code execution" thing is already there, it is called JavaScript. Almost every browser has it. Add-ons use it all the time.
JS on any webpage can't do whatever it wants, since it's restrained to the webpage itself. otoh I'm sure this "studies" thing can change my browser configuration (including my certificates, making me vulnerable to MITM) and probably even execute any command with my current user privileges.
The difference between spyware and telemetry is intent - use of data - and anonymization measures.
If you don't trust the company making the browser with user studies (and their toggle), you probably shouldn't use their build - and you can disable study code completely on compile time.
If Mozilla decided to be evil like a certain Alphabet company, there is nothing to stop them but forking and writing another web browser.
It's pretty clear what they are worried about. That's not really arguing in good faith. And "intent" has nothing to do with it--also there is no singular intent from an organisation, if it goes wrong it's just stuff that happened but nobody to point a finger at whose intent it was.
Also, anonymization measures are a joke. It just shows an "intent" to anonymize. But when it turns out that the data is in fact easily de-anonymized somewhere between the browser and the aggregation unit, or in combination with the newest "opt in" monitoring feature, again no fingers to point and your only recourse is better having been safe than sorry.
(Which apparently played part in the Mr Robot idiocy: since it didn't collect any data, it was easy to get it through the process...)
I don't like lots of stuff Mozilla is doing, but I trust them more than the alternatives to actually do what they claim privacy-wise.