Block Fingerprinting with Firefox
blog.mozilla.org
blog.mozilla.org
I kind of wonder if it would be possible to force the issue legally as an accessibility problem, but other people than me would need to do it, and in any case it feels a kind of dirty to me to use blind accessibility as a tool in the fight for privacy.
On the other hand, it also feels dirty to me that being blind would mean you're not allowed to do as much on the web to protect your privacy. Blind people should be able to use Tor.
That'd be very cruel to ignore those with vision, but who don't have anything close to perfect vision or correctable vision through glasses. It would also ignore those who have poorer vision as well as have difficulties in recognizing patterns. There's a whole spectrum of accessibility issues, and trying to "fail people" who seem to have enough vision to click on an audio button would be the definition of being evil.
> I kind of wonder if it would be possible to force the issue legally as an accessibility problem, but other people than me would need to do it, and in any case it feels a kind of dirty to me to use blind accessibility as a tool in the fight for privacy.
Even if this is not possible legally in all jurisdictions, enough publicity and outrage could help. There should certainly be some journalists from major publications/site reading HN (or HN readers with journalist contacts) who can investigate and write about this.
If everyone would block it the website owners would have no choice other than to move to a different captcha system.
The only way to make that happen is to stop using Chrome and tell others to do the same.
Google took over with shady practices, with the help of tech savvy people.
"It works in Chrome and Edge, which is based on Chrome, so what's your problem, again?"
And before I get accused of shilling, I hate chrome and despise Google with a passion.
It seems pretty clear from the fact that nonsense user agents like "TotallyNotMicrosoft" and "IE6" worked, that there is a blacklist, not a whitelist.
It seems pretty clear from the fact that nonsense user agents like "TotallyNotMicrosoft" and "IE6" worked, that there is a blacklist, not a whitelist.
Then maybe the standards process needs disruption. But if we don't build to standards then we are building roads that only certain cars can drive.
I also love sending him patches to show how easy it is to fix his stuff so it works in Firefox, Chrome, Edge... and of course Safari.
DRINK VERIFICATION CAN
It shouldn't be the case, and I don't want to block people who have a legitimate reason to use Tor. Unfortunately there isn't a "block Tor traffic from assholes" option, so all I can really do to reduce the malicious traffic is block exit nodes.
> Unfortunately there isn't a "block Tor traffic from assholes" option
What exactly is "Tor traffic from assholes"? Bulk DDoS attacks? E-mail spam? SSH login attempts? Please share your valuable experience with everyone here, so that all of us could stay safe by learning from your example.
Most "asshole" traffic I see falls into one of two categories - attempts to exploit vulnerabilities (../../../etc/passwd stuff) and account takeover attacks.
The first I can forgive, I don't frankly care where that traffic comes from and the responsibility is entirely mine as website admin to prevent these types of attacks through good coding practices, WAF, etc.
The second I have less control over because customers / the general public sucks at security. They re-use passwords they've had for 10 years and won't opt-in to 2fa. And as a merchant, my company generally eats the cost of fraud that these attacks generally result in.
If no or little legitimate traffic is coming from Tor, and a significant percentage of malicious traffic is coming from Tor - at great cost to me / my company - why the hell would I allow it to continue?
There are many types of "abuse" (not just trolling) - mass downloading/scanning. (Ex: several types of port scanning can't be done via Tor since it doesn't support UDP)
Now you're just training many Google machine learning algorithms by classifying data. In which they get more useful for the consumer, thus more powerful.
What is the purpose of those choices then?
Not to get all tin-foil-hat, but this is going to sound like it, but if you have a car that has 9+ cameras upon it that drives in areas full of these, then maybe there would be some use for it for Google.
Bear in mind that I'm not saying that they are doing this but to dismiss it unequivocally as something that can't or wouldn't be done entirely ignores the premise that it could prove useful to other areas of their business, which might have a vested interest in such use (say, for example, if Google or it's parent company were trying to break into the self-driving car area[0]).
I would love to see some evidence (a link or something) of this. I see captchas that look like pretty good edge-detection discriminators- street lights in tree limbs, bicycles against brick, and so on.
I dislike Google reCAPTCHA, however, it brought down contact form and comment spam to almost zero. (With the price of an unknown number of false positives and some frustrated users.)
Great to read something like this on mozilla.org.
But they're happy to pay via google's search and tracking. Mozilla doesn't have a lot of options open to them.
I'd honestly pay $2 per month (12 times "my share") for a Firefox that completely disavows the ad model and produces a truly user-centric experience sans ads, fingerprinting, etc. However, given that over 95% of their revenue comes from Royalties, I don't see that turning around any time soon.
I think nearly everyone would be willing to pay the ~$2/year to use Firefox if all browsers weren't free.
At that price, the main reason not to pay is the hassle rather than just downloading.
Thanks for the context about the revenue of Firefox. I had never given it any though.
Don't forget $2 in USA buys you different things than in Russia, China, India, or Africa.
Besides paying for a product doesn't mean that it becomes privacy-friendly, look at how Spotify still tracks your every actions even when you're a paying customer for instance.
A lot of people here also have huge double standards regarding Mozilla.
After all there was a time where most of us trusted Google and their "Do No Evil" motto. And then eventually in morphed into "Do More Profit" and we have the corporation that we know today.
DDG may change how they do things, but I expect that if they do there will be someone else that shows up to make money by providing a value-added anonymizing wrapper on top of search performed by a larger company - and it may not even be on top of the duopoly as it exists right now (are there actual search providers in the US not wrapping Google or Bing?). This may particularly happen if a new company grows in India or China then its able to start spreading coverage to other parts of the world.
I’m not affiliated with them. Just a happy user.
So donation money goes to outreach and similar. Which is useful but doesn't fund Firefox.
Someone please correct me if this is wrong.
the donations are still useful though because if there were none mozilla foundation would die, and in turn, mozilla corporation would also die or be sold as its fully owned by the foundation
Tax-exempt charities (which must by definition be non-profit, but not all non-profits are charities, and not all charities are tax exempt!) must spend money in a way that's aligned with their mission, and there are rules on how much they can spend outside that. (The really big no-no has to do with political lobbying and the endorsement of candidates for public office -- a relic of a more civilized age when apparently we thought that should be left up to individuals. But I digress.)
The Mozilla Foundation is a California corporation with tax-exempt status under US Internal Revenue Code 501(c)(3), which covers "public charities, private foundations or private operating foundations". There are slightly different rules for each category.
I'm not sure what category Mozilla Foundation is; my suspicion is they are either a public charity or a private operating foundation. In either case, there's nothing that would prohibit them from funding software development, as long as it doesn't unfairly benefit someone involved in the organization's governance.
Their 2016 financial statements (I couldn't find anything newer) are available:
https://assets.mozilla.net/annualreport/2016/2016_Mozilla_Au...
tl;dr: In 2016 they spent over $250k on software development as a line-item, out of about $500k in revenue total. It's by far their biggest budget item.
> https://assets.mozilla.net/annualreport/2016/2016_Mozilla_Au....
> tl;dr: In 2016 they spent over $250k on software development as a line-item, out of about $500k in revenue total. It's by far their biggest budget item.
The numbers are actually $250 million and $500 million. All the tables this report (as well as a newer one I have to search the link for) list the figures in thousands.
i would even pay a whole $3/month for that! =D
To have a premium product, you need to have a non-premium product, and given that most users would use the non-premium product, firefox would quickly become associated with a browser that has the actually desirable features turned off...
Which would probably be even worse than their low market take up at the moment (and I am typing this on firefox).
The people who would pay for a subscription are surely some of the most valuable for advertising to, and FF in its current form exists because of advertising.
Although the Foundation wholly owns the Corporation (we call them MoFo and MoCo internally), money donated to MoFo does not go towards paying MoCo employee salaries as far as I am aware.
A subscription model of some sort would probably make sense, but I don't think you'd want to gate those kinds of features on it.
[0] https://donate.mozilla.org/en-US/?utm_source=foundation.mozi...
I believe those backfired since all their marketing has been propped on morality. When they claim ads and tracking are evil, it bit them whenever they ventured anywhere near that stuff. Give many startups here an initial audience of 200M+ engaged users and they'll figure a way!
The real irony imo of FF being considered the alternative browser, but not actually competing against Chrome where it could have a serious edge only entrenches the pro commercial anti user status quo.
You might consider the positive aspects of your use of the money out with the negative aspects of your aiding murder, say, but that's not quite what you outlined.
If someone you hate offers you a billion dollars, you should take it—because in doing so you’ve made someone you hate a billion dollars poorer! It’s like stealing the money from them, with less work!
Imagine, analogously: a lottery whose proceeds go to a charity supporting statistics education.
If you keep taking their money you're morally complicit in their actions too.
You’re essentially talking about the https://en.wikipedia.org/wiki/Cobra_effect. (The government sets a bounty on snakes? Bounty hunters realize that the cheapest way to get snakes to turn in to the government, is by breeding them themselves. Now you’ve got more live snakes, not fewer.) When greed or need-for-money is an incentive (such as in a for-profit corporation), you’ll be driven to do whatever perpetuates the income stream; and, if someone is paying you to do something, it’s cheaper to just do that thing because you get to continue working with them in the future (so your marketing costs for finding new work are zero.)
But, importantly, the Cobra effect doesn’t apply if your goal (as a person, or as an organization) isn’t to make money, but rather to use up money (i.e. to bankrupt your ‘patron.’) If you’re not a bounty hunter, but simply someone who hates snakes, you won’t ever bother to breed them. You’re not in it for the money. You’re in it for there being fewer cobras.
There are, of course, organizations which are not for-profit corporations. Mozilla itself is a non-profit, despite there also existing a Mozilla Corporation.
As well, even with a for-profit corporation, the income of such an organization can be completely divorced from how it deals with an arbitrary stream of money. Banks, for example, despite being for-profit corporations, do not spend the money you deposit with them. Your money is not an asset on their balance sheet; in fact, it’s a liability.
Mozilla Corporation could, for example, just donate all the money it receives from unsavoury sources over to Mozilla-the-nonprofit, and keep none for itself. This would remove its profit motive vis. this income source.
Analogies:
Police confiscate stuff from criminals, and then sell that stuff at auction. They aren’t driven to confiscate as much stuff as possible, because they don’t directly see the proceeds from those auctions (it goes into the city budget, which does eventually fund them back, but in some inscrutable, non-motivating way.) Instead, the police department usually just has a mandate to take the stuff and sell it. (There is a broken incentive around police confiscation of drugs and cash, because these are so hard to trace that police can and do directly profit from these confiscations. But money wired between corporations as a result of an invoice is not untraceable like cash, so the confiscation of cash isn’t really analogous. A closer analogy is the confiscation of pimped-out cars—the police do not, and cannot, make personal use of these. So they don’t really care how many they find.)
Oil-and-gas engineers aren’t driven to flare as much natural gas out of oil fields as possible, because there’s no useful purpose to flaring natural gas (for now); they’re just trying to use it up and get it out of the way of the stuff they do want.
Building renovation contractors aren’t driven to collect as much asbestos as possible. They only collect and remove it because they can’t certify the building until it’s all gone. (Imagine an alternative world where you could turn in asbestos to the government for a reward. We’d get a Cobra effect so fast.)
In all these cases, you’re not driven by your need to collect the thing; and there’s no element of greed driving you to collect the thing; it’s just part of your job to collect the thing. As you diminish the number of illegal weapons out there, or amount of natural gas in the oil field, or the amount of asbestos left in buildings... you can simply do less sequestering. Nobody is put out when criminals run out of guns, not even the police. The oil-and-gas engineers who did the burn-offs are done their work at that oil field, sure, but they just move on to another oil field. The renovators have plenty of other jobs to do, and the people who specifically handle asbestos removal will just retrain to remove the next thing people want gone from buildings, toxic mould or what-have-you.
——
What we’re essentially talking about, here, is a ‘parasitic’ nonprofit—the organizational equivalent of a mosquito, something that wanders around sucking its ‘hosts’ dry, but which doesn’t expect (or attempt) to subsist indefinitely on a single ‘host’. It expects to either kill its host; be killed by its host; or be “swatted away” by its host, at which point it can find a new host.
And, because a parasitic organization serves no useful purpose to its host—it offers no attempt at symbiosis—the host will eventually become aware of its nature, though how fast this happens can vary dramatically, depending on how bureaucratic the host is, and the time-scale of the deal the host and parasite originally made. (Imagine how long it would take the US government to figure out that a weapons subcontractor is a foreign-government led operation with the aim of “siphoning money out of the US defense budget while avoiding actually satisfying the demand for a given weapon”, purely through the regular business-side interactions between the government and the contractor, without the assistance of the government’s background-checking process. Unlike governments, private companies do not generally do background checks on their contractors’ employees, so an IBM, or a GE, is not safe from this attack.)
Of course, unlike in the animal realm where every animal at some point deals with a parasite from a state of complete ignorance, parasitic organizations can get reputations that precede them everywhere. This is what I’d call the host “killing” the parasite nonprofit.
But, well, the same people can form as many organizations as they want... and perhaps even use successive organizational vehicles to drain the same host companies repeatedly, if they just ensure to put a different face (different figurehead CEOs, etc.) on the parasite each time.
These are the same proven strategies that “fake” charities use every day to line their own pockets! Just turned to a purpose other than selfishness.
I've also been giving through Flattr as an alternative to ads for micro-funding on the Web - anyone knows why their plugin/extension/addon isn't listed on addons.mozilla.org anymore ? (You can still install it from their official website.) Might it be due to a conflict of interest between Google and Eyeo ?
Over at Google they are trying to sell fingerprinting as a feature.
Next captcha from google will be even more aggressive, you're not logged to Google = you're a bot, you can't access that content.
You may be right. But you know what:
If I encounter captchas nowadays and unless I really need to get to that site it's "Fuck you very much!" time.
I'm just not that interested in most of the web to make it woth my while and provide free work for Google.
I really hope the EU hits them hard with a GDPR investigation, the amount of identifiable data they collect with reCaptcha is unacceptable.
I've never seen a reCaptcha on HN. Is that because I registered my account something like 10 years ago?
I am not convinced that training google’s image recognition algorithms is the only way to solve the captcha problem
I spent days trying it out with screen readers and tweaking it to work with as many as possible.
To me, it sounds like your system is just security by obscurity. It wouldn't scale, if it did become used prevalently then it would be very easy for bots to circumvent.
It won’t scale, because it mustn’t scale. It is a dead simple solution to a complicated problem and works as long as it works, without selling your user data and brainpower toone of the biggest tech companies there is.
If it should happen that the spam bots overcome it or your site becomes big enough to be targeted you just change it for something stricter, stronger or more sophisticated.
Actually I'm not sure I need to go to full ML: after a few rounds I can probably just use image compare (not ML) and just feed humans images that I haven't seen before.
Of course round two of the above is to expand on the above. Doing ML for image recognition isn't hard (other than CPU cost). I can also collect statistics, images humans take longer on I will take longer on as well (I can potentially collect eye movement so I have better data than google here - this can feed into ML). Images that humans are unsure of I will fake unsure of by sometimes clicking sometimes not at similar rates to humans.
I don't know what ML google has that isn't public, but we also don't know what scammers have. Ultimately google needs to expose enough data to scammers (who see more captchas than anyone else by nature of their operations) that their ML algorithms have a large training set. Once a scammer realizes the types of data good is looking for it isn't hard to collect other samples for your private training set. Go outside in any city and you will find stoplights and street signs... you now have a training set of data that isn't googles to test on - you need a few cities and seasons worth of course, but that is an implementation detail.
The game is more expensive for google because google needs expensive people to create the scheme, they can hire cheap people to figure it out. (if cheap people can't figure it out google has failed) They only need expensive people only if/when they decide to automate the scheme.
In short your metric doesn't work.
All the public computer researchers and browser vendors are years behind the techniques to fingerprint devices (probably 5+).
Canvas, WebGl etc are techniques of the past. There are much more advanced ones, than can identify devices with completely uniquely (on both desktop and mobile)
Also we know when users fake their fingerprints, and the algorithm respects the decision even though we know who the user is despite faking with all state of the art methods.
Latest methods dont even use JavaScript. Just CSS is enough to identify every device uniquely but you'd need JS to send the data back.
Every public researcher I've seen are given honeypot techniques that they consider state of the art even thought the industry is way ahead of the researchers.
Google, Facebook advertiser have more specific budgets, especially Facebook which has a large number of small advertisers.
Large adnetworks however get large advertisers with advertising budgets in tens of millions on average.
There is a larger pressure on Google and Facebook to be competitive then say smaller ad networks.
Also the techniques that I mention of are not in use in wild after the POC on millions of devices few months ago. They're a backup plan. Also not every adtech company has them. Maybe 2 or 3 at the most are at the cutting edge of tracking.
Google knows this very well. You really think Google couldn't counter fraud? Its a fake and manufactured outrage. No one wants to give away their "secret sauce" just yet.
Also right now many adtech companies are going bankrupt. Many larger one are waiting for smaller ones to be gone after which the landscape changes.
As someone currently working in IT for an adtech company, I can at least provide one data point in that the company I work for is slowly (but surely) dying.
Also this is nothing but getting dimension of screen and other browser attributes which are useless now. The current state of the art cannot be mitigated unless you put a 95% penalty on performance on the CSS engine AFAIK.
Ours was more advanced then this. As far as I've read the paper cited on the source above, they are like 30% of ours tech POC back in 2015.
Now we're waaay past this easy stuff to fake stuff. This now considered to be basic.
Look into distill networks, but their public product is very far behind what we did. Not sure if they have better tech to be used in future.
1. There is magic css/js that can not only tell different browsers and devices apart, but can tell two phones from the same manufacturing run with the same software apart.
2. Despite the fact that this magic code would have to run in the client browser where its content, execution, and the data it sends back are all plainly visible to anyone who can hit ctrl-shift-j, no "public researcher or browser vendor" knows anything about it.
3. This technology is not used to combat ad fraud because of some weird conspiracy at Google.
It could be true, I suppose, but I don't see why anyone would believe this based on the evidence so far.
However the author of the paper could not get it to work on low end devices, whereas we could. And we discovered this around 2015.
Also we know many exploits to bypass noscript if we wanted to (yes I know there are bounties for this, but we were paid much higher then any public bounty for this stuff)
> Wait for the new CSS version over which our team had a watch. Wont require JS after it comes out. ;D
So how does that work considering what I said above?
Why would I believe you over all the public research available? If you really were working on this why would you be stupid enough to post about it here?
Trying out Firefox now...
More importantly it would go against the mission statement.
Mozilla isn't around to make money, it's around to make progress toward a mission. (Search revenue helps fund that, but revenue is not the end goal for Mozilla).
By contrast Brave has had things such as blocking of fingerprinting for months (years?), and also natively supports OPT-OUT ad blocking, script blocking, third party cookie blocking (which FireFox does also but once again in a less direct fashion), single click native TOR access + ID swapping anywhere, and more. And I think the biggest difference is that this is all directly exposed to the user. If a user clicks the big iconic Lion icon in the top right they get a popup that shows nothing but:
- [x] Shields Up (adblocking/etc)
- [x] Third party trackers blocked
- [x] Connections forced to HTTPS
- [x] Scripts blocked
- [Third Party/All/None] Cookies blocked
- [Third Party/All/None] Device recognition blocked
So even users that know absolutely nothing and don't bother to navigate through menu options will almost definitely immediately be exposed to all of these privacy options, though again given the opt-out nature of much of it - even if they weren't, it would be less of an issue.
Well it was not a bad decision to make since most of their users would set Google as their default anyway (no matter how privacy concerned you are, you still can't do without Google search unless you really really try hard, which most people don't).
In my opinion it was a sensible decision.
Brave is an excellent browser but it is only a matter of time until the remaining features are brought over to Firefox. Not to mention some feel they aren't "out of the grasp" of Google until they're fully away from Chromium.
In contrast I installed Brave, and it appears to have all adblocking and anti-fingerprinting as default settings, easily accessible if you wanted to change them.
The OP reads to me as a PR piece to keep geeks onboard, knowing that regular users won't ever change default settings.
I mean FF have the telemetry they know exactly how many users disable defaults.
It can be argued that Brave has a harder dependency on Google than Mozilla does. Because Mozilla has not outsourced their core competencies.
Just to give an example, with Manifest V3, Google is deprecating extensions like uBlock Origin or Privacy Badger. What will Brave do? Maintain their own fork? Well that can get expensive fast. So if it was a business-driven decision to piggyback on Chromium, I don't see why they wouldn't adopt Manifest V3 as well. Manivest V3 will offer mediocre means to block ads too and the average user will not know the difference.
When Brave implements its own engine, or maintains an actual fork of Chromium, or when DuckDuckGo implements a web crawler and stops leaking data to Microsoft, that's when they can play the righteous game.
> often hidden behind menus that your average user will probably never visit
The average user will not install Brave either so this point is moot.
I do not agree that writing a renderer from scratch is a wise idea. I mean in theory it's a great idea, but in practice? The Chrome renderer is very well done but, much more importantly, is also going to be what what 100% of web devs will test their sites with. Even browsers with quite large userbases, including FireFox/Safari/etc, tend to get B-tier treatment, if that. Of course standards alone should mean all sites ought render/behave the same with any compliant browser but... again, that whole theory vs practice thing.
There are also a couple of other major issues. Google can use their clout to rapidly change standards that third party projects must play keep-up on. But perhaps the biggest issue is Google using their monopoly in other fields, such as with YouTube, to change their products in ways that 'coincidentally' end up rendering poorly or slowly on third party renderers, as they have done multiple times. This [1] being one particularly stark example of such behavior.
The future of web usage is always difficult to predict. We've gone through numerous phases of seemingly unbreakable web domination from Netscape to Internet Explorer to Chrome. In my opinion Manifest V3 could finally be the tipping point of Chrome, but that may idealistic - we'll have to just wait and see.
[1] - https://www.neowin.net/news/mozilla-executive-claims-that-go...
They'll expose the webRequest API:
https://twitter.com/BrendanEich/status/1133767653472923648
And uBO + uMatrix will continue to be developed by gorhill for Brave, at least.
To be fair, you did follow it up:
> as they claim FF is always the first browser to fail in the hacker games
What are their sources? I also "know such people" and I am unaware of such claims. If one uses Kali Linux, it has Mozilla Firefox as default browser. The same for Debian (on which Kali is based upon).
The thing is, you can harden your browser after installation. The first thing I do with a browser is installing uBlock Origin and uMatrix.
I think things have improved though.
With the fancy new anti-fingerprinting Safari on macOS Mojave I get just over 14.5 bits of entropy with the most entropic source being my canvas fingerprint (1 in 600).
With Safari on iOS I get 11.71 bits of entropy, with the most entropic value being my screen size and color depth.
That's actually pretty good, considering tor browser (which has resistfingerprinting enabled) with default window size (1000x1000) has 14.82 bits of entropy.
See https://en.wikipedia.org/wiki/Canvas_fingerprinting for more info.
Is there a legitimate use case for being able to read back pixels?
Because we don't know how to make CPUs do pixel perfect images every single time. (I wrote a little more above)
Longer: this is actually a viable way to do many types of fingerprinting, not just canvas. I'll give an example. In a graphics class I took our professor gave us output images to compare to. Two people with the same model computer, same specs, would frequently have a pixel or two different from one another. Change the specs and you're easily a dozen off. Worse than that, the pixels that are off from the original image can be different pixels. This comes down to the silicon lottery. So if you can think of anything that you can access where you can get the user's computer to do some sort of floating point calculation, you can probably get a fingerprint out of that.
So to fix this problem, you'd have to figure out how not just to make pixel perfect images, but for two CPUs of different types (which even same type doesn't currently) to always calculate the save answer to the same precision, every time. There's tricks that can be done like rounding, but it gets hairy really fast and becomes unpractical. But if you do know how to solve the problem, I'm sure people would really appreciate the answer.
I mean, one of the major reasons for using canvas over DOM is to get pixel perfect placement of things, like text connecting to an arrow. If your fonts suddenly change size that won't work anymore. SVG has the same problem, on some computers with slightly larger letter spacing a line might become too long so it wraps and become two lines, totally spoiling the desired diagram.
It just bloocks a couple of known scripts based on the disconnect list.
Of course they don't tell us in their marketing posts.
1) blocking known fingerprinting scripts.
2) blocking underlying techniques.
The second is the one people here are talking about, and it can be enabled by going to your settings and turning on resistFingerprinting. Keep in mind it will do things like normalize your time zone and decrease timer precision.
I understand what the original posted link is talking about, but the specific thread you're currently on is very clearly talking about more than whether or not Panoptoclick's tracking script is blocked. They're talking about how well different browsers can resist the techniques it uses[0]. Why else would anyone be comparing their results to Tor?
I had assumed it did, cause why else would we be discussing it here, and neither the OP post nor the FF setting are very clear about what it does. So I would have been thinking it was protecting me.
You can verify if it's exposed on this site[2].
[1] https://www.zdnet.com/article/android-and-ios-devices-impact... [2] http://www.albertosarullo.com/demos/accelerometer/
On firefox, the big contributors are HTTP headers (my native language is announced), hash of WebGl fingerprint and time zone.
On Tor big contributors are hash of webGL fingerprint, screen size.
On chrome, they are system fonts, hash of canvas fingerprint, user agent, and time zone.
I am not too concerned about the fingerprinting in firefox since I have strict blocking on, ublock origin, and separate containers for facebook and google. Based on the small amount of data facebook has on me, all the blocking is working pretty well.
How did you get all data, that facebook has on you?
Edit: Answering my own question. In `about:config`, change the `webgl.disabled` preference from `false` to `true`. This reduced the "bits of identifying information" from WebGL from 11.26 to 2.56.
Edit 2: Apparently the CanvasBlocker add-on is a better solution as it randomizes the data used for fingerprinting on each read, and works for several exploitable APIs, not just WebGL. https://addons.mozilla.org/en-US/firefox/addon/canvasblocker...
This is why Safari tries to give a universal canvas fingerprint so you can "blend in" with other users.
Anyone who wants to sell ads to the technically-inclined and privacy-conscious? In any case, I wouldn't be surprised if a simple ML picked up on this pattern.
In particular I was going to make a snarky comment that the site seems to, appropriately, not work when script blocking is enabled on Brave. I do get the site to do the refresh business a couple of times, but no results are ever displayed.
Doesn't tor randomise the window size on startup? Though I guess it chooses some sensible size for your screen which is then leaking info about your screen size (in a pretty indirect way).
https://tor.stackexchange.com/questions/15705/why-does-tor-b...
On my initial run, I got an overall entropy of 17.63. My two biggest identifiers were screen resolution (1000x595x24 which was approx 1/22000 browsers) and webgl hash (approx 1/3800 browsers). I fixed screen resolution to 1000x600x24 (approx 1/85 browsers) and disabled webgl hashing (approx 1/6 browsers) and the overall entropy did not change one iota, despite also closing browser, flushing cache and cookies, etc. I gave it another run with a deliberately weird resolution (1420x701 which was something like 1/105000 browsers) and once again, the overall entropy was exactly 17.63. So based on my experiment, it seems that screen resolution and webgl hash have no effect whatsoever on [Panopticlick's] overall entropy score.
As a side note, I ended up re-enabling system fonts because disabling them broke a large percentage of web sites' CSS.
anyone know of a list of the most used values for these so we could lower our uniqueness by setting our browser values to them?
Maybe due to the "uBlock Origin stops it from working" mentioned elsewhere, or some other glitch. Disabling uBlock Origin on panopticlick.eff.org didn't make a difference.
with this new setting turned on + uBlock Origin + NoScript
Since I'm on the topic, other two lesser known extension I have are CanvasBlocker (fakes canvas fingerprinting (or disables it)) and Privacy Badger (heuristically detects and disables trackers; complements ublock).
"Periodically changing user agent" sounds pretty unique if you ask me. Especially if the extension isn't super-clever and changes the user agent for accesses that happen on the same page.
And the fingerprinter could be super clever and look for features that your purported browser isn't supposed to support... And if your browser does support them, that's a strong identifier.
Your UA will correlate with other means of fingerprinting you making you more common. Being clever can make things worse.
For example, the most common UA is from an iPhone, but the most common screen width is 1920 pixel. If you decide to make your UA an iPhone with a 1920 pixel screen, then you will be easily identified.
Performance
- Single-threaded CPU performance
- Multi-threaded CPU performance
- WebGL performance
- Video performance
- Network performance (how long does it take to transfer data to various locations, what's the lag, is the lag consistent, etc.)
- (Maybe) Time it takes to execute certain JavaScript functions
User behavior
- How does the user use their mouse when navigating web pages?
- Not at all?
- Jerky movements?
- Smooth movements?
- If the user uses the keyboard, do they appear to be advanced keyboard users, do they have an IME, etc.
- Does the user press X buttons on tiny annoying popups that wouldn't interfere with the page's browsing experience?
- Does the user appear to block access to certain resources? (ad blocker)
- Does the user's workplace/country/etc. appear to block anything?
This is why I stay attached to making simple HTTP apps that don't require JS, but this is clearly not the direction the web is going at this time.
Your entropy is determined exclusively based upon the people that have used the site in the past 45 days. For now that number is about 204k. So for instance if you see something has an etropy of 9.08 (as my user agent does) you'd also see that it says 1 in 542.15 browsers have this value. 2^9.08 ~= 542.15. The ~ there only because the thousandths and onward digits are not showing. My exact entropy would be about 9.08254825596. All that means is that of the ~204k people that have used the site in the past 45 days, 377 had the same user agent.
The problem with this is that the people using this site are going to be a heavily biased sample. And so by tuning to reduce your entropy, you are not actually reducing your trackability but instead making yourself look more like the subset of people that are actively using this site. And this becomes an even bigger problem since I do imagine this site is actively shared on more technically orientated sites, such as this one. But the settings of technically orientated users are often going to vary somewhat significantly from the settings of the other 99% of users.
The point of this is that by working to reduce your entropy on this site you may, ironically, end up making yourself more trackable. So the numbers should be taken not as a measurement of trackability, but rather as an interesting insight of your browser/setting differences/similarities of other users with the site.
---
Also, 100% agreed on the silliness of them marking you down for not allowing cookies marked Do Not Track friendly. Until such things are enforced, in code and ubiquitously, they're meaningless unenforceable promises that rely on tracking and advertising corporations never lying.
However, some of the information sent by my (stock browser) is clearly false:
User Agent: Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0
Platform: Linux x86_64
I didn't mess with my user agent, so I assume this is related "resistfingerprinting" in about:config.
This definitely seems like the edge that Mozilla will have when trying to stand out against Chromium-based browsers going forward (especially now that everyone else seems to base their browser off of Chromium).
I know Mozilla has been working hard on the engine (rewrite with Rust?) and new versions like Firefox Focus on mobile is blazing fast, but keeping a separate renderer (and developer tools!), with its own issues and discrepancies, seems like a lot of sweat and pain when the Chromium project seems decently sound OSS. I know being able to put in practice your own interpretation of standards is a great exercise in freedom and web diversity, which seems to reinforce their mission, but still... the end result is probably millions in economic impact worldwide to keep website codebases aligned with browser standards, even if the differences are apparently minimal and 99% of the time it just works.
Is being a fully independent browser Mozilla's main raison d'être?
Everything else will just turn into an arms race between those who don't wanna be tracked and those who wanna track.
If the US did something like the GDPR but in our constitution I wouldn't be surprised if a cottage industry opened up overnight in secure data-warehousing. I get that it would complicate things for small companies but we brought this on ourselves.
This represents the sad state of Internet we are all living through. I have noticed that when I turn on privacy settings on Firefox, some major websites are broken and rendered unusable. It seems that the Internet is rampant with tracking and privacy violation, and we consumers are passively accepting it, by and large.
That sounds interesting. Have you published it or made source available? I'd love to try.
It's a pain to configure but the example JSON in the "Preferences" section of the add-on should be enough to get started. Just paste it into the textarea, save, then visit HN or Reddit, you'll probably see a few blank lines where links should be.
Right now, the top post on HN is a WSJ link. I don't want to see their links because I don't ever want to click them just to hit a paywall I already know I'll never accept. So my HN page looks like this [3].
The tool uses regular expressions on text and element attribute values. Anything that matches gets a given CSS style applied. I think it would be great if uBlock Origin could do this but it doesn't allow the level of granularity needed to accomplish the end result.
[1] https://addons.mozilla.org/en-US/firefox/addon/ssure/
In some cases it is because Firefox's tracking protection is based off of a curated list of websites [1]. This breaks a site I built called reVddit [2].
In my uneducated opinion, this list is weird. I had some discussion about this with Mozilla devs [3]. In that message chain, devs acknowledged reVddit is not doing anything wrong, rather it is reddit who could infringe users' privacy. Yet it is the non-infringing site that is rendered broken.
Further, the devs' suggestions for remedy are not workable. They propose moving requests to the server so that reVddit.com makes the requests to reddit.com. There are multiple problems with this,
* It would hide more code from users
* Reddit rate-limits requests coming from a single source
* Infrastructure becomes expensive on what is supposed to be a low cost website
My conversation with devs was good but needs more. I don't understand their point and they do not seem to understand mine.
[1] https://github.com/disconnectme/disconnect-tracking-protecti...
[3] https://groups.google.com/d/msg/mozilla.dev.privacy/XO84Ezrw...
Why is this necessarily better? I guess personally, I've always thought that regulating the content of the ads, rather than the usage of sufficiently anonymized data for ad targeting.
The issue people have with tracking is not 'what ad am I getting on a given website'. To get a targeted ad they need to maintain a database of privacy infringing information. 3rd parties having this data, and what they might do it with it (or who they might lose the data to) is what many people have an issue with.
Being served a targetted ad is just a strong signal that someone out there has this private data on you.
For example, chances are that google has a pretty rich database of your location history. If not you specifically, they do for most people. You can probably imagine a few different scenarios where someone else obtaining that data could be bad for someone. You're trusting google with it, but is that trust warranted?
For products that can benefit from information asymmetry[1] fingerprints are an amazing tool.
For the former, I agree it's a little hard to find realistic examples that don't involve having something to hide (but if you do, those are easy: porn history, extramarital affairs, time spent goofing off on various websites, surprise gifts, pregnancy, financial problems, stalkers, ...) Still, do you close the door when you take a shower? Do you sing in public? Do you disclose your salary in casual conversation? Those might seem silly, since the discomfort there mostly hinges on fully public disclosure, but the data are getting shared so widely now that it's getting easier and easier for the data to escape to places where they can be pulled up by someone who is bothered by your NextDoor post.
The other main category is the problems with massive numbers of other people's data being available to these companies. Those are more societal effects, like segmenting the population, radicalizing us, and setting us against each other. Outrage culture. Hyperpartisanship. Phishing. Vulnerability to external trolls/griefers/fake news publishers. Functionality being lost because it's overloaded by targeted spam. Harassment of minority groups (heck, you only need preferred language for some of that, though purchase history would reveal a lot more.)
If you think that is fair then I have a lovely Harbour Bridge in Sydney that I think I get you a great deal on.
In Netherlands, prior to World War 2, they made a "comprehensive population registration system for administrative and statistical purposes", which included the ethnicity. As a result, the Netherlands had one of the highest death rates among Jews. (I can't find a good source for this though, unfortunately)
Sounds good?
now do this for every other thing you buy online.
Good enough?
Thanks for the facetious argument and hand-waving though.
Apps and websites want to sell you things. Well many of them. They then need to know for how much. If they know, they can extract more profit. Which is why they try to find out. Really. No dogma.
What do you think I do with your fingerprint as you engage with my sales website?
"Improve my service?" I hope you never buy a used car.
Basically, you can't load reVddit pages on Firefox because reVddit accesses reddit's API, and reddit is listed on Firefox's list of websites that are considered trackers [1].
In my uneducated opinion, this list is weird. I had some discussion about this with Mozilla devs [2]. In that message chain, devs acknowledged reVddit is not doing anything wrong, rather it is reddit who could infringe users' privacy. Yet it is the non-infringing site that breaks.
Further, the devs' suggestions for remedy are not workable. They propose moving requests to the server so that reVddit.com makes the requests to reddit.com. There are multiple problems with this,
* It would hide more code from users
* Reddit rate-limits requests coming from a single source
* Infrastructure becomes expensive on what is supposed to be a low cost website
My conversation with devs was good but needs more. Is there any solution here, or do we just go our separate ways?
[1] https://github.com/disconnectme/disconnect-tracking-protecti...
[2] https://groups.google.com/d/msg/mozilla.dev.privacy/XO84Ezrw...
My general impression is that tracking protection is low-priority for Mozilla and anyone who actually cares is using uBlock Origin / uMatrix or similar extensions since those use filter lists that are actually updated.
It is on by default, and as you point out, breaks many innocent sites. People may migrate elsewhere. That should bump up its priority.
I don't believe Safari has anything like what Firefox or Privacy Badger offers built in. So you wouldn't be able to use your default experience with Safari as a comparison.
[1] https://www.cnet.com/news/new-safari-privacy-features-on-mac...
> That's the stated reason but it's pretty weak to me. Safari hasn't had to make similar compromises.
Safari's the only browser engine available on iPhones, and its users can't easily switch to another. That means more websites test compatibility with it, and its users are locked in even if they don't.
Apple more market power than Mozilla, so it doesn't need to compromise as much (and get get away with being a bit of a bully). Firefox is forced to tread lightly in comparison.
My guess is that about half of sites had issues of one sort or another. So many load javascript from 3rd parties, or other domains under their control, that strict blocking quickly breaks the browser experience.
Individuals’ security and privacy on the Internet are fundamental and must not be treated as optional.[1]
...did anyone figure out what the hell that is supposed to be, or look like? Why wouldn't they just put a screenshot.
Apparently they just mean the security settings and selecting Custom in those. Except it's on the right. And it's stripes, not a circle. shrug
> Clearly, you don't want to throw your computer out of the window and never use the internet again, just to get rid of ads.
https://blog.mozilla.org/firefox/de/loesche-deinen-digitalen...
How much of Firefox success depends on donations?
I have seen successful crowd-funding projects where the budget is always transparent and communicated to the public. I am certain this motivates the masses to donate.
Wouldn't it be better for Mozilla to make their funding fully transparent to attract the masses?
You lose your timezone and ALL dates appear in UTC. This is definitely not desirable.
Fingerprinting cannot be allowed for some sites, and thus things like android messages cannot work because it cannot accurately identify the browser.
Hopefully they'll do something about all this.
Seems like an easy fix would be to have client based converter, even more simple than what fingerprint blocker does with screen resolution.
Yes, every single company has made mistakes. FireFox is no exception. Some of them were pretty egregious. Mistakes are - hopefully - an opportunity to learn and adjust, move forward, and continue progress towards something we all want: privacy.
We should absolutely call out companies when they make mistakes or ill-advised choices. I'm not saying we shouldn't. However, we should also _applaud_ efforts that are in-line with bringing privacy to consumers. Not just spend all of our time looking for something negative to be outraged at.
This always-negative/outrage attitude just erodes any sort of meaningful discussion.
The funny thing is, no matter how I reply to your comment I lose by default. If I say I have - you say I'm lying. If I say I haven't, your point is proven. What option do I have?
Perhaps you'd like to chime in on the discussion at hand rather than speculating on my personal life.
I tried to word my comment in a way that made it clear that I believe this mentality should apply to _all_ companies, including Google, when a company makes a move in the direction of benefiting consumer privacy. I perhaps could have made that more clear in my original comment.
They made me look dumb.
I learned my lesson.
You may not remember this, but Google used to be cool. "Don't be evil", and all that. There was a lot of hope - when Microsoft was still the bad guys. Working at Google was the dream - they made movies about that.
Nowadays we all feel stupid, obviously. Right up to deleting "Don't be evil". Literally taking it out. The nerve.
No they didn't. Please don't spread misinformation.
https://www.searchenginejournal.com/google-dont-be-evil/2540...
http://time.com/4060575/alphabet-google-dont-be-evil/
I am more right than I am wrong.
Functionally, they took it out. Both by not using it in the new parent company, and deleting it out of the preamble of Google itself.
Yeah okay it still occurs somewhere. But "Do the right thing" as substitute to "Don't be evil" has clear implications except if you are terribly naive.
If they never put it in, then they never took it out. There is no need to play the language game to try to make something false sound true.
That's a meaningful insight. I think Web is in a place now where anyone with technical insight is frustrated. Yes, frustration is the right word. And confused. And it's this mix of confusion and frustration that has people going around bad mouthing all browsers, or at least I think so. Mozilla Firefox is the only significant browser that has the economic incentives to take care of privacy (there's no debate about that right? well there could be Safari, but it's closed source). I'm pretty close to chanting "the end is nigh". If you compare the resources available to the privacy-invading businesses, and the privacy-preserving businesses, how does it look? Or maybe regulative action will be taken? 100x more restrictive and better thought through than GDPR should be enough. Somehow I don't see that happening. Someone with a lighter outlook, chime in.
Sure there is. Mozilla depends heavily on revenue from Google whereas Apple doesn't. For Mozilla it's life or death and for Apple it's not (to be the default search engine).
There isn't a single tech company where the business incentives are more aligned with privacy than Apple.
Since they are closed source and secretive, there is a significant information asymmetry and we will never know how honest they are being.
Firefox, on the other hand, has an incentive to honestly preserve privacy, as their attempts to test the water on privacy-reducing features have a high probability of becoming public.
If you compare the resources available to the
privacy-invading businesses, and the
privacy-preserving businesses, how does it look?
I think this highlights an underlying problem: invading privacy has proven to be extremely profitable, which gives the companies that do it disproportionate resources when it comes to controlling the privacy discussion. Someone with a lighter outlook, chime in.
Oops, nope that's not me...If privacy first was truly the Mozilla mission, we won't have Google Analytics on extension internal pages, the Mr Robot Ad, the Yahoo ad deal, and the ability to inject code remotely in your browser. Privacy seems to be a Mozilla concern but it's not a primary one.
Arg.
- For better or worse, most people aren't scared of the Internet, so they don't want a detailed, itemised list of risks and mitigations to allay their fears, they just want to get down to business. How do you ask and inform a user who refuses to answer or read?
- People want to use the web-browser that works best with the sites they visit, and the connectivity they have available. While every person's situation is different, the Pareto principle says an awful lot of people will be in a very similar situation, so any browser vendor willing to accurately measure people's situations and optimize for them would become tremendously more attractive for most people. Refusing to implement telemetry, or leaving it as opt-in, means voluntarily giving up the mass market to less scrupulous browser vendors.
Firefox has fought this uphill battle before and they didn't need telemetry to do it. When chrome first came out it had improved the UI and it didn't need telemetry to do it.
Since firefox added telemetry their market share has declined and their UI has got worse, the idea that telemetry improves products needs to die.
I say this as someone who uses firefox on every device he can.
How so?
> In some cases, they've doubled down on them.
Which cases?
I (and many others) use Firefox because we need a trustworthy browser, but issues like these take away from that trustworthiness.
They destroyed some of my bookmarks when they dropped RSS support. That isn't privacy-eroding, it's data destruction, and they didn't even let me opt out.
I know they probably had a lot of conversation about it, but when the conversation ends with "And then we destroy the data of random people without letting them say no", you need to back up a few steps and look closely at what went wrong in your process.
In addition:
>Firefox will tell you when support for Live Bookmarks has ended and will do the following:
>Automatically export all existing Live Bookmarks to an OPML file on your desktop named Firefox feeds backup.opml which you can import into another feed reader.
>Live Bookmarks will be turned into regular static bookmarks if Firefox can identify the URL. If the URL doesn't exist, the original Live Bookmark is removed.
>ESR version 60 will support the built-in feed reader and live bookmarks features. Support for these features will be removed in October 2019, when ESR 60 is no longer supported.[2]
So, what would suggest instead of (or in addition to) providing months of warning, automatic export, and extended support that will continue for another 4-5 months?
[1]https://www.gijsk.com/blog/2018/10/firefox-removes-core-prod... [2]https://support.mozilla.org/en-US/kb/feed-reader-replacement...
I shouldn't have to make "alternate arrangements" to prevent software from deliberately destroying my data.
Giving the users commenting negatively the privacy they want would mean that Firefox would not implement the "features" that its developers believe are necessary for a "good browser".1
What "good browser" really means to these developers is a browser that does what the "competing" browser does first and foremost, not the ideal browser some vocal group of ad-loathing, privacy-conscious users want. That is how Mozilla defines "good". "Good" to them means "competitive". To the users who comment on Firefox flaws, "good" means something else. It does not necessarily mean one that "competes" with Chrome.
The honest response from Mozilla to negative comments would be to acknowledge they do not exist primarily for all users. They exist primarily for the developers who work there, as part of a project to be "competitive" with commercially-driven browsers.
Cutting ties to the revenue stream of internet advertising and the browsers that it finances is not an option for Mozilla. It is not volunteer-driven like many open source projects. It has to pay developers a competitive salary.
The idea of "something we all want: privacy" is at odds with developers who are being paid to support the internet ad business. The pervasive advertising found on the internet would not be possible without the cooperation of browser authors.
1 "Without the Yahoo ad deal, or "the ability to inject code remotely in your browser" i.e. automatic updates, or reliable telemetry from the majority of Firefox users, it would have been impossible to build a good browser." - Mozilla employee
I don’t understand- how is trying to offer a competitive, viable product not “for all users”? Are you suggesting that if they focus on a non-competitive product that’s better for “all users”?
The point I was trying to get across is this:
Companies do bad things, sometimes intentionally, sometimes by accident, and sometimes because they were misguided. Companies also do good things, sometimes intentionally, sometimes by accident. How are we, as users, able to communicate our thoughts with the company in question in these cases?
One method is by calling out the negatives and applying pressure so that, hopefully, the company feels some obligation to act or risk user exodus. This is an example of what you are doing - and it is a valid way of communicating displeasure with a company when they have made a decision the users don't agree with. Negative reinforcement absolutely has its place.
However, an often forgotten method of communication is positive reinforcement. This is how we can tell a company "Hey, good job on this specific thing. It's in a direction we would like to see you keep moving in.". This signals to the company that they are on the right track and, hopefully, encourages them to continue developing that way.
In the specific context of Mozilla, this means that I try to encourage them when they do positive things (blocking fingerprinting) while still expressing my displeasure over the certificate fiasco and other issues.
However, my original post was not meant to be read only in the context of Mozilla, nor was it meant to be read in a way that makes you think that you cannot also raise your concerns. There is a time and place for both positive reinforcement and negative reinforcement. It just seems like people forget about the positive one.
Mozilla doesn't exist for its developers. Most of its developers could make a lot more money working elsewhere.
The reality is that if Firefox isn't competitive in performance, security, and Web compatibility, very few people will use it, in which case why even bother?
There's more at stake here than just privacy, too. An open platform that isn't controlled by a single vendor, that doesn't have gatekeepers, that has lots of content AND lots of clients is really important. The standards-based Web is the only candidate at this point. Mozilla cares a lot about that, and they need a competitive browser with significant marketshare or they have no leverage.
Irrelevant. Conflicts of interest aren't a problem in and of themselves. Most people and companies have conflicts of interest all over the place—if you're prepared to look hard enough. It could be as simple as the conflict between retaining good employees and turning a profit. Conflicts are everywhere.
The question is whether the conflict is causing the company to make decisions which you think are bad—and whether you can convince others to agree with you that they're bad.
The remainder of your post is an equivocation fallacy between the ability to deeply track individual people and the ability to run advertisements at all. You don't need deep tracking in order for advertising to work well. (...unless perhaps you're relying on a fully automated algorithm to do all the work...)
Obviously having a spyware company like google control the web is a bad thing, but that doesn't make mozilla good, they've been poor stewards for a long time and we should be looking toward others, the pale moon fork to name one example.
This change from Firefox does seem well intentioned.
The criticisms like "why isn't this the default", "why didn't you do this when you had patches years ago", "why did you play along with standardization of these mechanisms in the first place", and "what about all these other things you're doing" might reflect a knowledge of technology and history. And frustration, since, now, with Firefox's diminished market share, and having already given up privacy&security ground, Mozilla probably has to tiptoe.
A possible alternative to tiptoeing... With Google handing Mozilla a huge freebie right now, with the anti-adblocking move, there might be a new opening for Mozilla to "go rogue", from the perspective of many dotcom abusers, reclaim some lost ground, and start actually making the abusers angry. For that to work, Mozilla needs users who, when an abusing site says "Firefox broke this; switch to Chrome", will yell at the abusing site, and leave the site. They'll also need to live up to the expectations of those dedicated users, not do data-grabbing/leaking dotcom behavior themselves, which will require some internal rethinking. If they piss off some funding sources, they'll need to find some minimal level of funding, to pay for the jobs that simply can't be done by volunteers, and for expenses for things actually essential to the core mission. (And to get all their hardware&connectivity infrastructure donated by companies that would like the goodwill, and who will sign legal commitments to not use incidental data, with severe penalty clauses.)
It could be interesting to have a drop-down in the browser to select a "who I want to be today" profile and be able to see the world from that perspective.
I would happily use another IM, but the bad thing about network effect is that one would need to convince everyone else to make the switch, too.
In order to take over, freedom-respecting services need to become _better_ than the non free ones not only on a technical level, but on a UX one, too.
I'd like to see Firefox premium services (like a dropbox clone etc.) to provide independent revenue, so they can be aggressive for privacy.
They claimed that there was no breach, but yet all of their database is being sold on the darkweb.
Is it so easy to gather their database and publish it?
Given all that, features like this will not make their way to Chrome.
>Users who receive a version of Firefox with Cliqz will have their browsing activity sent to Cliqz servers, including the URLs of pages they visit.
https://blog.mozilla.org/press-uk/2017/10/06/testing-cliqz-i...
> Less than one percent of users in Germany installing Firefox from our main download page will receive a version of Firefox with Cliqz recommendations enabled out of the box.
> Cliqz does not build browsing profiles for individual users and discards the user’s IP address once the data is collected.
> One of Mozilla’s core privacy principles is No Surprises: we will use and share data in ways that are transparent and benefit our users. That is why we are telling you about this today. We
> We hope that users will appreciate the improved experience, but if users want to turn it off, they can always disable data collection or remove the Cliqz add-on entirely.
I switched years ago because of performance reasons. Whenever I tried to switch back I felt stabbed in the back shortly thereafter by Mozilla.
So - with Chrome I know what I am getting and I treat it as such. With FF I only wanted a Browser. I never aigned up for their (internal and external) advertising, Pocket stuff and other st like this.
So no - because FF brands itself as a privacy option, I hold them to a different and much higher standard - and the fail every time.
> "PSA: Huber Burda Media, the majority owner of Cliqz, which owns many media and digital brands, owns the computer magazine "Chip", its online platform offers "secure installers" which are used to distribute malware (adware)."
and
> "One interesting thing I've found on the Cliqz about page, is that they call themselves a "small startup". This is a lie since they're a sub division of Burda Media which is one of the biggest media companies in Europe. How can you trust a company if they even lie on their about page?"
and the Booking.com snippet https://www.reddit.com/r/firefox/comments/abfdym/mozilla_on_...
> "I skimmed the source code of the Cliqz extension back during the scandal and as far as I could tell it sent back enough information for it to be possible to identify and create profiles for quite many of the users. Now it is perfectly possible that Cliqz were honest and handled the sensitive data carefully (e.g. by throwing away IPs), but we have no way of knowing that."
Remember 2006 when AOL search data was deliberately anonymized and made public, and then de-anonymized? https://en.wikipedia.org/wiki/AOL_search_data_leak
Even if Cliqz do "throw away IPs" that's not enough for it to no longer be personally identifying. It says nothing about Cliqz throwing away the data. How long before Cliqz realizes they're sitting on a trove of "valuable" data and changes their policy so they do retrospectively build profiles of users, or sell out to Facebook?
That's not responsible stewardship of data, and disclosing it on a blog page nobody read, just saying "it might happen to you, quietly and opt-out" is not responsible disclosure.
Excerpt: To gain your trust we have open-sourced all of our front-end code (and hence everything that sends something from your computer). We know very few people will ever look into the code, but: you or everyone else could every time check that we’re honest. And hence we cannot hide anything.
Excerpt: History and bookmarks are always processed only locally and never sent to us
Excerpt No IP addresses collected
I could go on.
My problem is that every time I wanted to return to ff, Mozilla f...ed Up again.
I feel like I am between a rock and a hard place with ff and Chrome.
I take the known evil every time.
Of course they do. That's literally their business model, to use that data to serve more relevant ads. If they gave it to third parties then they would lose their biggest competitive advantage.
And really, they couldn't be any more clear about it: https://safety.google/privacy/ads-and-data/
>We do not sell your personal information to anyone.
If you're going to suggest they are lying about it, then please provide some evidence to support that argument.
That's a technically true and practically meaningless statement. No lying required.
Google's business model relies on giving advertisers a way to target you based on that data and to track you to other activities down the line. Advertisers might never see the data itself, but all that means is Google is selling the product that lets advertisers do the things they were going to do if they actually did have the data, just without being able to see your specific info.
Whether you consider that equivalent to selling your data is a separate question. You'll find a lot of disagreement here about it.
I can't remember previously seeing an argument that this is equivalent. Sharing one quality (in this case the ability to target users on Google's platform based on data Google has collected) does not make two things equivalent. Data passing between hands is obviously different than one entity providing an interface for another entity to utilise data without having it themselves, as in the former case you are now trusting both entities to safely store it which increases the chance of public disclosure (or private exposure that results in negative personal effects such as embarrassment and/or blackmail).
HurpaDurpaEdit: s/latter/former
Esp. from a company that tries to brainwash me with this "we care for your privacy" shit. While still using my data.
If they cared for my privacy, they would provide a browser that does not tell FF/Mozilla anything about me other then that I did download it via their original dl-link.
All else the talk about respecting my privacy, my data and stuff like this is nothing more. Just talk. And I do not like being bullshitted.
And that is the difference to Chrome: I know - because Google tells me - My data is being used. I know what I am in for. This is honesty - even if the end result is that I am the product. At least I am it knowingly.
https://www.fastcompany.com/90273549/fbi-and-google-take-dow...