Loved that part.
Loved that part.
It demonstrates that support for Google Analytics is not unanimous within Mozilla, and even if someone removes it from a product page that action is detected by others and reversed.
Privacy aware users should block this sort of thing at their router using a hosts file, or Pi-hole, which is far more effective than calling companies out on Twitter and hoping for the best.
Privacy aware users should take all resonable steps to protect their on privacy, but it is also appropriate to call out Mozilla.
Mozilla (and advocates) promote Firefox as the privacy conscious browser while Mozilla repeatedly takes actions that would appear to go against that claim.
> In this new era of looking for premium service opportunities I suspect there will be value in having metrics of some kind.
Mozilla is either stupid or ill-intentioned. It's 2019 so they've lost the benefit of the doubt for me.
Part of their (written) agreement with Google is that none of the analytics data generated from Mozilla properties will contribute towards Google's tracking database.
"Mozilla has a legal contract with Google that prevents them from using our Google Analytics data for mining or from sharing it with third parties, among other privacy-protecting provisions."
"Mozilla went through a year long legal discussion with GA before we would ever implement it on our websites. GA had to provide how and what they stored and we would only sign a contract with them if they allowed Mozilla to opt-out of Google using the data for mining and 3rd parties." https://bugzilla.mozilla.org/show_bug.cgi?id=697436#c14
Privacy isn't a zero sum game, there can be improvements.
I'm not sure that would still be the case if the decision were being made today, and would quietly hope not, but I guess we can charitably say that the reason now is "inertia".
Personally, I think they may have underestimated (or failed to fully predict) the anti-google, pro-privacy sentiment in the wings, and it's clear even from this thread and the issues on bugzilla that it's probably cost them enough privacy-capital at this stage to have justified the extra work required to self-host.
But hindsight is 20-20. There are sunk costs now which also must play into the decisions.
The same argument applies to the whole of Firefox. It's more work and it's a lesser product. If Firefox can be a better product, than Mozilla Analytics could be too.
At this point it's clear that Mozilla is a business (with well paid management and staff) like Google that is using Privacy as a promo like Google used Don't Be Evil. Mozilla might be better in practice today, but it's not on a principled foundation. It looks like a Google Lite - Firefox vs Chrome, Rust vs Go, etc.
Or maybe the "anti-google, pro-privacy sentiment" isn't really all that big. Could be a relatively small but vocal set of people.
There is Matomo (formerly Piwik): https://matomo.org/
This is disingenuous. They basically locked themselves out of China voluntarily many years ago. They're really scary otherwise and I agree with you, but don't lessen your point by including exaggerations, in my opinion.
"Mozilla went through a year long legal discussion with GA."
I wonder why. Implementing some basic analytics on a few pages shouldn't be that hard.
Plus, the amount of data that they get from Mozilla must be tiny compared to the amount of data that they collect through their search engine: it's only data on mozilla.org, not data of everyone that uses the browser at all times. It is not wise to risk a lawsuit over it.
> I wonder why. Implementing some basic analytics on a few pages shouldn't be that hard.
Maybe defining a contract to prevent use of Mozilla data without loopholes is harder.
There's surely no way to tell what they do with the data at the other end? It's Google and their serf, Mozilla, I can't imagine it's wholesome.
Do you have you any basis for this assertion?
I believe this to be a lazy and ignorant opinion, and I think you are hoping no one will call you out for this.
"Google has proved time and time against they cannot be trusted with privacy". This is a contract between two businesses, which carries legal weight (and in some countries, carries more legal weight than just contract law), so could you source for me perhaps 2-3 (you said "time and time again", so 2-3 should be quite easy!) of your most iconic times that Google openly violated contract terms with major organizations regarding privacy controls?
At least in the US they weren't breaking any laws. I'm not saying they would never break any laws for financial gain, just that most of the breaches in privacy aren't technically illegal (thus the need for privacy laws)
Broke the law.
If Google has a culture of "grab all the data, and use it in whatever way you can figure out to make money,"—and they do—then the real question is if they even have the institutional capability to not accidentally use this data the same way they use all the other data they have.
I don't want to be a broken record of "this opinion sounds lazy and under-researched and I'm calling you out" but.....
* Google was cleared of wrongdoing under the Wire Tap Act after an investigation by federal law enforcement
* The wifi data capture was a 20% time engineer project which rolled out unintentionally, was never commingled with other data, and was destroyed without being used
* The DoJ and Federal Court of Appeals disagree on the details and the Supreme Court of the United States refused a petition to clarify any parts, so any assertion that they "Broke the law" is either ignorant or malicious, IMO, because to summarize a situation where law enforcement said "No law breaking " and an Appeals court said "Maybe law breaking" as "Law Breaking" can't be considered a rational and intellectual attempt at understanding
Some of the procedures were put in place after the wifi scanning incident.
And that's not to say bad things can't still happen. One thing that sounded particularly bad about the now-cancelled Dragonfly project was that they were allegedly avoiding privacy review. This project was being kept secret from the rest of the company because it's not how things are usually done.
So, my guess as an ex-Googler is that they can guard it and probably will, at least under normal conditions.
It’s like the Snowden revelations didn’t happen. I am pretty sure US intelligence agencies have access to your Firefox GA analytics.
This misrepresents the ability of a contract.
No law can prevent a thing, no written agreement can prevent cheating. Law can only set out that such cheating might be illegal in the sense that it can be argued in court that penalties should apply.
We can be a little more charitable in not demanding legalese from someone who was casually paraphrasing somebody else, given the context (a bug report).
Mozilla make open source, they're not open like a publicly accountable body, are they?
Open companies was probably a bad term to use because it might imply something beyond most/all(?) of their products being developed in the open, but I think the point stands well enough regardless.
I won't edit now, but please read my original "open" as "open source".
This is asinine stuff. Contract law is one of the oldest parts of the legal system and contracts are protected. Violating contract terms leads to a discussion of damages. It's not about illegal contracts, it's about liability and damages.
If you trust Google to always uphold its contract, than by the same logic you should trust the government to never abuse your encryption keys. But we don't, because insider access is (eventually) outsider access. Bits don't have color.
This is like saying criminal law doesn't prevent crime, which again under some literalist and pointless definition sure a murderer isn't physically prevented from murder by a law, but the punishment of murderers does prevent many people from becoming murderers.
Similarly, contract law influences the behavior of people who agree to them by establishing damages and liabilities for various situations, and these incentives influence and control normal actors in predictable ways. A summary of the influences and controls on normal actors in contract negotiation could be "contracts prevent things".
My contract with my ISP prevents me from reselling my bandwidth to my neighbors. It doesn't physically prevent me, but it establishes a liability for me that I want to avoid.
My contract with my car insurance company prevents me from working for Uber. It doesn't physically prevent me from clicking Sign Up in the Uber app, but it establishes limits on my coverage such that I would be driving illegally if I were to continue, and I want to avoid that, so the contract prevents me from doing it.
Let's not be naive. The Big Brother agenda of Google didn't happen in a vacuum. They have government support and protection from some factions of our intelligence agencies to this day (although, perhaps not for much longer). The whole original concept of "Google" as a search engine (and tracking app) was originally a program of DARPA (same for Facebook - originally called "LifeLog"). Do you really think they cut all ties with the government when they went public? Neither Google or Facebook are what they appear to be.
"Privacy" in the sense that it pertains to selling your info to advertisers is just a sideshow; i.e. not the real problem.
No, being found in a court of law to have done so does, but when the contract terms are easy to violate without the other party being aware it is especially inaccurate to portray this as the violation itself leading to this result.
My bank argues the same way and uses Google Analytics to track their visitors, including inside the online banking system. Fine, so they trust Google to honor agreements and not connect profiles, but I'd still prefer Google to simply not know when and how often I'm logging in to check my account balance.
It's good that Mozilla goes the extra mile to get a custom contract, but I believe that most people aren't expecting a self-proclaimed privacy champion to use an anti-privacy-service by one of the largest corporate enemies of privacy. Explicit opt-in would be the right thing to do here.
Do they really think people are that naive?
If Google is not going enough, Mozilla shouldn't use Google for analytics on the add-ons page when there are plenty of other options and an opportunity to do something valuable by building a site-private analytics product as part of their core mission of protecting the web.