Latest Firefox Brings Privacy Protections Front and Center
blog.mozilla.org
blog.mozilla.org
In the past month about 3 of my credit card sites stopped working on FFF, as well as my ISP's site. Some would flat out reject the agent ("Your browser is no longer supported"), others would let me log in but then immediately tell me I had been logged out or redirect back to the home page. So now I'm forced to open them back up in regular Firefox, history and tracking included.
It's one thing to say "Don't use sites that exploit your data", but it's not like the average person really has a choice when it comes to paying utility bills.
They shouldn't need it, but from their point of view why on earth wouldn't they sell their customers out at every opportunity if it means more money for them? Companies are amoral monsters who care about nothing but making money. If a company can do something that will make them more money you should expect them do it regardless of how ethical or legal it is.
But you should still use all of the anti-surveillance tech you can, lest the downward spiral continue. The methods are implemented gradually, with soft heuristics. The more customers they have without such vulnerabilities, the harder it is to justify turning the screws.
“Hiding within those mounds of data is knowledge that could change the life of a patient, or change the world.” (Atul Butte, Stanford)
"Information is the oil of the 21st century, and analytics is the combustion engine” (Peter Sondergaard, Senior Vice President, Gartner)
“Without big data analytics, companies are blind and deaf, wandering out onto the web like deer on a freeway.” (Geoffrey Moore, author and consultant)
.
.
.
And the quotes go on and on...
Which sites are these? When you make claims like this, you should specifically name the businesses that do this, so the rest of us can try to avoid them.
I actually pay through my online banking now but I'm forced to receive paper bills unless I agreed to some insanely-long new T&C.
The online banking I use (some local credit union) uses a 3rd-party site so in order to use it I must accept 3rd party cookies on this site. But you don't whitelist <the bank site> you have to find and whitelist <the 3rd party site> which requires some knowledge/skill in this area. I don't know how any "normal" user will be able to use Firefox after these updates; if you can't log in to your bank you're just going to go back to Chrome, right?
With that said, let's say I specifically name "Chase". Are you going to cancel your existing Chase bank account or credit card upon hearing this?
Well put it this way: if you specifically name "Chase", I'm going to think twice about applying for a credit card there or opening a bank account there. It's harder when you're already invested in a business, but when someone is shopping for a new one, when they hear credible information that shows that business to be a bad actor or that it will provide them a bad experience, it's pretty easy to cause many of them to choose something else.
BTW, I would never advise anyone to get a Chase bank account; they're pretty well-known to be horrible. You can get far better service and interest rates from a good online bank like Ally, Schwab, Discover, etc.
Again, it was a placeholder name. But I'll be honest for the sake of those curious and just say "the credit card that's offered through Costco" :)
And that is one of the reasons why we are allowed to have multiple accounts on this site, as long as they aren't all throwaways.
I bet you are aware of this already, so I'm mentioning this mostly for the benefit of those who haven't wasted half a decade (or more in my case here.)
That's fine by me. It's an up-front indication that I don't want to use that service. In the case of bill pay, I would just change my user agent string.
He also mentioned "others would let me log in but then immediately tell me I had been logged out". If they implement logging in with some tracking cookies, then changing your agent won't help.
You can always use a dedicated browser for that and only that. Brave, Opera, Vivaldi, IE, Chrome, whatever. At least there's enough browsers around to have each dedicated for certain purpose.
https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
With the usual provisos, of course:
It's a shame the designers of this feature didn't think of the abuse potential.
Blocking trackers makes Google suspicious, so they're adding more and more recaptcha challenges to let me pass their tests, sometimes 5 to 10 in a row. I'm now working for Google's IA for free just to be able to make purchases online, access some services that I already paid for, or filling in support request forms (sometimes it's for websites operated by local communities and funded by tax payers).
I have absolutely no control over what Google does with all my recaptcha inputs, it could be to build a fleet of autonomous cars (that could end up killing the public transportation in my city), or improving an algorithms that helps drones identify targets during a social unrest (could be a future me).
Just because I want my privacy rights to be respected to the minimum (just don't track me for political/advertising purposes), I have to spend several minutes of my day working for Google and help them make money on advertising and sell AI to governments.
How dystopian.
Don't forget that public transportation can also be self driving and it will be cheaper than riding in a self driving car. So I don't expect public transportation killed, I expect self driving buses.
The recommended way of integrating reCAPTCHA v3 is to load it on every page of your site, not just on pages with forms. Given the popularity of this service, reCAPTCHA v3 is set to become a browsing history and behavioral data collector on a global scale.
Sites have brought this sort of thing on themselves by enabling (or directly engaging in) the abuse of users. That abuse forces me to take a very defensive posture when browsing the web. It's simply a matter of self defense.
If that means that I can't access the sites, whether it's because of recaptcha or other issues, then I won't access the sites. Easy.
I use the same mechanism - but with persisting user data - for things like banking etc. in which I only open that one site.
Whenever I see a link to a website I suspect of siphoning off all my data (usually news websites), I right-click it and select "Open in new Trash Container". Do my thing, then close the tab, and all cookies and such for that site are cleared. It's almost like a Firefox Focus tab, the main difference being that it's not discernable from a regular tab.
When you open a link that opens in a new container, you loose the history that brought you to that link. Clicking a link actually opens a new tab and simultaneously closes your current one. Going backwards is now broken and you have to shift cmd t to go through all your recently closed tabs or dig through your history if you are a user who regularly uses back on a browser.
I also ran into a bug where infinite temporary containers would open until the browser finally crashed. The fix was removing the add on.
Great idea, sloppy implementation.
I don't have that enabled, even ctrl-clicking something opens in the same container for me. Not perfect in terms of privacy paranoia (my HN container gets cookies from sites I go from HN to, unless I take the effort to explicitly open in a different container) but it has never annoyed me.
But if I still need to allow/use the site, I use containers. Hopefully this gives me some security.
Your utility only takes payments through their website? That's hard to believe. In most places I've lived, the utility companies contract with various local businesses to allow you to pay your bills in person through them, and all have still accepted payments through the mail.
Usually you give them personal info about what you do on their site so that they can monetize you, in return you get news, messaging, etc.
If you're unwilling to give them that stuff, maybe it's OK that they are unwilling to give you their (presumably valuable, because you're requesting it) stuff (articles, videos, etc).
Often when I get "we won't show this to you with an adblocker on", I simply turn it off for that page. I want to read that article and I'm happy to exchange some personal info to get it for free. At least in this context I have the chance to opt-in.
I agree that there are probably a lot of places where anti-content-blocking tools are overused (i.e. services that I have already actually paid $$ for), and probably other situations where I'd like more options ("plz disable adblocker OR pay us $0.05 for this article [obviously need some way to pay that doesn't in turn expose my personal info]")
I rarely see things break anymore.
Doing the right thing should be a much greater desire than minor inconveniences.
Are there other reasons you don't like FFX or prefer other browsers?
Having said that anecdotally I'm sure google do ip/wifi network tracking as after I was connected to a friends wifi network while he was in the process of moving house I began being served ads for moving companies even though I had done no similiar searches or visited related sites.
The recs are poor enough that I don't mind blanket-banning an entire channel from my feed. Youtubers so frequently "compete" by using clickbait titles and thumbnails, I'm glad I at least have this method to punish that kind of behaviour.
If you are subscribed to enough good channels, you won't notice anything aside of suddenly having much more free time. And whenever you're bored, unlock recommendations for a while to learn about new channels (I do it once every few months).
[0] https://github.com/TeamNewPipe/NewPipe
[1] https://vanced.app/ , beware of scam sites
[2] https://apps.apple.com/us/app/ivory-video-player/id129434748...
[3] https://www.youtube.com/feed/history (on old YT layout)
This has never worked for me. I've tested this while signed in without blocking anything - "not interested in this channel" has never once caused a channel to not be recommended to me.
The same thing happened to me except I'm a cis woman and my front page was filled with transgender posts/subs. Reddit seemed to conclude that the only reason I could possibly be interested in DevOps is because I'm actually be a man.
For example, the wiki.debian.org blocks users of (at least) privateinternetaccess VPN. (You get a 403 forbidden. This doesn't happen when I use my personal VPN routed out through a VPS provider, only through PIA.)
I have encountered this with various other sites as well, both outright blocks and degraded experience.
Frustrating. Although I don't really trust VPN providers, I trust my ISP even less, and a VPN helps me get by some of their more heavy handed shaping.
I also gets recommendation for videos that my SO watches even though we don't use the same computer. It's rare but it happens.
> Even if you opt out of Ads Personalization, you may still see ads based on factors such as your general location derived from your IP address, your browser type, and your search terms.
Could just be "We don't know anything about you but these things are generally liked"
Besides that, I have block the whole recommandation landing page that Youtube gives you with uBlock, since it was huge distraction for me
If Firefox becomes the bastion of privacy sensitive people it will become more and more like Tor users, all tainted with the same labels. I mean it's already the case that recaptcha will more likely trigger on Firefox than Chrome, asking for multiple rounds of checks. Like visitors existing Tor exit nodes, in a bit less worse.
It's not, the Internet is the only medium where it's assumed that tracking/targeting is necessary for advertising. TV, Magazines, radio, podcasts, cinema don't track users.
When I download a few different podcasts, I get an mp3 with targeted ads inserted in it, and they're presumably connecting IP geolocation info.
But if something like this happens, I will be happy to build/use an extension for the other browsers that makes such websites invisible in all major social networks.
He never said anything about blocking, here his exact quote about the retaliation:
> Why spend money optimizing for a browser that doesn't generate revenue?
Nobody ever optimized for a browser that had the Google toolbar installed. It's hard to stop doing something you never did.
As the other parent comment said, it will happens naturally by the mere fact that theses users won't appears on statistics. For sure it will depends on the developers, and many of them will either use Firefox directly, or simply care enough about their craft to optimize for most of the browsers even though they don't appear on stats.
Maybe sites will move to a model that you'll be offered to pay for their services if you block trackers. So you'll have a choice of paying with your data or paying with your money.
Either way someone has to foot the bill at the end. I guess in this case most users will let trackers work instead of paying.
Perhaps if we consider information on the internet to be vital to daily life, a program like food stamps could be implemented? It sounds rather over engineered but it's the only idea I've ever heard for working around the "privacy is only for the wealthy" concern.
A browser dedicated to websites that exists for reasons other than serving ads? Sign me up!
Google Analytics isn't the only analytics tool and as blockers have become more prevalent relying on GA as your sole source of truth is becoming increasingly desperate to worship Google. Ideally you run a simple analytics tool alongside that is lightweight and doesn't get blocked (ie, privacy friendly) as well as running a log analyzer on your apache/webserver logs.
They don't provide a lot of demographic information (even browser used, afaik) but provide sufficient information for my purpose.
edit: I should mention that this a paid feature ($9 a month).
edit2: I do notice a higher number of traffic when compared to some free analytics which work on the client side, and respect Do Not Track.
Apparently not, as one other comment on this site lists one of the apparent benefits of using cloudflare as that they provide "the exact numbers on how many people requested or visited my site"
I think we need to nail down what we mean by unique visitors -- we're talking about an estimation which pools from many different sources to calculate as best we can the number of different real human visitors. There is good data in the server logs but if that's your only source of data then your estimation is going to be coarse.
This can be good enough for certain applications, and is plenty for sites with simple access models but you do lose information compared to what you get from client-side tracking.
Nope. It blew my mind as well. I used to work for a company that spent about 70 million per quarter on advertising and they most certainly wanted every .. last .. access log .. line. They would scrutinize the way I did log rotation to ensure nothing was lost.
At my current gig, the web marketing team didn't even know what access logs were. I don't think they left out a single tracker on the site.
The only self-hosted one I can find that has a funnel feature is Matomo.
Log parsing is an option. There are self hosted options. There are also services like https://simpleanalytics.com/ (I have not used them or know much about them tbh).
Personally, on my recent projects I start without analytics. If I want to measure health or growth, I define my own "metrics" and use sql or logs to generate. I don't need to know what country you are in. I don't need to know what browser you are using. If I do need to know something, I can look at useragents. If it truly is for user benefit and not just my curiosity, I can actually ask my users with a survey.
And if you obfuscate your Matomo client script to get around the user's preference for trackers you're not being very ethical.
I'm not sure I agree, but you made interesting point and I'm glad you brought it up!
Personally, I don't think I would classify that as unethical. Ethics need to be looked at with intent in mind, and if you are comfortable being honest about what you are doing, I _think_ I would be okay with this. Not sure, though–I do have doubt.
Theoretically you could use the same way to feed third-party analytics too though.
Even without cookies and without JS you can still get some data for analytics.
A fair share of that is probably because GA is much better at identifying the same user across multiple browsers / devices. If they identify two browsers as the same person on site A, they can know they're the same person on site B, even if site B on its own doesn't have enough to figure it out (so piwik can't know it).
When I see a tracker hit ublock origin does it mean that it bypassed firefox anti-tracker blocking, or is it the reverse?
Having three anti-trackers installed is also a bit inconvenient when this breaks a site, I have to disable each one successively to try to make it work again...
https://github.com/mozilla/addons-frontend/issues/2785#issue...
When Microsoft is more honest and upfront about user privacy then you are, then you have a problem.
Numbered on Chrome, you mean.
It is not pure evil, there are security reasons behind that. Manifest V3 is also a security improvement so I wouldn't put it passed Mozilla to implement it.
[1]: https://blog.mozilla.org/addons/2019/09/03/mozillas-manifest...
I use Chrome mostly to edit the GSites or present GSlides in full screen (in FF it still shows the window chrome in fullscreen).
I use this because I value my privacy, but choose not to use uBlock Origin because I understand websites I use need revenue. It is about finding your own personal balance.
I've never had a problem with a website that was solved by turning off Easylist. I also almost never see ads. So it seems high quality to me. What problems have you had?
[Edit: previous general discussion about EasyList https://news.ycombinator.com/item?id=20593563 ]
user_pref("extensions.pocket.enabled", false);edit: originally referred to blog.mozilla.com
- received venture capital from Peter Thiel (Chairman of Palantir)
- BAT tokens aren't backed by any real value
- https://jlelse.blog/posts/ditch-chrome/
More reasons: https://twitter.com/corbindavenport/status/11341432093896663...
Feel free to check it out - https://old.reddit.com/r/firefox/comments/dligci/a_goto_thre...
Devtools
Every benchmark: https://arewefastyet.com/linux64/overview?numDays=365
Anecdotally, Firefox uses a lot more CPU, memory, and battery. Makes sense since the JS engine is so much worse. In this era the browser is just a VM for JavaScript.
Those users don't typically show up in whatever javascript-based metrics you're looking at. I don't think you'd care, either. You're literally building an echo chamber and then yelling into it that it's the best echo chamber.
Chrome is neither the "best" nor the "worst" javascript VM, nor is Firefox. Chrome is simply the most prolific. And that has nothing to do with Chrome's javascript implementation and everything to do with Google pushing hard for users and developers to switch to Chrome by putting it in front of their faces as much and often as possible. Everything from default-homepage being defaulted to Google.com, to that home page then asking users to switch to Chrome, and even "open sourcing" the engine and pushing for games and "competitors" to utilize it.
I have yet to find Firefox use more CPU, memory, or battery than Chrome. Of course I don't go around with Javascript turned on with every website either.
Given that so many websites utilize Google-based services it makes me wonder just how much of the "more CPU, more memory, and more battery" is also just "more of the same underhanded tactics from Google". Google already demonstrably does that for other products; why leave out third parties' websites from the shenanigans?