Dear Facebook: Stop cross site tracking by default
foundation.mozilla.org
foundation.mozilla.org
One of the most unavoidable tracking services is reCAPTCHA, and the latest version works best when it is embedded in every page of a site. reCAPTCHA v3 collects sensitive personal data, such as mouse movements (which may reveal health issues), it maps how you interact with content, and your browsing history can be reconstructed from the pages you visit. Think of it as Google Analytics, but one from which you cannot opt out, because that means you're denied service on the respective site.
Given reCAPTCHA's popularity, this is effectively an inescapable data harvesting operation, since it uses Google's company-wide privacy policy, which gives them the right to use your data for ad personalization.
The turning point for Mozilla would be to call this out, and stand up against personal data collection for which consent cannot be freely given.
At the same time Facebook doesn't really give a fuck what Mozilla, you, or the EU, have to say. Maybe Mozilla is attempting to raise awareness with this petition, instead of getting Facebook to stop.
edit: grammar
[0]: https://mobile.twitter.com/jonathansampson/status/1165858896...
Edit: I changed my mind. Why is this page infected with google analytics?
Mozilla seems to be one of the least un-trustworthy tech companies, at least in my opinion I'm honestly surprising to me that someone who's been in this scene so much longer than myself would ask this question about Mozilla.
Why not address this to webmasters?
Alternative: log on in Chrome, surf with Firefox or the other way around.
On the CII best practices badge site, we implement responsible links. As explained in our security assurance case, "We do have links to social media sites (e.g., from the home page), but we do this in a privacy-respecting manner. It would be easy to use techniques like embedding images from external (third party) social media sites, but we intentionally do not do that, because that would expose to an external unrelated site what our users are doing without their knowledge. We instead use the approach described in "Responsible Social Share Links" by Jonathan Suh (March 26, 2015), specifically using share URLs. In this approach, if a user does not press the link, the social media site never receives any information. Instead, a social media site only receives information when the user takes a direct action to request it (e.g., a click), and that site only receives information from the specific user who requested it."
Source: https://github.com/coreinfrastructure/best-practices-badge/b...
Suh's page: https://jonsuh.com/blog/social-share-links/#use-share-urls
I don't mind people sharing information on Facebook, as long as they choose to do so. If they chose to do it, that's fantastic. What bothers me is Facebook being able to track people without their consent.
There's also the advertising trackers that track every aspect of your website's users. These are usually added as is and for a variety of reasons - measure conversion, tag a user as converted to not show them ads anymore, retargeting...etc. Good luck convincing your marketing team to not add any of these trackers.