Can Chrome Sync or Firefox Sync be trusted with sensitive data? (2018)
palant.info
palant.info
> Since the Mozilla-hosted sync servers will not trust assertions issued by third-party accounts servers, you will also need to run your own sync-1.5 server.
The tutorial refers to the old unmaintained version: https://github.com/mozilla-services/syncserver, see https://github.com/mozilla-services/syncserver/commit/8d9804...
The alternative is https://github.com/mozilla-services/syncstorage-rs which is ridiculously hard to set up.
> https://github.com/mozilla-services/syncserver/pull/294
> So basically they stopped running the older version themselves but don't consider the newer version production-ready yet. What a mess.
This doesn't seem to have improved much since...
Some of my experience self-hosting the whole stack previously:
https://news.ycombinator.com/item?id=30315816
https://github.com/mozilla-services/syncstorage-rs/issues/49...
This is the issue to watch, supporting SQLite. This makes it feasible to run a simple sync server for a single user or a small group. But this is not moving forward.
Floccus for bookmarks (https://floccus.org/) : it works also on mobile devices : a great plus ! You need only a webdav server (or a Nextcloud account), I use Dave (https://github.com/micromata/dave)
Vaultwarden for the passwords (https://github.com/dani-garcia/vaultwarden)
A huge advantage of this solution is that you can have synchronization also between different browsers and on mobile devices.
I'm sympathetic to wanting to limit data access to things. But this data seems to already be available to the browser? Having a separate process to manage that seems somewhat natural?
Every ad blocker gets full and complete access to all your data. It needs that kind of access in order to … tada … remove ads. It’s really simple: ads are on all websites, so an ad blocker needs access to all websites.
You probably mean that Adblock Plus abuses this access? Surely this is something you have proof for? Here you can see an example of how this kind of thing looks like: https://palant.info/2023/06/05/introducing-pcvark-and-their-.... You can look around in my blog, there is more.
It has been a while since I’ve been involved with Adblock Plus. I sincerely doubt however that ABP’s privacy stance changed that much since I’ve left. But I’ll wait for you to find proof for your claims.
Except uBlock Origin Lite¹ which is permission-less.
¹) https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...
Yes, they fixed this particular issue (and a few more), the article mentions it. But the update I published today explains why Chrome Sync is still very bad privacy-wise (as opposed to outright horrible which it was back in 2018). https://palant.info/2023/08/29/chrome-sync-privacy-is-still-...
Google moderates Google Collections items - https://news.ycombinator.com/item?id=37301600 - Aug 2023 (38 comments)
https://strangeobject.space/@silvermoon82/110969122337810598
That's where collections live, and apparently they can be shared.
Not to defend google, for sure. I just wanted to stop the spread of incorrect information.
EDIT: I like many others didn't know about this feature and had no idea what was saved there or how it got there.
The terminology might have been inaccurate but in spirit, it's the same. It's a disgrace.
https://palant.info/2023/08/29/chrome-sync-privacy-is-still-...
https://bugs.chromium.org/p/chromium/issues/detail?id=820976
They fixed this particular issue (and a few more), the article mentions it. But the update I published today explains why Chrome Sync is still very bad privacy-wise (as opposed to outright horrible which it was back in 2018). https://palant.info/2023/08/29/chrome-sync-privacy-is-still-...
No. You could make a case for E2E encrypted data where the storage provider does not have keys. That's pretty rare though. The point is, nobody gives a flip about your privacy. As soon as men with guns come asking for your data, any data business will hand it over without hesitation. Men with badges are only very slightly less threatening than men with guns, as everybody knows who the men with guns work for. So if you think anybody or any business is going to die on the hill of protecting your donkey porn collection, you're delusional.
Firefox Sync encrypts all data on the client side before sending it. Chrome Sync can do the same if you know which settings to use. 1Password, Bitwarden, Dashlane – every password manager worth their salt encrypts data locally (LastPass is the only one which failed really badly here). How is this rare and not something we should expect?