Mozilla gets a lot of flak (especially around here!) for their sometimes heavy-handed usage analytics, but it's nice to see that used for its stated purpose! Great use of data here.
Mozilla gets a lot of flak (especially around here!) for their sometimes heavy-handed usage analytics, but it's nice to see that used for its stated purpose! Great use of data here.
Edit: I'm not saying that Lynx should be a daily driver or that it's more secure, but it's a neat little project that avoids some of the bad patterns in modern browsers.
100% true, definitely
There's also a ton of promoted garbage on your homepage and privacy switches that need to be toggled off by default. Those settings don't carry-over when you sync your account settings.
I still prefer Firefox, but they are not immune to the encroaching enshittification.
https://en.wikipedia.org/wiki/Autofac
on the other hand Microsoft and Facebook are doing this all the time.
But I hold the others to zero standard. There is less than zero trust there. I expect to be abused by them because their mandate requires them to ignore my wishes. It's not a failure but a success to them.
Most US hospitals are non-profits but you still see people complaining about them.
Pseudonymous user so concerned about privacy that they use the browser with by far the greatest density of exploitable flaws.
Lynx definitely takes less telemetry data than Firefox, but it also gets substantially fewer updates, including security updates. I think text-based browsing is pretty fun but I don't really use it in no small part because of the infrequency of updates.
"I love Lynx" is different from "I use Lynx for security-sensitive browsing," and "greatest density of publicly documented exploitable flaws" is, even if true (I don't know), not the same as "greatest density of exploitable flaws."
This advice mainly applies to people using old OSes or who don't update their browsers.
Telemetry doesn't make it possible, it makes it less expensive.
2) Conduct user studies
How are companies that aren't software vendors and aren't able to spy on their customers able to do it? Did software companies not have good ways to do this before spying on their users?
Only listening to data from 1 & 2 results in the sort of angry posts you frequently see on HN complaining that devs aren't listening to "real users" or have the wrong priorities.
You end up needing data from additional sources, telemetry being one of them.
If that's the sort of responses your studies produce, then your studies are seriously flawed.
Significant bugs can affect only 1% or 0.1% of a browser's userbase but at Chrome scale or even Firefox scale that's like a million people. If you don't have telemetry it is REALLY hard to hear from those people about their problems and understand them. There simply are not alternative solutions that work half as well as opt-in (or opt-out) telemetry. People who say web browsers don't need telemetry are simply ignorant of what it's like to ship one and try to keep it working in the face of a constantly shifting environment - broken drivers, broken VPNs, malicious websites, malicious extensions, broken hardware, and users who are confused or tired or simply just bad at using software. No one is speaking on their behalf, you have to dig their suffering out of the data by looking at crash reports and performance metrics.
Shipping a web browser used by a million (or a billion) users means that you have a responsibility to do a good job. If your browser is not well engineered and reliable and responsive to users' needs that can result in data breaches or third-party server outages when your browser misbehaves or incorrectly channels user intent.
I'm personally a fan of making usage telemetry opt-in instead of opt-out, but browsers are a case where I don't opt out because I know how important the data is for browser vendors to make informed decisions.
This is of course different from sending your browsing history to Google, Microsoft, or any other company. I encourage people not to opt in to that stuff and not to sync their history/bookmarks/etc to those companies.
It's probably no accident that spying on users got popular just as this became the case. Constant network traffic while web browsing didn't start to become the norm until late in the '00s, either. If you weren't clicking links, you could often open Wireshark or sniff with Netcat and see nothing. Not from your browser, not from anything. Certainly ~nobody was collecting heatmaps of where you move your mouse, or firing a network request if you selected text. Or recording entire user sessions for playback, or so you can watch them live (god, those tools are creepy as hell)
When the internet was young, and most people were using dial up connections, just collecting the dates and times that a person was online and using a program was (and still is) a massive violation of privacy. Software "phoning home", even just to check for updates (collecting IP addresses, timestamps, and version numbers) was enough to get your software branded as spyware.
No software company needs to know which hours I'm awake, when I'm using my computer, which hours I work, which hours I use their program, how long I use their program, how long it's been since I last used their program, etc. It's intrusive, entirely none of their business, and it's insane that they all feel entitled to that kind of information.
If I print something, don't print something, or what the things I print are is also none of their business. Neither is what I'm printing it for, where I put the printout after I take it from the printer tray, or if I use tape or a thumb tack to secure it in place, but you can bet that if software could easily collect that data it would and somehow it would be considered impossible to write good software without that information.
From a privacy standpoint telemetry is always invasive, which is why I disable it any way that I can. Even without the privacy aspect telemetry is a bad idea. I don't want program updates that remove features just because I (and others) don't use them very often. I don't want updates that constantly shuffle the UI around according to how they think "most" people have been using it this week. I don't want my workflow disrupted every few months because it's uncommon. I don't want the way I choose to use the software on my device to influence how other people are expected to use it either.
Telemetry is much better when it's limited to reporting errors and bugs, but even that should be opt-in only.
Data analysis is difficult to perform and understand well. It is easy to draw mistaken conclusions or to twist results to show the conclusion a person wants, and using detailed numbers can lead to a false sense of confidence in the results.
Companies are first and foremost optimizing for their benefit, not the user. Detailed tracking can uncover interesting ways for a company to make more money at the expense of the user.
I feel like people who are fully against telemetry never had to deal with such issues in big apps
If a team is so unfamiliar with their product and customer base that it cannot take action without telemetry, maybe they're not the right team to make that product. Statistics are not a substitute for domain knowledge.
Whenever I hear that an app is collecting telemetry I feel conflicted between leaving it on for maintainers to gain a better understanding of performance and potential issues, or off so that it's not used to profile me.
It would be nice if telemetry was somehow simply differentiated through some app options.
Example: https://source.chromium.org/chromium/chromium/src/+/main:bas...
I’m mentioning this, because this open-closed ambiguity is a typical Google strategy. Similarly, Android in the AOSP flavor is open, but the OS that actually ships on phones is different.
(Edited, original comment read: "What more information does that give them than just buying a few computers at different price points?")
That doesn't seem very useful for the metrics shown in that article. For hard to find bugs sure, for 95th percentile calculations and so on you can just buy a few computers at a retail store and get the same information.
Once you do have a model of badness I agree it's better to try to set that up yourself.
Preferences > Privacy > Firefox Data Collection and Use. Uncheck a couple boxes.
* Found this: https://github.com/K3V1991/Disable-Firefox-Telemetry-and-Dat... I haven't compared their list to the one I've used before but it's along the same lines and explains the discrepancy between the config settings and Firefox's actual behavior.
https://www.reddit.com/r/firefox/comments/7k3r9u/mozilla_is_...
> Telemetry data is stored locally by default. As long as the relevant options in the settings' UI are unchecked, or datareporting.healthreport.uploadEnabled is set to false in about:config, this data won't be sent. <https://medium.com/georg-fritzsche/data-preference-changes-i...>
There's likely to still be some non-telemetry chatter, like checking for available Firefox/plugin updates etc.
If there is one thing we should have learned over the past decade, it should be that if the data is collected, it will be sent.
I followed the argument and I understand what you are saying. What I am saying is that it was not that long ago that FF decided to disable plugins remotely ( I think we even discussed it on HN[1]). What makes you think they won't one day push an update to just upload that local data?
I'd imagine it's a buffer; presumably someone using Firefox for a decade with telemetry off won't accumulate ten years worth of telemetry pings.
Another example is usage telemetry tells developers what part of the app is being used and can help them focus popular features or on working to let people know about useful but under used portions of the app.
My main complaint about people who dislike telemetry is they never acknowledge its good uses and they never state what telemetry is objectionable.
It’s like you’re arguing about the good things the church does when it’s a discussion on separation of church and state.
But I mean I’m an atheist and I think religion is, on net, bad. But we’ve allowed a sort of less dangerous version of it to persist in most advanced countries, in the form of separation of church and state. If it was really just all bad, I suppose we’d ban it altogether.
I think people can generally see that there are some pros to things they don’t like. Not engaging with the aspects of something that are inconvenient to your case puts you in the realm of propaganda and rhetoric, not good faith discussion.
There's a good reason for that: it is an asymmetric relationship.
The person who enabled telemetry isn't necessarily the user of the software. Ie. it can be mandated or put on by a sysadmin (even by mistake), without user's say. On top of that, the user of the software and/or sysadmin are unable to assess whether they want to share the data because they cannot analyze the data beforehand. They lack the expertise in doing so.
Meanwhile I have to disable telemetry every friggin' time I use Mozilla Firefox. It gets old, having to say 'no' all the time, ya know? I now realize how it feels being a young woman on the market. Geez, I feel sorry for my daughter. The shit she'll have to endure, sayin' 'no' all the time.
Probably because there's little disagreement about the existence of the benefits of it or what they are. That's not the issue.
For me, the issue (as with all things like this) is about consent. Opt-in telemetry? I have no issue with it. Opt-out telemetry? Very sketchy, but at least you can opt out. Undisclosed or mandatory telemetry? Completely unacceptable.
You can get directly there by copying into the url bar
about:preferences#privacy