Web Browser Telemetry
sizeof.cat
sizeof.cat
There is no technical reason that a browser (or any software) couldn't open a single connection, and funnel every piece of data it can extract from your machine to a remote host. That remote host could then distribute that data to any number of other hosts/services without your awareness.
For the purposes of privacy, all connections numbering more than 0 are functionally identical. At a minimum it might be helpful to include some information on the amount of data transmitted over these connections.
A striking one is that many browsers continue to claim to be privacy respecting, when in reality they are not even though it is easilly verifiable.
You are correct in saying that from the standpoint of privacy there is either zero telemetry or everything else. There are other drawbacks from having many unnecessary 'phone home' requests, like performance in slow connection environments.
And may I add - telemetry on by default is just not decent, browser is supposed to be my ("user") agent, not somebody else's.
1. I don't think an IP is particularly identifiable information for a browser vendor - the information they have is "this device currently associated with this IP uses our browser", which is not significant.
2. Just because the IP is sent doesn't mean it's collected and stored. They may drop it as soon as the data gets to the server - meaning that the IP may have been transferred but it in no way is analyzed to attribute any information to you.
That is entirely respectful of user privacy.
- If it's not opt-in, it's not privacy respecting.
- IP is a significantly identifiable piece of information.
- Regardless, we have seen that as few as 4 pieces of individual data collected about a user is enough to identify someone 90% of the time (https://archive.nytimes.com/bits.blogs.nytimes.com/2015/01/2...)
- Browsers collect far more than 4.
User privacy is no longer something you can tiptoe around - it *has* to be informed and opt-in; i.e. if you slipped into someone's bed at night and had sex with them without consent, was it okay?
You didn't address the major point I had, which is that they can just drop your IP and not store it. Soooooo, anyway, I'm ignoring the rest of your post because I don't care about the debate, I was just trying to explain that telemetry is privacy respecting.
The point is that you don’t know that and you cannot guarantee it. You just assume the best case.
As analogy: is sending your bank password a privacy problem? You argue no, because they could just throw it away immediately, instead of going on a Christmas shopping spree. That's an insane argument to make.
Before it becomes a benchmark, I think it kind of leaks a measure of the amount of things that are being done on the first run, all possibly exposing yourself in various ways.
Not really, because "thing" is a totally arbitrary concept, and can be implemented as "service1.example.com/api/" or "example.com/api/service1". Whether the former or latter gets chosen and with what probability is dependent on organizational factors, so comparing between companies makes little sense.
Even a browser that launches zero connections upon first startup could start doing so after a random delay and/or while you're connecting to a legitimate website. And if you visit any website from any entity that produces the browser, it can smuggle out data without opening any new connections, e.g. Chrome could backchannel data up to the mothership when you access any Google-owned website. And on desktop, who's to say that the installer itself didn't already send up data, or otherwise install a separate binary that will? And on mobile, Google and Apple already have half the world's data, because they own the OS!
So in effect, this benchmark shows nothing at all. It's a web browser, at some point you're going to access the web with it or else you wouldn't have installed it, so demonstrating that it has network connectivity is not particularly interesting.
However if a browser claims to be privacy respecting than it has to be zero telemetry by default, otherwise it isn't. If you do not care about it being privacy-respecting, than sure, why not relay information to browser vendor and/or 3rd parties on startup.
Sometimes a conclusion isn't necessary. Just having that information written down and spelled out is useful in terms of informing people. There are a lot of things we take for granted, and some heinous things that are happening that shouldn't be but are allowed to happen because the consequences don't feel real or tangible enough.
>Include related matches in Find on page
>When enabled, your Find on page search and the webpage contents will be sent to Microsoft to help find better results, including synonyms, alternate spellings, and answers to questions
- Modern Windows versions introducing new telemetry options (to say nothing of existing disabled options being toggled back on...)
- LinkedIn with with new notification types that are turned on by default, with no option to disable all notifications entirely (there are now so many notifications that the notifications settings page has a nested page)
- My former University's newsletters mailing list, which keeps adding new types of newsletter that I am default subscribed to, despite previously unsubscribing from every other newsletter (I finally just created a mail rule to block the entire subdomain.domain.edu).
And the list goes on...
You know your org has too much money and/or power if you don't even bother with domains anymore but just request another custom TLD for your infrastructure hosts.
The correct metric here is “number of requests initiated”, but that’s harder to collect than copy-pasting logs from LittleSnitch and gesturing theatrically at them as this post is doing.
Agreed that this post isn't particularly illuminating, but where is the theatrics?
It's just a list of connections, and the author even refuses to put a conclusion.
This document as presented is only meaningful to two audiences: those who already agree with the author’s viewpoint on connections made by browsers when no user action has occurred, and those who have already formed viewpoints on the concerns around browsers and outbound connections.
This is theatrics. The author clearly has opinions, and has crafted it to be attractive and interesting solely to those who have already formed an opinion on these issues — as is evident from the context that leads to such a post existing at all, much less reaching the HN front page.
A less theatrical post could have stated why counting these connections matters to anyone, and plainly stated the author’s view that browsers with a count of zero are preferable.
Instead, they buried their opinion in a later paragraph, declared it absent when it’s present, and left things vague enough that any supporter of their viewpoint can argue to any detractor of their viewpoint that they never stated an opinion at all. Instead of supporting productive and nuanced conversation, they fan the flames of belief with data structured to promote their view, while attempting (and failing) to claim the neutral high ground.
A useful datapoint for evaluating their viewpoint here would have been, “Are all of the browser’s outbound connections first-party to the browser’s author and/or the site navigated?”. For many mobile browsers embedded in mobile apps, is wholly untrue: they monitor and report on your page views to themselves, which is a gross violation of privacy. Another would have been, “Do any connections occur before site navigation?”, to which a simple Yes or No suffices; either it’s Yes, or it’s No, as for tracking purposes it doesn’t matter whether it’s 1, 2, or many — only if it’s zero or non-zero. Those two questions would lead to productive discussion and debate, in a way that lists of hostnames with a statement of neutrality does not.
That said, it is hard to understand how much stuff is going on in the background unless you have good browser extensions and proxy or outgoing firewall.
I use firefox and just block mozilla.[net,com,org] firefox.* etc.
Mullvad, Orion, Tor, Ungoogled Chromium - 0 (zero telemetry)
LibreWolf - 3
Safari - 6
Brave - 7
Chrome - 9
Chromium - 12
Vivaldi - 13
Firefox, Yandex - 15
Edge, Opera - 21
Arc - 44
I'm using Cromite at the moment.
For example, I can't log into the Linode console using Cromite, but I can with Chrome.
Has anyone encountered anything similar or know how to fix it? I'd much rather not be using Chrome.
> Version: 1.33.106
> […]
> - ftx.com on TCP port 443
Hopefully that one is no longer present…