Mozilla Monitor Plus: automatically remove your personal info from data brokers
blog.mozilla.org
blog.mozilla.org
If they use the data you provide (such as your address) to search other data brokers, doesn't that potentially give the data broker MORE information than they already had on you? Do the companies in this space prevent this somehow?
Edit: Lest people think this is somehow impossible otherwise - all it should take would be to search for just your name + location, get the query results, then filter on the client side. Which is exactly what a human would do for the brokers that have a "remove this entry" option when you see (presumably) yourself in the search results. However, this not only requires the data brokers to support such an API, but also requires the deletion services to actually put in the effort to do it this way for every broker they can, which seems nontrivial. Hence my question of whether these services make such an attempt at all.
> Optery, Inc. must send your PII to the data brokers and information aggregators included in the Removal Lists... We cannot control, guarantee or warranty how these third-parties will treat your PII or what they will do with it.
I think the same algorithms that are used for password storage would work for this without modification (except the data broker would pick different salts during each session, and you'd send the hash over the network).
DNS now has something widely deployed called "query name minimization". For no particular reason other than it made server's lives easy (which it does, as we will explain) the recursion process historically sent the actual qname (what was asked for) to each nameserver contacted.
Much was made of this in recent years, that this leaked potentially important information to servers which demonstrably couldn't have the actual answer for the qname (even if they could provide a useful referral).
Two flavors of qname minimization exist in the field. One flavor asks qtype A questions of the form "_.example.com" until it triangulates on the server with the answer; the other asks qtype NS questions (regardless of the actual qtype). (In case you've noticed a change in the mix of your DNS traffic.) In a nutshell, qname minimization asks questions which enable it to triangulate on the server which can potentially answer the question, before sending the actual question to it.
A good rule of thumb is that with a cold cache qname minimization will result in nearly twice as many queries being issued / answered during the resolution process, assuming nothing goes wrong. Both of these approaches are prone to mistakes when servers don't conform to assumptions about how proper DNS should operate.
So, seems like somewhere in the midst of this process, one of the 240 brokers that Optery sends your information to get it removed, someone aggregated it, sold it to Progressive and in the underground realm of data brokers and buying and selling data, someone unfortunately (or fortunately?) is now targeting 'Paige Notfound' and 'Meg A. Byte'.
I got the last laugh! :)
P.S. Just a heads up that you may have basically revealed your address by sharing those fake names (though I haven't tried to search), unless you also made up those names just now for illustration...
I can't think of other ways to verify yourself other than to verify yourself.
It's tempting to just automate sending a mass email to all the brokers with your full name, DOB, and address asking for deletion (some services actually do this - beware), but that exposes you to a bunch of new spam.
I've been building Kanary for 4+ years (we're a removal service & YC grant recipient) and we take a conservative approach to each site. I wrote a bit more about why this matters: https://www.kanary.com/blog/dont-get-spammed
(I'm an engineer on Monitor.)
Time is a finite resource, and a lot of these data brokers seem to be very geographically-specific and have their own ways of requesting deletion.
Personally, for this specific functionality, I don't think the EU wouldn't be at the top of the list though: these types data brokers are way more of a problem in other countries. We have laws like GDPR :)
Also: are you the JohnTHaller of PortableApps fame? If so: thanks for making my high school computer usage bearable, way back when!
- USA
It is listed in places, but clearly not explicitly enough in the right places.
haveibeenpwned will notify you if your email address was in a breach.
The Mozilla offering seems to include the same, but also cover other pieces of personal data, and the ability to request removal from data brokers.
And yes, you could probably go and ask the brokers directly, but that is certainly a lot of time and effort, so paying for it might make sense, assuming you trust the service provider.
The new thing is scanning for your info at data brokers (for free, but USA-only), and automatically removing them and continuously checking that they stay removed (paid, US only).
>Every month, we use the information you provided about yourself (name, location and birthdate) to search across 190 data broker sites that sell people’s private information. If we find your data on any of these sites, we initiate the request for removal. Data removal can take anywhere from a day to a month. This feature is available for Monitor Plus users only.
Anyone know if there are any local/open source tools to do this?
I use <website>@<personal-domain>.<tld>, and you cannot enter a wildcard in Permission Slip.
I'm also not sure it gets me that much. I do get to see how was compromised or sold my data, but most of that just goes to spam anyway. I also usually find out about the compromises from other sources anyway.
https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-Li...
The Mozilla offering looks somewhat comparable, but I do wonder if they’re going to beat a company which has the sole focus of solving this problem.
https://news.ycombinator.com/item?id=39276106
beyonddd should really identify themselves as the founder of a competitor. Nothing wrong with posting, but pseudo-anonymously disparaging the competition seems very inappropriate.
It also adds some credibility: You actually know what you're talking about in regard to this kind of service.
If nothing else, I’m glad there are more offerings showing up on this space because of the competition this will hopefully generate.
Consumer Reports also has a semi-related offering called “Permission Slip” that is focused on opting out of data sharing with individual companies, e.g. Netflix, Home Depot, etc.
Optery generally has 2 types of customers:
- The first type are those that care a lot about their privacy and the cost of an ongoing subscription is insignificant to them, so they keep the service running on an ongoing basis for the ongoing automated scans and removals and for getting new data brokers they get coverage for immediately as they are added into the system.
- The second type of customer is more price conscious and is basically looking back and forth between their credit card statement and their Optery dashboard each month and then they either pause or cancel the subscription when they feel they're reached a good stopping point. Optery's pause subscription feature is very popular for this type of customer and you can use it to automatically re-start the service in 3, 6, 9 months, etc.
- Another thing to point out is many other services only offer Yearly subscriptions, Optery offers Yearly or Monthly. If you're price conscious, the Monthly is nice because you can turn it on and off, or pause it as you wish.
More detail on the topic of keeping Optery running on an ongoing basis is on the Optery Help Desk here:
https://help.optery.com/en/article/why-should-i-keep-my-opte...
Your documentation says:
"You can only select one email and one phone number for scans at this time. However, Optery's engineering team is actively working on providing more configuration options such as the ability to run scans on demand for multiple email addresses and phone numbers."
Any comments on when this will be an option? I would want automatic scans on all of my emails and phone numbers. Not very useful for me without this.
That said, Optery recursively searches through data exposed by data brokers to alleviate the need to input numerous old phones and emails by the customer. In PCMag.com review they said this of Optery's recursive phone number search functionality:
"It uses data found in data broker profiles to recursively expand its reach. For example, in my latest testing, I only gave it my current phone number, but it found records associated with an old number that I used for some 25 years."
I get what you're saying about how emails aren't the primary means of finding people, but it is a way, and something people often do have more then one of. I'd humbly request you reconsider and try to better incorporate support for automated scans on multiple emails/phones into the main product. For what its worth it looks like Mozilla's product supports 5 based on their docs.
That said, after submitting this comment I'm going to go ahead and sign up for the one year ultimate anyway in hopes that you will reconsider my request if I'm a paid user. :)
Also, you mentioned using Experian's data removal service previously. Do you mind me asking how many exposed profiles the Optery scan located that Experian missed?
You can also just use the free version to collect a list of brokers your self and manually contact all of them to find out how much of a pain in the ass it is.
That might not be the most effective way to reduce spam or reduce targeted attacks, because it ignores many hard to remove exposures.
We have a similar price point at Kanary (I'm the founder) and it covers the resources we invest in the cat & mouse game required to escalate and complete removals on a wide variety of sites, not just a handful of easy ones.
- Optery's Ultimate plan covers 300+ data broker sites and offers Unlimited Custom Removals providing the most comprehensive coverage in the industry. Optery has a variety of plans for different coverage needs (Free, Paid, Family, Business), and the ability to pause or cancel a subscription at any time.
- Mozilla Monitor Plus is powered by OneRep, which partners with data brokers through its affiliate program: https://imgur.com/a/juSC66b. This is a fine line most data removal services do not cross. Optery's removals are proprietary and are not powered by any other company.
- Optery (YC W22) was awarded the Fast Company Next Big Things in Tech in 2023 and PCMag.com Editor's Choice award in 2022 and 2023, over DeleteMe, Kanary, Incogni, IDX Privacy, etc.
- Optery has completed its SOC 2, Type II security certification. To our knowledge, DeleteMe is the only other data removal service with this certification. This is probably the most overlooked attribute when selecting a data removal service.
Nothing against your company specifically, but at this stage anything associated with YN is a negative.
So, you have a clear conflict of interest with onerep not blocking data brokers from their affiliate. It probably doesn't go very deep, but with the subscription-based nature of these privacy services you start to wonder what happens when you churn...
(some basic info here: https://www.kanary.com/enterprise)
I like how the solution to the privacy issue is _yet another account_. I don't know why, but I find it highly amusing. I do get it, you need to share your details with them so they know which details to delete, but I still can't help but laugh.
HIBP supports domain searches[^1] at least, but part of the problem is also how we keep trying to reinvent the e-mail system to not fall prey to this, much how Fastmail have Masked Emails, and Apple have Hide My Email.
In a sense, it sounds like the advice of the services is less subscribing to them than trying not to have a few e-mails that map to your personal identity.
Firefox Relay is a great way to do that :) https://relay.firefox.com
Integrating that with Monitor is pretty high on at least my personal wish list.
Eu regulations on card networks make such a service much harder to offer, privacy.com makes money on card fees, which you can't really do here. Such a service would either have to be paid or bundled with other services which you can make money on, which is what Revolut does.
But until Firefox Relay supports custom domains, I am of the opinion that it’s not ideal.
I want with Addy over others because plans are per badwidth used instead of per alias, so one-time email verifications for some signup doesn't count towards a total limit.
Id just like it if Firefox Relay had these features.
My personal domain is for things that are really important in the long term, but for things like concert tickets, I prefer having the added anonymity.
Thats how it is with Simplelogin (which is a similar service).
The article mentions (obviously) Mozilla Monitor.
When I follow the provided link (leads to https://monitor.mozilla.org) in the default Firefox container and enter my email a new tab (now https://accounts.firefox.com) is created in a Google container (despite the fact that nothing suggests me leaving https://accounts.firefox.com)
Automatically remove your personal info from data brokers you say?
For comparison, see Onerep's very clear pricing page here: https://onerep.com/pricing
And as Kanary scans, we suggest members that match your information too to make them easy to add (and these notifications are easily dismissable).
This is a lot of money for most people. What would the benefit be of doing this all the time versus just subscribing once a year? How quickly do details reappear in databases?
Hell with the current economic environment I unfortunately spend more than this on my morning coffee.
Most people would also wonder why this is a perpetual subscription as opposed to something they can pay for one-off once every year or two.
And if they can't, what's the point of a monthly subscription?
Do I really need to login to get pricing information?
Anyone have experience with this kind of thing?
(You can scan for brokers before upgrading to Plus for automatic opt-out, so you can also check beforehand that you can see your data.)
Still, I'm not giving up a plausible solution because potentially it's only a partial solution.
If you're serious it's because having a fig leaf is useful to reduce risk in controversial business practices, especially if the vast majority of people don't take advantage of it.
Either that has literally never happened, or there's inadequate auditing/enforcement, and I don't consider the former to be plausible.
For example, my info is definitely not on mugshotlook.com... And about 2/3 of the results I've clicked on have already been removed by Kanary (full disclosure, on the team, but was a happy customer before) or weren't real to begin with.
OpenRep is another one I've seen mentioned. Covers 190+ sites: https://onerep.com/sites-we-remove-from
One thing I can't find is a list of sites that Mozilla Monitor covers.
Here's a comparison. I only listed the individual plans since Mozilla seems to only offer that. The other 2 offer plans for multiple persons
DeleteMe: https://joindeleteme.com/
brokers: 750+ https://joindeleteme.com/sites-we-remove-from/
edit: I just realized looking through that list that they are a bit deceiving. They have qualifiers next to each website:
* Included in Standard Plan and above (90 sites)
** Included in Business Gold, Diamond, Platinum and VIP Plans (27 sites)
*** Included in Diamond, Platinum, and VIP Plans (1 site)
ᵒ Exclusively in Platinum and VIP Plans (13 sites)
~ International requests (12 sites)
^ Custom Requests (665 sites)
Seems like the majority need a "custom request" which defeats the purpose of signing up for something that is supposed to handle things automaticallypricing: https://joindeleteme.com/privacy-protection-plans/
- individual plan: (they also have couples and family plans)
- $10.75/month if you sign up for 1yr
- $8.71/month if you sign up for 2yr
-------------OpenRep: https://onerep.com/
brokers: 190+ https://onerep.com/sites-we-remove-from
pricing: https://onerep.com/pricing
1 person: $8.33/mo, they also offer family (up to 6 ppl) and teams (10+)
-------------
Mozilla Monitor: https://monitor.mozilla.org/
brokers: 190 data brokers (could not find a list of data brokers they cover)
pricing: https://monitor.mozilla.org/#:S1:
- "Monitor" - their FREE tier where they scan the data brokers and just inform you which ones have your info and you have to manually go in and remove your information from each one through whatever process each site uses.
- "Monitor Plus" - Automatic Data Removal - $13.99/month, or $8.99/month if you sign up for a year
Both tiers come with "Data Breach Alerts" which I guess is similar to haveibeenpwned's notify me.
--------------
edit: adding one more: https://www.optery.com/
brokers: 305+ https://www.optery.com/pricing/#data-brokers-we-cover
pricing: https://www.optery.com/pricing/ & https://www.optery.com/business-pricing/
will only cover the personal pricing:
free - self-service (similar to Mozilla's free tier)
3.99/month - removal from 110+ sites
14.99/month - removal from 200+ sites
24.99/month - removal from 305+ sites
So your service will handle (up to) 305+ data brokers automatically? depending on how much you are willing to pay of course
What actually creates this cost, though? I was hoping it'd be free or at cost for the infrastructure and maintenance.
"If you are located in the United States and have a Monitor Plus subscription, OneRep receives your first and last name, email address, phone number, physical address and date of birth in order to scan data broker sites to find your personal data and request its removal. OneRep keeps your personal data until you end your Monitor subscription in order to check whether your information shows up on additional sites, or has reappeared on the sites you’ve already been removed from."
This was my instinctual, cynical assumption, too. Unless there's a GDPR-like law in place and some standard for differentiating identities, they're just going to find loopholes to recapture peoples' data (e.g. remove middle initial, modify address format, etc.).
We have a free trial that auto-downgrades into our free tier. We encourage everyone to compare services before joining. https://www.kanary.com/#sign-up
As with for-profit healthcare in the USA, just seems scumbag to profit off of misfortune and misery.
There is no law and no prospect of one soon. Mozilla can partially solve the problem by providing the service - I think that's great. Otherwise people would have less recourse.
And also, Mozilla must have money to operate; charging for this service seems among the least-bad options.
They push on the legal aspects of other problems, but I don't see them pushing on the legal aspects of this.
Mozilla receives half a billion dollars per year from Google, making up most of their revenue. Mozilla's CEO is also paid millions of dollars each year. If they can't survive as-is whilst paying out those kinds of salaries with such revenue, that's a management problem.
So? Do doctors want you to have cancer? Do undertakers want you to die? Yet they still get paid.
> They push on the legal aspects of other problems, but I don't see them pushing on the legal aspects of this.
That's not persuasive, unless you are in that business. Where is a list of the things they do?
> If they can't survive as-is whilst paying out those kinds of salaries with such revenue, that's a management problem.
While I don't like the CEO's pay, competitors have far greater budgets - and pay CEOs far more - as do many businesses. The amount itself isn't evidence. Where is the evidence that Mozilla isn't allocating funds well?