Mozilla Drops Onerep After CEO Admits to Running People-Search Networks
krebsonsecurity.com
krebsonsecurity.com
This is rent-seeking (https://en.wikipedia.org/wiki/Rent-seeking). Rent-seeking is an economic drag and ethically indefensible.
Regulation is how this problem gets solved and it's the only way it gets solved.
The article had no examples of public agencies perpetuating the problems they set out to solve.
Public agencies don't exist because of profit. They exists because of government mandate.
Also the website states it's just a single PHD that claims "I created Effectiviology to provide people with research-based information about psychology and philosophy they can use.", but it's in reality owned by 'Super Privacy Service LTD' according to https://www.whois.com/whois/effectiviology.com.
Don't trust this source.
Article: https://effectiviology.com/shirky-principle/
HN discussion: https://news.ycombinator.com/item?id=39491863
Now the aftermath could use a fighter, looking for how they could legally disassemble the entire racket. Not only because it's arguably on-mission, but more importantly because Mozilla has a reputation to redeem on this now.
(For example, no matter how that party has squeaked by wrt consumers, maybe there's a new angle in their dealings with Mozilla, such as a different kind of fraud. And Mozilla is much more able to pursue the matter than most individuals would be.)
If so, then would you say much of their current messaging has the right idea?
Would you also say that we've seen genuine progress (and also regression resistance) in that direction with the browser?
Personally, I'd say yes to all those. Two things that I don't understand are what one executive was getting paid, and some of their decisions during that executive's tenure, for a long time.
One guess is that some people were letting it be run like a tech company, and furthermore a tech company coasting along in some ways without being very effective. And that would have to be multiple people, since everyone answers to someone. If that guess were accurate, then not only do you have to ask the watchers why that was allowed to happen, and figure out how to fix that, but you also have to look for cascading effects within the organization from that having gone on.
Mozilla could massively help non-technical people regain privacy by shipping Firefox with actually private defaults and uBlock Origin built-in (they've got the infrastructure to download Pocket on first run, so they can do the same for uBlock), but doing would actually mean "doing something" and put them at risk (I'd expect the Google money to stop the second this is released, meaning they'd need to actually start operating a real business with a real business model), where as merely writing puff pieces is safe as it doesn't really hurt anyone.
I'm guessing a very hard problem is figuring out how to fund Mozilla's non-profit mission, without behaving entirely like a for-profit tech company.
I have a lot of sympathy for that difficulty, but no tolerance for some of the behavior that's gone on.
Suppose Joe Salesman sells your friend Al a used car and it turns out they got a bad deal, the car was a lemon. What lesson should be learned from this?
a) This was an honest mistake. We expect this kind of variance in used vehicles, and the market works out kinks. I should feel comfortable buying a used car from Joe, should the need arise.
b) The information that this car was a lemon was available to Joe, who did not share it with Al because Joe thought Al was a sucker. I am better at diagnosing cars than Al, (or better at reading people), and I should feel wary about buying cars from Joe.
c) Joe only sells lemons, his business model is to rip people off, and there's no way to get a good deal on a used car from Joe. I should look elsewhere to buy a car.
d) This describes the business model of all used car salesmen, I should not buy a used car from a business that sells used cars.
e) This describes all business models when there is information symmetry between buyer and seller. I should not buy anything whose utility I cannot bound from below. (I need a warranty or similar arrangement from the seller).
There are obviously other options here, this is just to illustrate the spectrum of assumed adversariality. There was an article on HN recently declaring that salesman were more likely to get ripped off. I think this is because salesmen tend to think the answer to this question is (b) because salesmen exclusively interact with people who think that the answer is either (a),(b), or (c).
It's not just salesmen, actually. I think the phenomenon is equally well represented in people with business degrees. The core belief of an MBA is that you can subvert the regulatory structure, and people's psychology, to get them to give you more money for the thing than it costs you to make the thing. That's after all, where MBA income comes from. I think this comes much more naturally to people who think that the answer to the question above is (b).
I think by and large, whenever you hear that their company decided to purchase anything at all (but particular some sort of service), your instinct is that the purchaser was a gullible idiot, and that things would obviously work much better if no one was allowed to buy anything.
Personally, I do not think that ferocious skepticism is necessary to solve this problem. I think that it is much more cheaply and easily solved by having a moratorium on buying shit. Mozilla does not, EVER, need to be a customer.
Does Mozilla still need to be the seller or partner in deals with commercial entities (e.g., Mozilla getting paid to be the default search engine or LLM within the browser UI)?
If so, would ferocious skepticism within Mozilla be appropriate in vetting and monitoring those deals?
We @ https://redact.dev are working on a pure software mechanism for doing these optouts directly from your own device. We already have full mass deletions for over 40 social media and utilitys.
As much as I routinely fine-tune and fix up a comment after initially writing, I will happily go back to the old days before such ability became common, in trade for the sanity of references that don't disappear or change meaning after the fact. The typos don't hurt as much as the swiss cheese and schitzo conversations.
Yes, I do see the irony of writing that here. :'(
It's pretty clear you're putting something in the public when you're commenting on HN; this isn't a surprise and nothing is done surreptitiously. If you contribute to a debate in some TV discussion programme then you can't have that deleted later either.
And there are options without wholesale deletion: specific comments can be deleted or edited for specific reasons, and your account can be "soft-deleted" by changing your username to something random.
If you want to have more ephemeral temporary conversations then that's fair! But HN is not the right platform for that, IMHO.
This made me curious about archivist ethics: https://www2.archivists.org/statements/saa-core-values-state...
> Privacy: Archivists recognize that privacy is an inherent fundamental right and sanctioned by law. They establish procedures and policies to protect the interests of the donors, individuals, groups, and organizations whose public and private lives and activities are documented in archival holdings. As appropriate and mandated by law, archivists place access restrictions on collections to ensure that privacy and confidentiality are maintained, particularly for individuals and groups who have had no voice or role in collections’ creation, retention, or public use. Archivists should maintain transparency when placing these restrictions, documenting why and for how long they will be enacted. Archivists promote the respectful use of culturally sensitive materials in their care by encouraging researchers to consult with those represented by records, recognizing that privacy has both legal and cultural dimensions. Archivists respect all users’ rights to privacy by maintaining the confidentiality of their research and protecting any personal information collected about the users in accordance with their institutions’ policies.
Yes, it makes the web poorer as a knowledge base, but it's in response to companies like reddit ruining the internet by baiting in users, changing the agreement and then trying to keep the content that was written under the previous agreements.
Edit: this looks like a totally different service. Mass deletion of old posts is one thing, removing PII from data brokers is another.
The pricing seems to implicitly acknowledge this: $35/m billed monthly vs $8/m billed annually! Would you really expect anyone to intentionally renew monthly? I can't argue that people forgetting to unsubscribe pays the bills, but as a business model it leaves a bad taste.
It’s hard to imagine what the situation actually looks like behind the scenes.
random companies will buy the data, do a little collation and merge datasets from multiple sources, start their own frontend, and resell it to consumers doing google searches for phone numbers, names, etc
because they’re not directly affiliated with the primary brokers, there are hundreds of these independent frontends… and unless you contact each one, they can all resell their data (even to each other)
so if you miss one removal, it’s possible your data gets picked up by a new frontend from that frontend… your data can kind of proliferate through this gross ether forever
These "data removal" services spend a lot of effort going after the frontends, which is pretty self-serving: they can show the customer that there's something new to remove every single month or quarter, so you have to keep paying forever.
Parent's argument is that current approach leads to an endless cat and mouse game the user ends up paying, when there would be ways to end it faster and cheaper.
Does that mean the user keeps paying just to have someone somewhere do "something" ?
And that, even if fundamentally it can't solve the sutiation, can't prove it's even improving in any specific ways (telling you it removes hundreds of instances doesn't tell you how many have been added in the meantime), and they also have no incentives to be too zealous as the numbers in the reports would be going down and the motivation to subscribe also diminish.
Ps: perhaps the way out of this is to make it a non profit that provides jobs to people in need, and have the subscription a recurring donation ?
yes this is what I mean, you need to contact each one to have data removed… there are hundreds of these
a real flaw is that companies in this niche are actually centralizing data to re-sell while adding a new line in the dataset that says "wanted to remove their data footprints"
edit: and as a result of automation, our prices are also way lower than most similar services
Open source doesn't mean hosted by a third party. You would run the software on your own computer.
Also makes me wonder what other shady connections fellow services might have, waiting to be uncovered. Looking at you, popular podcast sponsor, DeleteMe!
https://builders.mozilla.community/ https://builders.mozilla.community/old/alumni.html
With respect to Kanary, I have my entire family the platform and it's drastically reduced the amount of garbage (figurative) that comes through our door. Needed help with something non-standard the CEO personally took care of things while learning more about our specific use case.
People complain about the Google search deal and I get why, but I've been using the browser since back when it was called Phoenix, and at this point I'm pretty sure the Google deal is the only reason it's still alive. The engineering is still solid; its stewardship seems anything but.
This is why it's so important to require disclosure of beneficial owners for all companies. The world is filled with people that will poison you just so they can sell you an antidote, or, better yet, life long treatment.
Kinda like partnering with Google while promoting Firefox as the "privacy browser".
Don't you mean on your, the user's, privacy?
What specifically did this influence, or is likely to be influenced? What specifically is made worse by this?
There's always these vague accusations, but never any specifics.
Details are readily available if you know how to search.
These are just more vague accusations, and just as unencumbered by any evidence as your previous vague accusations were.
You are not engaging with anything I said. I asked for evidence of Google's control over Firefox beyond "they have a search engine deal", and you seem unwilling or unable to provide it. Therefore I can only assume it does not exist and are simply making spurious claims for which no evidence exists.
The lack of default privacy and ad blocking in Firefox is the evidence.
The fact that Google continues to pay even as Firefox marketshare shrinks to irrelevance is evidence.
The more pertinent question for potential users is evidence that it does not influence tbem. By any reasonable measure, default Firefox is not "the privacy browser".
In this case why does the browser have a pop-up blocker? Or why does it warn about potentially malicious websites (via SafeBrowsing)?
If it's not their job to curate what you see then it should show you the raw unfiltered badness of the web and let you deal with it yourself.
Hey your email provider also shouldn't do curation either, then why does it have a spam filter?!?! Checkmate atheists!
Ad blockers just use a list of known malicious URLs/domains/CSS selectors and use that to block/hide elements.
This is identical to Safe Browsing (preventing loading of known malicious domains) which you seem to be fine with and don't see as "curation".
What did it take for them to uncover it?
Generally speaking, GMU grad students may have have more time and plenty of expertise. When those grad students leave school and get jobs at Mozilla, they may be too busy to go down rabbit holes looking for long shots.
Unless there is massive senate/house/pres unification on absolutely crushing the endless disgusting behavior of spying on people to diminish them and enrich yourself is made illegal WITH CONSEQUENCES. Nothing will change. This will never happen because the US gov is the both the biggest customer and purveyor of these services.
Mozilla is basically the last place that even gives lip service to privacy and they are in bed with this guy. That is how hopeless the situation is.
Data brokers post a lot of your PII on the clear web for free. It doesn't cost anything to find out someone's names, the address of every place they've lived, the names of their family members, etc.
I have to believe the expertise gained in people-sesarch would be exactly the expertise one needs to remove people from the roles used by those organizations.
The real question is whether or not there is data brokerage out of Onerep.
This seems like a triumph of optics over substance...
Are there any more trustworthy alternatives? data brokers are scum.
https://www.optery.com/optery-statement-following-investigat...
https://www.pcmag.com/reviews/optery
https://www.pcmag.com/reviews/the-kanary
Here's another well-researched and unbiased review:
https://blog.infostruction.com/2023/08/12/privacy-powerhouse...
I see a few of our members commented on this post already, so I'll let them speak to the trustworthiness / impact of our work.
You can also read up on us on reddit r/kanary or r/privacy where myself and the team post updates. Reviews like PC Mag are fine, but that one is almost a year old and includes the bias of the reviewer - if you're on hackernews, you know how much software can change in a year.
https://www.optery.com/optery-statement-following-investigat...
https://krebsonsecurity.com/2024/03/ceo-of-data-privacy-comp...
But there is a clear conflict of interest if he is still actively engaging in the dubious behavior.
Is the implication that all pentesters are black hats until axiomatically proven otherwise? High bar.
It’s fascinating how easy it is to fall prey to a fraudster when they claim they’ve gone legit. You’re probably better off believing they’re still a fraudster.
https://louisianavoice.com/2021/04/26/new-book-further-debun...
https://en.wikipedia.org/wiki/Frank_Abagnale#Relationship_wi...
I would say that lying about your life story to write a successful book & then get a movie made about that book by the world’s most preeminent directory would count as a wrongful deception intended to result in financial or personal gain. But that’s just me.
His whole Wikipedia page is a list of constant fraud and larceny. Some persecuted, probably most not. As for how much damage he’s causing these days I don’t know, but he clearly has in the past.
Some examples:
> in March 1965, Abagnale identified himself as a Scarsdale, New York, police officer and entered the apartment of a Mount Vernon, New York, resident claiming that he was investigating her teenaged daughter.
> After being released into the custody of his father to face the stolen-car charges, 17-year-old Abagnale decided to impersonate a pilot.
So we worry Firefox will die.
If it had been "I have worked on identity-selling services for 15 years, saw it wasn't a good thing, and now I'm trying to fix the problem" then okay, fair enough. This is something we can at least start with. but this doesn't seem to be that.