"Firefox added [ad tracking] and has already turned it on without asking you"
mastodon.social
mastodon.social
Q: What fraction of the corresponding GDP would it take to fund a serious browser-as-public-good initiative that would develop this technology to its full potential without the perverse constraints of adtech business models?
A: 0.0001%? Too small to compute?
The idea that critical communication infrastructure must be (directly or indirectly) supported by advertising interests is certainly not obvious.
Advertising businesses, like all businesses or individuals should be guests on that global platform, playing by the rules, not setting the rules. The status-quo is a unique and singular failure that has been normalized for reasons that historians will surely describe with gory detail in due course.
There are more ways to fund things than either adtech or dazed and confused individuals paying/donating directly for software. Especially when the stakes are extremely high.
Mozilla's attempt to provide a more palatable alternative while accepting the premise that the web is an ad-funded technology was, alas, always doomed. Its market share is trending to zero and it is just a matter of time before complete disaster...
Like what?
Interesting thought experiment.
I think, the question can pretty much be answered with "whatever is necessary to fund a company, their personnel and keep them afloat and honest".
Not sure when and why Mozilla has deviated from that path/mantra. Did they get greedy? Corporate bloat?
https://en.m.wikipedia.org/wiki/Mozilla_Corporation#Finances
A publicly-funded equivalent of MSIE 6, heroically made 100% secure and private, would be a disaster for the web. And that's a pretty likely outcome if it's designed by a government committee and prioritizes safety above all.
Hard disagree. The web was a much better place when IE6 was still relevant enough to reign in web developers.
Meanwhile the incumbent browser vendors profiting from online ads are on the committees that decide what will be the standards.
Have also seen Mozilla supporters on HN claim Firefox must "compete" with Chrome and that this means matching nearly all of its features.^2
For a recent example, see
https://web.archive.org/web/20240713084435/https://www.jwz.o...
(An HN commenter suggested sending Referer: news.ycombinator.com to www.jwz.org may have adverse consequences hence the use of IA)
The tunnel-vision ignorance and stupidity of this comment is over the top, IMHO. Have seen similar comments on HN.
1. I am submitting this comment with a text-only browser that is maintained by a single person and implements only a small fraction of web standards. It does not support ads. There are no "cookie pop-ups". Clearly, such browsers have value. In many cases I find I can access more information more easily and more rapidly than people using larger browsers like Firefox who are constantly battling against the influence of advertising and "web development" just to read some text.
2. The definition of "compete" as used by these folks does not account for the possibility that some www users (cf. web developers) may want less features, not more.
May I suggest to said reader that anyone technically inclined who still keeps that misfeature enabled in their browser deserves the targetted response they get.
I think the problem is more that the trend over the last 5-7 decades has been to privatise things. The EU (for instance) has rules forcing (e.g.,) privatisation of train companies and postal services. This has caused previously government-owned services to be privatised.
In this day and age, I'd be surprised to hear of any successful case where a non-public good was made public in a Western country. (I'll restrict my surprise to there because of insufficient familiarity with other countries to make such sweeping statements.) Whether it'd be web browsers, water treatment facilities, energy-related, healthcare-related, infrastructure-related, etc.: if it's currently privatised, it will emphatically not revert to public; if it's currently public, it might be forced to be privatised.
You might think about "privatised-but-with-strings-attached" variants, like in California with "carrier-of-last-resort", or in EU with public transport concessions requiring also services that operate at a loss to service small population centers / unpopular hours. Typically, these impose restrictions on the market parties on what they must deliver in order to be granted the concession. That seems like a way to guarantee the kind of service a government would deliver, but by market parties. And it is! But once you encode rules, you can start eroding them. Every new concession tender going out, you can try to dilute such conditions. A bit is enough - every step gained can be relied upon in future negotiations ("you're asking for more than last term"). And, of course, every small step can be argued by increasing costs - because cost will always increase anyway.
The TL;DRR (didn't read the rant): the public commons has a tendency to erode in favour of privatisation. There is pressure to do so, and no real counterpressure to reverse, only to not go too fast.
The private/public border is volatile and heavily contested and by all accounts will forever be a topic of political debate.
But notice how unusual the context of web technologies: Its not that a private monopoly is controlling and selling some piece of web infrastructure (that might, instead, be opened to more competition, turned into a public good etc).
No, what is happening is that a very specific business sector (advertising) is controlling universal communications infrastructure.
A loose analogy would be if a single private oil company would manufacture and distribute all automobiles in circulation - for free, but securing that they can run on nobody else's energy.
The conjectured "public-good" browser is not crowding out any private interests as there is no market for selling browsers. There is a market for advertising but its not competing for surfaces, it owns all surfaces.
Guess what, in this terminally conflicted arrangement you would never see an electric vehicle.
The highjacking of central infrastructure to serve narrow private interests will inevitably reduce innovation and welfare and any techie that is worth their title knows thats already the case.
1) Google's model. They try to control all the ways that people discover goods and services, and then sell ads to the providers of services. Whether people are looking for electronics, flights, restaurants, contractors or nannies, they are going to use Google Search or Google Maps or another Google service to find it, and service providers need to pay Google to be discovered. Google is using ads to get a cut of every business transaction.
2) Apple's model: They try to control all the ways that people pay for things. For digital goods, that's the App Store and In-App-Purchases, for traditional things it's Apple Pay and Apple Card and Apple Cash. Apple is using payment services to get a cut of every business transaction.
The UK is renationalising railways now.
"For the last few months we have been working with a team from Meta (formerly Facebook) on a new proposal that aims to enable conversion measurement – or attribution – for advertising called Interoperable Private Attribution, or IPA." https://blog.mozilla.org/en/mozilla/privacy-preserving-attri...
We owe Meta nothing. I have zero reason to donate my data to them.
I understand the need to work with Google and Meta. I don't like or trust the advertising business but I recognise that these companies are billion-dollar giants.
However, activating a feature without asking users is a failure to uphold the mission statement. And Meta is a repeat offender in the domain of security.
Mozilla, this is a failure.
Here is a fork of Firefox that I have been using:
I confess that I don't understand a need for them to work with Meta. What does anyone but Meta gain by adding this feature? A quick search doesn't show that Mozilla gets significant financial support from Meta (although maybe that's just bad searching on my part). If not money, what does Mozilla gain from this? Goodwill and a hearty thanks?
I have an intense dislike of Meta. But the company prints money and its tentacular toxicity touches almost everything on the Internet.
> what does Mozilla gain from this? Goodwill and a hearty thanks?
One supposes it's money because nothing else is a plausible reason for Mozilla behaving exactly like Meta.
2. Set dom.private-attribution.submission.enabled to false
I've added the configuration value to the following page:
https://wiki.mozilla.org/Privacy/Privacy_Task_Force/firefox_...
I'm not affiliated with Mozilla, but I do understand how wikis work. ;-)
You don't seem to understand why this is problematic though, so I'll explain it to you: enabling tracking when you know that one of your selling points to your users is respect for privacy is a huge breach of trust.
They mostly exist as a Google owned shell now...
Ok, maybe they should update firefox's home page, then?
Very first lines:
> Get the browser that protects what's important
> No shady privacy policies or back doors for advertisers. Just a lightning fast browser that doesn’t sell you out.
or should I use Nightly, and risk crashes and catastrophic loss of data
choices, choices
Edit: Just found out that on that link above, you can set general.aboutConfig.enable to true to enable about.config.
It looks like the xml page and the about.config one are the same, as the modifications I made are synced.
It has sane defaults and about:config is accessible.
Differential privacy is not fake, although quite complex to do in practice.
According to Mozilla[1], Firefox's implementaion uses the "Distributed Aggregation Protocol" (DAP)[2]. Individual browsers report their behavior to a data aggregation server, which in turn reports aggregate data to an advertiser's server using differential privacy. But the aggregation server still knows the behavior of individual browsers, so basically it's a semantic trick to claim the advertiser can't infer the behvior of individual users by defining part of the advertising network to not be the advertiser.
Now, Mozilla says the data aggregation server they use is run by the Internet Security Research Group[3], which is a non-profit, so perhaps the social incentives truely are aligned in this case to ensure individual user behavior isn't shared with advertisers. But it's disingenuous to claim user privacy is protected absolutely by technical measures when in reality it's only protected by social measures.
Finally, ad conversions can easily be measured without cookies by serving unique URLs with each ad, so what's even the point of this technology? I'm not clever enough to discern any ulterior motives (if there even are any), but the complexity of the approach is suspicious to me, since ostensibly a much more obvious solution would suffice.
[1]: https://support.mozilla.org/en-US/kb/privacy-preserving-attr...
[2]: https://datatracker.ietf.org/doc/html/draft-ietf-ppm-dap
[3]: https://en.wikipedia.org/wiki/Internet_Security_Research_Gro...
Example: Count Jackboot (your favorite evil politician, Trump or Biden or whoever) is running for office. He wants to know voter opinion on topic X so he can lie about it. He commissions a reputable polling firm to ask people about X, and give him only the aggregated results. The polling firm contacts you, asks your opinion about X, and promises you that your opinion can't be linked back to you. You'll be helping the Jackboot campaign completely anonymously.
You believe the anonymity promise, but that's irrelevant, you hopefully don't want to help the Jackboot campaign at all! Saying everything is private because Jackboot only gets anonymous information is a self-serving rationalization by the advertisers and data collectors. The only way to be private is give no information whatsoever.
I believe the goal is to infer the impact of impressions which do not require a click or user interaction.
Privacy-preserving attribution works as follows:
Websites that show you ads can ask Firefox to remember these ads. When this happens, Firefox stores an “impression” which contains a little bit of information about the ad, including a destination website.
If you visit the destination website and do something that the website considers to be important enough to count (a “conversion”), that website can ask Firefox to generate a report. The destination website specifies what ads it is interested in.
...
https://support.mozilla.org/en-US/kb/privacy-preserving-attr...
"However, now that Ladybird has forked and become its own independent project, all constraints previously imposed by SerenityOS are no longer in effect. We are actively evaluating a number of alternatives and will be adding a mature successor language to the project in the near future. This process is already quite far along, and prototypes exist in multiple languages."
If not, then yes it can’t be taken seriously.
The reality is that no language is actually 'safe', and 'safety' itself is a complex trade-off between enforced restrictions, flexibility, and other factors, just like in life.
There are several research, already published here many times, which show that something insane like 75%+ of all the security exploits would be rendered cold dead in their tracks had Rust been used.
I don't know how anyone, even a C/C++/VisualBasic/PHP coder, could not like that.
What would be interesting are detailed separate posts such as what you mention about security exploits addressed and of course the stream of wonderful software that people are writing in Rust (and other languages as well for that matter). Bringing it up in relationship to Ladybird, which is an amazing accomplishment already, is incredibly petty and off-putting. The poster can do better and the community deserves better.
I don’t read this as petty, it’s well noted by now that memory safe languages are increasingly recommended to avoid classes of errors.
As for petty. "[B]uilding a new browser in 2024 using an unsafe language is such a facepalm it's hard to take the entire project seriously." sounds pretty darn petty and dismissive to me for a project that is making good progress. We desperately need diversity in terms of web browser implementations and "not taking seriously" a project which could very well become viable within the next few years solely based on their programming language of choice feels wrong to me (even as someone with next to no love for C++).
I don't think the open web is really as dependent on the browser anymore anyway. We already have multiple choices today, but the web is still mostly controlled by a huge big companies and nations. Doesn't feel particularly open. A new browser engine won't really solve that.
Meanwhile a million dollars could go towards some network R&D or popularizing Freenet instead.
The world doesn't need a dozen HTML renderers. If we actually want a free and open web, that's a infrastructure and content censorship/algorithmic promotion issue, not a layout engine or JS engine problem.
This version of Firefox, 128.0, was auto-installed by Ubuntu update.
Has someone filed a bug report on Firefox yet?
> Firefox now supports the experimental Privacy Preserving Attribution API, which provides an alternative to user tracking for ad attribution. This experiment is only enabled via origin trial and can be disabled in the new Website Advertising Preferences section in the Privacy and Security settings.
> Firefox now supports the experimental Privacy Preserving Attribution API, which provides an alternative to user tracking for ad attribution. This experiment is only enabled via origin trial and can be disabled in the new Website Advertising Preferences section in the Privacy and Security settings.
https://www.mozilla.org/en-US/firefox/128.0/releasenotes/
This is the page users saw when they updated to 128. No mention of this setting.
https://www.mozilla.org/en-US/firefox/128.0/whatsnew/?oldver...
It is located at "Settings" -> "Privacy & Security" -> "Website Advertising Preferences" and is checked by default.
Boolean dom.private-attribution.submission.enabled False
It disabled the checkbox after updating Firefox. I set it to true to test and it enabled the checkbox also.
> I recommend turning it off, or switching to a more privacy-conscious browser such as Google Chrome.
Which seems an interesting comment from someone so extremely anti-advertising.
"Now to be clear, the disclosure Chrome provides to users is not adequate. Their wording of the "Ad Privacy" feature popup is highly disingenuous and the process to disable once notification is given is too complex and must be performed on a per-profile basis. But at least they do it"
What's the expression; 'So much depends on reputation. Guard it with your life'. Mozilla seem to be just throwing it away.
Apple, Microsoft, Google?
Realistically, these are the organizations that can afford to develop a high performance browser engine.
All the chrome and firefox forks probably don't have the devs or infrastructure to fork blink/gecko and keep up with security and features.
It's easy to be excited about Ladybird -- and maybe it will work, MAYBE.
It's fair to argue that we've let the web evolve into such an advanced platform that building a secure high performance browser is a HUGE moat.
People are so fast to criticize Mozilla. Maybe, this isn't all bad.
Sure I trust Mozilla more than Google/Microsoft.
But less so, now.
But wow this is vile. I did not expect this from them. Bad enough that I'm not sure if I can reccomend Firefox over a fork anymore
This is about "privacy-preserving attribution" https://support.mozilla.org/en-US/kb/privacy-preserving-attr...
I got studies, something about "adjust" and some telemetry thing.
Also they were already all off so it must not be one of them, I think.
> Anonym was founded in 2022 by former Meta executives Brad Smallwood and Graham Mudd.
https://blog.mozilla.org/en/mozilla/mozilla-anonym-raising-t...
You got me there. Switch to Librewolf
Ultimately you probably either need a clean-room NGO that ensures the data cannot be de-anonymized, or accept that ad impact counting is BS anyway and only measure profit increases across A/B ad phases.
At some level, trusting that privacy-friendly advertising through Firefox actually respects privacy is going to have to involve trusting Mozilla. Mozilla seems to have gone out of its way over the years to erode user trust, and this is just one more step down that road. As the author says, if Firefox is even sneakier about this than Chrome, what scope is there for trust?
Apple tried this with iOS 2 and 3. Minor versions cost users roughly 5-10 USD per update.
Therefore many users did not install the latest OS on their devices. The cost, although small, was a barrier for many people.
Apple quickly pivoted and now all software updates are free of charge to all supported devices.
If Mozilla starts charging for Firefox, I predict either people stick with the oldest version that is free, or stop using Firefox and use a fork that maintains its free (in cost) license. Or maybe only 2% of users convert to a paid version of Firefox.
Apple charging for updates is idiotic because as a user I don’t have a choice to go use a different OS.
Adding security updates and new features costs time and money.
You don’t even have to touch their services revenue to consider ongoing iOS development a significantly successful return on their investment.
They stopped doing it after they lobbied congress to change the law.
If firefox asked me once a month "Enjoying the entire internet? Is it worth $1 to you?" I'd press the button often.
The only thing that seems to somewhat work is Patreon, which seems to work fine for some developers that are good marketers, but even there the number of creators that can support themselves is very small, and I don't know of any Patreons that support more than a single person.
To support a browser, you need a team, and there is no plausible way to pay for that team with donations.
It's not that nobody has tried financing open source with donations, it's just that nobody has found a way to make it work yet.
No, AFAIK you cannot.
The inability to donate to Firefox is a valid and longstanding criticism of the Mozilla corporate/foundation setup.
Mentioning this deficit in a comment chain about the projects financial sustainability is relevant and appropriate.
It is also true that many projects have funding problems, but that does not negate the parents point.
Mozilla is not a particularly good steward of Firefox and there should be a way to donate specifically to Firefox development, if just for Mozilla as an indicator on what should be their priorities.
What I am saying is that it is extremely unlikely that people would donate to Firefox, even if was possible to do so. At least not enough to actually pay for more than a few developers. (And you need more than a few developers for a browser, even if you cut useless features nobody asked for like Pocket integration.)
* Donations to Mozilla go to a non profit which is separated from Firefox development and has questionable effectiveness in general
It's very hard to believe that an average user would ever pay for a browser, when alternatives like Chrome and Safari exist. It's the same as paid email services, in my opinion. Like sure, there will be some segment of users who'll do it, and they'll probably get $10-20M/year if it offers some features free email services don't. But hitting that $100M through donations on a yearly basis would be hard when there are free equivalent alternatives.
1. The average user doesn't have to pay for the browser in a donation model, you just need enough users to feel passionately enough about it to fund it sufficiently to develop it.
2. No one is arguing that Mozilla should replace their revenue from Google overnight with donations. We're just asking that Mozilla give us the option to pay for Firefox already.
Another user (trying to demonstrate to me that donations would never be enough [0]) figured that if we assume a similar rate of donations as Thunderbird gets then Firefox would bring in $70m/year just in donations.
That is a heck of a lot of money. That funds 140 developers even at inflated Bay Area salaries, 280 developers if you're willing to branch out of the Bay and offer closer to $200k/year on average as a base salary (still an insanely high average rate in most of the country and the world). Even if you took a full 50% for general/administrative and overhead, that sum would still pay for 70 bay-area or 140 rest-of-the-world developers.
If Mozilla really does need more developers than that for Firefox specifically, then fine, they can keep accepting money from Google—no one is saying they should only be funded by donations. But that they don't even make it an option is frankly bizarre.
Upvoting you in the hopes that more people in this thread will put their money where their stated principles are and help support a privacy focused browser with clear funding sources so that Orion doesn’t go the way of Opera.
What’s your Firefox use case that Orion doesn’t handle? (Sincere question; that wasn’t meant as “it works for me so stop complaining!” snark.)
Other than that, the browser is pretty amazing. Blazingly fast, support for both Firefox and Chrome extensions, and lots of customization. There's a lot to love about it, and as soon as the two features above land I'll likely be switching to it as my primary driver (on MacOS)
[1] https://orionfeedback.org/d/43-something-like-firefox-multi-...
A reasonable way to survive would be to have invested part of the half billion dollars per year they've been taking in for the last 15 years and built up a trust to permanently pay for developers.
>PPA is enabled in Firefox starting in version 128. A small number of sites are going to test this and provide feedback to inform our standardization plans, and help us understand if this is likely to gain traction. PPA can be disabled in Firefox settings.
https://support.mozilla.org/es/kb/privacy-preserving-attribu...
More discussion: https://news.ycombinator.com/item?id=40952330
This feature is supposed to replaced the current tracking methods for advertising purposes – and is better (or less worse) from a privacy point of view. It is currently on by default to ensure there is enough testers. If the test is not successful, the plan is to remove this feature again.
There is a long term benefit for everyone if this is adopted.
Let’s not forget how Google is clawing onto third party cookies, etc., and put Firefox’s position in relation to this.
It does leave a lot of critic points open though: * enabling it by default is really putting a negative light on it. I understand that if it’s disabled by default, no one will allow it and the test will fail due to lack of data points, there is simply no good solution here I can think of. * will advertising companies really renounce the other tracking methods if this method proves useful for them or will it become just one more tool on their belt?
As usual, the worse part if all of this really is Mozilla’s communication, they could have done much better. How could they imagine for a second it wouldn’t become a shitstorm, I wonder…
That said, keeping up with changes in JS/ecma seems hard. Whats the answer?
Ads aren't very important really, if you want to help, I recommend donating all your money to those in need and volunteering at a local homeless shelter, soup kitchen, or anything of the like.
I think Mozilla is at the point where they realize it is no longer beneficial to continue the race against advertisers. It is time to collaborate. This way both users, advertisers, and maybe Mozilla themselves can all benefit from stepping back one foot.
I personally support this move. Morally speaking, content creators I consume deserve income from my visit, as long as my privacy is preserved. Seems a good compromise if it works.
I doubt that most people in these discussions wouldn't agree with that point. The problem lies in the details. Advertisers don't take anything less that complete personalized targeting. We are not in the 2000s era of buying ad space on related websites/forums anymore. The problem is there are misalignment between targeted ads and privacy. And I didn't find all the proposal for anonymity successful, it is always possible to de-anonmize the data.
sad for the content creators (I do actievely try to donate and subscribe to quality content when apt), but I simply don't tryst my privacy being preserved any longer. So opt out of this setting and keep Adblock extension on. The well has long been poisoned for me.
But I'm also in the minority and it seems there's still enough adrev going that I'm barely an atom in the market.
Except, it actually is not a two way street. It's purely one way. Without users, the content sellers can't survive. But if users stop consuming ads and eliminate content revenue streams, the users will be just fine. So what if TikTok goes out of business or something?
All the failure of online advertising would mean would be regressing to a time when the internet was not very commercialized yet, which was an amazing awesome time when we had pretty much all the positives of today with few of the negatives.
They need us, but we don't need them. Big Content is a parasite.
For me, tracking is not my primary concern with ads: I use an ad blocker as an accessibility tool to allow me to even exist on the internet at all. I have ADHD. Nearly all content on the internet is flanked by ads that make it impossible for me to actually read or watch it—they're intentionally distracting enough to draw the eye of a neurotypical person, and it's hopeless for me.
I dread a world where even Mozilla embraces advertising and the false idea that the only thing to solve is privacy. Ads are a problem for many, many reasons, and we need to find alternative answers for funding.
So far though, they show no intentions of doing non-hostile advertising. Instead they're constantly striving to make it even worse.
So I'll keep the adblocking as it remains a reasonable and necessary defense measure.
Television and radio advertising exists and has existed long before the Internet without any need for detailed conversion tracking. Brief "To help us improve our business, could you please tell us how you heard about our brand?" questions in order forms has sufficed. A/B testing of billboard placements have sufficed.
Put simply, "Privacy Sandbox" is presented as a solution to a "problem" that doesn't exist.
Put content out there, if I like it, I'll pay. If it's not good enough for enough people to pay for it _consciously_, then it's not good enough, and you stop doing that. You move on to better things and so does everyone else, with the added benefit of the content pool being a little less diluted.
the best Mozilla can hope to gain is to get some scraps from google.
disgusting.
btw this wasn't discussed in any of the public Mozilla forums we monitor.
The implications are numerous:
1. There is no user interface or settings yet available to change the whitelist of Google-enrolled (Google being the only enrollment option today as far as I have discovered) ad-tech domains that are allowed to set the supercookies or use these supercookies to track users between sites.[2] By contrast, users can currently configure cookie settings such that they are only allowed for certain user-whitelisted sites.
2. There is no user interface yet to view and delete the supercookies, as one can currently do with normal cookies.[3]
3. Supercookies are shared across all Firefox containers breaking existing expectations of container isolation.[4]
4. Supercookies were shared across private browsing and non-private-browsing sessions until v120.b5, then Private Attribution was disabled in private browsing sessions (for now, and pending decisions on whether supercookies should persist across private browsing sessions).[5]
5. The setting privacy.firstparty.isolate is not honoured by Firefox's Private Attribution feature.[6]
6. Users are at greater security and privacy risk due to implementation of an extremely complicated and obfuscated draft standard that is full of technobabble bullshit which deliberately avoids real security and privacy impacts.[7] For example, the specification hand waves away the significance of a 64-bit supercookie as somehow being difficult to use to track users between sites. Reality is that only 33 bits is needed to uniquely identify every human alive today, and 37 bits for every human who has ever lived. The specification's section on privacy and security impacts does not address, for example, a website including an ad that proceeds to fingerprint John's browser as an 18 bit identifier as demonstrated at [8], then combine it with other identifiers such as the netblock/ASN of John's home internet connection. Later when John is in a completely different Firefox container connected to his employer's WiFi network browsing another site, the browser fingerprint or other tracking data within the 64-bit supercookie can trivially be used to associate John with his employer.
This Firefox partial implementation of "Private Attribution API" is just a small part of the full set of "Privacy Sandbox" anti-features Google is busy adding to Chrome, including, and of much greater concern:
1. "Private Attribution API" event-level reporting. Currently Firefox appear to have just implemented aggregate-level reporting, so the supercookie values aren't shared outside of the browser. The full specification from Google also allows event-level reporting where the supercookie values (which are set by an ad-tech company such as Google when the user visits site A) are later re-shared with the ad-tech company when the user visits a completely different site B.
2. "Protected Audience API". Execute within the browser auction bidding JavaScript bots from multiple advertisers where the bot can peek at private user data in order to bid on the impression, and then the winning bot will display the ad and report back the winning impression.
3. "Topics API". Summarise browser history in order to tell ad companies what categories of websites the user has been visiting. For example, John is interested in boats, fishing, car racing, beer and travel. Jane is interested in rock climbing, exercising in gyms, yoga, Italian cuisine and furniture.
[1] https://searchfox.org/mozilla-central/source/dom/privateattr...
[2] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/At...
[3] https://bugzilla.mozilla.org/show_bug.cgi?id=1901106
[4] https://bugzilla.mozilla.org/show_bug.cgi?id=1901103
[5] https://bugzilla.mozilla.org/show_bug.cgi?id=1901792
[6] https://searchfox.org/mozilla-central/source/dom/privateattr...
I agree it's not good that this is on by default. But saying that Chrome is better because it at least asks is disingenuous. Chrome simply presents you with the "Enhanced Ad Privacy" window and a button "Got it" or "Settings". That's clearly a dark pattern and technically not "asking" at all. The Topics API which you enable by clicking "Got it" is, at least from what I read, clearly worse than what Mozilla has implemented. Calling "differential privacy" a fake is simply untrue. It is not easy to implement, but if done properly, it's absolutely not fake.
I agree though that Mozilla has, as usual, dropped the ball here in how they have introduced this technology. They are obviously desperate, and they know if they would ask, probably the vast majority of people would not agree. Also as usual, they will probably roll back this setting once the outcry is large enough, and they have once again lost trust and gained absolutely nothing. It's also clear that with the tiny market share Firefox has nowadays, thinking they could introduce a new ad technology is simply hubris.