For advertising, Firefox now collects user data by default
heise.de
heise.de
1) Hamburger menu -> Settings -> Privacy & Security
2) scroll down to the new section entitled "Web Site Advertising Preferences".
3) Make sure the box marked "Allow web sites to perform privacy-preserving ad measurement" is not checked.
[1] https://support.mozilla.org/en-US/kb/privacy-preserving-attr...
The underlying pref is dom.private-attribution.submission.enabled. I'm going to force this off in my policies.
Now I install an organizational policy that sets the prefs. I use NixOS to apply this and it looks like this:
environment.systemPackages = [(pkgs.firefox.override {
extraPrefs = ''
lockPref("dom.private-attribution.submission.enabled", false);
''
})];
I think this is just creating a `prefs.js` file under the hood, so you should be able to replicate on other systems that you manage.Edit: This is creating a lib/firefox/mozilla.cfg. IDK how exactly this applies to other distros.
The syntax is: user_pref("dom.private-attribution.submission.enabled", false); // Disable Privacy-Preserving Attribution
You can find a lot of examples and "documentation" on https://github.com/arkenfox/user.js
I don't care if the feature cures cancer or gives me a free puppy. I don't want a feature running without my explicitly commanding it to run.
sudo rm $(which firefox)https://old.reddit.com/r/firefox/comments/1e43w7v/a_word_abo...
What isn’t clear, in retrospect or otherwise, is why companies/apps/services need to keep learning this lesson. The user outcry was utterly predictable from even before the first web article was out. The fact that no one with decision power at Mozilla saw it coming is worrying: either they have zero understanding of people’s concerns for privacy or they don’t care. Neither is good.
Or the third option: they feel the tradeoff of HN & co's criticism style is not a big deal in the end. Criticism of Mozilla in general is very warranted right now, but the way(s) in which everyone is doing so just feels very out of touch with the actual situation. ;P
They're - by their own words - trying to do something in a privacy preserving way because the ad industry is not going away. They might fuck it up at first, and that's why it's an experiment. It's also possible to disable it, it's not like you're trapped in it.
This thread in general feels like it leaves Mozilla no room to experiment or find any form of growth. People want them to be "just a browser" but then also expect them to be stewards of the web - and then cry foul when they actually try to find a setup that fits into the current model of the web.
That’s the second option: they don’t care.
> This thread in general feels like it leaves Mozilla no room to experiment
If you you’re going to experiment with something that’s going to cause this amount of backlash (and my criticism is that they didn’t take the obvious reaction into account), you show a dialog on first run that tells you what the feature is, perhaps include a “Learn More” link, and have an option to accept or deny. You can even have the former as the default. And do it in your betas first.
Would that still cause some backlash? Possibly. But it would’ve been significantly milder and you would have seen a lot more defence of Mozilla for not doing without asking.
Mozilla in particular is frequently pulling crap like this and getting flak for it. They have to constantly apologise and back track. After a while you’d expect they learned something.
Well, right now, with their dwindling market cap, I feel like their only userbase is HN & co's type of user.
They repeatedly failed to increase their user base with non privacy conscious adjacent communities. So antagonizing the ONLY folks that go through the trouble of installing a non default browser to have a worse user experience seems like a big brain moment.
That's the start of full blown stockholm syndrome.
No data is ever fully anonymous, don't pretend otherwise. So no data should be send at all.
Mozilla is welcome to experiment. The issue here is:
- The default opts the client in instead of the client making that choice to be a Guinea pig in the experiment
- I get emails almost weekly that amount to Mozilla playing the role of internet privacy police. They *are* well aware of the rights and wrongs. Are they going to call out themselves?
- As for growth? How about paid pro-privacy email hosting? And a suite of applications (a la Google docs)? Advertising might not be going away but there are still opportunities that align with Mozilla's ideals and brand... And they're too busy being hypocritical internet police???
they're bending for the ad industry because they want their money. they could also just keep blocking their tracking and call it a day.
> the ad industry is not going away
But users do. Let them have a great faking love affair with the ad industry.
Do people really expect that? I'm glad they're part of whatwg etc., but I'd much prefer they just made a good browser instead of tooting their own horns about how much good they're doing for society. In the end I think society would have been better off if they'd just focus on good tech like Gecko/Servo and Rust and not bothered with all their side stuff.
One reason is that the people who would be promoting Firefox aren't.
Personally I feel mostly ashamed to admit I'm using Firefox. In theory Firefox is great. In practice they coming up with new ways to treat their core user base badly.
Or so they say, in order to make people be OK with it. They might play the waiting game and in a year or two will make the setting not do anything and still collect / send data, hoping that by that time people have forgotten.
They are trying to find a funding model that makes them independent from Google.
- Building a fast, privacy-oriented browser that keeps up with web standards and fixes security bugs takes people, organisation and therefore money. Yes, much more than that CEO salary.
- No one wants to buy for a browser.
- No one wants to pay a subscription fee for a browser.
So you are left with ads. Mozilla is trying to find a balance there between privacy and ads with a clearing house approach. People who hate ads out of principle scream. How should browser development be funded?
One of the most common Mozilla complaints I see on the web is that you cannot fund Firefox development directly. People want to give money to it, but cannot.
Which makes sense, I guess. Anecdotally, Mozilla is by far the company I know with the most vocal users that get completely ignored.
It's like email. You need to get people over the mental hump. But then if you offer a good product, buyers will be happy they got over it.
The one funding model they haven't experimented with at all is actually asking people to pay for Firefox. Donations or subscription, they haven't even tried it once.
And yet people will over and over again insist that that would never work. Doesn't that strike you as odd? They're willing to flail about trying thing after thing after thing that their users hate and yell about and they end up having to pull back, they're willing to burn credibility over and over again, but the one funding model that their users keep telling them they want they refuse to even try on the grounds it would never work.
"We should have communicated more" seems like a passive-aggressive way of saying "Oh, you poor simpletons... We should have talked slower, used more, simple words, and been more persuasive. We failed to properly explain why you're wrong. If only we did that, you'd more readily accept what we're giving you."
One possibility is they knew there would be an outcry but estimated that the loss in user support because of it would be limited enough that the upside of having the majority of users with the setting left on wins.
Oh maaaaaaaaaaaan do I despise hearing variations on this "non-pology."
It's never "Wow, we fucked up by doing something harmful to you." It's always, "My bad, I failed to explain exactly why you're wrong to think this is harming you. I take total responsibility for not explaining why this is actually good for you. I'll try again."
Please. This is never about learning and better communication. This is universal corporate English for: "you got us, but we really don't give a flying ef and we will fulfill our goals step by step - no matter what you say".
I've seen enough of:
Step 1 - outrageous move Step 2 - apologize, progressively pull back Step 3 - people spread word they made it better Step 4 - stick to still outrageous but comparatively better "middle" move
To really give it any excuse anymore. And so have you. If "Unity" tells you nothing... I'd like that rock, please, I'll need it to survive the incoming 4 years of social media.
I'm not saying its impossible for apologies to be in bad faith, just that if it becomes impossible to apologize and move on after making a mistake, it becomes impossible to do anything productive.
We always see the decisions that blow up, but we dont notice the thousands of decisions nobody cares about. Sometimes it really does look like just another minor feature request at coding time.
Agreed in general, disagreed in the specific Mozilla case. They’re an internet-related company where “privacy” is one of the stated core goals, yet they’ve stuck their foot in their mouth so often they could open a shoe shop. Failing to see this one is at best incompetence.
> First, in the absence of alternatives, there are enormous economic incentives for advertisers to try to bypass these countermeasures, leading to a perpetual arms race that we may not win.
It's very likely that this arms race will lead to DRM in web publications and video feeds (which Google is already experimenting with).
And maybe that will be the Web healing. If all the value extraction moves elsewhere, we might finally have a sane web of hypertext documents again.
Realistically, the best outcome at this point is that enough users are willing to send enough data to advertisers so they allow the open web to continue.
The alternative is that sites will eventually only work in Chrome or Safari on limited, locked down platforms (read: no Linux support at all).
So we're not even going to try.
I might be misremembering?
This has happened before. Remember the critique against Encrypted Media Extensions (https://en.wikipedia.org/wiki/Encrypted_Media_Extensions): Oh no, DRM in the browser! But remember that web video used to require Adobe Flash for the longest time, and even after a decade of HTML5 video, sites were still clinging onto Adobe Flash (and later also Microsoft Silverlight) for what turned out to be DRM purposes. At the time, these plagued proprietary blobs were not going anywhere. Except, after EME had widely supplanted this last holdout usecase, they were quietly allowed to die. The result is that we have much smaller-scoped proprietary blobs in the form of content delivery modules with a lot fewer bugs and portability issues.
The current situation is worse.
EME requires that the browser ship with a DRM library like Widevine.
Flash used an industry standard plugin model and could work in any browser.
If you have telemetry disabled, this feature is also disabled, even though that isn't represented in the UI and looks like it's turned on.
It's not good that it exists and is on by default, but if you have already opted out of telemetry previously, you're opted out of this too.
> we consider modal consent dialogs to be a user-hostile distraction from better defaults, and do not believe such an experience would have been an improvement here.
You know what's user-hostile? Doing things without the user's knowledge or consent. The new tab page of Firefox after an update often advertises features of the release Mozilla sees important (their VPN offering, Firefox on mobile, etc.). This time the new tab page told me nothing about this change. Communicating it to me was "free" and they still actively refused to do it.
"Doing something" about surveillance starts with transparency but if Mozilla's leadership doesn't see this as important they have no place leading such a company. Mozilla doesn't seem to wrap its head around the fact that their users use Firefox because they don't want the same kind of shady tactics Google or Microsoft keep pulling, they don't want their browser control to be handed over to some guy in a board room who needs a PR team to give a lengthy non-answer to the problem.
I see a lot of words spent on why they came up with this technology but barely a mention about the biggest issue here especially from a company that presents itself as a champion of user rights: they pushed the change in the dead of night and took an actively hostile decision in the users' names by enabling a clearly controversial setting without any warning or communication.
> we should have communicated more on this one
This kind of PR speak for "we actively kept it hidden" is the best way to alienate the users who investigated and chose this browser for a reason.
The problem we currently have with cookie banners is thanks to the browser vendors not caring about it.
An API could exist which a page can query, where the user has already pre-selected how they want to deal with cookies. For example reject all but the essential ones, reject none at all, reject some, according to certain criteria.
Even more, the browser could check if the page is adhering to the user's expectations, and if it doesn't, block it for a period of time, like a week or a month, and publish the fact that they ignored the user's wishes.
Possibly also give the user a signed document which claims that this page did not respect the user's privacy expectations, so that the user can use it in court.
These should be solvable problems.
So I guess that both the user and the site can't get what they want and we should scrap the internet.
This requirement to constantly ask the user while using these dark patterns is what makes normal people just give up and "accept".
If the page is expected to ask the browser which preferences the user has set regarding the cookies, then this problem is gone, because the page no longer is expected to ask a person via a popup.
> "there are enormous economic incentives for advertisers to try to bypass these countermeasures"
Then:
> We’ve been collaborating with Meta on this
Given Meta's track record with scooping up just about any personal data they can find, it's pretty obvious that this is just going to be yet another datapoint in Meta's collection.
It shows that the topic is merely now considered as a technical point, rather than a principal-based one.
I don't believe in cooperation with an industry that has shown no remorse with tracking users at all. That will not be successful. Advertisers will employ this and still track. And it is possible to not get tracked and deliver false data, even today.
The arms race will continue as it does today, but advertisers will have yet another avenue to exploit in the form of the attribution API.
Yeah, like Mozilla.
This is not the first time they silently added tracking and avertisement. The toggle with "firefox shares basic telemetry with the adcompany Adjust" has been there activated by default since a while (among other stuff). This is just more tracking from them, while claiming to defend privacy. Another day, another scandal.
> I’ll do my best to address [your questions], though I’ve got a busy week so it might take me a bit.
That means: I'll answer the easy ones, and ignore the hard ones, or ask the legal team to come up with some weasel words.
Data is their edge. It's how they compete with each other.
The privacy "arms race" isn't just between the browser vendors and the trackers, it's also between tracker a and tracker b.
Giving them a new data point (no matter how """privacy preserving""" it is) is just that, another data point. It's not going to make them give up on the others.
I suppose it shows who's paying Mozilla.
Is it just me that sometimes get the feeling that when companies have to explain them selves with this amoubt of text, they actually know that they are doing something wrong but are trying to cover it up by these long and unnecessary explanations?
That's what most of folks says in this sub-tree
Mozilla is a joke nowadays.
[1] https://en.wikipedia.org/wiki/User:Guy_Macon/Wikipedia_has_C...
Found it. Go to settings, type privacy into the search box. The last item under "Firefox Data Collection and Use" is a check box labelled "Allow websites to perform privacy-preserving ad measurement".
It was already unchecked on mine when I looked just now.
open chrome://geckoview/content/config.xhtml, set general.aboutConfig.enable to true
open about:config, set dom.private-attribution.submission.enabled to false
dom.private-attribution.submission.enabled
to false in the gekoview?I guess the question is whether the aggregation services can be persuaded by clever attribute manipulation to give the ad site a near unique report for a user across many sites.
<https://support.mozilla.org/en-US/kb/privacy-preserving-attr...>
<https://datatracker.ietf.org/doc/html/draft-ietf-ppm-dap>
<https://github.com/mozilla/explainers/tree/main/ppa-experime...>
programs.firefox.policies.Preferences."dom.private-attribution.submission.enabled" = false;
(https://gitlab.com/engmark/root/-/commit/bbb3ff9efb878ddda38...)And it felt kinda good, i actually thought that Firefox was different and a part of "the good guys", now it doesn't feel that way anymore. Sigh.
I know of no workaround short of installing from the Beta or Nightly channel.
source: https://connect.mozilla.org/t5/ideas/firefox-for-android-abo...
Before anyone tries to respond with it. It is https://donorbox.org/ladybird
Here's the Servo link: https://servo.org/sponsorship/
It is not ready, to be a public browser.
EDIT : Actually they still update it. Last version is 115.
Things are progressing faster than you'd think.
Or, if one dreams for a moment, if slower becomes the norm, web apps will have to become less complicated. Fast seems to just enable more and more ad tech
Let's build something that is Ad resistant from the start. Something that uses native technologies.
Edit: We need something that does not need backing of large corporations or huge funding to access the web.
Internet was always simple. We have become over dependent on browsers and http stack.
You can make a free web browser from Firefox's current engine just as easily as from Servo, I would fund the person who does that.
Short term, deshittify Firefox. Mid term move to some like Lady bird. Long term, if Lady bird is corrupted, start on browser replacement number 2.
Alternatively, the hardest step of just walking away for heavy internet usage I guess.
And fallback to Firefox when things don't work. Which is usually on sketchy websites, websites that have heavy bot protection and fingerprinting or ones that use gpu APIs.
* There is no legal entity behind the project. Should anything ever happen with the project (it can happen, even if unlikely), there are no legal ramifications.
* The binaries aren't signed. Yes, code signing is a bit of a racket, but there is some merit in it.
* There is no auto-update mechanism. Might not seem like a big deal, but IMO it is, especially on Windows where you're recommended to rely on 3rd party client to update the browser for you. You've now added a middle man, and since the binaries are not signed... well there's no guarantee you aren't downloading a malicious binary.
To me, this seems like a plus. If you want users to update, provide them with something worth updating to. This tracking suddenly being enabled for a ton of users is the very result of automatic updates.
A UK Ltd. is less transparent than Librewolf, an open-source project run by many volunteers without the incentive to make any money.
Point 3 is no longer true, the installer comes with the option to enable auto-update and on Linux, it also auto-updates, depending on distro, etc.
The risks you are talking about are not inherent to Librewolf, but to Linux and open-source, and thus are not legitimate criticisms of Librewolf.
In app update prompts work for me, they have a TOS / Legal Entity it seems. They broke away from Startpage in recentish years.
Plenty of feature trade offs to compare though with Librefox.
Chrome on the other hand (and believe me I despise Google in so many different ways) has consistently been okay. Not great, but okay, and certainly better than Firefox. This while having the same browsing, tab and extension habits in both browsers.
With comments like my original above I've always seen a bunch of people come out with all sorts of caveats defending or justifying FF, but personal experience has consistently shown me differently.
1. Define some baseline set of M impressions with various ad identifiers and from various sybil advertisers.
2. For each target user, define some set of M marker impressions, also with various ad identifiers and from various and sybil advertisers.
3. Save all impressions (marker + baseline) on a bunch of sybil browsers to get above the reporting baseline with some probability.
4. If/when a target user visits a target website, request a conversion report for each ad/advertiser.
You now have a baseline signal (from the baseline ads/advertisers) and a marker signal (from the marker ads/advertisers). If this is one of your target users, you'd expect their "marker" signal signal to be stronger than the baseline.
Might be worth opening an issue if you believe there's merit to the attack?
And I'm now quite sure this system is insecure. Fundamentally, either:
1. There is some magical sybil protection: An attacker can only spend their own privacy budget without affecting the rest of the system.
2. The system can be saturated: An attacker can spend everyone's privacy budget.
3. The system is not private: An attacker can exceed the "safe" privacy budget by combining information from multiple sybils.
Everything else is just agreeing with the advertising industry on their idea that profile-building is fine.
These advertisers nowadays think they have they are entitled to everything, and Firefox just helped them.
All the other images are hosted by Wikipedia themselves and are not ad-related, so I don't see where's the issue here.
The value of words is leaving the web.
The "ad industry" is a cancer and we need legal protection against this "industry". The solution is political not technical and definitely can not be left to "the market".
Haven't you had enough?
The bad people will change the API, lock the bootloader, implement a problematic standard (ACPI, SecureBoot) or add more DRM.
We cannot solve political issues (law) with technical solutions (programming). If we don’t like locked iPhones, the solution is a law. If we don’t like tracking, the solution is a law. But the EU Cookie-Directive of failed? Because malicious compliance, they made a business case out of it instead of ending it (cookies for logins are fine). And if we want public APIs, local computing and open-source the solutions are laws.
The FSF uses the law :)
Let us go a step further, change it.
And the GPL is dying. Every year fewer projects are maintained under the GPL standard. Violations abound anyway. The MIT License and other permissive licenses; or commercially restrictive licenses like the SSPL, are the new go-to; because the GPL didn’t think about SaaS or “Tivoization” until it was too late.
At least on my Debian I retain full control using the shim and my own enrolled keys. So seems less an issue with the technology but perhaps with how some vendors (that are already locking you in anyway) use secureboot?
from https://wiki.debian.org/SecureBoot
>> Shim then becomes the root of trust for all the other distro-provided UEFI programs. It embeds a further distro-specific CA key that is itself used for as a trust root for signing further programs (e.g. Linux, GRUB, fwupdate). This allows for a clean delegation of trust - the distros are then responsible for signing the rest of their packages. Shim itself should ideally not need to be updated very often, reducing the workload on the central auditing and CA teams.
Absolutely true, but how do you expect that to happen or come about?
Rampant advertising is similar to the copyright law problem. The majority of users may not like what's happening but their opposition and or dislike is but mild so when it comes to political action it collectively amounts to little more than nought.
On the other hand, advertisers, like copyright holders, have strong vested interests thus are highly motivated to ensure politicians act in their favor (one only has to look at the lopsidedness of lobbying interests to see that).
The real enemy is indifference, as a whole the citizenry is not motivated enough for things to change. Simply, we have ourselves to blame.
In the same manner through which legal protection for various other matters have come about. By raising awareness, sharing thoughts and solutions, and organizing.
I observed a friend of mine click on a malicious ad link recently in front of me when driving a presentation for a community meeting. It was shown as an overlay for a seemingly harmless site I found. In my home with a pihole I didn't see any of the ads.
I felt terrible that I was partially responsible for her clicking it. This knowledge and habit of ad-blocking and secure computer usage takes factors of time, effort, and money to learn, and not everyone is going to, or is capable of, devoting what's needed.
People forget that before ad-supported "free" services took over we had community-run actually free services.
The internet does not need ads.
What you say sounds reasonable. And I'm not trying to say "well, it's impossible because of some current status quo", because we could change that.
What I'm trying to say is that we need this "industry" to work out the practicalities. Otherwise we are "protected" in a same way the GDPR protects us against 3rd part trackers (you don't need a cookie banner if you don't allow 3rd parties to track your users. Yet here we are...)
So if company X sells data to company Y and then Y sells to company Z then company X has full liability for leaks or misuse from all entities in the chain.
No more free credit monitoring. Banks, credit card companies, and end users get to directly sue these companies. May not completely solve it but you can try to make it so expensive to mine data you don’t truly need that it ends the whole industry.
I am sure there are holes in this but we can at least try to kill the data brokers and bad actors.
Done.
I agree that something needs to be done about the ad industry and rampant data collection, but your emotionally manipulative comments are not it, and actively make it harder to discuss solutions to the problem.
What would these political solutions achieve that aren’t achievable instantly today via technical solutions?
Most people don’t care about what the ad industry is doing.
More laws and larger governments doesn't have to be the answer to all problems. If consumers care enough they'll change their usage, if they don't change their usage they likely don't care enough.
I don't particularly have an issue with advertising itself. If adverts get on my nerves on a product or page I just leave, as you suggest: problem solved.
The actual issue is the stalky tracking of me throughout my life that is currently inseparable from the advertising. I can't just walk away from that: it happens behind my back, it has happened before I get the chance to walk away.
> can stop using whatever product has been ruined by ads
Which will not stop the stalky behaviour of the ad industry. They'll still track me if I happen to click the wrong thing, or track me through my connections to other people. I suppose I could walk away from life and become a hermit, but that would be just a little extreme.
> or find ways to remove the advertising.
Which is, while I do take part, an ultimately fruitless task. Every block we make for the stalky behaviour, be it technical or legislative (other than outright banning the tracking of personal data except with explicit opt-in without exceptions, and properly enforcing punishments for breaking the ban), they'll find a way around. Removing it is not a long term solution, it is a war or attrition where we have to have our guard up all the time and they only have to get lucky, or just be particularly sneaky, every now and again.
> More laws and larger governments doesn't have to be the answer to all problems.
This has often been said by companies and their shills. Oddly, they are all in favour of extra laws and government reach when it is, for example, to protect what they consider to be their intellectual property.
Vaguely referencing more laws or larger government doesn't mean anything. We're not talking about all problems but a specific one. There is an obvious imbalance between the power and information an individual consumer can use to shield themselves from activities by companies that are detrimental to them. We are also not expected to test our own food for toxins.
More platitudes and soundbites doesn't have to be the answer to all problems.
More laws and larger governments are generally undesirable (for obvious reasons) but saying that we shouldn't make any laws at all is throwing the baby out of the bathwater.
If you're thoughtful and deliberate about how you write your legislation, you can have a disproportionately positive impact with a very small amount of additional weight.
For instance, instead of trying to enumerate every single way that data could be leaked and forbid that (see: HIPAA), you should just make the end state (PII in the hands of someone the user didn't explicitly authorize it to be in) illegal and mandate a fine per unit of information (e.g. 1% of the median US salary for SSN) to every entity in the leak chain (because a chain of custody for personal information is just about mandatory at this point).
Details will vary, but this general approach is vastly better than the crazy laws we have in other areas that attempt to "enumerate badness" in the intermediate rather than the end state.
tldr: Some of us are tired of fiddling with things where were we shouldn't have to.
<< More laws and larger governments doesn't have to be the answer to all problems.
If market participants can't behave ( and they clearly can't help themselves ), it is the only real answer.
<< If consumers care enough they'll change their usage, if they don't change their usage they likely don't care enough.
Or.. options for consumers are limited, which affects what they do. In all seriousness, streaming execs seemed to admit the ads simply bring more money for them so they don't care if non-ad version is profitable. It is not enough.
My household dropped Netflix and Prime over their silliness. We currently still have Disney until they get too greedy. And that is just streaming. Regular net is soooo much worse without a way to scrub the ads away.
As with this kind of regulations, we now have to wait for the law suits to target a few select large companies, then the courts to reconfirm that the regulations says what it says, and then appeals, and then finally the large companies will pay a large fine and then comply, followed then by the industry in large.
Delay, delay and then delay some more has been the response from the data collection industry for the past 10 years. Same for right to repair regulations and smartphones.
At least ublock origin makes that easy, but it's still ridiculous.
On the bright side, French courts have ruled that this kind of cookie popup is illegal under the GDPR so maybe they'll slowly be destroyed
Maybe check out Brave Browser, LibreWolf or Vivaldi.
Do you have proof for this? I'd be curious. I also fail to see how is that related to the collecting data by default thing. Is that a leftist thing now?
https://blog.mozilla.org/en/mozilla/first-steps-toward-lasti... https://blog.mozilla.org/en/mozilla/leadership/mozilla-racia...
[1] https://blog.mozilla.org/en/mozilla/we-need-more-than-deplat...
> Maybe check out ... LibreWolf
GNU says hi.
https://news.ycombinator.com/item?id=40954535
https://news.ycombinator.com/item?id=40966312
https://news.ycombinator.com/item?id=40952330
https://news.ycombinator.com/item?id=40971247
https://news.ycombinator.com/item?id=40965161
...and probably a few I missed.
Opera? Other recommendations?
Fennec[2], the F-Droid build of Firefox, does have about:config enabled.
[1] https://news.ycombinator.com/item?id=39816429
[2] https://f-droid.org/en/packages/org.mozilla.fennec_fdroid
For those that don't know, Elinks is a text only terminal browser.
I'm sadly falling out of love with the web. So much fun and enjoyment have left the web in the past 20 years and I don't enjoy or to some extend even benefit from the modern hellscape of modern commercial web.
Recommend Mull or something else sensible.
Edit: Whoopsy, oversaw your /jk
Go to: chrome://geckoview/content/config.xhtml then enable about:config after that dom.private-attribution.submission.enabled can be set to false.
> This acquisition marks a significant step in addressing the urgent need for privacy-preserving advertising solutions. By combining Mozilla’s scale and trusted reputation with Anonym’s cutting-edge technology, we can enhance user privacy and advertising effectiveness, leveling the playing field for all stakeholders.
I can only interpret this as the urgent need is money, and wants to sell its "scale and trusted reputation". Mozilla has been down this road before. It was not good for them.
> Anonym was founded with two core beliefs: First, that people have a fundamental right to privacy in online interactions and second, that digital advertising is critical for the sustainability of free content, services and experiences. Mozilla and Anonym share the belief that advanced technologies can enable relevant and measurable advertising while still preserving user privacy.
This is some pretty weak wording for a press release. The economics of the situation are that advertising will always trump privacy. Researchers have successfully de-anonymized anonymised data sets, including medical records. Why would these data be any different?
> As we integrate Anonym into the Mozilla family, we are excited about the possibilities this partnership brings. While Anonym will continue to serve its customer base, together, we are poised to lead the industry toward a future where privacy and effective advertising go hand in hand, supporting a free and open internet.
Anonym’s customers are advertisers, right? The same people who for decades poured money into eroding that free and open internet that we had…
> About Anonym: Anonym was founded in 2022 by former Meta executives Brad Smallwood and Graham Mudd. The company was backed by Griffin Gaming Partners, Norwest Venture Partners, Heracles Capital as well as a number of strategic individual investors.
Well, it seems Anonym, Smallwood and Mudd had a nice piece about them written in the Wall Street Journal [1]. From the second paragraph:
> Graham Mudd and Brad Smallwood each spent more than a decade building Meta’s advertising system, which allowed the company to offer granular data about how ad campaigns worked with individual users, often by tracking their web and mobile activity.
[0] https://blog.mozilla.org/en/mozilla/mozilla-anonym-raising-t...
The companies buying ads aren't keen on privacy, at least not if it comes at the cost of optimizing sales, so I don't see anyone but small "do good" niche companies would buy into what Anonym is selling. Alternatively Mozilla will make money and start relaxing privacy restriction in order to extract even greater profits. I don't see them stopping half-way. The Mozilla leadership has again and again shown that they do not understand their user base.
Firefox is a great browser, but so it all Chromium based browsers. Mozilla apparently never considered why someone might stick with or switch to Firefox, when Chrome, Edge, Safari and other browsers do the exact same thing, sometimes perhaps better. I really want to ask the Mozilla CTO and upper management what they think their product is, because I got a in increasing hunch that Firefox isn't the first thing that would come across their lips.
Personally, right now the only reason I'm not switching to something like Vivaldi is my desire to ensure that rendering engines beyond Blink is represented in statistics.
Yes, this is Cliqz all over again and that scandal cost them most of their German userbase.
I mean, let's imagine this works as explained -whatever, let's imagine it does and with no downsides even-. Now as far as I can understand this aggregate information ends up producing something like "this particular ad placed here ends up producing this number of conversions". Is this really something an advertiser wants to know? Maybe to some extent, but to me it sounds a lot more like something an advertising platform would want to know. Which is why I'm not surprised by Meta's interest.
To me this feels like a good tool to avoid paying small websites at all for just having ads. Impressions would be finally and completely discarded as something payable. Now for the ads on your site to earn you something at all you need conversions that you can now reliably track. For a site owner to be paid, they'd need to increase the CTR; they can't just "provide ad space", they have to work to earn clicks.
So maybe -probably- I'm way off here. Maybe someone can correct me. But as I see this, this tool seems very specifically made for the big advertising platforms.
Safari seems to be the only decent, privacy-focused browser left on the market.
Until the Ladybird arrives.
Safari has Private Click Measurement: https://webkit.org/blog/11529/introducing-private-click-meas...
And AFAICT, Mozilla's implementation is technically superior?
Since this is days old news with lots of discussion (https://news.ycombinator.com/item?id=40952330 and more)
the more recent development is Firefox CTO posting thoughts: https://old.reddit.com/r/firefox/comments/1e43w7v/a_word_abo...
I can't wait for Ladybird to get good, in a decade realistically, swimming against a massive current of Google pushing its unstandardised nonsense on Chrome, and web developers jumping on the bandwagon, making web standards more and more complex by the day so no one ever is able to catch up.
You can add to the dead internet theory the fact that the Web is now maliciously impossible to recreate and access from scratch if you are unable to compete with the billions Google spend to maintain their hegemony. Heck, even Microsoft found it was more efficient to join Google rather than to try and direct what they laughably call "an open standard." There is more competition to build reusable space rockets than in web browsers.
A sad day, and sadder days await us. Shame of Mozilla, and on the CTO trying to sell this feature as a good thing.
I presume you refer to the fact that most income of Mozilla comes from Google paying a fee to have their search be the default. While that is worrysome, it's not control nor ownership. Let alone direct control. At most it gives Google leverage.
I don't see that happening in a decade. What makes you so optimistic?
Honestly I don't have much to add to the conversation. Mozilla made a bad move, Firefox's big thing was privacy and not being Chromium and it's lost the first thing.
1. https://support.mozilla.org/en-US/kb/privacy-preserving-attr...
Because it's very confusing now.
Settings -> Advanced -> Allow Privacy-Preserving Measurement of Ad Effectiveness
More discussion among others: https://news.ycombinator.com/item?id=40952330
Does this new "privacy preserving attribution" feature respect multi-account containers? Or is it somehow not considered necessary, because it's meant to be less invasive than the tracking cookies it's supposed to replace? Call me skeptical for now.
I'm a happy user of multi-account containers, which lets me separate my cookie identities in Firefox. Before, I had to use different browsers for work and private, and yes, it solves this problem, but the best part is that I don't have to worry about tracking cookies, because they aren't tied to my personal accounts: In my experience, I can to a great extent escape the echo chamber I'm in, and the ads I see in it, by just deleting the cookies of my sacrificial default container.
Other than that, considering the status quo – that the web is already an unfriendly GDPR nightmare, I'm positive to the initiative. And because of the power of the default, I can understand that the feature wouldn't likely take off if it was opt-in, so I won't criticize Mozilla for that move either.
Edit: Weird, some people seem to have received more options than me. For me there was just one option to accept (Zustimmen) and nothing else. Everything was in German but I read German anyway. I was on mobile though, perhaps this is why? I can't see it again because I already pressed it.
A practice (pay or accept cookies) which was actually ruled in breach with GDPR but many German sites seem to do this somehow.
I agree with the criticism on Firefox but this is very hypocritical. Heise used to be a good company. I even used to subscribe to C'T and iX.
- does reader view toggle works? if yes, consult, end here
- am I really looking for some information that might be there? if "no I just clicked a link from somewhere on the internet", then end here
- still here? Hey, what about looking at the DOM, if the information looked for is not a simple small segment of text, there are good chances a few CSS/HTML tweak will reveal this. Got it? end here, though you might consider to automate this process with Greasemonkey if this domain often fall in your research.
- no luck so far? It’s ok, you know Internet is vast, there are plenty of other page to visit. WTF are you doing here anyway, don’t you have a job, hobbies and people to cherish? And what about a small walk, you look like you need some fresh air, you know?
No, this part is mandatory:
> Datenverarbeitungen von Werbeanbietern einschl. personalisierter Werbung mit Profilbildung [Zustimmung erforderlich für kostenfreie Nutzung]
Our Data Protection Agencies ruled it okay. There was a recent court case that called it into question again, so we’ll see how things develop.
FWIW, my normal blockers manage to block the heise.de pay-or-track banner, different from, e.g. golem.
- choices presented must have the same visual weight (e.g for buttons)
- there must be no default choice preselected (e.g for radio/toggles)
- the fallback when no choice is made (e.g a dismissal or a "failure to display" a.k.a bug or nag blocker) must be equivalent to deny all
Instead we get this mess because enforcement requires litigation from users and these companies make just enough to claim "oh we thought it was Ok plus we go through a off the shelf pluggable third party so not on us" plausible deniability.
from https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...
> If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.
> Consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment.
from https://www.edpb.europa.eu/sites/default/files/files/file1/e...:
> Example 6a: A website provider puts into place a script that will block content from being visible except for a request to accept cookies and the information about which cookies are being set and for what purposes data will be processed. There is no possibility to access the content without clicking on the “Accept cookies” button. Since the data subject is not presented with a genuine choice, its consent is not freely given.
> 41. This does not constitute valid consent, as the provision of the service relies on the data subject clicking the “Accept cookies” button. It is not presented with a genuine choice.
> The use of pre-ticked opt-in boxes is invalid under the GDPR. Silence or inactivity on the part of the data subject, as well as merely proceeding with a service cannot be regarded as an active indication of choice.
> In the digital context, many services need personal data to function, hence, data subjects receive multiple consent requests that need answers through clicks and swipes every day. This may result in a certain degree of click fatigue: when encountered too many times, the actual warning effect of consent mechanisms is diminishing.
> This results in a situation where consent questions are no longer read. This is a particular risk to data subjects, as, typically, consent is asked for actions that are in principle unlawful without their consent. The GDPR places upon controllers the obligation to develop ways to tackle this issue
Most (all?) companies which developed a browser have lax policies on data privacy. At most those are inline with major directives like GDPR. However, it's not in their best interest to protect / not leverage user data. So the real discussion should've been about the set of features that would attract a sufficiently large user base who would pay ~10$ per month subscription in order to make the model sustainable on the long-term.
https://en.wikipedia.org/wiki/Mitchell_Baker#Negative_salary...
No idea how much the new CEO is being paid. Probably just as bad.
> likewise, agencies within the U.S. government variously fund Tor (the U.S. State Department, the National Science Foundation, and – through the Broadcasting Board of Governors, which itself partially funded Tor until October 2012 https://en.wikipedia.org/wiki/Tor_%28network%29?wprov=sfla1
When it comes to privacy apps, I’d place significantly more trust in something like that than literally anything closed source or unscrutinized to that degree.
There is no negotiating with the advertising industry. No system will stop them from acting unethically to gain an edge.
--
My idea for such a system: random GUID added to each ad. Browser plugin collects GUIDs. Client protects itself with random GUIDs removed and new random GUIDs added. Client sends GUIDs to a Collector they choose. Collectors run client GUIDs against Advertisers lists (bloom filters). Advertisers pay Collectors, and Collectors give to orgs.
Edit: replace GUIDs with 6 random bytes, so the existence of an id is not proof of it's being viewed. it needs to be plausible that the client added an id randomly, and that's not the case with a GUID.
I can sympathise about general usability concerns but they don't really relate to the OP.
I personally run Ungoogled Chromium for anything that doesn't work in LibreWolf, which is fortunately not too much.