Short, we need to ditch chrome, but what is best alternative?
Short, we need to ditch chrome, but what is best alternative?
Or there are a bunch of other options that care about privacy (see https://privacytests.org/). Brave, Librewolf, Arc, Zen, Orion (Kagi's thing). I tried Orion for a few days recently, but it started crashing randomly and felt unstable and slowed down after real-world use (3-6 windows, many many tabs, dev tools, etc).
I really wish there was more competition here from the smaller, privacy focused players...but the reality is building a browser is insanely difficult for the modern web.
And thank WHATWG for making it impossible for indie players to remain compliant with modern standards by turning W3C's eminently reasonable and wholly sufficient specifications into a hulking monstrosity that's simultaneously large enough to be used as a stress test for your mobile browser's rendering engine (seriously. go try to load up 'view-source:https://html.spec.whatwg.org/'. At the time of writing, the HTML for that single-page version is over 98,254 lines composing over 15MB of plain HTML) while simultaneously quite literally being defined as a continuously moving target.
They had other options, including not collecting and selling user data. The California law is working as intended.
Businesses like to avoid risk where possible, and Mozilla's lawyers pushed this wording to ensure compliance with the riskiest possible interpretation of California's ambiguous and poorly-worded law.
Explain how that qualifies under California's law. The requirement that data be shared to another business or third party seems pretty explicit.
The Mozilla Corporation sharing user metadata with the Mozilla Foundation to assist with internal decision making may technically meet California's definition of "sale of data" despite constituting absolutely nothing even vaguely resembling what laypeople would consider a "sale of data".
Note that the CCPA's "third party" clause is part of an "OR" set, alongside "another business". Mozilla Foundation and Mozilla Corporation are respectively "another business" relative to each one's self, despite not being unrelated third parties.
The problem is not that Mozilla is actually selling user data (they're not in the sense that any layperson would understand "selling data" to mean), the problem is the way the California law is worded.
As usual, tech-illiterate politicians aren't even competent enough to write laws with the nuance and understanding required to not botch the entirely good and justified intention without pointing a loaded legal gun at the heads of the genuinely innocent. Think along the lines of the CFAA's legal risks to good-faith security researchers¹, or how the DMCA would technically criminalize discussion of how to decode Pig Latin if that was used as a copyrighted media protection technique.
¹ At least up until the Biden administration instructed the DoJ to be more sane and reasonable about this: https://www.justice.gov/archives/opa/pr/department-justice-a...
It appears you are trying to explain why CCPA's does not meet the laypersons definition of "selling data". After reading your explanation I'm none the wiser. Given no one has replied, I suspect that's true for most people. They've just scratched their head and moved on.
I was about to do that too, when it dawned you probably have no idea people don't understand what you are saying. Maybe an example would help. Its needs top be something a layman would not consider to be "selling data" but the CCPA defines that way.
TLDR: The "OR" was a drafting error that Mozilla erroneously quoted. The final text of the CCPA removed the "another business" part.
> The reason we’ve stepped away from making blanket claims that “We never sell your data” is because, in some places, the LEGAL definition of “sale of data” is broad and evolving. As an example, the California Consumer Privacy Act (CCPA) defines “sale” as the “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by [a] business to another business or a third party” in exchange for “monetary” or “other valuable consideration.”
How is the CCPA stupidly-worded when that's what a layman would think "selling data" means?
I do wholeheartedly agree with your sentiments about the WHATWG though, as someone who contributed to Pale Moon's development. That web browser cartel should be investigated by the US government for anti-competitive practices as they did with Google and Microsoft.
Because it is the twisty logic that lawyers can apply which is relevant to mitigate legal risk, not what a layman would think.
Where I work, our lawyers are convinced that running our code in the cloud to run our service counts as "distribution" under the terms of open source licenses. Because a cloud employee might accidentally look at it or something? Who knows. A lawyer sees legal risk in things you or I don't; they should know I guess!
The Mozilla Corporation sharing user metadata with the Mozilla Foundation to assist with internal decision making may technically meet California's definition of "sale of data" despite constituting absolutely nothing even vaguely resembling what laypeople would consider a "sale of data".
Note that the CCPA's "third party" clause is part of an "OR" set, alongside "another business". Mozilla Foundation and Mozilla Corporation are respectively "another business" relative to each one's self, despite not being unrelated third parties.
The problem is not that Mozilla is actually selling user data (they're not in the sense that any layperson would understand "selling data" to mean), the problem is the way the California law is worded.
As usual, tech-illiterate politicians aren't even competent enough to write laws with the nuance and understanding required to not botch the entirely good and justified intention without pointing a loaded legal gun at the heads of the genuinely innocent. Think along the lines of the CFAA's legal risks to good-faith security researchers¹, or how the DMCA would technically criminalize discussion of how to decode Pig Latin if that was used as a copyrighted media protection technique.
¹ At least up until the Biden administration instructed the DoJ to be more sane and reasonable about this: https://www.justice.gov/archives/opa/pr/department-justice-a...
> As an example, the California Consumer Privacy Act (CCPA) defines “sale” as the “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by [a] business to another business or a third party” in exchange for “monetary” or “other valuable consideration.”
Is actually from a draft. The final version of the CCPA removed the "another business" part which was a drafting error as covered by this article from the IAPP: https://iapp.org/news/a/ccpa-cpras-hidden-third-party-busine...
I will cut Mozilla some slack here because they probably have taken the supposed final text of the CCPA from Wikipedia's article of it: https://en.wikipedia.org/w/index.php?title=California_Consum... (and the website in the infobox still links to when it was an Assembly Bill at https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...)
This is the true final definition of "sale" in California's privacy law: https://leginfo.legislature.ca.gov/faces/codes_displaySectio...
Anyway even then I'm not sure if the Foundation would've been considered "another business", since "business" is defined first as any "legal entity that is organized or operated for the profit or financial benefit of its shareholders or other owners", which MoFo clearly doesn't do. There's the second definition might've covered the Foundation (since they control the Corporation which is covered by the first definition), but AFAIK the Corp doesn't share any consumer personal info back into the Foundation (if it does that would be concerning)
Your attention to detail here is exceptional and commendable. I used to feel that Mozilla's decision here was defensible and misunderstood, but it's now looking more like Mozilla and I are guilty of misunderstanding, after reviewing your claims here.
Thank you for having the patience to explain in such detail! Posts like yours here are part of the magic that elevates HN discussions over so many other forums on the web these days :)
You don't think Mozilla ought to have a firm legal opinion on this that doesn't involve just going to Wikipedia and going "yeah that's good"?
Omfg. You fly-scroll it on mobile as fast as you can and the scrollbar barely moves.
I doubt any privacy conscious people use the default settings… not really relevant it seems to me.
Fast, runs light on battery, i've seen zero ads since using Brave. it's baked in you don't even think about it.
they added some kind of weird stuff like ai and wallets but you dont need to use it or invoke the ui
[1] https://en.wikipedia.org/wiki/Brave_(web_browser)#Business_m... [2] https://en.wikipedia.org/wiki/Brendan_Eich#Appointment_to_CE...
While I don't support Prop 8 personally, I don't think we should judge technical products on political opinions of their author. You may think it's funny to advocate for bans and boycotts, until the other side does it too and we get a world split in 2 (or more).
There is nothing funny here at all. I'm so cynical about all of it that, as a many years long Brave user, I'm actively discouraging people from using it, because if Brave ever has enough users to be a problem for adtech, it will be destroyed. So if the crypto stink or ancient crimes against the progressive project can help forestall this for a few years, then at least they're good for something.
As for Eich and JavaScript; technically, I doubt more that 0.1% of working coders are fit to lace his boots. Myself included.
That seems pretty extreme.
Eh. It's one to not knowingly support a bad person, e.g. if they kept their opinions to themselves. But once an individual has made their positions crystal clear, it's a lot harder to morally support their innovations. Someone can do great work in tech, but if they are a known total piece of shit, I may/probably will avoid their products. I find a lot of tech-types try hard to decouple the humanity aspect from the innovation aspect - I presume this is a veiled attempt to get an "be an asshole" pass. Reality is people won't want to be around us if we suck as a humans, no matter how much code any of us put down.
IMO, calling Brendan evil or bad is the kind of moral shortcut that Progressives love taking. A microcosm of the election, really: all the capable moderates were effectively canceled or marginalized by self-righteous radicals, who deemed that the only "good" candidate was someone who couldn't even win a primary.
It's bad politics and lazy morality.
Mozilla has never used the data you upload/send via Firefox to non-Mozilla websites (as it should be), and they shouldn't have that permission just as Epson the company shouldn't have the right to use for any purpose a paper marked as classified just because some fed employee sent a digital copy of it to an Epson printer.
Just read the terms rather than spread misinformation. That data doesn't leave the user's computer.
Do you just not care what happens to Mozilla? How does it help to spread misinformation about them?
> Mozilla processes certain technical and interaction data, such as how many searches you perform, how many sponsored suggestions you see and whether you interact with them. Mozilla's partners receive de-identified information about interactions with the suggestions they've served.
> Depending on your location, Mozilla derives the high level category (e.g., travel, shopping) of your search from keywords in that query, in order to understand the types and number of searches being made.
> Mozilla may also receive location-related keywords from your search (such as when you search for “Boston”) and share this with our partners to provide recommended and sponsored content.
Your claim "That data doesn't leave the user's computer" is simply not true. Mozilla isn't selling empty files to their advertising partners. The only true and valid defense you've put up for Mozilla in the past week is that they're trying to anonymize the data before they sell it, but that's not nearly as strong an argument as you seem to think it is.
You are focused on some concept of perfect confidentiality, which is not how real engineering or confidentiality works.
I'm not interested in your personal comments. Keep them to yourself.
You said "That data doesn't leave the user's computer". It does. You may not consider it personal or valuable and may trust Mozilla's anonymization to be sufficient, but well-written privacy laws rightly do not grant Mozilla (or anyone less trustworthy than Mozilla) that kind of wiggle room.
Ladybird isn't even targeting an alpha release until 2026.[^1]
The Browser Company has basically decided to kill off Arc in favor of...Dia, whatever that is/will be.[^2]
And Brave...oh Brave. Too much controversy there over the years to be interesting, honestly.
Tier 1 is actually just Firefox, maybe Safari if you only care about MacOS/iOS.
Interesting up-and-comers are Orion and Ladybird, but both are far from "tier 1" currently.
[^1]: https://ladybird.org/
[^2]: https://www.diabrowser.com/Arc is kind of promising, but I never really tried it after discovering that it's the only browser I've ever seen that requires (!) you to have an account with them. The obvious next question is 'what for?'
[1] - https://reddit.com/r/browsers/comments/1j1pq7b/list_of_brave...