Help EFF test Privacy Badger, our new browser extension for privacy
eff.org
eff.org
Spent hours after hours at not only making it work, but also making it work efficiently (wrote custom ABP engine from scratch which doesn't suffer the real one's abuse of memory/CPU), and yet barely anyone is noticing it.
EFF is also one of the recipient I suggest for people who really want to donate something for my work.
In any case, an important warning concerning any extension which modifies HTTP headers on Chromium-based browsers: only one extension is allowed to modify the HTTP headers[2], and since EFF's badger does modify outbound request headers, it will break any previously installed extension which relies on also modifying these headers to work properly.
This means mine[1] is incompatible, one of the two extensions won't be able to do what it says it does. This applies for any other extension modifying outbound HTTP headers.
[1] https://github.com/gorhill/httpswitchboard#http-switchboard-...
[2] https://developer.chrome.com/extensions/webRequest#implement...
I just installed your extension and it looks pretty slick so far! I had been using RequestPolicy, CookieMonster, and NoScript on Firefox to do something similar, but wasn't aware of something like RequestPolicy for Chrome. Your extension fits the bill nicely.
Couple questions:
* Your documentation says "Efficient blacklisting ... javascript won't execute". Is this because you prevent the request altogether or do you somehow allow the Javascript to be fetched but then sandbox it or something? The latter seems brittle and prone to issues (tptacek's warnings about security/javascript in the browser come to mind).
* The control panel seems to let me block scripts from the domain I'm actually on (so, not a 3rd party request). Does this include inline script tags in the HTML? Obtrusive javascript via "onclick=..."? Last I checked, I thought Chrome didn't give you hooks to be able to stop, with an extension, the evaluation of scripts. In fact, that's why I've been using Firefox w/ NoScript, since I didn't think Chrome could match it. Is that not the case?
* When I search Google (but no other page), it seems to flash and reload since installing the script. What's that?
Thanks for your hard work on this! I appreciate it a lot.
Regarding javascript execution there are two cases:
External javascript: won't execute because the net request for the external resource is blocked.
Inline javascript: won't execute because a Content-Security-Policy directive is injected into the main page or sub frame.
This week I had to write an explanation of how this work because the idea that inline javascript can't be reliably disabled on a Chromium-based browser is still going strong. Here are the details:
https://github.com/gorhill/httpswitchboard/wiki/Blocking-jav...
Regarding the "flash and reload", I noticed that too lately, I have to look into this to understand what is happening.
One last question (sorry!): I just used the "Google" preset configuration to load gmail and it all just worked. I'm still trying to get the hang of interpreting the grid, but at the top left I see in blue ".google.com". Does that mean these whitelistings only apply to pages in a Google subdomain? For example: google analytics requests from some other* domain aren't whitelisted?
Yes, the top-most left-most box is for choosing where the rules apply, I call it the scope selector.
"" = global scope
".example.com" = any web page which sits on 'example.com' or a subdomain of 'example.com'
"example.com" = any web page which sits exactly on 'example.com'
If multiple scopes exist for a given web page, the most narrow one is used. Also, scopes are really sandboxes, there is no inheritance of rules across scopes (trying to implement this is opening a can of worms both on usability and code-wise).
Man, I'm sure that must be really frustrating. It looks like your tool takes a different strategy than EFF's and there will be room for both -- I hope you keep it up.
As a general perspective (not just directed at you, gorhill), it's worth bearing in mind that the EFF has earned their clout by working hard and getting results since 1990 -- almost a quarter of a century. You can think of them like a startup founder who has a lot of money and connections to launch new companies, because she's been building winning companies for decades and built up those resources. For her, backing a new project means betting some of that capital. For you, starting on your own without that kind of track record means you'll have to hustle longer and harder to find success.
This analogy is particularly helpful if you (again, not just gorhill) actually do want the EFF or a similar organization to back your project. That startup founder is going to be constantly getting pitches from people who want her time or attention or just money. The ones she'll want to help will be the ones she knows and trusts because they've helped her out before.
That makes projects like this Badger thing a great opportunity to get involved with an organization -- they're asking for your help. It's a chance to prove you have the coding skills/social skills/enthusiasm/values/reliability/whatever that make you a good fit. Then when you're starting your own project, they'll be relatively likely to put some of their reputational capital behind it.
gorhill, there are very few people who are both interested in and qualified for building software of this sort. You've essentially just proven to the EFF that you're the exact person whose help they should want with this, so you have an opportunity to join forces with them and build not just an amazing product, but an amazing product that does exactly what you originally set out to do!
This is the same principle behind so-called talent acquisitions ("acquihires"); the difference here is that we're talking about a non-profit organization and two open-source projects, so there's even less friction in joining forces. And more importantly, you can always change your mind if you ever decide to. Nothing holding you back!
- One of the Privacy Badger devs
Also, it caused some of my pages to stop working which I know aren't doing anything odd (internal helpdesk software).
https://github.com/gorhill/httpswitchboard/wiki/How-to-use-H...
At one end of the spectrum, the extension can be used without no filtering of any kind, and the user still has a comprehensive reporting tool to see what a web page does.
>function addLoadEvent(func) {
> var oldonload = window.onload;
> if(typeof window.onload != "function")
> window.onload = func;
> else
> window.onload = function() {
> oldonload();
> func();
> }
That's awesome! At Mozilla we've been daydreaming about incorporating something like that into the product. Especially with the proliferation of both in-browser content policies (CSP, Mixed Content blocking, etc.) and out-of-browser content policies (addons like Privacy Badger, ABP, Ghostery, etc.) it's almost impossible to understand the root cause of what's breaking a page, especially if you're not a technical user.
> but also making it work efficiently (wrote custom ABP engine from scratch which doesn't suffer the real one's abuse of memory/CPU)
For the Firefox version of Privacy Badger, we also eschewed the ABP engine in favor of something we wrote ourselves. Don't get me wrong, ABP is a great tool and we learned a lot from its code - but we wanted something as lean and performant as possible. I'd be interested to see the approach you took!
> only one extension is allowed to modify the HTTP headers
> it will break any previously installed extension
That sounds like a shortcoming in Chrome's Extension API. Firefox is somewhat better in that we do not restrict addons based on the behavior of other addons, so multiple addons are allowed to modify a request's headers. Unfortunately, the order in which the request is passed from handler to handler is not guaranteed, so in practice this may not end up being so useful.
We're trying to improve this situation by rewriting the Gecko Content Policy API [0], but that's a large project with no clear deadline.
[0] https://groups.google.com/forum/#!msg/mozilla.dev.platform/v...
Generally I think your addon and Privacy Badger are targeted at different audiences and have different use cases. It is too bad they are incompatible with each other - I, for one, would like to have both installed. Perhaps we can resolve this by talking to the Chrome devs about their Extension API?
- One of the Privacy Badger devs
I usually ask people to at least read this one page [1], not to convince them, but rather just so that it is understood that the extension is fully configurable: it can be at any point in the full block-all / allow-all spectrum.
[1] https://github.com/gorhill/httpswitchboard/wiki/How-to-use-H...
I just added a 3rd example of how the extension can be used without blocking anything, while still reporting everything. If anything, this can be useful to keep the other privacy extensions open for scrutiny.
It's maintained by EFF, and more things will get added as time goes on.
Luckily this was a one-line patch: https://github.com/EFForg/privacybadgerfirefox/pull/63 (though in the future, it is better for the whitelist to have wildcards in the cases where it's necessary).
Thanks for testing. Really helps a lot.
Disclosure: I didn't work on Privacy Badger Chrome but at least I can fwd you on to the right people. :)
Sorry, that does sound frustrating. I joined EFF partly because it was a good way to make software that people would actually use.
(One constraint that most people may not realize is that EFF has very strict privacy policies for our tech projects. There's lots of projects I'd like to do, but the lawyers probably wouldn't approve. So there's plenty of room for other developers to do projects that step over lines we wouldn't cross.)
That said, you talk about all the effort that went into building it only to have nobody notice it...I have to ask, how much time did you put into promoting it and how did you approach that?
I don't intend for this to come off rude, but if you didn't do much to promote it, is it possible there's a bit of "Field of Dreams" syndrome at play here (the "if I build it they will come" fallacy)?
Regardless, I think there is a lack of trustworthy and well-known resources for getting the word out about new advancements in the privacy space like yours. I'm in the digital media world, and while I'm acutely aware of this stuff, I'm unaware of any sites that serve that purpose.
I'd love the EFF to put their weight behind a list of trustworthy add-ons that they inspect and maintain (in addition to theirs) since this needs to be a larger effort than they alone have the resources for. The big problem is getting the public more aware, and they are one of the best loudspeakers for that at the moment.
--
[1] For example, consider what happened with Adblock Plus. For years, it blocked all ads, but then in 2011 its developer announced it would allow "acceptable ads" by advertisers who had partnered with Adblock Plus. (For the details, see http://en.wikipedia.org/wiki/Adblock_Plus#Controversy_over_a... ) The EFF is extremely unlikely ever to do something like that.
"Advertisers and other third-party domains can unblock themselves in Privacy Badger by making a strong commitment to respect Do Not Track requests."
https://www.eff.org/dnt-policy
Quote:
What does the dnt-policy.txt promise mean?
Posting the dnt-policy.txt file makes a promise to the users who interact with their domain. We [EFF] believe it would be a false and misleading trade practice to post the policy without the intent to comply in good faith. However, EFF is not in a position to enforce this promise or monitor compliance.
I don't want it to be a negotiation between the EFF and a website as to the state of my privacy - I want the final say in who is going to be trusted.
When you click on the plugin icon in the browser toolbar, a popup box displays all the trackers Privacy Badger has found. There is a slider next to each tracker, with three states, green, yellow and red. Red means blocked.
As Privacy Badger works, it moves the slider for a tracker when it notices it following you across domains. But you can still manually drag the slider across to Red if you want.
This really reminds me of the early years of antivirus on Windows, when you needed at least two antivirus suites to catch everything. Just as vendors eventually acknowledged (mostly) their responsibility for security on their OSes, browsers need to step up and start implementing these features by default, and innovating. It's crazy that, at the moment, I have to grant a third party total and unlimited access to my browser and history in order to protect my own privacy.
This should be on, by default, since most people are generally either adamantly against being tracked or ignorant of it and their options.
The handful of people that have a hard-on for targeted marketing should be ticking checkboxes in preference panels and installing plugins, not people who would rather Neilson not know everything about them...
> Is Epic Open Source?
> Yes! Epic is open source software. Chromium which Epic is built on is also open source software. We haven't had a chance to formally release Epic's source code because we've been giving 200% to get the product ready, and Chromium is a HUGE code base so to release it in an organized way will take a bit of effort. That being said, if you want to know anything about Epic's changes to the core Chromium, if you want any files, any code, anything at all, just write us and we're happy to get it to you. We will be releasing all the code in organized git repository soon as well -- sorry for the delay.
However, please note that Epic uses a builtin proxy. Also from the faq:
> Who powers Epic’s proxy service?
> Spotflux at present powers Epic’s proxy.
2. Source Code
The program must include source code, and must allow
distribution in source code as well as compiled form.
Where some form of a product is not distributed with
source code, there must be a well-publicized means of
obtaining the source code for no more than a reasonable
reproduction cost preferably, downloading via the
Internet without charge. The source code must be the
preferred form in which a programmer would modify the
program. Deliberately obfuscated source code is not
allowed. Intermediate forms such as the output of a
preprocessor or translator are not allowed.
So it really depends on your interpretation of "well-publicized means of obtaining the source code". I don't think I would label a "send us an email and (maybe) we'll give you the source or the patches) as Open Source, mostly because if a company doesn't already have their source in the open, they don't want it in the open, doesn't matter what they write on their site.Of course my willingness would vary depending on the project, community, features, stability, etc... but there's precedent. I've had no problem donating similar amounts to browser projects in the past, or smaller amounts (+/- $10) to privacy plugins (Adblock, Disconnect).
As a mac user, it's Safari, Chrome, or Firefox. All three are to varying degrees beholden to advertising powers who want my data, and aren't going to challenge the status quo in a major way. That needs to change, and I'd be willing to support that.
Simplifying, 39% of the world's 7.1bn population is using the internet [1]. That's 2.8bn people. Opera, the least popular major browser, has a 1.8% market share [2].
If the $40 browser could match that share, it'd be a $2bn p.a. business.
Why hasn't it happened already? Are we so enamoured with "free" software that this couldn't get off the ground?
[1] http://en.wikipedia.org/wiki/Global_Internet_usage [2] http://www.w3schools.com/browsers/browsers_stats.asp
Microsoft has traditionally been in the business of developing and selling user-centric (as opposed to advertiser-centric) software. Why wouldn't they develop a user-centric browser and sell it like they do the Office products? I'm genuinely wondering. Would it be hated by developers as it'd limit their earning opportunities?
Opera's market share has been both increasing and decreasing over the last few years[1] but it looks like it is taking market share from IE users and more people are switching to chrome. So I would predict Opera's share would go down in the future.
The big questions for me, would then be: What am I getting from a browser that I pay for over a free one? Can I get the same features out of plugins for a more widely adopted (and hence better supported or developed for) browser?
Microsoft is really business and student oriented with the majority of their products. A browser only matches part of their design goals. They want people to keep paying for their OS and don't want products to migrate to the web where they have to compete with Google (Though they already have to do this to some extent).
Don't get me wrong, I would be personally interested in something like this but don't believe that many people outside of developers (and people doing criminal things whether moral or not) would be.
Not sure what you mean with the last point/question. The market share would be decidedly small, it likely wouldn't be developed for (unless it used a major library like webkit) and most business people wouldn't notice much difference in their ad-based revenue from such a small market share.
Sexual orientation? Medical records? 24/7 location tracker? Banking status? Purchase records? All private correspondence? Check all, and you get a nice fast browser in the phone with integrated e-wallet, e-medical, e-dating, and email.
When you ask how much someone is willing to pay for their privacy, we are comparing a product with uncertain hidden cost vs informed priced products. The result will always end up the same: you get lemons until the information asymmetry is solved.
for example:
https://en.wikipedia.org/wiki/FTP_clients
https://en.wikipedia.org/wiki/Comparison_of_numerical_analys...
If this is for average users, something like "Privacy badger stops advertizers from secretly tracking your movements and activities online" be better. "browser-add[sic] on tool that analyzes sites to detect" etc. etc. is too complicated, people won't read it IMO.
"When you visit websites, your copy of Privacy Badger keeps note of the "third party" domains that embed images, scripts and advertising in the pages you visit. If a third party server appears to be tracking you without permission, by using uniquely identifying cookies to collect a record of the pages you visit across multiple sites, Privacy Badger will automatically disallow content from that third party tracker."
Words you probably shouldn't use for a layperson friendly explanation: embed, script, server, disallow, "third party" (without explaining precisely what you mean in this context). The top question on the should be broken out into a "how does it work (generally speaking)" and "how does it work (more technical)." I'm afraid people will get stuck on that say "this is too technical" and not read the rest.
"When you see an ad, the ad sees you. When the advertiser 'sees' you it sees what site you are on when you view the ad. This information can be used to build a profile about you: where you shop, what blog or news sites you read, what forums you post on, etc.. Privacy Badger stops your browser from requesting the ads, so the advertiser never 'sees' what sites you're visiting.
When you see an ad, the ad sees you... Privacy badger stops you from seeing the ad and stops the ad from seeing you!!"
Ideally you'd just copy this: http://donttrack.us/ but specifically for ads.
On the other hand, EFF's fanbase is generally very technical compared to the average person and I'm sometimes afraid of coming off as imprecise or belittling to them. Striking the balance is hard.
There are many trackers that are known in advance and there is no need to analyse them. Stop them right away.
New ones crop up, or old ones change domains, watch them and block them.
And randomize my headers so even if cookies are blocked, they can't fingerprint me statistically.
Btw. what is the point of Privacy Badger without the Do Not Track header?
https://www.dephormation.org.uk/?page=81
Just bear in mind the default installation can break some pages (Soundcloud) or worsen your user experience (many web sites, Google, Wikipedia or Ars Technica among others, redirect you to the mobile version if you have a certain user agent).
> Btw. what is the point of Privacy Badger without the Do Not Track header?
Not sure I understand. Privacy Badger Alpha currently sets the Do Not Track header on all requests.
People keep confusing the adserving/retargeting sector with the identity-sector (Google, Facebook). Identity (centralized) vs anonymous (or decentralized) is an important debate. But the adserving industry are not picking sides in that debate. they don't want your name, and they are not keeping any data any milisecond longer than required, because it's all low-margin: costs matter a lot.
People want all their content for free. People don't want annoying popups all the time. So when you look at some product, you get a cookie. That product-id and the cookie-id (that refers to your browser, not you) go into a typical cassandra or redis cluster for about 30 days. Then they are deleted.
End result: (1) your content is free (2) you are not drowning in ads (3) your privacy was not violated. Nobody in _this_ sector wants to store your personal stuff.
People should be concerned about what identity-providers (like Google or Facebook) do with your information. And people should be very wary of identity-providers where you are not the customer. But pure adserving companies, the ones targetted with this tool, were never messing with your privacy in the first place. All tools like this do, is put websites out of bussiness.
Can the intelligent people in HN please start getting more informed about the difference between these two sectors?
Retargeting-sector ==> Be anonymous, see few ads, get free content. Low-margin, technology-driven.
Identity-sector ==> Give all your info, see lots of ads, spam your friends. High-margin, social-life-extortion-driven.
And maybe, not freak out so much about 'retargeting'. Retargeting is fine: its why so much of the internet is free. It funds many YC companies (like Reddit). Just don't ever deal with identity providers who also sell ads. But that's about 10 scripts of the thousands that are blocked by this tool.
Can you blame them when the latter keep buying the former? Google bought Doubleclick. Twitter bought MoPub. Facebook bought Atlas. And so on...
To block tracking background requests:
-> RequestPolicy: https://addons.mozilla.org/en-US/firefox/addon/requestpolicy...
To block ads/trackers:
-> Adblock Edge: https://addons.mozilla.org/en-US/firefox/addon/adblock-edge/
To eliminate tracking via cookies/persistent Flash cookies/Localstorage:
-> Self-Destructing Cookies: https://addons.mozilla.org/en-US/firefox/addon/self-destruct...
The other two however, go for them, they're not intrusive to the user experience at all in my experience.
Is there a reason why you suggest Adblock Edge instead of Adblock Plus?
Adblock Edge is not known to have such issues, as of yet.
Personally, I'd rather call the usual +/- 20 background requests per page (of which each company may track you) "intrusive". But I suppose that's a matter of preferences.
EDIT re: Adblock Edge instead of Adblock Plus:
Adblock Plus has sold out, taking money for unblocking certain ads.
For those who don't know, Request Policy (RP) simply blocks requests outside the website's domain. I configured mine to deny all requests unless I whitelist them (by hostname). It eliminates most security issues; Ghostery rarely has to block any trackers, for example.
I would never recommend it for a typical end-user; it requires too much understanding (e.g, to understand enough about CDNs to identify which hosts need to be whitelisted). For most people reading this, it would be no problem.
It comes with large, pre-configured whitelists that cover many common websites. Many sites work fine without anything whitelisted, though most need at least one host for their CSS. More complex sites, such as those running applications, can take some effort to get running. Once you figure out a site, RP remembers the whitelist and the site works indefinitely.
The interface needs work but it's functional. There is a beta of a new version, which is supposed to fix some interface issues, but I haven't tried it.
https://addons.mozilla.org/en-US/firefox/addon/smart-referer...
The results are meant for a github page, but I decided to present them here, and I reformatted specifically to be HN friendly (hopefully).
In short, any of the following blockers help a lot against no blocker at all. Some are less likely to break web pages, while some other are more likely, and every users have their own requirements when it comes to striking balance between privacy and convenience. This is for information purpose only, not to make a statement that one is better than the other. With the proper information, people can make an informed choice according to their own prerogatives.
I ordered the list by the amount of distinct domains which are "touched". I figure the more distinct domains are touched, the more metadata is leaked to different parties. The format of the results is n / N, where n is the number of distinct 3rd-party domains, and N is the total number of distinct domains.
"3rd-party" is from a DB-less machine point of view, i.e. if a domain name differs from the one of the URL of the page, it is deemed 3rd-party. Despite this caveat, I think this still allows to compare blockers between themselves for the same benchmark ran inside the same narrow time frame.
Benefit to the users: It's nice to see privacy becoming more and more a top issue and more and more choice to address this particular problem.
So here:
No blocker
Domains: 420 / 421
Hosts: 641 / 720
Scripts: 518 / 641
Outbound cookies: 263 / 341
Net requests: 2,079 / 2,849
Privacy Badger 2014.5.1 (BETA) Domains: 192 / 193
Hosts: 299 / 381
Scripts: 334 / 455
Outbound cookies: 52 / 115
Net requests: 1,340 / 2,176
Disconnect 5.17 Domains: 93 / 94
Hosts: 171 / 248
Scripts: 262 / 385
Outbound cookies: 19 / 83
Net requests: 1,124 / 1,936
HTTPSB 0.9 Allow-All/Block-Exceptionally Domains: 54 / 55
Hosts: 101 / 153
Scripts: 169 / 265
Outbound cookies: 2 / 43
Net requests: 930 / 1,648
Adblock Plus 1.7.4 Domains: 54 / 55
Hosts: 97 / 149
Scripts: 177 / 272
Outbound cookies: 1 / 33
Net requests: 913 / 1,612
Ghostery 5.2.1 Domains: 52 / 53
Hosts: 99 / 160
Scripts: 173 / 286
Outbound cookies: 8 / 47
Net requests: 966 / 1,722
HTTPSB 0.9 Block-All/Allow-Exceptionally Domains: 21 / 22
Hosts: 49 / 75
Scripts: 0 / 0
Outbound cookies: 0 / 0
Net requests: 680 / 1,199
[1] https://github.com/gorhill/httpswitchboard/wiki/Comparative-...My challenge is that I looked at this data and the web page on Github and I may not be the sharpest tool in the shed but I'm not certain how to interpret the data and understand the real world implications. On the GitHub page it states that "The most important figure in my opinion with regard to privacy is the 3rd-party Domain count" which is a good hint but if I look at Disconnect 5.17 for example I see 93/94 which is "3rd-party count / total count". What, exactly does that mean? Does that mean for the 15 web sites visited that 93 http requests were from 3rd parties and only 1 from a first party? And that with the specified tool it is blocking those 93 requests?
Thanks for any additional explanation.
So if you're testing Privacy Badger on a profile with no browsing history, it is bound to do worse than other extensions. You have to "prime" it with some browsing data before it's really effective.
In Firefox, PBadger Alpha doesn't have permission to operate in Incognito mode yet, so it will just be off.
[1] https://github.com/gorhill/httpswitchboard/wiki/HTTP-Switchb...
Wasn't there already plans to "block" third party cookies from being delivered as standard anyway, when the top level site domain changes?
Probably if all third-party cookies are blocked, then Badger doesn't have anything to work with.
It's overall a fun job. I wrote most of Privacy Badger Firefox with help from Mozilla folks in the last two months, and it's very satisfying to see people using and reporting bugs in the software that I made almost immediately after launch. :)
"In some cases a third-party domain provides some important aspect of a page's functionality, such as embedded maps, images, or fonts. In those cases, Privacy Badger will allow connections to the third party but will screen out its tracking cookies."
This pull request will also apply the whitelisting to subdomains of the domains on the whitelist: https://github.com/EFForg/privacybadgerfirefox/pull/63.
Unfortunately blocking all those sites and making users whitelist them manually is a lot of work for most users. So we ship a whitelist.
I fully intend to contribute to my browser's extension's repository. I hope other developers on HN will join me.
Fixed that for you :)
http://www.wired.com/2009/08/you-deleted-your-cookies-think-...
One current option: https://addons.mozilla.org/en-US/firefox/addon/betterprivacy...
Or just use click to play to activate flash on your browser, at least then they can't be set anywhere in the background.
> Does Privacy Badger contain a "black list" of blocked sites?
> No, unlike other blocking tools like AdBlock Plus, we have not made decisions about which sites to block, but rather about which behavior is objectionable. Domains will only be blocked or screened if the Privacy Badger code inside your browser actually observes the domain collecting unique identifiers after it was sent a Do Not Track message. Privacy Badger does contain a whitelist of some sites that are known to provide essential third party resources; those sites show up as yellow and have their cookies blocked rather than being blocked entirely. This is a compromise with practicality, and in the long term we hope to phase out the whitelist as these third parties begin to explicitly commit to respecting Do Not Track.
This is an alpha release; we've been using it internally and don't think it's too buggy. But we're looking for intrepid users to try it out and let us know before we encourage millions of people to install it. If you find bugs, you can file them on github against either the Firefox or Chrome repos as appropriate.
> How is Privacy Badger different to Disconnect, Adblock Plus, Ghostery, and other blocking extensions?
> Privacy Badger was born out of our desire to be able to recommend a single extension that would automatically analyze and block any tracker or ad that violated the principle of user consent; which could function well without any settings, knowledge or configuration by the user; which is produced by an organization that is unambiguously working for its users rather than for advertisers; and which uses algorithmic methods to decide what is and isn't tracking.
> Although we like Disconnect, Adblock Plus, Ghostery and similar products (in fact Privacy Badger is based on the ABP code!), none of them are exactly what we were looking for. In our testing, all of them required some custom configuration to block non-consensual trackers. Several of these extensions have business models that we weren't entirely comfortable with. And EFF hopes that by developing rigorous algorithmic and policy methods for detecting and preventing non-consensual tracking, we'll produce a codebase that could in fact be adopted by those other extensions, or by mainstream browsers, to give users maximal control over who does and doesn't get to know what they do online.
I can't speak for anyone else, but I'd be happy just to have a version of Firefox that didn't leak memory like a sieve and become unusably laggy after a day or so. Strangely enough, though, Mozilla's "research", which is nothing more or less than a "click this or this or this" sort of poll, doesn't offer any option for "I'd like your product to suck less please".
Naturally, I've grown quite accustomed, in those rare cases when I muster the temerity to express this opinion, to being shouted down for it. I am surprised to see that happen on Hacker News, though; on 4chan it'd be de rigeur, of course, but I expected better here. I don't know why, though; after all, it's precisely the same attitude which characterizes Mozilla's approach to bug reports.
The memory issues are bad, but only apparent with you have lots of tabs open for long periods of time. I can at times have over 50 pages open and it is around this time things start to crash. Why 50 pages at one time? Well that is how i use my browser. Also the fact that firefox still does not have its tabs on their own threads is frustrating for these crashes as it takes out all tabs, where as sometimes when chrome crashes you don't always lose everything.
Anyway FireFox is a great browser just wish they stopped following the chrome team around like lost puppies.
[1] I probably restart or crash once or twice a month.
But my main point is, with hundreds of millions of users, what are our anecdotal experiences worth?
To Mozilla, any user's experience means little enough at best. On the other hand, any user's "anecdotal" experience of how well Firefox works, or doesn't work, means a hell of a lot to her.
1. Many of Firefox's stability issues are due to 3rd party components (plugins and addons). I recommend disabling all of them, restarting the browser, and seeing if the issues persist. You can then selectively enable (or click-to-play, for plugins) them to improve your experience while maintaining stability. 2. You could also try a profile reset [0], which tends to magically fix some problems (especially if you've had the profile for a while).
[0] https://support.mozilla.org/en-US/kb/reset-firefox-easily-fi...
On the other hand, per a decision made a couple of years ago, I also stick with the ESR release track rather than keeping up with the mainstream releases, because I got tired of having to restart for updates even more frequently than for performance reasons, and also of having the user-interface tablecloth yanked out from under me every time the major version changed -- on that latter point, incidentally, if I want Google Chrome's UI, I know where to find it.
It's possible that running Firefox 24 ESR means I've missed out on some recent stability and performance updates, although I had the impression that both sorts of fixes were generally backported to the ESR branch; given my prior experience, I'd be astonished (and delighted) to see those missed updates make a major difference, but who knows? Perhaps in June, when Firefox 31 ESR drops, I'll find myself astonished and delighted.
I appreciate that it is frustrating when your browser is misbehaving, but your generic complaint "my browser leaks like a sieve!" cannot possibly garner anything other than generic suggestions. Memory issues can be caused by buggy websites, websites that use some feature that Firefox implements poorly, addons, plugins, buggy graphics drivers, and so on. Issues that come up after days of heavy browsing can be particular hard to diagnose.
> although I had the impression that both sorts of fixes were generally backported to the ESR branch
ESR mostly just receives security updates, plus the occasional crash fix.
The poll in question: https://webwewant.mozilla.org/
Privacy may very well be the top issue on users' minds, but calling this evidence seems a stretch.