Unless you want to remove WebRTC and that's just stupid.
Fortunately it can be toggled off in about:config easily.
Set loop.enabled = false to disable hello, set media.peerconnection.enabled = false to disable WebRTC. If you don't want pocket, set browser.pocket.enabled = false.
You can even make yourself one big user.js file to fix the bad ideas that have been added to Firefox lately. Mozilla still has a good thing going for them, and that is user choice. However stupid the defaults get.
Off should be default. Let those that want to use these features turn them on if they want. Or better yet, ship a damn extension.
I'm a Pocket user, but I have no idea why that needed to be integrated into the browser, seems like an insane decision to me. I hope they got a good pay day out of that.
Same as the history based advertising tiles. Sure, it's checked locally, it still seems creepy and annoying... but again, browser.newtabpage.enhanced = false.
Unless we lose this level of user choice, I don't see a better alternative. It would be nice if someone would ship some tool to automatically update a user.js file, however, I think many of us have different opinions about what feature we do and do not want enabled in our browsers.
Off by default is neither removing user choice, nor is it preventing Mozilla from saying they ship with feature X. It is the right way to present it.
It lets more sophisticated users choose. Less sophisticated users however will more likely switch to a different browser the moment a site doesn't work before poking through settings.
I think a better way than a separate setting would be to go in the direction of many software firewalls and present it to the user as a choice when an application requests it as many browsers currently do with the location APIs. This would provide individual domain-level control over what permissions sites are granted by you. I don't know why this sort of policy seems to be restricted only to the location APIs...
Before, mozilla was implementing their own pocket competitor. Switching to pocket, and existing solution, allowed them to save money.
Firefox doesn't even predefine some of the things in "about:config" that need to be set to turn off some of these undesirable features.
There's IceCat, a GNU fork of Firefox without all the proprietary extensions.[1] It may start getting more traction as Mozilla puts more junk in the browser.
These things are lazy loaded and wont run until you turn them on. No footprint when they're off the UI (minimal footprint when they are on)
I still think WebRTC enabling peer to peer connections is better than running all of your data through a third party server.
Extremely few people have active IPv6, it seems unlikely to catch on now. In addition to that, IPv6 privacy extensions may allow a solution to this problem for many users, but if their link local IPs are also published that may lead to further trouble, depending on configuration. Remember though, this leaks all interface IPs, I have many virtual machines installed with their own network adapters added to my system, VPN adapters, etc which also leaks data as all of those adapters will have v6LL IPs on them even if they're not in use.
Additionally, this issue is already actively being used for fingerprinting. Not some exploit of tomorrow. There was a New York Times advertiser caught doing it a few days ago.
> I still think WebRTC enabling peer to peer connections is better than running all of your data through a third party server.
Yeah, which is why I encourage disabling it completely. Until either they fix the privacy issues or the value of using some WebRTC application appears to trump them to you.
Except that over 20% of the United States has IPv6 connectivity. In fact, you might be using it without knowing (most mobile providers have it now, in fact some use IPv6->IPv4 translation methods) [1].
>Remember though, this leaks all interface IPs
Does it? Maybe you should file a bug so that only routable interfaces and non-LL IPs are used. This does seem like a problem.
[1] https://www.google.com/intl/en/ipv6/statistics.html#tab=per-...
The entire rest of the world has near-zero, just look at your own link. I'm in Canada and we have 0.55% here. No local ISP will offer it to me, and the one that did withdrew it completely last year. So perhaps I'm just slighted. There are a few other countries with 5%+ but it still makes up only a very small percentage of internet users. To top it off, while there has been some IPv6 adoption in the US, CGN has also caught on pretty heavily all over the world and seems to be, sadly, the solution most ISPs will actually go with for the near term at least.
> Does it? Maybe you should file a bug so that only routable interfaces and non-LL IPs are used. This does seem like a problem.
https://diafygi.github.io/webrtc-ips/ is able to immediately reveal all the VM interfaces on my system even with no VMs using them. I suspect this is done so that faster routes may be established, but it is indeed a major problem for anyone who doesn't like fingerprinting.
IPV6 isn't going anywhere: IPV4 exhaustion is a real concern and with the internet / internet of things growing, the only place to grow is really the IPV6 space. NAT only delayed the inevitable.
See here - https://ipv6.he.net/statistics/ - for current statistics on how many IPV4 addresses are left.
(And of course I go against the public opinion here on HN, but I wonder how many people did actually use Pocket before trashing it?)
I'd reinstall the old one but "This add-on has been removed by its author".
2) Click "Customize"
3) Drag pocket and / or hello from the tool bar into "Additional tools and features"
4) Take a breather, phew that wasn't too hard was it?
https://support.mozilla.org/en-US/kb/customize-firefox-contr...
If a masochistic user wants to navigate the labyrinth of dark patterns meant to confuse them into not understanding that the "Additional tools and features" category is also the "completely disabled features that run nothing in the background" category (why would anyone think that, ever?), then they can go ahead and do it. If these things are so great, then I'm sure users would be happy to put that extra work into enabling them. After all, it's 3 simple intuitive steps!
I've been using Pocket since it was Read It Later and I was pleased to see it integrated into the browser. Mozilla is working on a Reader mode[0] but it does not seem to be ready for public consumption yet (despite landing in 2012). Most people don't even know it exists, and it obviously does not save it for later (unless you bookmark it). The implementation is open-source (MPL license), although Pocket itself is proprietary. Hotword detection is not absolutely necessary for browser functionality, yet I hear no chorus of complaints from Chrome users. Should Mozilla be prohibited from partnering with proprietary third-parties whether or not it benefits their users?
Hello is even less of an argument. Firefox Hello is a simple Javascript UI for the existing WebRTC spec supported by Firefox, Chrome, and Opera[1]. It allows people to communicate without having to set up accounts, sign-in somewhere, and works against the platform lock-in of proprietary services such as Facetime, Hangouts, and Skype. If it's disabled by default, the service becomes useless. My parents shouldn't have to enable it about:config for me to talk to them, nor should they have to download another plugin to use a technology built-in to the browser. I understand the security implications[2] in IP leakage[3], but I don't see a simple fix that doesn't neuter the functionality (although this comes close[4]). W3C has stated their position on fingerprinting[5], but at least Mozilla is actively working on the issue.
0: http://www.ghacks.net/2015/02/07/mozilla-starts-to-push-read...
1: https://support.mozilla.org/en-US/kb/which-browsers-will-wor...
2: https://twitter.com/incloud/status/619624021123010560
3: https://bugzilla.mozilla.org/show_bug.cgi?id=959893
4: https://addons.mozilla.org/en-US/firefox/addon/statutory/
5: https://github.com/w3ctag/spec-reviews/blob/master/2015/05/f...