Live data from Hacker News

Ask HN: Firefox vs. Chrome security

news.ycombinator.com

51–60 of 73 posts

Re: Ask HN: Firefox vs. Chrome security

#51
post #46

Earlier quoted context omitted.

I'm objecting to the fact that you are calling this a change and that it supposedly collects more data. My understanding is that it is the opposite . Much of the stuff that you list is the update check and the update checks for add-ons, CA revocation checking etc, all things that have always been on by default and that can now actually be disabled more easily . I have no idea where you pull the "this seems to include…

You claimed that I was spreading FUD; rather than resort to ad hominem responses, please counter with facts. I'm happy to apologize if I am incorrect, but it appears that your information appears to be out of date: Telemetry was previously only enabled by default in Nightly and Aurora: https://blog.theochevalier.fr/telemetry-enabled-by-default-o... The telemetry data includes a lot more than just update checks. You w…

You are spreading FUD.

> (URL's? Form data?)

> this telemetry does cover usage.. i.e., this seems to include what URL's you're browsing; this could be a security risk for apps like Dropbox and OneDrive.

Back these claims up with something specific and concrete, otherwise they're just wild speculation.

The search bit you're quoting refers to when you, say, search for something using Amazon via the Amazon search provider built into the browser search box, a piece of data is sent along with the request to Amazon to attribute Mozilla as the source. In aggregate this influences how much Amazon pays out to Mozilla for their default presence in Firefox.

I'm happy to try to clarify any concerns about telemetry or other data collection you might have (in an individual capacity, not as a representative of Mozilla), but usually that should come before the flinging of damaging accusations over a public forum.

Re: Ask HN: Firefox vs. Chrome security

#52
post #27

Earlier quoted context omitted.

> Early next year should also see the rollout of a new GPU-accelerated rendering engine So what version will get Webrender exactly?

59 AFAIK

Where did you get that info? I'm running Nightly (v59) but it's not enabled by default. Can't find anything on their roadmap either.

Re: Ask HN: Firefox vs. Chrome security

#53
post #34

Earlier quoted context omitted.

I heard a different story. Firefox was not at the contest because it was not in the same league as the others browsers (and not in a good way). See the last sentence of your link "We wanted to focus on the browsers that have made serious security improvements in the last year"

A rather arbitrary claim with nothing to back it up. For sure, Firefox made more security improvements in 2016 than it did in some of the years where they did feature it.

look here: https://it.slashdot.org/story/16/02/12/034206/pwn2own-2016-w...

Re: Ask HN: Firefox vs. Chrome security

#54
post #48

Earlier quoted context omitted.

You claimed that I was spreading FUD; rather than resort to ad hominem responses, please counter with facts. I'm happy to apologize if I am incorrect, but it appears that your information appears to be out of date: Telemetry was previously only enabled by default in Nightly and Aurora: https://blog.theochevalier.fr/telemetry-enabled-by-default-o... The telemetry data includes a lot more than just update checks. You w…

please counter with facts I already did. Much of the stuff you mentioned has always been enabled and had nothing to do with telemetry. This is most obvious with the update checks. And yes, you DO need to send information to know which add-ons to update. Probing every installed add-on to see if there's an update amounts to sending over the list of installed add-ons. Let's be forthright about that. I quoted an article…

Personally, I actually don't have any issue with any of the individual telemetry data, although it can certainly be used to fingerprint and for other nefarious purposes, or even if it's opt-out instead of opt-in, but collecting it by default is definitely a new change.

In fact, your link explicitly explains that you cannot control the extent of data collection now. ("There is just one control for data upload for Firefox") It also explains that this is a new change ("which is on by default.")

Trying to spin this or casting aspersions on casual users who noticed a change won't change the facts.

Re: Ask HN: Firefox vs. Chrome security

#55
One interesting extension for desktop Firefox is Containers [0]. This is like per site incognito mode so tracking cookies do not escape between containers. While it's not a strict security thing for me it's one of more interesting aspects of Firefox as a browser.

[0]: https://addons.mozilla.org/en-US/firefox/addon/multi-account...

Re: Ask HN: Firefox vs. Chrome security

#56

Earlier quoted context omitted.

59 AFAIK

Where did you get that info? I'm running Nightly (v59) but it's not enabled by default. Can't find anything on their roadmap either.

Version numbers in Nightly should be treated as works in progress, as it's built straight from the working Firefox source tree. When the current cycle ends, the code in Nightly will be bundled up to become the 59 release, and the Nightly version number will tick over to 60. Nightly displaying the 59 version number doesn't mean all features of the 59 release are present there yet.

Re: Ask HN: Firefox vs. Chrome security

#57
post #46

Earlier quoted context omitted.

I'm objecting to the fact that you are calling this a change and that it supposedly collects more data. My understanding is that it is the opposite . Much of the stuff that you list is the update check and the update checks for add-ons, CA revocation checking etc, all things that have always been on by default and that can now actually be disabled more easily . I have no idea where you pull the "this seems to include…

You claimed that I was spreading FUD; rather than resort to ad hominem responses, please counter with facts. I'm happy to apologize if I am incorrect, but it appears that your information appears to be out of date: Telemetry was previously only enabled by default in Nightly and Aurora: https://blog.theochevalier.fr/telemetry-enabled-by-default-o... The telemetry data includes a lot more than just update checks. You w…

> You wouldn't need to send information to Mozilla to get an update or get CA revocation lists.

Any request to Mozilla is sending info to Mozilla, and thus should be covered under the privacy policy. Every check for an update likely also includes the current version running so they can send back info on whether the update is important/security related or not. Even if it was just a "list all versions" request, it still signifies that IP used the browser. Similarly, a CRL list update signifies that the IP used Firefox and that the conditions that trigger a CRL update were met (which might mean an HTTPS address was visited, or it might happen at startup).

Any time Firefox implicitly requests data from Mozilla, that's something that they would likely cover in their Privacy policy. Chrome got a lot of flack a few years back for essentially the same problem, but with a twist. Every time it started it would download a binary blob from Google. It turns out it was the code to do voice recognition, which was executed after download. Fairly innocuous if you trust Google, but it was executing remote code from Google on every startup, so people were rightly disturbed by what they saw going on until an explanation was put forth.

Re: Ask HN: Firefox vs. Chrome security

#58

Earlier quoted context omitted.

You claimed that I was spreading FUD; rather than resort to ad hominem responses, please counter with facts. I'm happy to apologize if I am incorrect, but it appears that your information appears to be out of date: Telemetry was previously only enabled by default in Nightly and Aurora: https://blog.theochevalier.fr/telemetry-enabled-by-default-o... The telemetry data includes a lot more than just update checks. You w…

You are spreading FUD. > (URL's? Form data?) > this telemetry does cover usage.. i.e., this seems to include what URL's you're browsing; this could be a security risk for apps like Dropbox and OneDrive. Back these claims up with something specific and concrete, otherwise they're just wild speculation. The search bit you're quoting refers to when you, say, search for something using Amazon via the Amazon search provid…

> You are spreading FUD

I was pointing out that this is a new opt-in change. The links that were posted prove it. Is that FUD?

> specific and concrete

In the absence of specific information, should we not assume the worst?

> data collection

That sounds reasonable for normal users, but any of this data can be used for fingerprinting, data mining, etc. Do you disagree?

One suggestion for improvement would be that the specifics of what data is collected and why would be a welcome addition to the Privacy Policy page, or perhaps a more detailed page that the PP links to. This would be something people could paste in public forums to refute incorrect statements... especially if the page was on mozilla.org instead of Medium.

Re: Ask HN: Firefox vs. Chrome security

#59
post #39
post #35

Earlier quoted context omitted.

Firefox does NOT do any this, as far as I know. What is the source of this FUD? A public discussion was started to get to know how people felt about privacy conserving telemetry collection that would be opt out by default. There was massive negative feedback (duh). The feature did not ship in 57. https://medium.com/georg-fritzsche/data-preference-changes-i... "instead we always collect LESS data on Firefox release."

> The feature did not ship in 57. But CliqZ did ship for some German users, randomly chosen. Which tracks your entire browsing history, and sends it to a company that’s most known for its tracking products. After this, Firefox deserves to be treated as just as much spyware as Chrome.

Why was this downvoted? I didn't know anything about this, but it seems (in)credible:

"Mozilla pilots Cliqz engine in Firefox to slurp user browsing data"

"Users who receive a version of Firefox with Cliqz will have their browsing activity sent to Cliqz servers, including the URLs of pages they visit," Mozilla says. "Cliqz uses several techniques to attempt to remove sensitive information from this browsing data before it is sent from Firefox."

http://www.zdnet.com/article/firefox-tests-cliqz-engine-whic...

Re: Ask HN: Firefox vs. Chrome security

#60

Firefox has been a low-priority target for a couple years due to its waning user-base. In fact, Firefox wasn't even at Pwn2Own 2016 because hackers didn't think it was worth their time[0]. Hopefully with Quantum and a resurge in popularity, it'll become a target of white-hat hackers again. [0] http://www.eweek.com/security/pwn2own-hacking-contest-return...

That is a great argument against the monoculture seen in some product categories.

If (almost) everyone runs Windows you’re safer if you run Linux.

Post reply on HN