Live data from Hacker News

Studying how Firefox can collect additional data in a privacy-preserving way

groups.google.com

31–40 of 450 posts

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#31

Earlier quoted context omitted.

I think the burden here is backwards? URLs may contain Protected Health and other Identifying Information. If this data leaks SSL and could be sent to a 3rd party, then it makes Firefox an unsuitable client for a great many applications. EDIT: OK. It's boolean flags (like use of flash) plus an eTLD+1 (example.org; not myname.example.org?). Even so, I believe this tracking should be opt-in with a disclosure screen tha…

They're not planning to send full URLs, only domains. Also, the system described is resistant to attacks even if the data is captured (SSL leaks). I don't have enough statistical knowledge to understand how that works, though.

That’s still personalized data.

Mozilla has been violating even the minimal legal standards in the EU for years, and no one cares.

It’s insanity that an organization promoting its products with privacy doesn’t even meet the minimal legal standards. We’re seeing Google Analytics tracking in parts of the browser ("Get new Addons" page, for example), without even the legally required cookie warning.

EU law is clear on this, as soon as you store any data, do any tracking, connect to any third party, or transmit anything for analytics, you have get opt-in.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#32
post #14

This is ridiculous. I use and recommend Firefox for pure ideological reasons, because frankly, Chrome/Chromium is miles ahead of them. If they start opt-out tracking using the same approach as Google I do not see any reason to use it nor install it for my friends and family. That's some data for you, Mozilla.

How is Chrome miles ahead? Both seem to work just fine for me, neither being noticeably faster or better. I like a couple of minor Firefox features, so that's what I stick with.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#33

This might not be so bad as I expected from the title, but implementation details will really matter. If, for instance, they collect exact homepage URLs, they cannot make it anonymous (some site include username as URL components).

They are only considering collecting "eTLD+1, e.g. facebook.com or google.co.uk" so this should almost certainly not be an issue.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#34
1. Any data collection at all deanonymizes the user, cf panopticlick.

2. Frankly even opt-out is not acceptable. I can't recommend any software that peridically asks users for data access, since there exist non-technical users who have a nonzero chance of clicking yes to everything. If they are related to me in some way this compromises my privacy also.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#36
post #14

This is ridiculous. I use and recommend Firefox for pure ideological reasons, because frankly, Chrome/Chromium is miles ahead of them. If they start opt-out tracking using the same approach as Google I do not see any reason to use it nor install it for my friends and family. That's some data for you, Mozilla.

How is Chrome miles ahead? Both seem to work just fine for me, neither being noticeably faster or better. I like a couple of minor Firefox features, so that's what I stick with.

Firefox -> Chrome is a sidegrade at best. Literally only reason I use it is because I got fed up with weird little CSS quirks I couldn't replicate in IE or FF, but were very present in Chrome.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#37
On one hand Mozilla doing something like that is anti privacy. On the other hand how is Mozilla supposed to impprove FF w/o detailed usage data.

In theory can be done, but in practice they are competing with Chrome and their team has waaay more data to use. And th is data gives them an edge at least on the decision which parts are worth improving.

So they can either start collecting some data and really piss off their most vocal privacy minded users and try to use this data to improve FF and steer it away from the death spiral it's on. Or they can keep the vocal privacy minded people happy continue to work in the dark and pretty much ensure that FF will become one of the insignificant .3% market share browsers.

Because somehow I kind of feel that multimilion fundraisers to make FF popular again aren't gonna happen second time.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#38
post #13

Note: "planning" means "reaching out for feedback about". Also interesting: the method they plan on using for anonymising this: https://en.wikipedia.org/wiki/Differential_privacy#Principle... If that is not sufficiently anonymous, then please submit the reasoning why to Mozilla.

Any submission of data requires the transmission of an IP address, which is personal data and necessitates appropriate protection.

I very much hope that the Debian maintainers (and hopefully also the guys preparing Fennec in F-Droid) will disable such data collection mechanisms, either completely or hidden behind an explicit opt-in instead of the opt-out suggested in the e-mail.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#39
post #9

I say it over and over. You can not completely anonymize data with any reliability. Please note the qualifier, many systems work for many vectors, but any sufficiently large dataset can be used to graph habits and correlate them. Maybe there is a safe way, but I put the onus of proving it on the person implementing it.

> You can not completely anonymize data with any reliability. Well... there's actually a field for that. I forgot what they call that field because of how niche it is but my friend at google is doing just that. He said there are math theorem to prove that it's sufficiently anonymize. He gave an example of how Netflix competition with the data they gave researchers were able to deanonymize it. And his job was to preve…

The linked Wikipedia page actually mentions that competition: https://en.wikipedia.org/wiki/Differential_privacy#Netflix_P...

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#40
post #37

On one hand Mozilla doing something like that is anti privacy. On the other hand how is Mozilla supposed to impprove FF w/o detailed usage data. In theory can be done, but in practice they are competing with Chrome and their team has waaay more data to use. And th is data gives them an edge at least on the decision which parts are worth improving. So they can either start collecting some data and really piss off thei…

Why would FireFox be on a dead spiral for not tracking it's users? If they want browsing data, then can use their own.
Post reply on HN