Live data from Hacker News

Studying how Firefox can collect additional data in a privacy-preserving way

groups.google.com

231–240 of 450 posts

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#231

Can we at least stop with the FUD please? > DRM EME is not DRM, it's a fully open source spec to support third-party DRM modules. If you don't actively choose to install a DRM module, there is no DRM in your Firefox. > 3-rd party apps Like what? Pocket is fully owned by Mozilla. > analytics, tracking So far this has been 100% opt-in. It might change with this new thing, but even that's not for certain.

> EME is not DRM, it's a fully open source spec to support third-party DRM modules So, it exists only to facilitate DRM. And I could have sworn that it defaults to enabled? > Pocket is fully owned by Mozilla It wasn't when it was added. >> analytics, tracking > So far this has been 100% opt-in Other than the Google Analytics on the add-on pane, maybe.

> And I could have sworn that it defaults to enabled?

It does not.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#232

Earlier quoted context omitted.

I'm not really sure what your concern is here. Let's assume for a moment that Firefox's implementation of differential privacy in this scenario is completely correct, and that as a result it's completely impossible (even in an information-theoretic sense) to learn anything about any individual user using this data; only about many users in aggregate. In this scenario, how exactly would Firefox's actions here compromi…

Differential privacy does not ensure complete information theoretic security as you say. There is a parameter ε that determines the amount of privacy, and in this case you do not get to set it, somebody else does.

Interesting point. Admittedly, my understanding of differential privacy is very rudimentary, but isn't that only a risk under the assumption that you can ask the same user the same question multiple times, and get a new, independently chosen answer every time? If you can only ask each question once and every subsequent time you ask you just get the same answer, is that not secure in the information theoretic sense? Perhaps there's some other factor I'm missing?

> in this case you do not get to set it

Nothing's been decided yet. If this is something you want to advocate for, maybe consider suggesting that in the thread linked in the OP?

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#233
Does anyone know why Firefox always phones home to:

    firefox.exe	3588	TCP	pc-name	49172	ec2-35-167-184-4.us-west-2.compute.amazonaws.com	https	ESTABLISHED	3	667	5	3,334		
I have a tool called TCPView (a Microsoft sysinternals tool) that inspects my traffic. I disabled all the Mozilla telemetry and it still phones home to this server. The connection is encrypted going through port 443. It even appears in different forks of Firefox like Waterfox. Is this unique to me, or does anyone else notice this? My best guess is that it's some sort of telemetry they're collecting. Keep in mind I disabled updates so it's not pinging update servers either. Also: It happens only when I visit a website, and doesn't appear when I start up the browser for the first time. I also have no plugins installed. Since I see some Mozillians in this thread I figured it's the best place to ask!

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#234

Earlier quoted context omitted.

Why is the choice between opt-in vs opt-out of automatic behavior? If Mozilla wants perf data, collect it and then prompt the user "crash reporting" style. I would totally opt-in to prompts. Give it a threshold and ask, "This page seems to frequently perform less well on your computer, would you like to send us a report?"

Random sampling, basically. The value of random sampling is hard to overstate - it gives you a real picture of what's going on. A non-random sampling gives you a picture, but you have no way of confirming that the picture is a reflection of reality. Random sampling and privacy run into conflicts not just in the browser space, but everywhere else. For example, recently the Canadian government went through a period whe…

I've used Netscape then switched to Firefox when Netscape became way too bloated, then enjoyed years and years of Firefox getting better, supporting new JS and HTML5 features all WITHOUT telemetry and with the Crash Reporting window where I can see the data that is being submitted and submit it if I want to submit it.

What have changed so much in last 5 years or so that now you have to get all this data? What is wrong with just building a standarts compliant browser that runs JS fast and has easy to understand settings (where I don't have to go to about:config to disable the WebRTC/telemetry/Pocket etc) ?

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#235

I can do a quick summary of what's being proposed and why. I work in the JS team at Mozilla and deal directly with the problems caused by insufficient data. Please note that I'm speaking for myself here, and not on behalf of Mozilla as a whole. Tracking down regressions, crashes, and perf issues without good telemetry about how often it's happening and in what context. Issues that might have otherwise taken a few day…

> Tracking down regressions, crashes, and perf issues without good telemetry about how often it's happening and in what context.

If that's what you're aiming at. Collect the data but keep it local. Install some sort of responsiveness/"problem" monitoring. Ask the user to send data relevant to the problem if a problem occurs. IMHO there is no need to systematically collect user data for that.

Or get the data from a random sample of users. You don't need data from everyone.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#236

Can we at least stop with the FUD please? > DRM EME is not DRM, it's a fully open source spec to support third-party DRM modules. If you don't actively choose to install a DRM module, there is no DRM in your Firefox. > 3-rd party apps Like what? Pocket is fully owned by Mozilla. > analytics, tracking So far this has been 100% opt-in. It might change with this new thing, but even that's not for certain.

> Can we at least stop with the FUD please? Can we please stop with using the word FUD for things that are not? The very idea of accepting DRM as a possibility in the browser was a slap in the face to those who believe in internet freedom. > Like what? Pocket is fully owned by Mozilla. Check your facts: it was added to FF 1.5 years before Mozilla bought it. It was an example of them just not giving a shit and adding…

So freedom is not having the choice to use DRM?

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#237

Can we at least stop with the FUD please? > DRM EME is not DRM, it's a fully open source spec to support third-party DRM modules. If you don't actively choose to install a DRM module, there is no DRM in your Firefox. > 3-rd party apps Like what? Pocket is fully owned by Mozilla. > analytics, tracking So far this has been 100% opt-in. It might change with this new thing, but even that's not for certain.

> Can we at least stop with the FUD please? Can we please stop with using the word FUD for things that are not? The very idea of accepting DRM as a possibility in the browser was a slap in the face to those who believe in internet freedom. > Like what? Pocket is fully owned by Mozilla. Check your facts: it was added to FF 1.5 years before Mozilla bought it. It was an example of them just not giving a shit and adding…

DRM was already possible in browsers by using NPAPI or similar plugins. EME is no worse in that regard, and is from a technical perspective a much better solution.

Pocket's integration during that time amounted to a button which sent a request to a potentially useful service. Such buttons have existed in firefox long before pocket ever existed, and you are of course welcome to no click on them.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#238
post #229

Earlier quoted context omitted.

> No phoning home. No telemetry, no data collection. No "light" version of the same, no "privacy-respecting" what-have-you. No means No. Nada. Zilch. Try and shovel any of that down people's throats and the idea of Firefox as a user's browser will die. https://github.com/mozilla/addons-frontend/issues/2785 And now this :-( I have been using Firefox since before it was called that. I develop my apps in it, even though…

> DRM Mozilla fought DRM until the very end and lost . If Firefox is to have any chance at remaining a mainstream browser it needs to support Netflix and the likes. You can't seriously blame them for this, because they are damned if they do and damned if they don't. EME is implemented as unintrusively, securely and privately in Firefox as possible. No DRM is downloaded or run on your computer until you specifically c…

> Mozilla fought DRM until the very end and lost. If Firefox is to have any chance at remaining a mainstream browser it needs to support Netflix and the likes. You can't seriously blame them for this, because they are damned if they do and damned if they don't.

Yes I can, and I will, because they sold out. They sold out their principles for the sake of market share. (And looking at their marked share, fat lot of good that did for them anyway.)

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#239

Can we at least stop with the FUD please? > DRM EME is not DRM, it's a fully open source spec to support third-party DRM modules. If you don't actively choose to install a DRM module, there is no DRM in your Firefox. > 3-rd party apps Like what? Pocket is fully owned by Mozilla. > analytics, tracking So far this has been 100% opt-in. It might change with this new thing, but even that's not for certain.

Pocket was included almost two years before the acquisition: https://blog.mozilla.org/blog/2017/02/27/mozilla-acquires-po... https://venturebeat.com/2015/06/09/mozilla-responds-to-firef...

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#240

I can do a quick summary of what's being proposed and why. I work in the JS team at Mozilla and deal directly with the problems caused by insufficient data. Please note that I'm speaking for myself here, and not on behalf of Mozilla as a whole. Tracking down regressions, crashes, and perf issues without good telemetry about how often it's happening and in what context. Issues that might have otherwise taken a few day…

You wouldn't say anything else, so your statements don't change anything: Any company which wants to collect more data would justify it in the same way.

The main reason to collect data is monetization. People don't like to think they're being sold, so it's justified on other grounds. That's a universal. Since the way data is monetized is to track and segregate users, claims that it can be done in a privacy-respecting fashion are, therefore, specious.

There is one conclusion to be drawn here, and it isn't that Mozilla is going to respect my privacy.

Post reply on HN