Live data from Hacker News

Studying how Firefox can collect additional data in a privacy-preserving way

groups.google.com

361–370 of 450 posts

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#361

I can do a quick summary of what's being proposed and why. I work in the JS team at Mozilla and deal directly with the problems caused by insufficient data. Please note that I'm speaking for myself here, and not on behalf of Mozilla as a whole. Tracking down regressions, crashes, and perf issues without good telemetry about how often it's happening and in what context. Issues that might have otherwise taken a few day…

> Tracking down regressions, crashes, and perf issues without good telemetry about how often it's happening and in what context. If that's what you're aiming at. Collect the data but keep it local. Install some sort of responsiveness/"problem" monitoring. Ask the user to send data relevant to the problem if a problem occurs. IMHO there is no need to systematically collect user data for that. Or get the data from a ra…

This. Firefox prompts for feedback semi-regularly. I seem to recall it even bends over backwards to make it end-user friendly by having "Firefox made me happy / Firefox made me sad" options. It seems like it would not be difficult to tie that screen to a secondary prompt that says, "Can you briefly turn on some additional telemetry for us so that we can try to fix the problem?" Let the users make that choice to temporarily lower their shields so that you can get some useful data out of their machines, in exchange for the implicit pledge that you will use this data for troubleshooting this one explicit issue (i.e. whatever prompted them to click "Firefox made me sad").

That seems like a reasonable compromise to me. I'm happy to send logs if my browser crashes whenever I visit a certain page, and if I know I'm gonna be monitored for that period, I'll isolate my browsing habit to only visit that page. I do not consent, however, to sending everything--even anonymized--on the offchance that Mozilla will see the crash events and use it to flag that domain and maybe fix the issue on that particular page.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#362

Earlier quoted context omitted.

There are a couple different reasons crash reports aren't sufficient: 1. Crash reports only report crashes. We need also want to see perf issues like GC and paint jank, etc. 2. Crash reports don't sample the general population, so statistically the information is less useful. If we get a perf issue, it's very important to know whether that issue is suffered by 10% of the users in general pop, or 0.5% of users in gene…

1. Then why not add a "perf reporter" and a "paint jank" reporter? "Hi! It seems that this page is loading unusually slowly, would you mind submitting more details to help Mozilla diagnose the issue? Click `More Details` to see exactly what information is being reported." You even already have a good entry point for one of these - the "unresponsive script" dialog. Personally, I'm far more likely to send you this data…

>You even already have a good entry point for one of these - the "unresponsive script" dialog.

Thanks for bringing that up.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#363

Earlier quoted context omitted.

But it means they have an equal value system: Convenience being always more important than Privacy. And that’s strictly incompatible with mine.

Except that's not true. Firefox collecting a small amount of data in a privacy-aware manner does not mean "convenience being always more important than privacy", not by a long shot. I don't understand why you're insisting on such an absolute black & white viewpoint.

Firefox being so arrogant to presume I want to collect the data by default is a very rude thing. You don’t just assume someone wants it, and do it for them, especially if it might hurt them.

First ask, then fuck up. Is that concept so hard to understand?

If you’d do that IRL to someone they’d never talk to you again, it’s the same with Firefox if they do this.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#364

I can do a quick summary of what's being proposed and why. I work in the JS team at Mozilla and deal directly with the problems caused by insufficient data. Please note that I'm speaking for myself here, and not on behalf of Mozilla as a whole. Tracking down regressions, crashes, and perf issues without good telemetry about how often it's happening and in what context. Issues that might have otherwise taken a few day…

Top-level domains are still betraying the user's privacy. Does it bug me that PornoTube is significantly laggier on Firefox than YouTube? Sure. Do I want Mozilla to know that I'm visiting it? Hell no.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#365

Earlier quoted context omitted.

Except that's not true. Firefox collecting a small amount of data in a privacy-aware manner does not mean "convenience being always more important than privacy", not by a long shot. I don't understand why you're insisting on such an absolute black & white viewpoint.

Firefox being so arrogant to presume I want to collect the data by default is a very rude thing. You don’t just assume someone wants it, and do it for them, especially if it might hurt them. First ask, then fuck up. Is that concept so hard to understand? If you’d do that IRL to someone they’d never talk to you again, it’s the same with Firefox if they do this.

Firefox collecting data in of itself isn't at all rude, or problematic. Nobody cares if Mozilla has "data". What they care about is if they collect data that violates the user's privacy. The whole point of RAPPOR and differential privacy is it's an approach to collecting data that is supposed to preserve user privacy. So the real question is, does it preserve user privacy sufficiently that it's ok to make something opt-out instead of opt-in? But that's not what you're complaining about, you're just ranting because they're collecting data, period, without actually understanding the extent to which your privacy is being violated (if at all).

And of course this all started with you saying that you may as well switch to another company's products, a company which you know violates your privacy quite significantly. You still haven't explained why Firefox collecting a small amount of data in a way that tries to minimize any privacy violations means you should just give up any semblance of privacy and use a product that tries to collect as much personal information as possible.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#366
post #188
post #96

I still use Firefox specifically because of Chrome's privacy concerns and was under the impression after dropping FirefoxOS Mozilla was headed in the right direction. It seems they've convinced themselves that the only way to improve the product is to collect data on their users, rather than continuing to push the idea of privacy - which, in my opinion, if marketed correctly, could win over a lot of users. The browse…

It seems your premise is wrong since Firefox's market share has been steadily declining for years. Privacy apparently doesn't matter to that many people.

I'm sure losing the only advantage over technically superior Chrome is going to help their market share!

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#367

Earlier quoted context omitted.

Firefox being so arrogant to presume I want to collect the data by default is a very rude thing. You don’t just assume someone wants it, and do it for them, especially if it might hurt them. First ask, then fuck up. Is that concept so hard to understand? If you’d do that IRL to someone they’d never talk to you again, it’s the same with Firefox if they do this.

Firefox collecting data in of itself isn't at all rude, or problematic. Nobody cares if Mozilla has "data". What they care about is if they collect data that violates the user's privacy. The whole point of RAPPOR and differential privacy is it's an approach to collecting data that is supposed to preserve user privacy. So the real question is, does it preserve user privacy sufficiently that it's ok to make something o…

First off, I’m a developer myself. A developer in the EU. In Germany. Working on open source. In fact, on open source with goals to preserve privacy.

I’ve dealt with these issues before myself.

And I understand well what they collect, how, and why. I understand how painful it is when you have no data on what is used, and how, or not even crashreports.

But there also is a limit to how far you can go, and where consent is required.

And when transmitting anything, or collecting anything, consent is required.

You could make it dependent on situation. If a performance issue occurs, show a bar: "Is this website slow? Click [Here] to submit a report so it can be improved. [Details] [X] Always submit".

This gives the user a far better understanding of what is submitted, why it is needed, it is contextual, and it is still opt-in (but with far better conversion)

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#368

Earlier quoted context omitted.

Thanks for your input. Glad to hear someone from the Mozilla team on this thread. Its an interesting compromise... because without improved performance and features, we'll lose Firefox entirely, and all of the relative privacy / security gains that entails. This is a good example where "perfect" privacy that reaches only a few is the enemy of "good" privacy that reaches more people.

Firefox must continue to exist if we are to have any browser without an economic incentive to be user-hostile. If they need performance traces from websites, and they have an open, clear discussion of how to preserve as much user privacy as possible, they should collect them.

The data collection MAKES it user-hostile. If they start collecting data, then there's no point for Firefox to exist - they're just a crappier version of Chrome.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#369

Why is Firefox hellbent in reducing any advantage it has over Chrome and becoming an unnecessary clone. Who runs Mozilla, do they understand why anyone would choose Firefox over Chrome? Maybe it's time to put a spotlight on the management and decision making structures of increasingly important open source projects like Firefox to ensure they are being run in the public interest.

Because firefox as it is now is slowly dying. It looks like data collection is such a huge advantage that anyone not doing it is doomed in the long term.

Re: Studying how Firefox can collect additional data in a privacy-preserving way

#370
post #299

Earlier quoted context omitted.

> Or get the data from a random sample of users. You don't need data from everyone. To my amateur ear, that actually sounds like a good compromise to lessen the blow somewhat more. You should suggest it to Mozilla :)

That's what's proposed here. I guess no one actually read the post...?

There is no mention that once validated, that the RAPPOR-based metrics when fully deployed would be take from a random population. Only that the initial study of the system will be done to a random population.

FTA:

What we plan to do now is run an opt-out SHIELD study [6] to validate our implementation of RAPPOR. This study will collect the value for users’ home page (eTLD+1) for a randomly selected group of our release population We are hoping to launch this in mid-September."

Notably:

"this study will collect ... for a randomly selected group"

[6] - https://wiki.mozilla.org/Firefox/Shield/Shield_Studies

Post reply on HN