Live data from Hacker News

Ask HN: Firefox vs. Chrome security

news.ycombinator.com

41–50 of 73 posts

Re: Ask HN: Firefox vs. Chrome security

#41
post #35
post #29

Google has (always) gathered information about Chrome -- and Chromium -- users by default , including every keystroke typed into the "omnibox". Not easy to disable, either. This seems to be a recent Firefox policy change: all editions of Firefox is now collecting data, such as telemetry, information gathering, usage data. (URL's? Form data?) This is all opt-out instead of opt-in now, and you're asked only after insta…

Firefox does NOT do any this, as far as I know. What is the source of this FUD? A public discussion was started to get to know how people felt about privacy conserving telemetry collection that would be opt out by default. There was massive negative feedback (duh). The feature did not ship in 57. https://medium.com/georg-fritzsche/data-preference-changes-i... "instead we always collect LESS data on Firefox release."

> Firefox does NOT do any this, as far as I know. What is the source of this FUD?

"Firefox by default shares data to: Improve performance and stability for users everywhere

Interaction data: Firefox sends data about your interactions with Firefox to us (such as number of open tabs and windows; number of webpages visited; number and type of installed Firefox Add-ons; and session length) and Firefox features offered by Mozilla or our partners (such as interaction with Firefox search features and search partner referrals).

Technical data: Firefox sends data about your Firefox version and language; device operating system and hardware configuration; memory, basic information about crashes and errors; outcome of automated processes like updates, safebrowsing, and activation to us. When Firefox sends data to us, your IP address is temporarily collected as part of our server logs.

Read the telemetry documentation for Desktop, Android, or iOS or learn how to opt-out of this data collection."

via

https://www.mozilla.org/en-US/privacy/firefox/

Re: Ask HN: Firefox vs. Chrome security

#42
post #35
post #29

Google has (always) gathered information about Chrome -- and Chromium -- users by default , including every keystroke typed into the "omnibox". Not easy to disable, either. This seems to be a recent Firefox policy change: all editions of Firefox is now collecting data, such as telemetry, information gathering, usage data. (URL's? Form data?) This is all opt-out instead of opt-in now, and you're asked only after insta…

Firefox does NOT do any this, as far as I know. What is the source of this FUD? A public discussion was started to get to know how people felt about privacy conserving telemetry collection that would be opt out by default. There was massive negative feedback (duh). The feature did not ship in 57. https://medium.com/georg-fritzsche/data-preference-changes-i... "instead we always collect LESS data on Firefox release."

[deleted]

Re: Ask HN: Firefox vs. Chrome security

#43
post #41
post #35

Earlier quoted context omitted.

Firefox does NOT do any this, as far as I know. What is the source of this FUD? A public discussion was started to get to know how people felt about privacy conserving telemetry collection that would be opt out by default. There was massive negative feedback (duh). The feature did not ship in 57. https://medium.com/georg-fritzsche/data-preference-changes-i... "instead we always collect LESS data on Firefox release."

> Firefox does NOT do any this, as far as I know. What is the source of this FUD? "Firefox by default shares data to: Improve performance and stability for users everywhere Interaction data: Firefox sends data about your interactions with Firefox to us (such as number of open tabs and windows; number of webpages visited; number and type of installed Firefox Add-ons; and session length) and Firefox features offered by…

[deleted]

Re: Ask HN: Firefox vs. Chrome security

#44
post #29

Google has (always) gathered information about Chrome -- and Chromium -- users by default , including every keystroke typed into the "omnibox". Not easy to disable, either. This seems to be a recent Firefox policy change: all editions of Firefox is now collecting data, such as telemetry, information gathering, usage data. (URL's? Form data?) This is all opt-out instead of opt-in now, and you're asked only after insta…

brave and opera both sit on top of chromium so idk about those

Well, they both use webkit or blink for rendering, but I don't know how much of the actual chromium codebase is used. However that shouldn't actually matter, because they both claim to focus on privacy (especially Brave), which means that they've presumably removed or disabled the data tracking code from Chromium... or just changed the API endpoints ;)

Re: Ask HN: Firefox vs. Chrome security

#45
I actually noticed some weird and potentially concerning behavior with Firefox Quantum this morning.

I had a fair number of tabs open (~28 or so), and I restarted the browser so a change I made would take effect. I have FF set to show my windows and tabs from my previous session on start up, but it instead launched with a single tab showing my home page. Okay, no big deal, I'll just restore my previous session from the History menu. When I clicked on the history menu, though, I didn't see my most recent history, but instead a list of URLs from my bank.

I assume this is due to a syncing issue with my Firefox account (I changed my banking password just to be safe), but it's still concerning.

Re: Ask HN: Firefox vs. Chrome security

#46
post #41
post #35

Earlier quoted context omitted.

Firefox does NOT do any this, as far as I know. What is the source of this FUD? A public discussion was started to get to know how people felt about privacy conserving telemetry collection that would be opt out by default. There was massive negative feedback (duh). The feature did not ship in 57. https://medium.com/georg-fritzsche/data-preference-changes-i... "instead we always collect LESS data on Firefox release."

> Firefox does NOT do any this, as far as I know. What is the source of this FUD? "Firefox by default shares data to: Improve performance and stability for users everywhere Interaction data: Firefox sends data about your interactions with Firefox to us (such as number of open tabs and windows; number of webpages visited; number and type of installed Firefox Add-ons; and session length) and Firefox features offered by…

I'm objecting to the fact that you are calling this a change and that it supposedly collects more data. My understanding is that it is the opposite. Much of the stuff that you list is the update check and the update checks for add-ons, CA revocation checking etc, all things that have always been on by default and that can now actually be disabled more easily.

I have no idea where you pull the "this seems to include what URL's you're browsing; this could be a security risk for apps like Dropbox and OneDrive" stuff from. The only place I know of that these could potentially be recorded is a crash report, and this has always been the case if you allow it to send crash reports back because they contain the stack contents.

Re: Ask HN: Firefox vs. Chrome security

#47
post #46
post #41

Earlier quoted context omitted.

> Firefox does NOT do any this, as far as I know. What is the source of this FUD? "Firefox by default shares data to: Improve performance and stability for users everywhere Interaction data: Firefox sends data about your interactions with Firefox to us (such as number of open tabs and windows; number of webpages visited; number and type of installed Firefox Add-ons; and session length) and Firefox features offered by…

I'm objecting to the fact that you are calling this a change and that it supposedly collects more data. My understanding is that it is the opposite . Much of the stuff that you list is the update check and the update checks for add-ons, CA revocation checking etc, all things that have always been on by default and that can now actually be disabled more easily . I have no idea where you pull the "this seems to include…

You claimed that I was spreading FUD; rather than resort to ad hominem responses, please counter with facts. I'm happy to apologize if I am incorrect, but it appears that your information appears to be out of date:

Telemetry was previously only enabled by default in Nightly and Aurora:

https://blog.theochevalier.fr/telemetry-enabled-by-default-o...

The telemetry data includes a lot more than just update checks. You wouldn't need to send information to Mozilla to get an update or get CA revocation lists.

For example, from the privacy policy[1]:

    Firefox features offered by Mozilla or our partners (such as *interaction with Firefox search features* and search partner referrals). [emphasis added]
Many of your comments are about Firefox, development with Rust, etc. I didn't mean to offend you if you are closely aligned with Mozilla. A healthy browser ecosystem (and especially the great new rendering engine from Mozilla) benefit us all.

1. https://www.mozilla.org/en-US/privacy/firefox/

Re: Ask HN: Firefox vs. Chrome security

#48
post #46

Earlier quoted context omitted.

I'm objecting to the fact that you are calling this a change and that it supposedly collects more data. My understanding is that it is the opposite . Much of the stuff that you list is the update check and the update checks for add-ons, CA revocation checking etc, all things that have always been on by default and that can now actually be disabled more easily . I have no idea where you pull the "this seems to include…

You claimed that I was spreading FUD; rather than resort to ad hominem responses, please counter with facts. I'm happy to apologize if I am incorrect, but it appears that your information appears to be out of date: Telemetry was previously only enabled by default in Nightly and Aurora: https://blog.theochevalier.fr/telemetry-enabled-by-default-o... The telemetry data includes a lot more than just update checks. You w…

please counter with facts

I already did. Much of the stuff you mentioned has always been enabled and had nothing to do with telemetry. This is most obvious with the update checks. And yes, you DO need to send information to know which add-ons to update. Probing every installed add-on to see if there's an update amounts to sending over the list of installed add-ons. Let's be forthright about that.

I quoted an article from one of the Telemetry engineers explaining that now LESS data is collected by default.

I think that's a good enough rebuttal to your claim that there has been a change of direction to collect more.

Post reply on HN