Live data from Hacker News

Firefox bullshit removal

gist.github.com

171–180 of 183 posts

Re: Firefox bullshit removal

#171

Earlier quoted context omitted.

That doesn't make a whole lot of sense to me. Google's data is a part of their offering, but that doesn't somehow make me as a person a "product". Their products are AdWords and AdSense. These services network customers together who want to 1. make money from ads, and 2. advertise themselves. Google mediates this exchange between both parties, and uses data from users to target their ads more accurately. Calling the…

As a complete outsider to this conversation who has gotten caught up in the fearmongering mentioned, but who is too ignorant to really have strong opinions either way, thanks for having this conversation. It's scary, being in the Too Much Information age. It feels so easy to be misled when it's hard to devote the time to properly understand complex topics like this. I don't know if I feel any more confident in my bro…

Well thank you for willing to be vulnerable.

Personally I do still believe privacy is very important. I often take up the devil's advocate position on Hacker News because there is a lot of groupthink on this site. The issues are rarely black and white, and almost never come down to "X is evil".

My advise is to stay aware of the issues, but don't get consumed by them. In almost all cases a site's privacy policy will tell you exactly what they collect, and you always maintain the power to block that at the browser level if you want to.

eg. I use an adblocker to remove social media widgets. I find them clutter and I don't care for the tracking. Otherwise though my settings are pretty light.

I hope you find your happy medium.

Re: Firefox bullshit removal

#172
post #107

To this I would add: middlemouse.contentLoadURL=false This anti-feature means missing the target of a middle-click by a single pixel can leak the contents of your clipboard or load unexpected URLs. I don't understand why it's still on by default -- Mozilla has been willing to break peoples workflow for UI improvements many times before.

> middlemouse.contentLoadURL=false This is the default in Firefox 57 and later. See https://bugzilla.mozilla.org/show_bug.cgi?id=366945 > I don't understand why it's still on by default It's not.

I don’t understand, what does it do?

Re: Firefox bullshit removal

#173
post #172

Earlier quoted context omitted.

> middlemouse.contentLoadURL=false This is the default in Firefox 57 and later. See https://bugzilla.mozilla.org/show_bug.cgi?id=366945 > I don't understand why it's still on by default It's not.

I don’t understand, what does it do?

Seems to only apply to Linux, but basically it either pastes your clipboard content into any focused text field or tries to open the clipboard contents as an URL (and falls back to Google Search if that fails).

Re: Firefox bullshit removal

#174
post #172

Earlier quoted context omitted.

> middlemouse.contentLoadURL=false This is the default in Firefox 57 and later. See https://bugzilla.mozilla.org/show_bug.cgi?id=366945 > I don't understand why it's still on by default It's not.

I don’t understand, what does it do?

When set to true, lets you middle-mouse-paste into the content area to load the url in the PRIMARY selection. That way you don't have to worry about whether selecting the text in the URL bar so you can replace it with the URL will clobber PRIMARY.

Only relevant on X, where there is a PRIMARY, of course. See https://unix.stackexchange.com/a/139193 for a quick description of what PRIMARY is and how it differs from CLIPBOARD.

Re: Firefox bullshit removal

#175
post #32

Earlier quoted context omitted.

Where did you get that idea? His stance on SSM aside, Brendan Eich is not a guy I typically associate with evil. The whole raison d'être of Brave is to restore privacy to consumers of advertisements while being fair to publishers. The codebase is all MPL2 on Github. Nothing stopping you or anyone forking it, yada yada.

Not sure if it is the case, but the original plan was for Brave to replace ads with its own: https://arstechnica.com/information-technology/2016/01/mozil...

That is only if publishers and users consent. Both get paid in that case, 70% to publisher, 15% to user. But it's not the private ad model we are trying first.

What we're most excited about are opt-in, user-private and -anonymous ads, long form and at low frequency, where you get 70% of the gross revenue.

In either case some brand principles:

1. We pay 70% to the ad "inventory owner" -- the person who is giving attention space up for the ad

2. We always pay the user as much as, or more than, we take. This aligns our interests.

3. We never keep user data on any servers, whitelist ads for a fee, let trackers through to target or attribute/confirm.

The grand-parent post here is just flat wrong. In no case do we track user data for profit -- we never did and never will. All data in clear stays on your device. We use a ZKP protocol over a VPN for anonymous settlements/confirmations. Our site details all this: https://brave.com/.

Re: Firefox bullshit removal

#176
post #57
post #3

Interesting. Though at that point why wouldn't you just use Brave ?

Add-ons perhaps? Does Brave support those?

Yes, chromium extensions. We are curating, as we want to make sure they work correctly and aren't doing anything that goes against our privacy and security principles.

Re: Firefox bullshit removal

#177
post #163
post #97

Earlier quoted context omitted.

I think he's just pointing out the irony of someone purporting to aid the security-conscious having an expired cert on his own site. Unless this is really some meta-level social commentary on how people will trust a complete stranger's website despite an invalid cert because he seems like a nice guy.

> I think he's just pointing out the irony of someone purporting to aid the security-conscious having an expired cert on his own site. This is exactly the point I was going after. It would be one thing if the cert had just expired but cmon, October 31, 2017 really?

Cert expiration dates provide very little in the way of actual security. Normally it would mean that yes, your connection is secure, yes, everything matches, but you hadn't paid your protection money to the CA racket in a while.

In my case, it's because I haven't had the desire to go in and redo the nginx config on this machine. But sure, that makes the content wrong, or something.

Re: Firefox bullshit removal

#178
post #117

Earlier quoted context omitted.

i love “is blocker” for safari; it’s hugely configurable with regexes, allowing things on some domains only, allowing globally from some domains, blocking of canvas elements, XHR requests, frames, plenty more too!

When you use a thing like "is blocker", do you still need a separate ad blocker or is the JavaScript blocker sufficient to block ads as well?

sorry i didn’t see the reply... i meant “js blocker” and auto correct happened. i use ublock as well, because it picks up on regexes for things like piwik (you could have something like https://somesite.com/piwik.js allowed because you just unblock somesite.com, or ga hosted locally etc)

Re: Firefox bullshit removal

#179
post #163

Earlier quoted context omitted.

> I think he's just pointing out the irony of someone purporting to aid the security-conscious having an expired cert on his own site. This is exactly the point I was going after. It would be one thing if the cert had just expired but cmon, October 31, 2017 really?

Cert expiration dates provide very little in the way of actual security. Normally it would mean that yes, your connection is secure, yes, everything matches, but you hadn't paid your protection money to the CA racket in a while. In my case, it's because I haven't had the desire to go in and redo the nginx config on this machine. But sure, that makes the content wrong, or something.

> But sure, that makes the content wrong, or something.

If your own Nginx server cannot serve up a proper and protected session, why should I consider what you've written on the website? Actually how can I know that what I'm reading is what you wrote if the session is already compromised from the start?

> but you hadn't paid your protection money to the CA racket in a while.

Yes, you sometimes have to pay for that cert from a CA but that's not why certificates expire.

Besides, your CA is Let's Encrypt so this point is completely useless but it does make an easy excuse.

Enough with the drama please.

Re: Firefox bullshit removal

#180
post #157

Earlier quoted context omitted.

So if Google stopped paying Apple, what would they do? Switch to Bing? I'm sure their users would love that

Given that Apple had been using Bing for search from 2014-2017, I'm not sure users actually care that much. https://techcrunch.com/2017/09/25/apple-switches-from-bing-t...

That article is about Siri web search.
Post reply on HN