Live data from Hacker News

Firefox partners with ProtonVPN

premium.firefox.com

71–80 of 129 posts

Re: Firefox partners with ProtonVPN

#71
post #16

I only use firefox. But I don't feel like I can strongly recommend it because of the long list of bad decisions. - Google analytics baked into about:addons - Sending data to Cliqz - Pocket, as a service being added to the topbar - Pocket, as a service being added to the default home/newtab page - Firefox hello - Completely banning unsigned addons - Mr. Robot advert - And now probably this I want a browser that is rel…

You missed a few things:

- They have telemetry turned as the default

- They are experimenting with TLS over HTTPS and use beloved Cloudflare to handle every DNS request

- They are always in the headlines about some shady 'addon' or 'extension' been sold off and taken over by shady actors

- The TorBundle which is a fork of FF ESR is always in the headlines as been unsecure and way behind FF mainline release

Re: Firefox partners with ProtonVPN

#72
post #64

Earlier quoted context omitted.

You can find Proton's response to these false allegations here: https://www.reddit.com/r/ProtonVPN/comments/8ww4h2/protonvpn...

> false allegations These are nothing but facts backed by sources anyone can verify by himself.

Why is there an article about Hola in there?

Re: Firefox partners with ProtonVPN

#73
post #31
post #16

I only use firefox. But I don't feel like I can strongly recommend it because of the long list of bad decisions. - Google analytics baked into about:addons - Sending data to Cliqz - Pocket, as a service being added to the topbar - Pocket, as a service being added to the default home/newtab page - Firefox hello - Completely banning unsigned addons - Mr. Robot advert - And now probably this I want a browser that is rel…

Don't throw the baby out with the bathwater. These are minor things compared to having no other good choice but the Google browser.

Are we supposed to pretend that options like ungoogled-chromium don't exist?

Re: Firefox partners with ProtonVPN

#74
post #16

I only use firefox. But I don't feel like I can strongly recommend it because of the long list of bad decisions. - Google analytics baked into about:addons - Sending data to Cliqz - Pocket, as a service being added to the topbar - Pocket, as a service being added to the default home/newtab page - Firefox hello - Completely banning unsigned addons - Mr. Robot advert - And now probably this I want a browser that is rel…

You missed a few things: - They have telemetry turned as the default - They are experimenting with TLS over HTTPS and use beloved Cloudflare to handle every DNS request - They are always in the headlines about some shady 'addon' or 'extension' been sold off and taken over by shady actors - The TorBundle which is a fork of FF ESR is always in the headlines as been unsecure and way behind FF mainline release

Yes, I'm sure I missed some things, I was trying to keep the list as non controversial as possible. Here are some specific responses.

1. Agreed, but at least they do prompt fairly early letting you turn it off.

2. I'm only looking at things in the release version of firefox. As I note elsewhere they treat nightly/beta users much worse. Longterm TLS over HTTPS is great for privacy, and they had to choose some provider, so I'm mostly fine with this.

3. This isn't their fault, the same applies to chrome. An extension is a third party piece of software you choose to install.

4. Again, a third party piece of software, not under their control. Further they are actively working to improve this situation and bring Tor onto mainline firefox!

Re: Firefox partners with ProtonVPN

#75
post #16

I only use firefox. But I don't feel like I can strongly recommend it because of the long list of bad decisions. - Google analytics baked into about:addons - Sending data to Cliqz - Pocket, as a service being added to the topbar - Pocket, as a service being added to the default home/newtab page - Firefox hello - Completely banning unsigned addons - Mr. Robot advert - And now probably this I want a browser that is rel…

I would add:

- Public search for sources of other people's breached personal data via monitor.firefox.com (eg, you can enter anyone's email and see results, and not just your own, as there's no verification that you own the email until you sign up for continuous alerting)

That said, I love Firefox itself and think Mozilla usually try to do the right thing. Someone just lost the security vs usability debate there I guess.

Apparently informing people who won't check their email for a link but will enter their email into a form trumps protecting people who don't know the site exists from stalkers and other malicious actors.

Re: Firefox partners with ProtonVPN

#76
post #67

Earlier quoted context omitted.

I've never found the "choose this, because the other option(s) suck more" to be a particularly flattering argument for web browsers, programming languages, cars, or politicians.

The modern aversion to "lesser of two evils" is a thinly-disguised post-hoc rationalization for apathy (or worse, nihilism). It's not even false equivalence, because that would suggest trying to paint both "evils" as equal; no, this is simply saying that, when presented with two choices where one is better than the other, we might as well make the worse choice, because who cares?

Disagreed.

You should personally should choose the lesser of two evils when those are your only choices. Promoting the lesser evil is not such an easy call though.

From a practical standpoint, promoting an evil, even if it's a lesser evil, has the potential for harming your own reputation as a reliable source.

It is also fundamentally morally questionable, of course what is morally right and wrong is a matter of much debate. Suppose a psycopath calls you up and says "I'm going to do one of two things, shoot a random 5 year old named Joseph, or shoot two random 5 year olds named Kate, which should I do?". Assume for the hypothetical that you know they are telling the truth, and there is nothing you can do about the situation but choosing what you say back. In my view of the world saying "shoot Joseph" still makes you morally culpable, even though you were avoiding a worse situation.

Re: Firefox partners with ProtonVPN

#77
post #69
post #45

Earlier quoted context omitted.

I use to use nightly, then I found out they spy on you a lot more if you use nightly. I suspect the same applies to developer edition. [0] https://utcc.utoronto.ca/~cks/space/blog/web/FirefoxNoNightl... [1] https://lobste.rs/s/ri4kny/you_probably_don_t_want_run_firef...

When you first open a new Nightly install there's literally a banner across the entire browser telling you that it's collecting metrics, along with a button that displays more information and allows you to customize what data gets sent. The whole point of offering a Nightly build is so that they can have feedback on performance regressions and crashes. Characterizing it as "spying" is simply FUD.

And the event I'm linking to is a scenario where Mozilla updated nightly with no warning to share more data without telling me, against the policy stated about the setting in the browser. And a response by a Mozilla engineer saying that they thought this was perfectly acceptable behavior.

Re: Firefox partners with ProtonVPN

#78
post #49
post #41

Earlier quoted context omitted.

So if I understand correctly, you would want to know the details of how Mozilla audited ProtonVPN, is that it?

Everyone in Vilnius, Lithuania knows, that both, NordVPN and ProtonVPN, are being developed here by the people related to Tesonet, which has been recently sued in Texas Eastern District Court for the patent infringement in "Large-scale web data extraction products and services with residential proxy network ( https://oxylabs.io/ )"[1] by Luminati Networks, an Israeli data mining company behind HolaVPN[2]. The section…

Wow, thank you for posting. Protonmail's replies on Reddit are unsatisfactory, especially for this age's state of privacy. Any recommendations? Hard to trust any VPNs out there. We need some way to verify VPN server software, log deletion, and the like.

Re: Firefox partners with ProtonVPN

#79
post #28

I'm really excited about this idea, but I also think it isn't fully baked yet. I'm excited because VPNs are all about shifting trust: I'm no longer trusting Comcast not to sell my data, I'm now trusting SketchyVPN. If SketchyVPN turns out not to be trustworthy, then I'm paying for something that is worth less than $0 to me, and there's no way to detect that as a user. It's like paying more for organic food in a town…

I fully understand. If you can't trust Proton then you don't _actually_ benefit from anything.

If it helps however, ProtonVPN is by the people behind ProtonMail, the security-first email provider. They started in CERN as a mission to provide email to scientists that wouldn't be subject to censorship.

Their entire business - email and VPN both - embodies the same philosophy that Mozilla does.

It's rare that I trust any company but Mozilla and ProtonMail are two of a _very_ short list.

Re: Firefox partners with ProtonVPN

#80
post #16

I only use firefox. But I don't feel like I can strongly recommend it because of the long list of bad decisions. - Google analytics baked into about:addons - Sending data to Cliqz - Pocket, as a service being added to the topbar - Pocket, as a service being added to the default home/newtab page - Firefox hello - Completely banning unsigned addons - Mr. Robot advert - And now probably this I want a browser that is rel…

I would add: - Public search for sources of other people's breached personal data via monitor.firefox.com (eg, you can enter anyone's email and see results, and not just your own, as there's no verification that you own the email until you sign up for continuous alerting) That said, I love Firefox itself and think Mozilla usually try to do the right thing. Someone just lost the security vs usability debate there I gu…

> Public search for sources of other people's breached personal data via monitor.firefox.com

That page is powered by haveibeenpwned.com. Mozilla just made a fantastic security tool available to user who don't know about Troy's site.

> you can enter anyone's email and see results

This data is all very easily available online anyway. It's just aggregating leaks that already public, and neither HIBP or the Mozilla page provide the _actual_ personal info that was leaked.

> Someone just lost the security vs usability debate there I guess.

That's the thing though; this _is_ a valid security tool. And a powerful and valuable one at that. HIBP has been used for years by thousands of users to secure their accounts after data breaches.

Post reply on HN