Live data from Hacker News

Dear Mozilla, please stop spamming

palant.de

21–30 of 126 posts

Re: Dear Mozilla, please stop spamming

#21
post #7

Earlier quoted context omitted.

What browser would you suggest instead? I feel a bit cornered, especially now that literally every alternative is based on chromium.

Brave seems ok, has a pretty good built in adblocker

They're remarkably scummy. They swapped out advertisements for a cryptocurrency scam.

Maybe the browser itself is OK. I've never used it.

Re: Dear Mozilla, please stop spamming

#22

Mozilla is ethically compromised at the highest levels. They’ve made a shift over the last few years from a scrappy, low-rent, nonprofit dedicated to helping the web to just another data mining tech company. Just try setting your Firefox browser to a blank page with no requests on startup and watching the Wireshark log if you think otherwise.

> Just try setting your Firefox browser to a blank page with no requests on startup and watching the Wireshark log if you think otherwise

OK, so I just did this, and I don't really see what the issue is. Looking at Wireshark, I see requests for:

* detectportal.firefox.com, which is used to detect whether you're connected to a captive portal network and need to sign in before you can connect to the internet. As far as I'm aware, no personal information is transmitted as part of this request, and there's apparently a pref to disable it [0]

* A couple of requests for OCSP certificate validation [1], which seems like a useful feature, and is also pretty easy to disable if you really don't want it.

* A request to download.mozilla.org and another one to download.cdn.mozilla.net, which looks like it's checking whether an update is available.

I don't really see a problem with any of these?

[0] https://bugzilla.mozilla.org/show_bug.cgi?id=1307867 [1] https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...

Re: Dear Mozilla, please stop spamming

#23

Mozilla is ethically compromised at the highest levels. They’ve made a shift over the last few years from a scrappy, low-rent, nonprofit dedicated to helping the web to just another data mining tech company. Just try setting your Firefox browser to a blank page with no requests on startup and watching the Wireshark log if you think otherwise.

Requests like what, updating extensions? Telemetry? There's quite a bit that ships on by default but that can be disabled in about:config. What proof do you have they're data mining besides FUD?

Re: Dear Mozilla, please stop spamming

#24
post #3

In a similar vein, I'd appreciate it if Mozilla would stop using updates to Firefox as a mechanism to re-enable misfeatures I've explicitly disabled like Pocket integration and the "recommend X feature|extension while you are browsing but don't forget we totally respect your privacy!" settings. :-/

That sounds like a bug to me.

Re: Dear Mozilla, please stop spamming

#25

Earlier quoted context omitted.

What browser would you suggest instead? I feel a bit cornered, especially now that literally every alternative is based on chromium.

Good question. Other than Firefox, Webkit/Blink based browsers are pretty much the only thing usable on the modern web without crashing. That leaves ungoogled Chromium, which unless you're compiling it yourself (good luck) means just blindly trusting some random internet person for binaries. There's really no good answer at this point.

Worse: even if the person (or organization) providing the binary is well-meaning, they would need some serious resources (mostly programmers) to provide security updates quickly enough.

The least resource-intensive way to provide attack-resistance near the level provided by Google's Chrome team would probably be to notify the user when a vulnerability is disclosed so that the user can either switch to Chrome or restrict their browsing to safe sites till the binary provider can get a security update out.

I know of no one doing that or providing timely security updates however except Google, possibly Opera, possibly Brave and probably some day soon Microsoft.

Re: Dear Mozilla, please stop spamming

#26
post #20

Earlier quoted context omitted.

What browser would you suggest instead? I feel a bit cornered, especially now that literally every alternative is based on chromium.

This site suggests IceCat, Ungoogled Chromium, Iridium or Pale Moon: https://spyware.neocities.org/articles/browsers.html The also have a guide for enhancing privacy in Firefox

There's also Brave browser.

Re: Dear Mozilla, please stop spamming

#27
post #20

Earlier quoted context omitted.

What browser would you suggest instead? I feel a bit cornered, especially now that literally every alternative is based on chromium.

This site suggests IceCat, Ungoogled Chromium, Iridium or Pale Moon: https://spyware.neocities.org/articles/browsers.html The also have a guide for enhancing privacy in Firefox

After this discussion, I would think very hard before using Pale Moon https://news.ycombinator.com/item?id=19410928

Re: Dear Mozilla, please stop spamming

#28
post #7

Earlier quoted context omitted.

Brave seems ok, has a pretty good built in adblocker

They're remarkably scummy. They swapped out advertisements for a cryptocurrency scam. Maybe the browser itself is OK. I've never used it.

How's the browser a scam? I use it and enjoy it. I think their business model is the most egalitarian business model amongst all browsers.

Re: Dear Mozilla, please stop spamming

#29

Mozilla is ethically compromised at the highest levels. They’ve made a shift over the last few years from a scrappy, low-rent, nonprofit dedicated to helping the web to just another data mining tech company. Just try setting your Firefox browser to a blank page with no requests on startup and watching the Wireshark log if you think otherwise.

What browser would you suggest instead? I feel a bit cornered, especially now that literally every alternative is based on chromium.

Brave.

And what's wrong with Chromium?

Re: Dear Mozilla, please stop spamming

#30
post #22

Mozilla is ethically compromised at the highest levels. They’ve made a shift over the last few years from a scrappy, low-rent, nonprofit dedicated to helping the web to just another data mining tech company. Just try setting your Firefox browser to a blank page with no requests on startup and watching the Wireshark log if you think otherwise.

> Just try setting your Firefox browser to a blank page with no requests on startup and watching the Wireshark log if you think otherwise OK, so I just did this, and I don't really see what the issue is. Looking at Wireshark, I see requests for: * detectportal.firefox.com, which is used to detect whether you're connected to a captive portal network and need to sign in before you can connect to the internet. As far as…

>I don't really see a problem with any of these?

You seriously don't have an issue with being fingerprinted and tracked every single time you open an application on your computer?

The point is that there should be zero. I should not have a single outgoing network request triggered by opening a web browser to a blank page until interacting in some way. The fact that we've lost this as a standard is terrifying to me.

Post reply on HN