Live data from Hacker News

Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

blog.mozilla.org

101–110 of 246 posts

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#101

I agree with the general sentiment in the comments that this is good -- fingerprinting in particular is something browser vendors should be trying to combat. I am concerned about the approach however; a simple blacklist of fingerprinting scripts may be insufficient, in that non-blocked scripts can still access the data that is used to accomplish fingerprinting. Personally, I would like to see more security around the…

I'm also concerned with the general blacklists that are showing up. Some of the analytics companies in the list they are using from github don't use any particular fingerprinting technologies outside of setting a cookie. Given that there are a wide array of more aggressive and seemingly more malicious ways to fingerprint, bundling up cookie usage with that seems like a recipe for throwing the baby out with the bathwa…

That would suggest that there is such a thing as a "good" analytics company.

From my perspective as and end user, why would it be desirable for me to facilitate the "analytics companies" business model?

Sure, far-reaching blacklists are probably bad for analytics companies across the board, regardless of their intent. But as an end user, why should I care?

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#102
Feels anti-competitive to have defaults to block mining while not having default enabled advert blocking.

I'm much happier for a site to mine on their tab while I'm watching a video than to show me 2 minutes of advertisements every 10 minutes. On mobile in particular, where video ads end up eating a large chunk of my data costs.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#103
post #79

Earlier quoted context omitted.

Why can't they just allow the user to whitelist recaptcha?

It would be more interesting, to me, to see Google support something like CloudFlare's Privacy Pass. https://support.cloudflare.com/hc/en-us/articles/11500199265... Though it seems unlikely they would want to? (Though I don't know a lot about and would be interested to hear criticisms of it.)

They would have probably supported it when CAPTCHAs were still about digitizing books. Now that they've turned everyone into unwilling trainers for their visual machine learning they'll never do it.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#104
post #78

Earlier quoted context omitted.

In principle advertising is fine. Telling people that a product exists is useful. "Do you need a hat shaped exactly like a golf ball? At Dave's Golf Ball Hats we sell six sizes!". Targeting this advert to most likely be seen by people who actually had been thinking of buying a hat shaped like sporting equipment is still a good idea too. But an advert that steals from you, or harms you is neither of those things. Goog…

> Targeting this advert to most likely be seen by people who actually had been thinking of buying a hat shaped like sporting equipment is still a good idea too. Not if that targeting is done using data gathered about me without my consent -- as it almost universally is. Targeting based on context (what sort of website the ad is on, for instance), is fine.

I don't understand this new position (that GDPR follows) that consent is required for information to be gathered on someone. If someone sees me wearing a blue shirt and writes in their notebook that I wore a blue shirt then I don't feel like I have some inherent right to coerce them to erase it or prevent them from selling that information to Blue Shirt Emporium.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#105
post #24

> In the coming months, we will start testing these protections with small groups of users and will continue to work with Disconnect to improve and expand the set of domains blocked by Firefox. We plan to enable these protections by default for all Firefox users in a future release. While lots of people here already have uMatrix or other blockers running, blocking fingerprinting and cryptomining domains by default wo…

Cryptomining seems like a fine alternative to ads to me. Or just the general idea of making the client do some computation work for you.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#106

Feels anti-competitive to have defaults to block mining while not having default enabled advert blocking. I'm much happier for a site to mine on their tab while I'm watching a video than to show me 2 minutes of advertisements every 10 minutes. On mobile in particular, where video ads end up eating a large chunk of my data costs.

You are happier to have your resources stolen and not be aware of it (it's invisible, you can't see what's happening and react - right?) than to be shown an annoying thing which is very much in your awareness? I don't know, I'd rather know someone is harming me silently and have the means to stop it by default. The things that are shown in front of me, I can handle them...

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#107
post #98

Earlier quoted context omitted.

I'd rather buy a browser as a company's primary product, not donate to Mozilla which makes a browser and does many other things, many of which I disagree with and would rather not fund.

Could you give some examples of things they do that you disagree with? I can't really think of any controversial non-firefox things they've done.

Controversial != useless. I don't like they wasted money on Firefox OS or Persona; I don't want to donate to them if my money goes there instead of to Firefox. In fact, why not let us decide where exactly our money will go if we donate?

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#108
post #68

Earlier quoted context omitted.

> like to see more security around the data that is used for fingerprinting, such as user agent I think this is already available, just not enabled by default. In about:config one need to set privacy.resistFingerprinting to true. (be aware however that this setting causes problems with google captcha - the number of challenges that you will need to solve will drastically increase)

> this setting causes problems with google captcha - the number of challenges that you will need to solve will drastically increase No kidding. I'm talking about ~30-40 clicks (1 click per task in the captcha grid)

not to mention when google puts you in captcha-hell-ban.

often, after a few difficult ones, I realize I get stuck into the same 20 challenges. over and over. no matter if I get them rigth or not. We do run all browser in the office with figerprint protection on and run non-exit-tor-nodes in all offices. But those are hardly excuses.

The hell bans happens more often on firefox for android, but I guess that is what you can expect when you go against goliath.

It's literally google censoring me from talking (and sometimes reading) random sites on the web

Post reply on HN