Live data from Hacker News

Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

blog.mozilla.org

121–130 of 246 posts

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#121
post #24

> In the coming months, we will start testing these protections with small groups of users and will continue to work with Disconnect to improve and expand the set of domains blocked by Firefox. We plan to enable these protections by default for all Firefox users in a future release. While lots of people here already have uMatrix or other blockers running, blocking fingerprinting and cryptomining domains by default wo…

Cryptomining seems like a fine alternative to ads to me. Or just the general idea of making the client do some computation work for you.

I like my battery to last a whole day, pretty please. Whenever on mobile and AMP is not an option, I'll try Firefox Focus. If that doesn't work, I'm as likely to move on as to revert to letting the site's affiliates run Javascript on my phone.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#122
post #108

Earlier quoted context omitted.

> this setting causes problems with google captcha - the number of challenges that you will need to solve will drastically increase No kidding. I'm talking about ~30-40 clicks (1 click per task in the captcha grid)

not to mention when google puts you in captcha-hell-ban. often, after a few difficult ones, I realize I get stuck into the same 20 challenges. over and over. no matter if I get them rigth or not. We do run all browser in the office with figerprint protection on and run non-exit-tor-nodes in all offices. But those are hardly excuses. The hell bans happens more often on firefox for android, but I guess that is what you…

And it's going to get worse if this whole "privacy" thing catches on. Google is an advertising company which does adtech, and adtech is inherently about tracking and profiling people. Anyone who messes with that is actively costing Google money, and Google will... you know... stop them from doing that, whether subtly or overtly. There's nothing else they can really do, and "congressional hearings" and "calls for reform" won't change that fundamental fact.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#123

This endless war could be solved with a single meeting with the 3 major adtech companies. All browsers have to do is share a single advertiser ID and have it reset by the user whenever they want. No more cookies, pixel syncs, or fingerprinting and all the related countermeasures. This is the exact mechanism used by mobile apps right now so it's already well-tested and proven to work.

"Solving" fingerprinting by fingerprinting ourselves seems like it might miss the point for a lot of people.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#124
post #106

Feels anti-competitive to have defaults to block mining while not having default enabled advert blocking. I'm much happier for a site to mine on their tab while I'm watching a video than to show me 2 minutes of advertisements every 10 minutes. On mobile in particular, where video ads end up eating a large chunk of my data costs.

You are happier to have your resources stolen and not be aware of it (it's invisible, you can't see what's happening and react - right?) than to be shown an annoying thing which is very much in your awareness? I don't know, I'd rather know someone is harming me silently and have the means to stop it by default. The things that are shown in front of me, I can handle them...

Firefox already has tools to throttle tabs which are abusive CPU-load wise, which seems sufficient in this case.

And it's unclear such resources are being 'stolen' if it's stated in the site ToS.

Cryptocurrency mining is a lot less deleterious than ads. Mining doesn't need to track your behavior, it doesn't generate misleading native content, and it doesn't distract you from what you're trying to do.

Sign me up!

disclaimer: I was one of the founders of Tidbit, https://www.eff.org/cases/rubin-v-new-jersey-tidbit, the first(?) crypto mining ad replacer.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#125
post #121

Earlier quoted context omitted.

Cryptomining seems like a fine alternative to ads to me. Or just the general idea of making the client do some computation work for you.

I like my battery to last a whole day, pretty please. Whenever on mobile and AMP is not an option, I'll try Firefox Focus. If that doesn't work, I'm as likely to move on as to revert to letting the site's affiliates run Javascript on my phone.

I think you'd optimally be able to choose between ads, mining, or paying some kind of token, maybe linked to your (Firefox/Google/etc) account so it could be mined on your desktop and used on mobile, or the tokens are just bought.

Anecdotally my phone is about 4 years old maybe and the battery still does fine browsing with JS on in Firefox mobile. That is with ublock though.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#126

Earlier quoted context omitted.

Untargeted advertising is very often more egregious than merely telling people a product exists. Traditional pre-digital advertising runs the gamete from "Come to me and I'll fix your car" to "You are ugly and unpopular, but you can fix that by drinking our caramel colored sugar water." Advertising that tries to induce then exploit self esteem issues is a plague.

This little bit of misdirection Google and Facebook have propagated about how much better the advertising you get with tracking is the slimiest piece of bait-and-switch in history. Seeing people repeat it like it's fact is testament to just how insidious it is. Targeted advertising is not designed to serve the viewer, it's designed to serve the advertiser. So advertisements you get are even sleazier than non-targeted…

Targeted advertising is not designed to serve the viewer, it's designed to serve the advertiser.

Advertising doesn't help the advertiser unless it helps you. Showing you an ad for something you don't want, can't use, and would never buy, benefits nobody.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#127
post #90

Earlier quoted context omitted.

You already can donate to Mozilla: https://donate.mozilla.org

I'd rather buy a browser as a company's primary product, not donate to Mozilla which makes a browser and does many other things, many of which I disagree with and would rather not fund.

[deleted]

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#128
post #67

Earlier quoted context omitted.

Could we make Javascript optional as well while we're at it? "This site tries to run Javascript. Normal news sites shouldn't need this. [Allow this session] [Allow 5 seconds] [Deny]" I'd be particularily interested in the second option since it would allow us to use sites that depend on JS for content while they roll back the craziness that is depending on scripting to show static content. While I'm at it: I want bad…

Ha ha, "certification" is a cool idea, but it would be hard to get anyone to care about it. "Allow 5 seconds" is a feature I really want now - I might dig into the Firefox code (or No-Script) and see if I can figure it out! I have no-script on by default, and these days I need be convinced there's a REALLY good reason to temporarily whitelist a site. Sure, a lot of the web is now either a blank page (or "you need to…

I've wanted the "allow 5 seconds" thing for a long time too.

You can manually pause and resume js by opening up the debugger and hitting pause. The code exists it just needs to be exposed to the UI.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#129

This endless war could be solved with a single meeting with the 3 major adtech companies. All browsers have to do is share a single advertiser ID and have it reset by the user whenever they want. No more cookies, pixel syncs, or fingerprinting and all the related countermeasures. This is the exact mechanism used by mobile apps right now so it's already well-tested and proven to work.

"Solving" fingerprinting by fingerprinting ourselves seems like it might miss the point for a lot of people.

Missing the point is the cause of all this mess.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#130
post #106

Earlier quoted context omitted.

You are happier to have your resources stolen and not be aware of it (it's invisible, you can't see what's happening and react - right?) than to be shown an annoying thing which is very much in your awareness? I don't know, I'd rather know someone is harming me silently and have the means to stop it by default. The things that are shown in front of me, I can handle them...

Firefox already has tools to throttle tabs which are abusive CPU-load wise, which seems sufficient in this case. And it's unclear such resources are being 'stolen' if it's stated in the site ToS. Cryptocurrency mining is a lot less deleterious than ads. Mining doesn't need to track your behavior, it doesn't generate misleading native content, and it doesn't distract you from what you're trying to do. Sign me up! disc…

> “we do not believe Tidbit was created for the purpose of invading privacy.”

I don't see how a cryptocurrency miner was ever going to invade anyones privacy so this seems like a weird choice of words.

Post reply on HN