Live data from Hacker News

Waterfox Browser

waterfox.net

81–90 of 111 posts

Re: Waterfox Browser

#82
post #15

I don’t get it, the concern is that Firefox sends telemetry to Mozilla? Can’t you turn that off?

I suppose the difference is that in Firefox you have to opt out of it, and in Waterfox you opt in (?). The default makes a difference, since most users don't know about it.

It's about the audience. People who don't know or care about telemetry tracking are also probably not going to know about Waterfox.

The ones that do know about waterfox are probably technically savvy enough to disable telemetry in regular old Firefox.

Re: Waterfox Browser

#83
post #40

Earlier quoted context omitted.

I think they are claiming "you don't have to worry about any tracking or usage information being sent to the Waterfox developers ," but if so, they shouldn't say "you don't have to worry" (see also Lavabit and Protonmail's "you don't have to worry about government surveillance... well, not until the government decides to surveil you"). I agree it's weird for a web browser of all products to omit this clarity!

That's fair, but it is also very misleading. It also isn't hard to see how it is misleading, enough so that I'm sure I'm not the first to notice it and that I would assume it has been brought to their attention. If not, well... someone ping them.

I don't think it's misleading in the slightest.. When you disable telemetry in an application or operating system, you're disabling that application's collection and transmission of metrics to its developers.

Disabling telemetry in Windows doesn't prevent programs from collecting metrics, it disables the transmission of Windows metrics to Microsoft. Can you give an example of the kind of 'disable telemetry' option you describe which prevents third parties from fingerprinting or transmitting data?

Re: Waterfox Browser

#84

Earlier quoted context omitted.

> It's not worded precisely, but I believe what they have in mind is tracking performed without prior consent by the browser author. That was my interpretation. If I tell someone "I'm not collecting any data on you, so you don't have to worry about being tracked", it would be odd for them to accuse me of lying or being incompetent since obviously the government is tracking them.

> obviously No, it's not obvious. If you don't have any idea how it works, it's easy to read in that statement that not including telemetry in the browser prevents all tracking, including by sites.

This seems more like people having different ideas of what the word 'telemetry' means than a malicious statement meant to mislead users. Telemetry metrics were used before the digital age in diving equipment, rockets, airplanes, factory equipment, etc. Traditionally, they are used exclusively to better understand and improve the performance of the device collecting them (and nothing else).

Recent unethical practices of either using true telemetry metrics for advertising purposes or collecting data not used to improve the software under the guise of 'telemetry' have muddied the meaning of the term. I agree that the author could change the phrasing in that blurb to use a different word which has not shifted meanings in the last decade.

Re: Waterfox Browser

#85

Looks like there is another version of waterfox at the .org domain. Which domain is the correct one? Can you get the incorrect domain de-listed from google search results? https://waterfoxproject.org/en-US/

When you go to the blog/web log on the. Org site, it redirects you too the .net site, so I would guess the .net is the legit one

Re: Waterfox Browser

#86

> Waterfox does not collect ANY telemetry, meaning you don't have to worry about any tracking or usage information about what you do inside YOUR browser. This is woefully uninformed or malicious. There's a lot of tracking that is out of your hands. Such as canvas fingerprinting. Even sending back 0's (like tor does) doesn't prevent fingerprinting. In either case I lost confidence for the browser just by reading what…

This is like saying that a given browser is malicious, because it sends HTTP requests, accepts cookies and uses JS. It's a fork of Firefox (or distribution?), so you're barking up the wrong tree.

Re: Waterfox Browser

#87
post #45

Alternatives that allow you to still get your security and stability updates from Mozilla include two Gnu soft-forks. There's IceCat, which is the best-supported version and runs off of ESR. [1] There's also "abrowser" (that's literally what it's called) that is part of the Gnu Trisquel distribution, which is based on the most recent release. Both patch the browser to be more security and privacy friendly. [2] There…

The most recent version of IceCat at this time is 60.3.0, published on 2018-11-09 [1], 18 days after upstream [2]. Upstream is currently at 60.7.0, published on 2019-05-20 [3]. This puts IceCat more than half a year behind upstream. Waterfox published their version merging upstream 60.7.0 security fixes before upstream [4].

Using IceCat thus seems to a bad idea security-wise.

I use upstream ESR ever since FF disabled add-ons since they let their cert expire [5] and the release channel version ignores the 'xpinstall.signatures.required' flag.

[1] http://ftp.gnu.org/gnu/gnuzilla/60.3.0/

[2] https://ftp.mozilla.org/pub/firefox/releases/60.3.0esr/

[3] https://ftp.mozilla.org/pub/firefox/releases/60.7.0esr/

[4] https://www.waterfox.net/blog/waterfox-56.2.10-release-downl...

[5] https://arstechnica.com/information-technology/2019/05/firef...

Re: Waterfox Browser

#88
post #42
post #37

Earlier quoted context omitted.

It isn't linked from https://www.waterfox.net at all, so hard to say

I mean, about page says Alex Kontos, MrAlex94 is Alex Kontos, so it almost certainly is. Not linking the source code is somewhat understandable because it is likely to increase support burden without any increase in contribution.

I would say matching a repository based solely on a person's name is not a great way to ensure you have the right code.

Re: Waterfox Browser

#90

Earlier quoted context omitted.

I loved DownThemAll, but I'm not sad to see it go because I realised how rarely it was actually needed these days. The downloading interface built into Firefox really is fine 99% of the time. On the rarer occasions that I need to download extremely large files, I send them to an HTTP download client (pyload) that runs directly on my NAS in docker.

One thing that DownThemAll got right that I am not sure any other downloader I have found does is that if a download is terminated by the server before the reported file size of the file had been downloaded, it would see that as a failure and retry. Unreliable servers often terminate the download partway through and it seems most other download mangers, browsers etc. will just leave the truncated file on the disk and…

Yes, and I remember really appreciating DownThemAll's quite robust architecture back when I had a 1.5 megabit ADSL connection. But now that I have a 100 megabit connection at home, I'm rarely downloading anything that doesn't finish within 5 minutes. In the exceedingly rare event that a 10GB download fails, it's just not a big deal to start it again.

Obviously this doesn't apply to everyone.

Post reply on HN