Live data from Hacker News

LibreWolf – A fork of Firefox, focused on privacy, security and freedom

librewolf-community.gitlab.io

251–260 of 310 posts

Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom

#251

Earlier quoted context omitted.

> there's a bunch of 'features' disabled like […] auto-updates YIKES. Automatic updates are incredibly important for security. Disabling them by default is highly concerning. Does the browser support (manual) self-updates at all, or has that functionality been disabled entirely?

I have been burned often enough by software that auto-updates itself that I am positive I don't want it enabled by default on _my_ systems. Anywhere from between "this feature I really liked is gone" to "now it crashes every five minutes." Perhaps more importantly, companies that offer software that can auto-update itself, can also make it so that the software uninstalls itself. Or worse, installs something you don't…

> I have been burned often enough by software that auto-updates itself that I am positive I don't want it enabled by default on _my_ systems.

Even then, there's a difference between "automatic updates aren't enabled by default" and "the application cannot update itself at all, even if you ask it to, so you'll have to download the new version yourself" -- and it sounds like this developer has chosen the latter.

Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom

#252
post #237

Earlier quoted context omitted.

Telemetry isn't inherently bad or privacy violating.

> Telemetry isn't inherently bad or privacy violating. How can you tell?

In Firefox:

point your url bar to about:telemetry

It shows you all the data that has been gathered. (Though IIRC it might still show stuff even when you've disabled telemetry -- in that case the data is being aggregated locally but not sent.)

Go to https://telemetry.mozilla.org

To look at the data on the server side. There are more sophisticated ways of querying it, but obviously not everybody can just be handed access to run arbitrary analysis code.

Probe dictionaries:

https://searchfox.org/mozilla-central/source/toolkit/compone...

https://searchfox.org/mozilla-central/source/toolkit/compone...

https://searchfox.org/mozilla-central/source/toolkit/compone...

Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom

#253

Earlier quoted context omitted.

> there's a bunch of 'features' disabled like […] auto-updates YIKES. Automatic updates are incredibly important for security. Disabling them by default is highly concerning. Does the browser support (manual) self-updates at all, or has that functionality been disabled entirely?

I have been burned often enough by software that auto-updates itself that I am positive I don't want it enabled by default on _my_ systems. Anywhere from between "this feature I really liked is gone" to "now it crashes every five minutes." Perhaps more importantly, companies that offer software that can auto-update itself, can also make it so that the software uninstalls itself. Or worse, installs something you don't…

I’m sorry but if you think that disabling auto-updates on goddamn browsers, then you may not be as technical a user as you think of yourself.

Browsers run untrusted code 0-24, which get JIT compiled to machine code through a very complex and bug-prone process. Add to that that desktop OSs are quite lacking when it comes to sandboxes, so even with browser sandboxes, the potential for serious damage is quire hard.

So, staying ahead of bugs is a must.

Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom

#254
post #241

Earlier quoted context omitted.

> Until Firefox accidentally disables these settings or replaced them with new ones with new defaults, deprecates these plugins or introduces a new privacy invasion. Did anything of the sort ever happened at all or are we only entertaining thought experiments?

It happens all the time with different OS’, software, games, and apps. I don’t know of a single example of Firefox doing it, but I feel like it’s fair if people are thinking about it as a possibility.

> I don’t know of a single example of Firefox doing it, but I feel like it’s fair if people are thinking about it as a possibility.

This line of reasoning doesn't add anything of value because the same fear mongering applies to LibreWolf and any other project just the same.

Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom

#255

Earlier quoted context omitted.

How does google safe browsing make me safer? It’s just sending all my network data to google for them to tell me if it’s safe or not. If you don’t see the issue with sending every website you use to google for them to tell you if it’s safe I don’t know what to tell you. Sending your browsing history to a database has everything to do with privacy.

It's not even the privacy aspect alone. There have been repeated cases of absolutely legit, not even controversial sites landing on blacklists, for reasons of technical errors maintaining those, or some jurisdictions DMCAing some other site(s), hosted behind the same IP-range in the same data-center. Boom. Suddenly the site is gone, or at least you have to click around endless warnings about impending doom if you pro…

How often does a non-controversial site gets added to it vs the genuine threats/phishing websites it protects grannies from? I think it has an absolutely good tradeoff based on the relative percentages of the former categories.

Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom

#256

Earlier quoted context omitted.

I suggest you look up how Google Safebrowsing works; it's not how you may think. I'm pretty anti-Google and I leave this feature switched on because I believe the trade-offs are worthwhile.

>Google maintains the Safe Browsing Lookup API, which has a privacy drawback: "The URLs to be looked up are not hashed so the server knows which URLs the API users have looked up". The Safe Browsing Update API, on the other hand, compares 32-bit hash prefixes of the URL to preserve privacy. The Chrome, Firefox and Safari browsers use the latter. >Safe Browsing also stores a mandatory preferences cookie on the compute…

> The Safe Browsing Update API, on the other hand, compares 32-bit hash prefixes of the URL to preserve privacy. The Chrome, Firefox and Safari browsers use the latter.

How exactly?

Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom

#257
post #189
post #154

Earlier quoted context omitted.

> regular-user feedback, not power-users, is crucial in taking those decisions In general, that's true. But Firefox is an exception to this. The most important thing to a regular user, is that their websites work. But for websites to work, the developer had to test in Firefox. So, Firefox's alienation of power users has hurt its regular userbase. There's also the distinction between users vs customers. Most users pay…

Whether devs test in firefox or not is orthogonal to whether they like the product, it is entirely based on its market share. No sane person wanted to test on IE, but it was mandated by the company.

That's partly true. N of one, but I have Firefox set up the way I want it to, so I do all my development in Firefox and then occasionally test in Chrome. Essentially all my users use Chrome, so if I didn't prefer Firefox's ux it would get much less attention

Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom

#258
post #110

Earlier quoted context omitted.

This could be solved by a lot of transperancy about what collected telemetry is saying. A user can then check if the users that opted-in to telemetry are representative of his own use cases and thus make an informed decision if he should opt-in as well (if he's not well represented). Telemtry is a lot like voting.

The vast majority of people will not read about the collected telemetry, even fewer will read it and then make a decision to opt-in.The telemetry is optimizing for the vast majority, not the loud minority, hence opt-out works better in order to cater to a larger group of users. Your voting analogy is really bad. With that said, I don't really like telemetry and will turn it off.

I think voting is a good analogy for telemetry. You submit your use case to help decide development direction.

Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom

#259
post #2

Why are there not more successful forks of Firefox? While it's still my browser of choice, I think it's safe to say there are a significant number of developers who are not happy with the leadership of Mozilla. What's preventing other forks from taking off?

Some years ago Mozilla decided that rather than creating a browser toolkit that browser developers could build browsers a round, they would go the whole hog and combine the engine with the user interface aspects.

Even their own developers objected to the policy, but they went ahead anyway.

Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom

#260
post #195

Earlier quoted context omitted.

Based on their recent design changes (deprecation of compact mode, for example), they are either not collecting enough telemetry about the affected parts of the UI/UX, or they are ignoring what they have collected for whatever reason. Of course, there is a chance that telemetry confirms their vision, but based on the explicit feedback I've been seeing online, I doubt the rationality of their decision-making at least…

How do you compare strong voices of a few on a site like HackerNews or Reddit against many many many millions of data points of users around the world. Should written feedback overrule a bigger data set?

If the telemetry-based removal of a feature would turn out to be a dealbreaker for a critical mass of users, it should be reconsidered (think of Mozilla's position in the browser market nowadays: it can't afford to piss off the "power users" and evangelists of Firefox).

And it's not like Firefox has no Nightly or Beta branch to test the waters before making a significant change. For example, during the prerelease phase of the so-called Proton UI, there was no shortage of clear feedback about it. A lot of it was legitimate criticism about accessibility (harder to distinguish inactive horizontal tabs because the separators were removed; part of the new palette did not have enough contrast; etc.) and usability (e.g. in cases of low screen estate, some menus were suddenly so huge that they'd not fit within the height of the screen).

Mozilla is slowly fixing some of these issues, which is a good sign IMO, but also sticking to some other "deliberate design decisions" that still remain controversial. I largely do not believe in design-by-committee, by the way. However, I believe that all valid feedback should be evaluated and taken into consideration if it's critical.

Post reply on HN