Live data from Hacker News

Each Firefox download has a unique identifier

ghacks.net

131–140 of 480 posts

Re: Each Firefox download has a unique identifier

#131

Earlier quoted context omitted.

My point is that they failed only because they were betrayed by the free software tool they thought they could trust.

Mozilla has never advertised that their software was designed to keep you anonymous.

They never advertised either they were tracking every download...

Re: Each Firefox download has a unique identifier

#132
post #125

Earlier quoted context omitted.

If you position your product as being about privacy, your company about being about privacy, and talk about the importance of online privacy whenever you get any sort of opportunity, then it looks extremely bad if you can't refrain from spying on your users. I don't really think there is any way around this fact. If this type of telemetry is necessary for Mozilla to develop software, then perhaps they shouldn't be ta…

do you seriously consider counting how many installs are triggered from a download "spying"? Privacy is a bit more complicated than that IMHO.

> do you seriously consider counting how many installs are triggered from a download "spying"?

Yes. It is a unique identifier that they are fully capable of associating with telemetry data and other personal activity. It could be used by various parties to deanonymize me. That is spying. You are playing dishonest semantic games.

Effective privacy may well be complicated. Perhaps you can maintain effective privacy in various ways even while being actively spied on in some manners. That doesn't mean that spying isn't spying.

Re: Each Firefox download has a unique identifier

#134

Earlier quoted context omitted.

Mozilla has never advertised that their software was designed to keep you anonymous.

No, but they advertise that "Firefox automatically protects your privacy while you browse". https://support.mozilla.org/en-US/kb/enhanced-tracking-prote...

It's possible that they are tracking how many times an installer gets used without violating your privacy. Installers can be shared online or you can install it on someone else's computer. It's not like they are specific to a person.

Re: Each Firefox download has a unique identifier

#135
post #9

Earlier quoted context omitted.

A download identifier really isn't that bad. Maybe they need to actually show some numbers of their downloads to justify budgets and other things. It's not like they are having tracking JavaScript on 80% of the worlds Web sites like someone else I know, starting with Googl...

Download counts dont need you to embed a unique token. At the most basic level, you can get this by doing a count over http logs.

To tell how many downloads result in an actual install http logs are not enough. You will get extra noise on top of the data you care about.

Re: Each Firefox download has a unique identifier

#136
post #126

Suppose you want to do something anonymously. 1. Download installer from Mozilla from your home network - Mozilla now has your home IP and installer ID. 2. Transfer it via USB key to a secure, anonymous computer - one not linked to you, on a network not associated with you, such as public WiFi. 3. Install Firefox using that installer on said computer. It transmits the installer ID to Mozilla, which matches the one gi…

I hope you don’t use the internet at all if this is your threat model.

The threat model is reasonable behavior + a single warrant or data leak. It may not be the most likely way of compromise, but it's very possible, and such small insecurities add up. Mozilla should be making such compromise less likely, not more.

Re: Each Firefox download has a unique identifier

#138
post #14

They seem to be trying to gather a lot of telemetry to measure how they can boost popularity of Firefox. I wonder did they tried to measure how the measurement itself influences popularity? Social measurements are like quantum ones, they change reality. There was a funny story of a Hawthorn Experiment[1], which tried to find ways to boost productivity but at the end managed to state just that the very attempt to cond…

That seems like a very harsh interpretation. Very few people will care whether their specific download is tracked. I do honestly wonder how that adds vakuento Mozilla, but no one will not use Firefox due to this- especially as every single alternative is much worse than Firefox on such metrics.

If they really thought that 'very few people' would care about it ... why then didn't they 'the privacy browser' reveal this 'feature' when it was rolled out?

'Low-level skulduggery' is the nicest description I can muster (noone wants to hear what I really think).... Now (with telemetry 'turned off' each time before took it online) I have to wonder what else is 'protecting' me....

Re: Each Firefox download has a unique identifier

#139
post #10

Firefox users who prefer to download the browser without the unique identifier may do so in the following two ways: Download the Firefox installer from Mozilla's HTTPS repository (formerly the FTP repository). Download Firefox from third-party download sites that host the installer, e.g., from Softonic. It's nuts and another indication Mozilla doesn't understand the reason they exist, but it's not that hard to get ar…

3) Install Firefox from your operating system's repository instead of from Mozilla

Re: Each Firefox download has a unique identifier

#140
post #125

Earlier quoted context omitted.

do you seriously consider counting how many installs are triggered from a download "spying"? Privacy is a bit more complicated than that IMHO.

> do you seriously consider counting how many installs are triggered from a download "spying"? Yes. It is a unique identifier that they are fully capable of associating with telemetry data and other personal activity. It could be used by various parties to deanonymize me. That is spying. You are playing dishonest semantic games. Effective privacy may well be complicated. Perhaps you can maintain effective privacy in…

There is a very large difference between "X is spying on Y" and "X could spy on Y if they started to record and correlate things". And even "I don't trust them not to" is not the same as "they are". A lot about privacy involves not looking at things you could look at.

E.g. picking the example mentioned repeatedly in this discussion: Network transfers annoyingly involve IP addresses. That doesn't mean every server you talk to is spying on you, and there is wide a range from "doesn't record anything", over "keeps a log of errors for 5 days that's only used for debugging", over "looks in GeoIP database and counts visitors per country", to "immediately connects your IP to your user profile and shares that data packet with 50 ad networks". I have a hard time calling the first three "spying", it starts IMHO somewhere after that. And annoyingly, telling the difference comes down to trust at some point.

Or even simpler, I could trivially spy on my neighbors with what reaches my apartment. I don't though.

Post reply on HN