Live data from Hacker News

LibreWolf – Custom version of Firefox, focused on privacy, security and freedom

librewolf.net

161–170 of 178 posts

Re: LibreWolf – Custom version of Firefox, focused on privacy, security and freedom

#161

Earlier quoted context omitted.

Tracking is tracking, no matter what outcomes you derive from it.

So your general thesis is that software that tracks errors and problems the software might have, and software that deliberately slows down the machine to make you buy new hardware A LA Apple is 100% the same thing?

I’m saying anything that tracks a user is not good for mankind. Telemetry is increasingly used for nefarious purposes. I have no problem if you want to track your own apps, but you can leave me out of it. You can derive my behavior from my access, my id, and my requests. You do not need to track my clicks, my history, my search phrases, my shopping habits, my location (unless I grant it to you), my cookies…

You may not force feed me cookies.

Re: LibreWolf – Custom version of Firefox, focused on privacy, security and freedom

#163
post #152
post #151

Earlier quoted context omitted.

It makes these connections even when all the things mentioned in the official "How to stop Firefox from making automatic connections"[1] are disabled. This includes the captive portal detection you allude to. Regardless: The browser asks me if I allow it to make these connections. I tell it in unmistakable and irrevocable terms that I do not. The browser makes these connections anyway. The problem was never the conne…

Am I really the troll, or those who bring down the only remaining truly libre, open-source browser engine over stupid nitpicky bullshits, while not contributing anything positive to improve on the status?

The point is, if you provide an option to turn off telemetry, it should be off. No exception. In this case of an airport connection requiring a registration page intranetwork, this occurs via first request through their proxy with header redirect.

The point is, don’t lie about saying you respect privacy with half-baked options and telemetry for me but not for thee bs. If I turn off telemetry, you aren’t allowed to send telemetry. Of any kind. Not a crash log. Not an install token. Not a call home to see if maybe possibly your on an airport wifi and make-our-app-work-edge-case()

Re: LibreWolf – Custom version of Firefox, focused on privacy, security and freedom

#165
post #135
post #59

Earlier quoted context omitted.

> There is a big difference between tracking to try to understand how users are using a software or getting information on bugs and crashes, and tracking with the aim of monetizing personal data. I don't see the difference. In one case you are trying to improve your product using stolen data (which presumably results in your user sat scores and/or userbase going up and you continuing to receive a paycheck, ie monetiz…

It is human psychology 101 that the default option is chosen in order of magnitudes more cases -- people are lazy. Should they really just let all that usability statistics be lost, even though their owner would more than likely be fine with its usage in most cases? Are countries with opt-out organ donation also evil? Doesn't the litany of saved lives worth more than a post-death "inconvenience"?

> Should they really just let all that usability statistics be lost, even though their owner would more than likely be fine with its usage in most cases?

Yes, 100%. They should not exfiltrate data without consent. If the owner is fine with it, they can just ask! (I'll let you in on a secret: they don't ask because most users, when asked, do not want to be placed under surveillance!)

> Are countries with opt-out organ donation also evil? Doesn't the litany of saved lives worth more than a post-death "inconvenience"?

You don't need your organs when you are dead. You do need your privacy when you are alive.

Re: LibreWolf – Custom version of Firefox, focused on privacy, security and freedom

#166
post #35

Just use a custom user.js, LibreWolf doesn't deliver much beyond a few major tweaks and a logo.

do you have an example or directions?

You can start with mine, I've mostly stripped all the telemetry, added DoQ DNS (please, don't use my NextDNS id :D otherwise it's going to eat the free 300k limit), lots extra DNS/HTTP/rendering performance tweaks, some security fixes (e.g. deprecated ciphers) without performance penalties and personal Firefox's quality of life changes (smaller delays, ability to save everything, tracker stripping, etc). Some configs like the already mentioned Arkenfox's take security to a next level with first party cookies only, sandboxing and etc, it might be too overwhelming and not actually that necessary.

https://gitlab.com/ac130kz/dotfiles/-/blob/main/configs/user...

Re: LibreWolf – Custom version of Firefox, focused on privacy, security and freedom

#167
post #137

Earlier quoted context omitted.

> Telemetry and spyware are not the same thing Telemetry is spyware if it's done without the active informed consent of the user. What the collected data is actually used for isn't relevant. Consent is the relevant factor.

I'm sure it is written in some license agreement you implicitly accept by downloading/installing the software.

That's not true. Firefox is free software. It is licensed under the MPL.

Re: LibreWolf – Custom version of Firefox, focused on privacy, security and freedom

#168

I got fed up with Chrome recently (some real ugly on-by-default advertising tracking) and switched to Firefox on my work computer but not my home computer yet. Is anyone out there self-hosting firefox sync successfully? My googling seemed to only bring up a deprecated version so I haven't really tried setting it up yet.

Firefox sync encrypts your data with your password (it's not exactly like that but that's the gist of it) and Mozilla has zero access to it, none at all. I see no reason not to trust them with that. It's a lot easier and _safer_ to use their service then to set up your own. Why safer? Because with your own self-hosting, now you have to have an extra device wide open to the Internet whose safety and security you need…

You make a good point about a potential pitfall of self-hosting things. I'll mention though that if you are self-hosting for just yourself (or some small number of people), you can set up a VPN connection for secure access to your private network, which eliminates the need to open ports to the public internet at all. Other than the VPN of course.

Not that you should necessarily rely solely on the VPN for your security, but it helps.

Re: LibreWolf – Custom version of Firefox, focused on privacy, security and freedom

#169

Earlier quoted context omitted.

Everything I said is 100% true. There are a lot of people on this very site working in adtech who don't feel like they're doing anything wrong at all and use the exact same logic that people use to justify "telemetry". In their mind, they're making a better product and a wealthier, more productive world in the process. You have literally no logical or moral delimiter between how Firefox spies on me to improve Firefox…

You're arguing in bad faith.

No, you are.

Re: LibreWolf – Custom version of Firefox, focused on privacy, security and freedom

#170
post #59

Earlier quoted context omitted.

Telemetry and spyware are not the same thing (irrespective of whatever Firefox is doing). There is a big difference between tracking to try to understand how users are using a software or getting information on bugs and crashes, and tracking with the aim of monetizing personal data. I'm personally not crazy about telemetry implying information is uploaded to a software provider, but from experience I know that trying…

> There is a big difference between tracking to try to understand how users are using a software or getting information on bugs and crashes, and tracking with the aim of monetizing personal data. I don't see the difference. In one case you are trying to improve your product using stolen data (which presumably results in your user sat scores and/or userbase going up and you continuing to receive a paycheck, ie monetiz…

Like the argument with copyright, it's not theft. It's only theft if the user is deprived of something.

> In both cases you are taking private data without consent and using it to get money, or money-equivalent things (like a better product or more users)

This is just word salad. Opting in is consent. You are absolutely free to opt out, by following the clear instructions on the website [0], and you can continue to use the software. Your rights are being deprived here.

Secondly, "money equivalent things" is a reductionist argument. Not everything fits neatly into a black and white "right" and "wrong" bucket, and arguing it does is forgetting about the fact that technology doesn't exist in a vacuum any more than any other product or industry.

> Technically and philosophically there is absolutely no distinguishing feature between opt-out "telemetry" and spyware.

Technically there's no difference between me sending any kind of data to a remote service. Using rote logic to infer behaviour is a fallacy, and when I read comments like this I end up (unfortunately) coming away thinking "this person has no critical thinking skills". I'm aware it's an ad-hominem, but logically there's no other explanation other than you can't possibly understand anything other than your narrow world view.

[0] https://support.mozilla.org/en-US/kb/telemetry-clientid

Post reply on HN