Earlier quoted context omitted.
> Or the third option: they feel the tradeoff of HN & co's criticism style is not a big deal in the end. That’s the second option: they don’t care. > This thread in general feels like it leaves Mozilla no room to experiment If you you’re going to experiment with something that’s going to cause this amount of backlash (and my criticism is that they didn’t take the obvious reaction into account), you show a dialog on f…
> Mozilla in particular is frequently pulling crap like this and getting flak for it. They have to constantly apologise and back track. After a while you’d expect they learned something. Well, they learned: they fuck up, backtrack & apologize (it is free, no real impact, so no worries), and life goes on.
For advertising, Firefox now collects user data by default
391–400 of 523 posts
Re: For advertising, Firefox now collects user data by default
#392More discussion among others: https://news.ycombinator.com/item?id=40952330
Re: For advertising, Firefox now collects user data by default
#393Earlier quoted context omitted.
Firefox playing their game makes Firefox completely redundant. The advertisers get your data either way, so why not use Chrome? Firefox compromising heralds its own irrelevance.
> The advertisers get your data either way, so why not use Chrome? You might believe that the advertisers get less of your data if you use Firefox. Similarly: you might be less likely to have your house burgled if there are locks on the doors and a burglar alarm, even though people with those things still get burgled sometimes. You might be less cold outdoors in winter if you wear a parka, even though it's still cold…
Re: For advertising, Firefox now collects user data by default
#394Re: For advertising, Firefox now collects user data by default
#395Earlier quoted context omitted.
AGPL is a lawyer’s nightmare. Not just because of the restrictions - but because it’s very, very sloppily put together. Does connecting a AGPL-licensed database to your website make your whole website AGPL? What is the line between an innocent connection, or a viral integration? What happens if you add a proprietary protocol to the database specifically for your app? Do you need to open source it, if that database is…
Let's look at this paragraph, which is the only real difference between the GPL & AGPL, because I think the English is perfectly clear and understandable: > Notwithstanding any other provision of this License, if you modify the Program, your modified version must prominently offer all users interacting with it remotely through a computer network (if your version supports such interaction) an opportunity to receive th…
Because you are not a lawyer. The points I’ve made have been cited by actual lawyers. Your opinion as a technologist blinds you to the degree of legal ambiguity.
https://opensource.google/documentation/reference/using/agpl...
https://writing.kemitchell.com/2021/01/24/Reading-AGPL
Also, the very fact that these opinions exist shows this license is not safe. There’s never a correct interpretation that will perfectly win the day eventually, only rulings. As the AGPL has never been in court before, things could quickly go sideways.
As my second link, written by an actual lawyer, puts it: “Inebriated aliens might as well have beamed it down from space as a kind of practical joke.”
Re: For advertising, Firefox now collects user data by default
#396Enough of this waiting for virtuous entities to address legitimate concerns of the public. The "ad industry" is a cancer and we need legal protection against this "industry". The solution is political not technical and definitely can not be left to "the market". Haven't you had enough?
Anyone bothered enough by advertising can stop using whatever product has been ruined by ads, or find ways to remove the advertising. More laws and larger governments doesn't have to be the answer to all problems. If consumers care enough they'll change their usage, if they don't change their usage they likely don't care enough.
More laws and larger governments are generally undesirable (for obvious reasons) but saying that we shouldn't make any laws at all is throwing the baby out of the bathwater.
If you're thoughtful and deliberate about how you write your legislation, you can have a disproportionately positive impact with a very small amount of additional weight.
For instance, instead of trying to enumerate every single way that data could be leaked and forbid that (see: HIPAA), you should just make the end state (PII in the hands of someone the user didn't explicitly authorize it to be in) illegal and mandate a fine per unit of information (e.g. 1% of the median US salary for SSN) to every entity in the leak chain (because a chain of custody for personal information is just about mandatory at this point).
Details will vary, but this general approach is vastly better than the crazy laws we have in other areas that attempt to "enumerate badness" in the intermediate rather than the end state.
Re: For advertising, Firefox now collects user data by default
#397Earlier quoted context omitted.
That is because Mozilla has consistently moved Firefox in the direction of a Chrome clone. When Firefox started is was not a copy of existing browsers. There is no reason it would have to be now. But they have rejected their core users. So now the only option left is a Chrome clone because that is what people are used to.
People used to have a dozen different instances of IE6 open. It was a pain to switch between them and it made your computer run slow. Firefox had tabs. And it had AdBlock. Those were things people wanted. But these days, Chrome is plenty good enough for most people. Even if Firefox had a perfect privacy story and focused on their core users’ every whim, I don’t think their market share would grow.
Re: For advertising, Firefox now collects user data by default
#398Earlier quoted context omitted.
I was with you until secureboot. At least on my Debian I retain full control using the shim and my own enrolled keys. So seems less an issue with the technology but perhaps with how some vendors (that are already locking you in anyway) use secureboot? from https://wiki.debian.org/SecureBoot >> Shim then becomes the root of trust for all the other distro-provided UEFI programs. It embeds a further distro-specific CA k…
In theory the benefits of secureboot around attestation and hashing/measuring of boot components do not require a secure/verifiable chain of custody. You could self verify using PCRs. The boot loader signing aspects were always for control and restricting devices, IMO.
only using self verifying of PCRs is not an effective protecting against most attacks. (Against which a secure boot chain is supposed to help.)
Sure it depends a bit on what you want from secure boot. But in general if you need PCRs you also need to make sure only verified code can run. If you don't, you likely don't need PCRs either, and some simple flawed secure module key storage would work as good.
In a certain way having a trust verification of the boot loader is the most important part. Everything after that depends on how the boot loader is implemented, through having PCRs is still helpful.
Through this is where secure boot failed (very hard), as long as you don't enroll your own keys you are not really getting a secure boot chain. Something which IMHO is fundamental requirement for any company laptops and similar. (Or, instead of using custom PKs, you are MS and disable all 3rd party keys and disable any BIOS option to add/enroll 3rd party keys, like they did on some older ARM devices).
I.e. IMHO a secure boot chain and protocols related to it are a must have, but the current implementation is garbage, especially for most Windows users.
If you want to know in which direction things could be done you could look a ARM Mac Books more specifically the documentation Asahi Linux created for it. Through just the direction not the exact design.
Basically for PCs (even in huge companies with MDA) you don't need global trust chains, just local per-system trust automatically setup on first boot after "reset" and making sure a "reset" is roughly like a wipe (by using full disk encryption) is all you need (and want). The devil is in the details, but it isn't really that hard to make it work.
Re: For advertising, Firefox now collects user data by default
#399Earlier quoted context omitted.
> This thread in general feels like it leaves Mozilla no room to experiment or find any form of growth. Mozilla is welcome to experiment. The issue here is: - The default opts the client in instead of the client making that choice to be a Guinea pig in the experiment - I get emails almost weekly that amount to Mozilla playing the role of internet privacy police. They *are* well aware of the rights and wrongs. Are the…
I think the worst part of the funding equation is that had Mozilla stayed on mission and invested it's Google fees wisely, Firefox development could have been indefinitely funded. Instead, we have had Mozilla sprawling in numerous directions secondary to the browser and failing in nearly all of them.
If you dont grow at double digit percentages year of year, are you even trying?
Re: For advertising, Firefox now collects user data by default
#400Earlier quoted context omitted.
I recently started using Firefox again, because of all the madness around Chrome and the change of how add-ons (mainly uBlock and similar) would work. And it felt kinda good, i actually thought that Firefox was different and a part of "the good guys", now it doesn't feel that way anymore. Sigh.
I don't know of any "good guys" whatsoever that ever managed to build and maintain a browser. Anyone? Maybe one day we'll have a usable FOSS browser but I doubt it (the companies will fight tooth and nail against it including legal means, buying out companies, blocking content for them, etc.).