Live data from Hacker News

An update on Mozilla's terms of use for Firefox

blog.mozilla.org

111–120 of 381 posts

Re: An update on Mozilla's terms of use for Firefox

#111

Earlier quoted context omitted.

Companies have been long concerned about exfiltration of data and ran MITM proxies to stop it, which ironically has been the target of propaganda about "privacy" by the browser makers. Every home network needs a MITM proxy too.

"Every home network needs a MITM proxy too." I have been running one for long time now. I depend on it so much that I cannot imagine using the internet without it. It is much smaller and easier to compile than a graphical browser. Others will have different opinions but I personally remain skeptical that TLS provides internet users with more value than it provides so-called "tech" companies that profit from data coll…

> I personally remain skeptical that TLS provides internet users with more value than it provides so-called "tech" companies that profit from data collection, surveillance and online advertising services, and the CDNs that collaborate with them. While it can be used to protect a computer owners' data from eavesdroppers as it transits across the open internet, e.g., during "e-commerce", in practice TLS is used to conceal data exfiltration from the computer owner for commercial purposes by so-called "tech" companies. Not to meniton the issue of "Certificate Authorities".

I agree completely.

Google pushed HTTPS because it ensures that they are the only ones who can spy on users.

Re: An update on Mozilla's terms of use for Firefox

#112
post #14

> It also includes a nonexclusive, royalty-free, worldwide license for the purpose of doing as you request with the content you input in Firefox. I really struggle to understand what legal team believes this language is necessary in downloaded software. There is a lot of precedent for this kind of language in online hosted services, but not downloaded software. > This does not give Mozilla any ownership in that conte…

> I really struggle to understand what legal team believes this language is necessary in downloaded software. Exactly. Even if nothing is changing at Mozilla, their legal team has invented a new interpretation of copyright law. That’s a huge deal from a legal perspective—Apple, Google, Microsoft, etc need to be rushing to add corresponding terms to their applications. Mozilla PR is dropping the ball completely by try…

Switching to what? Honest question, not asking for a friend.

Re: An update on Mozilla's terms of use for Firefox

#113

Earlier quoted context omitted.

Companies have been long concerned about exfiltration of data and ran MITM proxies to stop it, which ironically has been the target of propaganda about "privacy" by the browser makers. Every home network needs a MITM proxy too.

"Every home network needs a MITM proxy too." I have been running one for long time now. I depend on it so much that I cannot imagine using the internet without it. It is much smaller and easier to compile than a graphical browser. Others will have different opinions but I personally remain skeptical that TLS provides internet users with more value than it provides so-called "tech" companies that profit from data coll…

> Others will have different opinions but I personally remain skeptical that TLS provides internet users with more value than it provides so-called "tech" companies ...

I think TLS can be helpful (for both sides of a communication), but the browser should not require it, and most servers also should not require it (but should allow it, if you deliberately choose to connect with TLS). HSTS is especially bad (I managed to disable it on my computer by using a hex editor so that the browser would no longer recognize the Strict-Transport-Security header).

Certificates can be helpful if you actually know which ones you specifically trust for a specific purpose (rather than being automatic), and if they will tell you information about a business (although as far as I know, Let's Encrypt does not do this and only verifies the domain name). However, sometimes if a certificate is changed or superseded, due to expiry, or change in ownership, etc, and it does not prevent the server operator from sending you malware; it only prevents spies from doing so. If a domain name is sold to someone else, that does not prevent cookies and other stuff from being sent, or from them adding malware, etc; however, it would be possible for end users to know the certificate to trust and avoid this problem (if a browser can be programmed to do this).

Client certificates could be helpful for authentication too, but this is rare with HTTPS (but it is commonly used with Gemini protocol). But, it does prevent someone who takes over the domain name from being able to use your information to log in, since a private key is required in order to use a client certificate.

Furthermore, the browser really should allow unencrypted proxies for encrypted connections, in order that if you deliberately want MITM then you do not need to encrypt and decrypt the data multiple times.

> IMO, this is analogous to the situation with Javascript. It has the potential to provide value to www users, e.g., as a language computer owners can use to extend and control a graphical browser ...

Yes, as well as other programming languages (if a browser supports it, which most don't).

(I disable JavaScripts on my computer, except for the scripts that I wrote by myself. I did write scripts to replace GitHub's UI (in much less lines of code than GitHub uses themself), and other things.)

Re: An update on Mozilla's terms of use for Firefox

#114

> You give Mozilla the rights necessary to operate Firefox. This includes processing your data as we describe in the Firefox Privacy Notice. It also includes a nonexclusive, royalty-free, worldwide license for the purpose of doing as you request with the content you input in Firefox. You don't need a license for data you never see. When I use Firefox to type a comment on HN, that comment goes from me to HN. It doesn'…

Right. Some people want Sync, Pocket, oneline translation, etc. Others like me just want a browser. There should be a simple option to choose between a browser and some multifunction beast that some people and even more managers at Mozilla are dreaming of.

Those things are Mozilla services. If they spoke of operating Mozilla services and data you input into Mozilla services, it'd be fine and expected. But instead they speak of operating Firefox and data input into Firefox, which is much more broad, and just happens to give them coverage for all kinds of data collection and abuse.

The fact they've issued this update and not clarified the scope as Mozilla services is disturbing.

Re: An update on Mozilla's terms of use for Firefox

#115
post #80

Earlier quoted context omitted.

> Trying to sell a browser now is an even weaker proposition to most users. To most users yes, but a group of power users like me can make them life-changing money. I'd happily pay a monthly subscription for my web browser. It just does not need to be a U.S. entity. Otherwise, people without a Visa or Mastercard will be left out. Crypto is fine for this use case.

It's interesting to me the uphill battle Kagi is fighting to get people to pay for ad-free search and browsing. I wish them all the best because I think it's a fight worth having. https://help.kagi.com/kagi/why-kagi/why-pay-for-search.html

Kagi is fighting the good fight. I admire them, though I'm not yet a customer.

I stumbled upon their Orion docs, I find the following concerning:

    Orion is a free, lightning-fast, privacy-protecting browser for Apple users, open to the web and all its standards and protocols. One day, we hope everyone will say Orion is the best browser for all Apple devices. We're glad you're here!
That's fine and dandy, but I'm not an Apple user (I'm South American). I'd assume Apple is the larger user base for their U.S. customers, but outside of the U.S., Apple is not really a thing.

Re: An update on Mozilla's terms of use for Firefox

#117

Earlier quoted context omitted.

In fact, one could argue that Google losing its case is what caused this. Google provided a substantial amount of revenue to Mozilla. With that now gone, new ways(TM) to get money are needed.

They really don’t need more revenue. They are nominally a not-for-profit and in 2023, they had 250 million cash and a billion more in investments. They’ve taken billions of dollars from Google since 2005, and now they’re turning their back on user privacy.

They spend well over 200 million a year in software development, and they've made those investments presumably expecting this revenue issue.

Building a browser is expensive, that's why there's only two of them. Even Microsoft considered it too expensive to continue.

Re: An update on Mozilla's terms of use for Firefox

#118
How many times have we seen this ploy? First you have a nice policy, then you change it to something extreme that causes outrage, then you walk back most of the change saying you had legal or whatever baloney reasons to make the change in the first place and somehow couldn't wordsmith the language well enough the first time.

I don't buy it. I hope some day business schools begin teaching that this ploy is a very bad idea. And if this really is the corporate lawyers being greatly insensitive then force PR and others to review every change they make to any policies that could destroy the company.

Re: An update on Mozilla's terms of use for Firefox

#119
> "...for the purpose of doing as you request with the content you input in Firefox"

I'm still confused about the scope of what this means. Is this post I'm writing now considered "content I input in Firefox"? If I upload an image to my own website, is that content I input in Firefox?

From my perspective, I'm not submitting anything "to Firefox", I'm submitting the content to remote servers and websites. I don't use Firefox cloud services or bookmarks or Mozilla account or anything. Even my bookmarks, I use raindrop.io at the moment.

Re: An update on Mozilla's terms of use for Firefox

#120
post #107

Earlier quoted context omitted.

Maybe Orion, if you trust Kagi enough? https://kagi.com/orion/ It's webkit-based, and you can pay for it ($150 for a lifetime license).

Proprietary?

Yes. Webkit-based but closed source for now. And terribly unstable... I tried it for an hour just now and it crashed 5-6 times for me, including while I was filling out a bug report, lol.
Post reply on HN