Live data from Hacker News

An update on Mozilla's terms of use for Firefox

blog.mozilla.org

321–330 of 381 posts

Re: An update on Mozilla's terms of use for Firefox

#321
post #207

> The reason we’ve stepped away from making blanket claims that “We never sell your data” is because, in some places, the LEGAL definition of “sale of data” is broad and evolving. As an example, the California Consumer Privacy Act (CCPA) defines “sale” as the “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or othe…

They also said "Mozilla doesn’t sell data about you (in the way that most people think about “selling data”)", and I'm struggling to fathom what they could possibly think that "most people" think selling data could mean other than "giving your data to someone else for compensation", which seems pretty much exactly what the California law says. Yes, it's embedded in some legalese, but surely Mozilla has lawyers?

CCPA/CPRA have a very broad definition of sale.

> (1) “Sell,” “selling,” “sale,” or “sold,” means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by the business to a third party for monetary or other valuable consideration.

Most people would view a sale as Mozilla getting cash back for the data. But that "other valuable consideration" (which the AG declined to clarify or create a factor-based approach for deciding) makes Mozilla vulnerable to lawyers.

The same parasites that claimed that embedding a chatbot on your website violates the California wiretapping laws and have been extracting cash from sites will figure out a way to do the same to Mozilla. see the wave of CIPA chatbot lawsuits.

For instance, suppose Mozilla partners with a search engine and could be claimed to get a discount or some other consideration for letting that search partner use search terms to improve the search engine. Something that isn't advertising related at all. That's probably a sale under CPRA.

Re: An update on Mozilla's terms of use for Firefox

#322

Earlier quoted context omitted.

Most people don't think about this stuff and are simply uninformed. Referring to what "most people think" is a cop-out from their side. But I think the sense Mozilla are referring to is the more obvious and over-the-top things like selling your name, phone number, email, postal address, your Amazon purchasing history, or to ramp it up more, your passwords, your credit card info etc.

The latter is a pretty high bar. Even Google doesn't do that.

Just saying that you can stretch it pretty far with vague language like "we aren't doing [bad thing] in the sense that most people would understand [bad thing]".

Re: An update on Mozilla's terms of use for Firefox

#323
post #321
post #207

Earlier quoted context omitted.

They also said "Mozilla doesn’t sell data about you (in the way that most people think about “selling data”)", and I'm struggling to fathom what they could possibly think that "most people" think selling data could mean other than "giving your data to someone else for compensation", which seems pretty much exactly what the California law says. Yes, it's embedded in some legalese, but surely Mozilla has lawyers?

CCPA/CPRA have a very broad definition of sale. > (1) “Sell,” “selling,” “sale,” or “sold,” means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by the business to a third party for monetary or other valuable consideration. Most people would view a sale as Mozilla…

> For instance, suppose Mozilla partners with a search engine and could be claimed to get a discount or some other consideration for letting that search partner use search terms to improve the search engine. Something that isn't advertising related at all. That's probably a sale under CPRA.

If a search engine partner wants to use search terms to improve their search engine, they only have to look at their own logs. They don't need Mozilla to collect, aggregate, and sell them any data to accomplish that. Mozilla doesn't need to worry about selling data if they never possess that data in the first place.

Your complaint about "other valuable consideration" is just a complaint that the law isn't crippled by stupid loopholes.

Re: An update on Mozilla's terms of use for Firefox

#324

Earlier quoted context omitted.

Companies have been long concerned about exfiltration of data and ran MITM proxies to stop it, which ironically has been the target of propaganda about "privacy" by the browser makers. Every home network needs a MITM proxy too.

Don't forget the push for browsers to ignore your DHCP-provided DNS server and instead get their DNS from a server outside your control over an encrypted tunnel. It's an obvious attack on stuff like PiHole, with little to no real upside for users.

If this is in reference to DoH then I found an upside. Generally, DoH servers allow HTTP/1.1 pipelining by default. This allows one to fetch DNS data in bulk over a single TCP connection. The DNS specification RFC 1035 suggests that computer users would be able to send multiple queries in a single _packet_: QDCOUNT is any unsigned 16-bit integer. The implementation of servers that can handle QDCOUNT greater than 1 has not happened. But at least with DoH I can send multiple queries over a single TCP connnection.

Once retrieved, I load the DNS data into the memmory of the "MITM proxy". This eliminates the need for DNS queries to be immediately proceeding associated HTTP requests for web pages, etc., or within some DNS cache duration period.

When I use other sources of DNS data^1, I eliminate the need for remote DNS queries altogether.

1. For example, I extract DNS data from Common Crawl data.

Indeed, it does not seem like DoH was implemented to improve life for computer users but, at least for me, it can be useful. It can also be useful for example to computer users who use remote DNS servers where their ISP is hijacking port 53.

Re: An update on Mozilla's terms of use for Firefox

#325
post #19

> Whenever we share data with our partners, we put a lot of work into making sure that the data that we share is stripped of potentially identifying information, or shared only in the aggregate, or is put through our privacy preserving technologies (like OHTTP). But if the data was fully stripped of potentially identifying information, then it should not count as "personal information" under the California Consumer P…

I dunno, if legal recommends wording for your TOS you should probably listen to them.

On the other hand, if legal recommends that they reword their TOS, their users also should probably listen to them.

Re: An update on Mozilla's terms of use for Firefox

#326

Earlier quoted context omitted.

And if everyone switches to Librewolf, Librewolf will die because Mozilla will no longer make money and won't be able to devote resources towards maintaining upstream Firefox. I use Firefox. I hate ads. I don't love that Mozilla engages in some level of affiliate deals to pay the bills, but it's the only viable alternative to Google controlling the entire web and doing much worse tracking/advertising at this point, u…

> Mozilla will no longer make money Mozilla could have added years ago a donation or subscription to fund the development of Firefox, but they don't want that. Mozilla wants all the money for its charitable activities instead. There will be a time when they have no money anymore, but it's only their fault.

> Mozilla wants all the money for its charitable activities instead.

Describing Mozilla's derailment as "charitable activities" is like describing the Mexican cartels as "self-help groups".

Never forget their "We need more than deplatforming".

Re: An update on Mozilla's terms of use for Firefox

#327
Curious what people would see as the longterm future of Firefox in the ideal world. Just being privacy focused isn't enough especially for the layperson, it needs some actual benefits like being faster or at least as fast, plus mindshare from developers... but it seems impossible to compete with Google's resources on any of that. Even if Firefox committed the resources to come ahead for a moment Google could just match it easily, in addition to building better dev tooling, etc.

That being said I'm surprised they dropped the Servo project, it seemed like a step in the right direction?

I actually think working adblockers is a great pitch, not sure what sites specifically the Manifest v2 version of uBlock Origin doesn't work on, but "download Firefox to watch ad-free YouTube" is a great pitch to convince people to use it. Sucks that Apple limited custom browser engines on iOS to just the EU, otherwise Mozilla could focus on full-fledged extension parity on iOS and the pitch would be to get sync + ad-free.

Re: An update on Mozilla's terms of use for Firefox

#328

Curious what people would see as the longterm future of Firefox in the ideal world. Just being privacy focused isn't enough especially for the layperson, it needs some actual benefits like being faster or at least as fast, plus mindshare from developers... but it seems impossible to compete with Google's resources on any of that. Even if Firefox committed the resources to come ahead for a moment Google could just mat…

I applaud Firefox for lower memory usage but it constantly shits the bed when resuming a new instance with previous tabs. If a tab crashes the whole thing crashes for me and the dev tools are really behind chrome for front end dev. I would also like if they would support input=type number ffs

Re: An update on Mozilla's terms of use for Firefox

#329

Earlier quoted context omitted.

If one opted out of all the possible data collection and privacy related options, are they still able to collect your data? If yes, how does it work? Is this called client-side scanning?

Companies have been long concerned about exfiltration of data and ran MITM proxies to stop it, which ironically has been the target of propaganda about "privacy" by the browser makers. Every home network needs a MITM proxy too.

Silly me, I just realized its mostly a concern for users using their "Sync" service. *Even a host file from filterlists.com won't block that unless you stop using their service.* A host file will stop you from using the service that's a better way to word this. Haha. Don't use their services.

Re: An update on Mozilla's terms of use for Firefox

#330
post #321

Earlier quoted context omitted.

CCPA/CPRA have a very broad definition of sale. > (1) “Sell,” “selling,” “sale,” or “sold,” means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a consumer’s personal information by the business to a third party for monetary or other valuable consideration. Most people would view a sale as Mozilla…

> For instance, suppose Mozilla partners with a search engine and could be claimed to get a discount or some other consideration for letting that search partner use search terms to improve the search engine. Something that isn't advertising related at all. That's probably a sale under CPRA. If a search engine partner wants to use search terms to improve their search engine, they only have to look at their own logs. T…

> Your complaint about "other valuable consideration" is just a complaint that the law isn't crippled by stupid loopholes.

That's not the law. The search engine partner using those logs is probably valuable consideration and hence a sale. Mozilla doesn't even need to keep the data; just an api passthrough will qualify.

Post reply on HN