Live data from Hacker News

Stop Firefox leaking data about you

github.com

31–40 of 97 posts

Re: Stop Firefox leaking data about you

#31
post #26
post #16

Earlier quoted context omitted.

It does send your IP address to Google, when you download the filter. And I can't tell if "Enhanced Protection" is enabled which actually sends your URLs to Google.

http://kb.mozillazine.org/Browser.safebrowsing.remoteLookups That's configured here

I couldn't find Browser.safebrowsing.remoteLookups in my about:config. Does it still apply?

upd: I am searching for it in the Firefox sources now. Just for curiosity: there are 117512 files in 8610 directories totaling 743 MB, and search in files is really slow even on SSD.

Re: Stop Firefox leaking data about you

#32
Mozilla has an annoying pattern of removing items from the user preferences to "avoid user confusion", an excuse companies often use when deceiving customers. (Example: Microsoft dropping the "RT" designation. [1]) "Accept/reject third-party cookies", for example, doesn't always appear in the preferences any more.

Mozilla's new "social" features don't have a turn-off option in the Preferences. You can disable them by going to "about:config", creating the tag "social.enabled" (it doesn't even exist by default) and it to False. Mozilla provides no easy way to do that. This add-on takes care of those convenient little omissions.

Obviously, Mozilla is doing all this to tie users to their mothership and make it harder for them to leave. It's not like users were crying out for "Pocket" integration in the browser.

[1] http://www.winbeta.org/news/surface-2-no-longer-has-rt-brand...

Re: Stop Firefox leaking data about you

#33
post #11

Earlier quoted context omitted.

I wouldn't use it since it: - Disables the malware and phishing lists/warnings. - Disables HTML5-video DRM (even if this has nothing to do with leaking data). - Geo location already brings up a popup (and thus disabling it seems petty).

Aside from the things you listed, it's ok to disable the other things?

Maybe. Both several of the other things can be disabled via the normal settings UI, so disabling them via about:config seems unnecessarily indirect.

Re: Stop Firefox leaking data about you

#34
post #21

Earlier quoted context omitted.

That is really disappointing. Particularly for firefox with their supposed focus on privacy, to enable a service that leaks ip when I run a vpn, contradicting the plain intention of the user, shocks me.

> That is really disappointing. Particularly for firefox with their supposed focus on privacy, to enable a service that leaks ip when I run a vpn, contradicting the plain intention of the user, shocks me. Firefox doesn't necessarily know that you're using a VPN, so it's not really contradicting "plain intention". The problem is the way that WebRTC works; it has to have access to this information in order to function.…

ff doesn't know I'm not using a vpn, so they shouldn't add features that leak ip addresses

and a setting buried in a pile of configuration is the same as it not existing for 99.99% of users

Re: Stop Firefox leaking data about you

#35

Please for the love of god do not disable the Google SafeBrowsing preferences. SafeBrowsing protects you from a lot of malicious websites, and does not leak much information to Google. For most people the security benefits of SafeBrowsing far outweigh the privacy concerns. It is important to remember that malicious websites and malware in general may negatively impact your security and privacy in extremely harmful wa…

Please for the love of god do not disable the Google SafeBrowsing preferences. SafeBrowsing protects you from a lot of malicious websites, and does not leak much information to Google. For most people the security benefits of SafeBrowsing far outweigh the privacy concerns.

I would never disable it for my mom, or any non technical friends. But I would hope the majority of HN users are pretty good at spotting, and steering clear of malicious websites.

Re: Stop Firefox leaking data about you

#36

Please for the love of god do not disable the Google SafeBrowsing preferences. SafeBrowsing protects you from a lot of malicious websites, and does not leak much information to Google. For most people the security benefits of SafeBrowsing far outweigh the privacy concerns. It is important to remember that malicious websites and malware in general may negatively impact your security and privacy in extremely harmful wa…

[deleted]

Re: Stop Firefox leaking data about you

#37
post #25

Seems like lots of FUD; how do Firefox Hello, Pocket and Geolocation "leak data about you" if you don't explicitly use them? How do DRM and Reader mode leak data at all? Also, Safe Browsing, DRM, Search suggestions, Telemetry and Health report can be disabled in the preferences UI. Don't need sensationalist about:config protips for that.

I would prefer it if they stripped out Hello and Pocket. They don't need to be there and their inclusion makes me wonder whay Mozilla's Firefox goals really are.

Re: Stop Firefox leaking data about you

#39
post #32

Mozilla has an annoying pattern of removing items from the user preferences to "avoid user confusion", an excuse companies often use when deceiving customers. (Example: Microsoft dropping the "RT" designation. [1]) "Accept/reject third-party cookies", for example, doesn't always appear in the preferences any more. Mozilla's new "social" features don't have a turn-off option in the Preferences. You can disable them by…

Mozilla is "obviously" trying to lock in their users with these tactics? There are Pocket add-ons for every browser and OS. How does Pocket integration represent lock-in? You can certainly argue that these additions are bad for users, but I don't see anything in that list that represents an attempt at lock-in.

Re: Stop Firefox leaking data about you

#40
post #20

Another thing worth noting is that if you are using Debian-rebranded Firefox (Iceweasel), you have a very unique user agent that is easy to track. There is a bug opened ( https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=748897 ), but as far as I know, no simple solution exists yet. You can change the user agent with an extension to keep it identical with the most popular Firefox version, but then you have to manuall…

If you don't want edit manually user agent, oscpu and platform in "about:config" then blender can do it for you: https://addons.mozilla.org/it/firefox/addon/blender-1/

EDIT: seems that this extension need to be updated, sorry...

But I don't know, if you allow javascript maybe you will leak your real user agent?

I like to switch between iceweasel and seamonkey, and I'm "proud" of my different and unique user agent :) Speaking of privacy, actually I'm more concerned about referer, third-party sites, content delivery networks and so on.

Post reply on HN