Live data from Hacker News

Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

blog.mozilla.org

111–120 of 246 posts

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#111

Earlier quoted context omitted.

This attitude from the Mozilla crew has convinced me to try switching from Chrome for a week. (I understand that these latest features aren't yet available in the normal releases)

I switched completely to Firefox on my work computer. Don't miss Chrome at all.

Me too. I am absolutely happy with Firefox after switching about 6 months ago. I don’t miss anything.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#112

Earlier quoted context omitted.

Since you work on ads, may I ask why you support this? Won't this make most of your features ineffective?

In principle advertising is fine. Telling people that a product exists is useful. "Do you need a hat shaped exactly like a golf ball? At Dave's Golf Ball Hats we sell six sizes!". Targeting this advert to most likely be seen by people who actually had been thinking of buying a hat shaped like sporting equipment is still a good idea too. But an advert that steals from you, or harms you is neither of those things. Goog…

An ad for a golf ball hat is a pretty benign use case but that exact same approach could be used in much more distasteful ways.

For example, suppose depressed people are more likely to buy expensive impulse item X. Person A is depressed. Lets show them ads for item X!

That would be a nicely profitable strategy that could emerge organically out of a sophisticated ML ad targeting model, something like... AdWords.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#113
post #108

Earlier quoted context omitted.

> this setting causes problems with google captcha - the number of challenges that you will need to solve will drastically increase No kidding. I'm talking about ~30-40 clicks (1 click per task in the captcha grid)

not to mention when google puts you in captcha-hell-ban. often, after a few difficult ones, I realize I get stuck into the same 20 challenges. over and over. no matter if I get them rigth or not. We do run all browser in the office with figerprint protection on and run non-exit-tor-nodes in all offices. But those are hardly excuses. The hell bans happens more often on firefox for android, but I guess that is what you…

I've had this happen frequently because my configuration really aggressively blocks this stuff. It's bad enough that I have a separate browser (Gnome Web aka Epiphany) just for logging into and using sites that have Captcha, like Pocket and Bandcamp, and I do everything else in Firefox. Captcha is horrible. I understand why sites use it, but putting a Google-wall in front of your content is a very bad idea.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#114
This endless war could be solved with a single meeting with the 3 major adtech companies.

All browsers have to do is share a single advertiser ID and have it reset by the user whenever they want. No more cookies, pixel syncs, or fingerprinting and all the related countermeasures.

This is the exact mechanism used by mobile apps right now so it's already well-tested and proven to work.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#115
post #24

> In the coming months, we will start testing these protections with small groups of users and will continue to work with Disconnect to improve and expand the set of domains blocked by Firefox. We plan to enable these protections by default for all Firefox users in a future release. While lots of people here already have uMatrix or other blockers running, blocking fingerprinting and cryptomining domains by default wo…

Since you work on ads, may I ask why you support this? Won't this make most of your features ineffective?

Google and Facebook have 1st-party direct connections to users that are signed in. They can already set cookies freely. They already know who you are. This only hurts their competitors.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#116
post #90

Earlier quoted context omitted.

You already can donate to Mozilla: https://donate.mozilla.org

I'd rather buy a browser as a company's primary product, not donate to Mozilla which makes a browser and does many other things, many of which I disagree with and would rather not fund.

But Firefox is Mozilla's primary product. It just so happens that Mozilla is big enough to also have some side products.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#117
post #78

Earlier quoted context omitted.

In principle advertising is fine. Telling people that a product exists is useful. "Do you need a hat shaped exactly like a golf ball? At Dave's Golf Ball Hats we sell six sizes!". Targeting this advert to most likely be seen by people who actually had been thinking of buying a hat shaped like sporting equipment is still a good idea too. But an advert that steals from you, or harms you is neither of those things. Goog…

> Targeting this advert to most likely be seen by people who actually had been thinking of buying a hat shaped like sporting equipment is still a good idea too. Not if that targeting is done using data gathered about me without my consent -- as it almost universally is. Targeting based on context (what sort of website the ad is on, for instance), is fine.

Data about you is not your data. Anyone can stand outside and watch what people do and take notes. That doesn't need your consent. It's the same thing here.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#118
I recently enabled privacy.resistFingerprinting in about:config (which basically is the configuration switch toggled by the UI described in this blog post).

Everything went fine, until I noticed WhatsApp web becomes unusable, because it does not generate the initial QR code for establishing the session (to be fair, it flickers, which seems worse, as it smells of an active countermeasure on WhatsApp/Facebook part).

While I did I not have yet the time do dig deep into the specific technical reason WhatsApp may have to expose such a maddening behavior, I am inclined to think that this is more a policy choice.

If so, it's troublesome. We collectively as users arrived to the point of willingly give up the keys of our online communication to a few megacompanies. It's their infrastructure and their product, so they are in power of steering it in whatever direction it wants.

I see this as something that will increasingly become a political problem. As tech versed person, I see the responsibility for not doing enough about it.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#119
post #78

Earlier quoted context omitted.

> Targeting this advert to most likely be seen by people who actually had been thinking of buying a hat shaped like sporting equipment is still a good idea too. Not if that targeting is done using data gathered about me without my consent -- as it almost universally is. Targeting based on context (what sort of website the ad is on, for instance), is fine.

I don't understand this new position (that GDPR follows) that consent is required for information to be gathered on someone. If someone sees me wearing a blue shirt and writes in their notebook that I wore a blue shirt then I don't feel like I have some inherent right to coerce them to erase it or prevent them from selling that information to Blue Shirt Emporium.

sometimes it is right to treat scenarios that are fundamentally similar as different beasts in practice when those scenarios are actually happening at very different scales.

i (and many others) believe that surveillance is like this. the effort that it takes to do what your describing does not scale, and cannot be used to implement dragnet surveillance and data collection (unless it's a police state and you have a lot of notetakers). lots of people (myself and many others) think dragnet surveillance (whether by private entities or governments) is a thing to be avoided (because it creates really bad power asymmetries, which i think are inherently a bad thing).

also, i don't think that large companies should be granted the same rights as individuals. just because a person can do a thing on their own doesn't mean that a large entity should be able to do something similar in spirit at thousands or millions of times the scale.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#120

Earlier quoted context omitted.

In principle advertising is fine. Telling people that a product exists is useful. "Do you need a hat shaped exactly like a golf ball? At Dave's Golf Ball Hats we sell six sizes!". Targeting this advert to most likely be seen by people who actually had been thinking of buying a hat shaped like sporting equipment is still a good idea too. But an advert that steals from you, or harms you is neither of those things. Goog…

Untargeted advertising is very often more egregious than merely telling people a product exists. Traditional pre-digital advertising runs the gamete from "Come to me and I'll fix your car" to "You are ugly and unpopular, but you can fix that by drinking our caramel colored sugar water." Advertising that tries to induce then exploit self esteem issues is a plague.

and... targeted advertising doesn't use these attack vectors? really?
Post reply on HN