As usual when people criticize Mozilla, this thread is way over the top. I agree it's not good that this is on by default. But saying that Chrome is better because it at least asks is disingenuous. Chrome simply presents you with the "Enhanced Ad Privacy" window and a button "Got it" or "Settings". That's clearly a dark pattern and technically not "asking" at all. The Topics API which you enable by clicking "Got it"…
"Firefox added [ad tracking] and has already turned it on without asking you"
121–130 of 178 posts
Re: "Firefox added [ad tracking] and has already turned it on without asking you"
#122Mozilla has been working with Meta on this. "For the last few months we have been working with a team from Meta (formerly Facebook) on a new proposal that aims to enable conversion measurement – or attribution – for advertising called Interoperable Private Attribution, or IPA." https://blog.mozilla.org/en/mozilla/privacy-preserving-attri...
I didn’t see that, and it makes it even worse. We owe Meta nothing. I have zero reason to donate my data to them.
I understand the need to work with Google and Meta. I don't like or trust the advertising business but I recognise that these companies are billion-dollar giants.
However, activating a feature without asking users is a failure to uphold the mission statement. And Meta is a repeat offender in the domain of security.
Mozilla, this is a failure.
Here is a fork of Firefox that I have been using:
Re: "Firefox added [ad tracking] and has already turned it on without asking you"
#123Earlier quoted context omitted.
> I'm not affiliated with Mozilla, but I do understand how wikis work. ;-) You don't seem to understand why this is problematic though, so I'll explain it to you: enabling tracking when you know that one of your selling points to your users is respect for privacy is a huge breach of trust.
What do you expect thangalin to do with this understanding?
Re: "Firefox added [ad tracking] and has already turned it on without asking you"
#124the best Mozilla can hope to gain is to get some scraps from google.
disgusting.
btw this wasn't discussed in any of the public Mozilla forums we monitor.
Re: "Firefox added [ad tracking] and has already turned it on without asking you"
#125This gives me impression like what happens to the nuclear weapon proliferation. At beginning, it is an arms race, between US and USSR, between users and advertisers. Either side thinks they can't survive without vanquishing the other. Eventually they realize it is stupid to continue, and reach a point to both step back. I think Mozilla is at the point where they realize it is no longer beneficial to continue the race…
So far though, they show no intentions of doing non-hostile advertising. Instead they're constantly striving to make it even worse.
So I'll keep the adblocking as it remains a reasonable and necessary defense measure.
Re: "Firefox added [ad tracking] and has already turned it on without asking you"
#126The fact they didn't loudly announce this 'feature' has seriously undermined their trustworthiness, for me at least. What's the expression; 'So much depends on reputation. Guard it with your life'. Mozilla seem to be just throwing it away.
Who would rather trust? Apple, Microsoft, Google? Realistically, these are the organizations that can afford to develop a high performance browser engine. All the chrome and firefox forks probably don't have the devs or infrastructure to fork blink/gecko and keep up with security and features. It's easy to be excited about Ladybird -- and maybe it will work, MAYBE. It's fair to argue that we've let the web evolve int…
Sure I trust Mozilla more than Google/Microsoft.
But less so, now.
Re: "Firefox added [ad tracking] and has already turned it on without asking you"
#127The implications are numerous:
1. There is no user interface or settings yet available to change the whitelist of Google-enrolled (Google being the only enrollment option today as far as I have discovered) ad-tech domains that are allowed to set the supercookies or use these supercookies to track users between sites.[2] By contrast, users can currently configure cookie settings such that they are only allowed for certain user-whitelisted sites.
2. There is no user interface yet to view and delete the supercookies, as one can currently do with normal cookies.[3]
3. Supercookies are shared across all Firefox containers breaking existing expectations of container isolation.[4]
4. Supercookies were shared across private browsing and non-private-browsing sessions until v120.b5, then Private Attribution was disabled in private browsing sessions (for now, and pending decisions on whether supercookies should persist across private browsing sessions).[5]
5. The setting privacy.firstparty.isolate is not honoured by Firefox's Private Attribution feature.[6]
6. Users are at greater security and privacy risk due to implementation of an extremely complicated and obfuscated draft standard that is full of technobabble bullshit which deliberately avoids real security and privacy impacts.[7] For example, the specification hand waves away the significance of a 64-bit supercookie as somehow being difficult to use to track users between sites. Reality is that only 33 bits is needed to uniquely identify every human alive today, and 37 bits for every human who has ever lived. The specification's section on privacy and security impacts does not address, for example, a website including an ad that proceeds to fingerprint John's browser as an 18 bit identifier as demonstrated at [8], then combine it with other identifiers such as the netblock/ASN of John's home internet connection. Later when John is in a completely different Firefox container connected to his employer's WiFi network browsing another site, the browser fingerprint or other tracking data within the 64-bit supercookie can trivially be used to associate John with his employer.
This Firefox partial implementation of "Private Attribution API" is just a small part of the full set of "Privacy Sandbox" anti-features Google is busy adding to Chrome, including, and of much greater concern:
1. "Private Attribution API" event-level reporting. Currently Firefox appear to have just implemented aggregate-level reporting, so the supercookie values aren't shared outside of the browser. The full specification from Google also allows event-level reporting where the supercookie values (which are set by an ad-tech company such as Google when the user visits site A) are later re-shared with the ad-tech company when the user visits a completely different site B.
2. "Protected Audience API". Execute within the browser auction bidding JavaScript bots from multiple advertisers where the bot can peek at private user data in order to bid on the impression, and then the winning bot will display the ad and report back the winning impression.
3. "Topics API". Summarise browser history in order to tell ad companies what categories of websites the user has been visiting. For example, John is interested in boats, fishing, car racing, beer and travel. Jane is interested in rock climbing, exercising in gyms, yoga, Italian cuisine and furniture.
[1] https://searchfox.org/mozilla-central/source/dom/privateattr...
[2] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/At...
[3] https://bugzilla.mozilla.org/show_bug.cgi?id=1901106
[4] https://bugzilla.mozilla.org/show_bug.cgi?id=1901103
[5] https://bugzilla.mozilla.org/show_bug.cgi?id=1901792
[6] https://searchfox.org/mozilla-central/source/dom/privateattr...
Re: "Firefox added [ad tracking] and has already turned it on without asking you"
#128Earlier quoted context omitted.
I didn’t see that, and it makes it even worse. We owe Meta nothing. I have zero reason to donate my data to them.
I have supported Firefox for a long time. I enjoy using Firefox with plug-ins such as uBlock Origin, Privacy Badger, Multi-Account Containers, and FlagFox. I understand the need to work with Google and Meta. I don't like or trust the advertising business but I recognise that these companies are billion-dollar giants . However, activating a feature without asking users is a failure to uphold the mission statement. And…
I confess that I don't understand a need for them to work with Meta. What does anyone but Meta gain by adding this feature? A quick search doesn't show that Mozilla gets significant financial support from Meta (although maybe that's just bad searching on my part). If not money, what does Mozilla gain from this? Goodwill and a hearty thanks?
Re: "Firefox added [ad tracking] and has already turned it on without asking you"
#129Earlier quoted context omitted.
Yup I don't understand the downvotes. I don't code in Rust but I also don't feel insecure about it: I wish more projects were written in Rust (or something similar). There are several research, already published here many times, which show that something insane like 75%+ of all the security exploits would be rendered cold dead in their tracks had Rust been used. I don't know how anyone, even a C/C++/VisualBasic/PHP c…
I suspect the downvotes are for a very simple reason: "Why not Rust?" comments are contributing next to nothing to the conversation. At this point, comments like this are tiresome and predictable. What would be interesting are detailed separate posts such as what you mention about security exploits addressed and of course the stream of wonderful software that people are writing in Rust (and other languages as well fo…
I don’t read this as petty, it’s well noted by now that memory safe languages are increasingly recommended to avoid classes of errors.
Re: "Firefox added [ad tracking] and has already turned it on without asking you"
#130Earlier quoted context omitted.
I suspect the downvotes are for a very simple reason: "Why not Rust?" comments are contributing next to nothing to the conversation. At this point, comments like this are tiresome and predictable. What would be interesting are detailed separate posts such as what you mention about security exploits addressed and of course the stream of wonderful software that people are writing in Rust (and other languages as well fo…
Unless I’m misreading, OP themselves didn’t actually say Rust at all. They just noted that Ladybird is written in an unsafe language. I don’t read this as petty, it’s well noted by now that memory safe languages are increasingly recommended to avoid classes of errors.
As for petty. "[B]uilding a new browser in 2024 using an unsafe language is such a facepalm it's hard to take the entire project seriously." sounds pretty darn petty and dismissive to me for a project that is making good progress. We desperately need diversity in terms of web browser implementations and "not taking seriously" a project which could very well become viable within the next few years solely based on their programming language of choice feels wrong to me (even as someone with next to no love for C++).