Live data from Hacker News

Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

blog.mozilla.org

171–180 of 246 posts

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#171

Earlier quoted context omitted.

This little bit of misdirection Google and Facebook have propagated about how much better the advertising you get with tracking is the slimiest piece of bait-and-switch in history. Seeing people repeat it like it's fact is testament to just how insidious it is. Targeted advertising is not designed to serve the viewer, it's designed to serve the advertiser. So advertisements you get are even sleazier than non-targeted…

Targeted advertising is not designed to serve the viewer, it's designed to serve the advertiser. Advertising doesn't help the advertiser unless it helps you. Showing you an ad for something you don't want, can't use, and would never buy, benefits nobody.

People buy crap they don't need all the time. The whole point of advertising is to sell. I believe the OPs are saying that they leverage information about you to bully you in to thinking that something is actually helpful and you should buy it, hence the talk about exploiting self esteem on a much more personal level. While I can't be sure if Google or Facebook actively do this kind of thing or sellers just use these platforms to do this, there's very little question that social media and consumer internet has gone rogue. Unless you've been living under a rock, you just have come across at least a few of those.

I, personally, have no issues with these platforms collecting my data and making money off it in exchange for their services that I use. But when they do the same even when Im not using their services or explicility expressing my disagreement, I'm not cool with that.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#172

Earlier quoted context omitted.

At this point can I just pay for a certificate or something? Like for $1 give me a certificate that I can use to say "I'm not a spammer" and I can anonymously buy as many certificates as I want. And then if a certificate is used by a spammer it becomes invalid. Seems like it's expensive enough to be worth using for existing spammers but let normal people pay a $1 every year or two to not have to deal with captchas.

Fingerprinting is designed to generate a unique identifier to track you. Certificates would be an even more accurate unique ID over what fingerprinting could provide

> and I can anonymously buy as many certificates as I want

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#173

I appreciate it when my browser takes the position that it acts as the user's agent, and not the advertising network's agent.

This attitude from the Mozilla crew has convinced me to try switching from Chrome for a week. (I understand that these latest features aren't yet available in the normal releases)

Thoughts on Brave browser?

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#174

Earlier quoted context omitted.

Why?

In this case the clue is the word fingerprinting. If someone outside your door was taking fingerprint impressions, your name, and then writing down your license plate and selling that info to anyone with money - would you just let that continue? Unlikely.

In the real world they can't physically touch you so let's replace that with passive facial recognition. In that case, yes they can do that all today. Someone can follow you all day from the moment you step out into public.

We might not like it but it is legal and they own their observations.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#175
I don't like this reaction to crypto mining scripts. I won't argue that a lot of crypto mining scripts out there are blatantly abusive but I think that as a concept it's a great business model. I wouldn't have a problem using sites that eschewed ads and used crypto mining scripts instead and I would have no reason at all to block them (unlike ads) as long as they're well behaved.

I think blocking mining scripts is a step backwards, hindering the adoption of something that could finally be an unobtrusive and ethical replacement for the failing advertisement model.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#176
post #106

Feels anti-competitive to have defaults to block mining while not having default enabled advert blocking. I'm much happier for a site to mine on their tab while I'm watching a video than to show me 2 minutes of advertisements every 10 minutes. On mobile in particular, where video ads end up eating a large chunk of my data costs.

You are happier to have your resources stolen and not be aware of it (it's invisible, you can't see what's happening and react - right?) than to be shown an annoying thing which is very much in your awareness? I don't know, I'd rather know someone is harming me silently and have the means to stop it by default. The things that are shown in front of me, I can handle them...

My computer is at maybe 20% resource utilization while I'm browsing the internet. Resource utilization only becomes a problem once you run out of resources; there is zero difference to me between 20% and 40% resource utilization other than very minor factors like a negligible increase in power draw and my fans spinning a little harder.

Of course people could (and do) build malicious mining scripts that try to use way too many resources, just like people could (and do) make malicious ads that spam you with INCREASE YOUR DICK SIZE BY 20 INCHES IN 5 MINUTES popups, but that's not an inherent problem with the model itself.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#177

Earlier quoted context omitted.

Fingerprinting is designed to generate a unique identifier to track you. Certificates would be an even more accurate unique ID over what fingerprinting could provide

> and I can anonymously buy as many certificates as I want

Do you really think that statistically noticeable numbers of people would do that and have perfect opsec preventing those perfect unique identifiers from being linked? I mean, even software developers tend to whine about paying $5 for an app which has far more immediate rewards.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#178

I don't like this reaction to crypto mining scripts. I won't argue that a lot of crypto mining scripts out there are blatantly abusive but I think that as a concept it's a great business model. I wouldn't have a problem using sites that eschewed ads and used crypto mining scripts instead and I would have no reason at all to block them (unlike ads) as long as they're well behaved. I think blocking mining scripts is a…

> I think blocking mining scripts is a step backwards, hindering the adoption of something that could finally be an unobtrusive and ethical replacement for the failing advertisement model.

If the content on a website is just a vehicle for delivering advertisements, I would consider such a business model to be fundamentally flawed.

Swapping "delivering advertisements" with "hijacking my processor cycles to mine cryptocurrencies" doesn't exactly offer anything that would convince me to change my mind.

I'm more than happy to pay for quality content, but I'd prefer companies to be forthcoming about the cost involved in providing it, rather than turning me or my data into a product that can be sold to the highest bidder.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#179

I've never understood why the user-agent string gives out so much system-specific information. Why not return less information, such as only the browser make and version?

I agree that User-Agent is suspiciously leaky, but it's microscopic compared to JavaScript. [1]

It's unfortunate that browsers are privacy-insane by default. Luckily, with a bit of effort, most browsers [2] allow you to mitigate this with plugins (e.g. User-Agent switcher, Cookie/Referrer controller, and JS/Adblocker). Pi-Hole [3] can help too.

Mozilla should be commended for trying to improve the situation.

1. https://panopticlick.eff.org/

2. Chrome's days are numbered: https://news.ycombinator.com/item?id=18973477

3. https://pi-hole.net/

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#180
post #128

Earlier quoted context omitted.

I've wanted the "allow 5 seconds" thing for a long time too. You can manually pause and resume js by opening up the debugger and hitting pause. The code exists it just needs to be exposed to the UI.

How would this interact with onclick handlers on buttons and the like? Would it be that after 5s the user couldn't interact with elements on the page like that (e.g. if they open an image, and wait a few seconds, they then couldn't close it because the 'x' onclick handler wouldn't run), or would each handler run by a user action (like an onclick) have 5 seconds to run?

Either, you could even have both as options.

The simplest way to do it would just be to pause js 5 (or maybe 15) seconds after page load, and have a button beside the url to resume/repause js.

The devtools keep working with js paused though, so it should be possible to do something like have a onclick handler that resumes and starts a timer to repause the js.

Ideally I think I'd like click's to resume js for a few seconds unless they are clicking on a link (with a href that leads to another page). I'm not certain that would be technically easy but it seems likely it would be.

Post reply on HN