Live data from Hacker News

Firefox built-in spyware that cannot be disabled

news.ycombinator.com

21–30 of 48 posts

Re: Firefox built-in spyware that cannot be disabled

#21
Here's your solution

https://librewolf.net/

Keeps version parity but removes all the nastiness with a lot of other beneficial config changes...and the ability to further customize in persistent js files.

Cachy Browser in CachyOS/Archlinux is more or less Librewolf with some other tweaks to make it faster.

Re: Firefox built-in spyware that cannot be disabled

#22
post #2

I noticed this as well and blocked it in my local DNS. I also disable DoH. grep firefox /etc/unbound/override/combined.conf local-zone: "firefox-settings-attachments.cdn.mozilla.net" always_nxdomain local-zone: "firefox.settings.services.mozilla.com" always_nxdomain

> I also disable DoH Why? DoH is good for privacy.

Depends on who the upstream provider is. Having a pihole or opnsense with dnscrypt and/or unbound setup is best.

Re: Firefox built-in spyware that cannot be disabled

#23

This is why I use LibreWolf, which is a patched version of Firefox that removes pocket and stuff like this entirely, instead of regular Mozilla Firefox with something like arkenfox to harden it. There's only so much a config, no matter how extensive, can really do for you against what's been hard-coded into a program itself, and configs need personal maintenance, whereas a patch version of a piece of software can pul…

LibreWolf is not a fork, and rather a Firefox profile with branding and UI fixes on top. The patches do not remove any telemetry. [1] OP's argument still stands, as LibreWolf's telemetry and normandy integrations are identical to upstream Firefox. [1] https://codeberg.org/librewolf/source/src/branch/main/patche...

You are incorrect. Please take a look at the default preferences that they ship, as they are a large and important part of it.

Literally on the front page: https://librewolf.net

You're here to astroturf for Mozilla or Google, aren't you?

Re: Firefox built-in spyware that cannot be disabled

#25

Here's your solution https://librewolf.net/ Keeps version parity but removes all the nastiness with a lot of other beneficial config changes...and the ability to further customize in persistent js files. Cachy Browser in CachyOS/Archlinux is more or less Librewolf with some other tweaks to make it faster.

That does sound appealing, but I don't see any information on who owns or maintains it.

You click "@ohfp" and it leads you to an incredibly empty github-ish thing with 7 total followers? That is not a good sign at all.

"About us" is completely missing, and that is extremely important to me.

I would need a bit more trust, maybe even something like EFFs blessing, to use this.

If you were being skeptical, would you trust them? Why?

Re: Firefox built-in spyware that cannot be disabled

#26

Here's your solution https://librewolf.net/ Keeps version parity but removes all the nastiness with a lot of other beneficial config changes...and the ability to further customize in persistent js files. Cachy Browser in CachyOS/Archlinux is more or less Librewolf with some other tweaks to make it faster.

That does sound appealing, but I don't see any information on who owns or maintains it. You click "@ohfp" and it leads you to an incredibly empty github-ish thing with 7 total followers? That is not a good sign at all. "About us" is completely missing, and that is extremely important to me. I would need a bit more trust, maybe even something like EFFs blessing, to use this. If you were being skeptical, would you trus…

You're right to be apprehensive and skeptical, most of the Firefox forks leave a lot to be desired. Usually maintained by anonymous randoms that most likely aren't experts on the technology. That's why I would instead recommend the Mullvad browser which is also a Firefox fork, but is being maintained by a profitable company with reputable engineers. Whose main product focuses around protecting your privacy and securing you.

https://mullvad.net/en/browser

The only potential issue with it is that it might be TOO good at anonymizing you, to the point that you set off security measures, ala Cloudflare, simply by NOT leaking any juicy data to identify you.

Re: Firefox built-in spyware that cannot be disabled

#27
post #15

Earlier quoted context omitted.

If I do not disable it then I can not block nefarious domains for all devices on my network and I can not monitor what devices are doing DNS lookups. I do not agree that it is good for privacy. Maybe one day if ESNI is implemented everywhere then there may be some truth in the idea, but that also assumes that we are not just moving the resolver from the local ISP to the big centralized platforms like Cloudflare or Go…

How does an application-specific configuration in firefox do anything about other devices on your network?

I think "disable DoH" there means "block all DoH servers at the router", not "configure Firefox to not try to use DoH".

Re: Firefox built-in spyware that cannot be disabled

#28

Earlier quoted context omitted.

> I also disable DoH Why? DoH is good for privacy.

Depends on who the upstream provider is. Having a pihole or opnsense with dnscrypt and/or unbound setup is best.

How is dnscrypt any better than DoH? And doesn't unbound still need an upstream resolver to talk to?

Re: Firefox built-in spyware that cannot be disabled

#29

Is pocket actually spyware / telemetry or is this just conjecture?

Either way you wouldn't know. Anything that phones home could be spyware, the difference is on the far side. So it could start out as not spyware and then become spyware. Or it may sometimes be spyware and at other times it is not.

Browsers should only do what their users tell them to do. In fact: that goes for computers as a whole.

Re: Firefox built-in spyware that cannot be disabled

#30

Earlier quoted context omitted.

LibreWolf is not a fork, and rather a Firefox profile with branding and UI fixes on top. The patches do not remove any telemetry. [1] OP's argument still stands, as LibreWolf's telemetry and normandy integrations are identical to upstream Firefox. [1] https://codeberg.org/librewolf/source/src/branch/main/patche...

You are incorrect. Please take a look at the default preferences that they ship, as they are a large and important part of it. Literally on the front page: https://librewolf.net You're here to astroturf for Mozilla or Google, aren't you?

The settings is literally what OP changed, and mentioned that the _source code which needs patches_ contains the URLs, which is correct.

You can verify that easily by grepping the codebase.

As LibreWolf doesn't patch these hardcoded URLs out, their marketing is wrong and a fraudulous statement. They don't remove these features and they are also not stubbing out the APIs (e.g. like TOR's patchset does).

I'm not here to astroturf anything, maybe just get your shit together and stop accusing people randomly?

Post reply on HN