Live data from Hacker News

Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

blog.mozilla.org

211–220 of 246 posts

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#211
post #78

Earlier quoted context omitted.

> Targeting this advert to most likely be seen by people who actually had been thinking of buying a hat shaped like sporting equipment is still a good idea too. Not if that targeting is done using data gathered about me without my consent -- as it almost universally is. Targeting based on context (what sort of website the ad is on, for instance), is fine.

Data about you is not your data. Anyone can stand outside and watch what people do and take notes. That doesn't need your consent. It's the same thing here.

>Data about you is not your data.

Stop thinking about data ownership. Ownership is irrelevant.

It's illegal to process any data about an identified or identifiable person unless you have a lawful basis to do so, and there are only a half dozen of those. "Because I own the data" is not one of them.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#212

Earlier quoted context omitted.

The people who're trying to avoid being fingerprinted are probably thinking of Google when they decided to go down this path. I'm willing to go through extensive captcha cycles if that's the cost of retaining some anonymity. I installed uMatrix a while back to recover some anonymity and it worked at first, my Captcha load spiked significantly which was a great indication that I'd succeeded but it has dropped over tim…

At this point can I just pay for a certificate or something? Like for $1 give me a certificate that I can use to say "I'm not a spammer" and I can anonymously buy as many certificates as I want. And then if a certificate is used by a spammer it becomes invalid. Seems like it's expensive enough to be worth using for existing spammers but let normal people pay a $1 every year or two to not have to deal with captchas.

This seems like a very cheap way to make spam look legitimate at least for a while. It now costs me $1 more to spam until I get caught and banned. But until that point I don't have to worry about any kind of filter, I'm a legitimate user.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#213
post #78

Earlier quoted context omitted.

> Targeting this advert to most likely be seen by people who actually had been thinking of buying a hat shaped like sporting equipment is still a good idea too. Not if that targeting is done using data gathered about me without my consent -- as it almost universally is. Targeting based on context (what sort of website the ad is on, for instance), is fine.

Data about you is not your data. Anyone can stand outside and watch what people do and take notes. That doesn't need your consent. It's the same thing here.

Metadata = Surveillance

https://www.schneier.com/blog/archives/2014/03/metadata_surv...

Quote:

"An easy thought experiment demonstrates this. Imagine that you hired a private detective to eavesdrop on a subject. That detective would plant a bug in that subject's home, office, and car. He would eavesdrop on his computer. He would listen in on that subject's conversations, both face to face and remotely, and you would get a report on what was said in those conversations. Now imagine that you asked that same private detective to put a subject under constant surveillance. You would get a different report, one that included things like where he went, what he did, who he spoke to -- and for how long -- who he wrote to, what he read, and what he purchased. This is all metadata, data we know the NSA is collecting. So when the president says that it's only metadata, what you should really hear is that we're all under constant and ubiquitous surveillance."

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#214
post #108

Earlier quoted context omitted.

> this setting causes problems with google captcha - the number of challenges that you will need to solve will drastically increase No kidding. I'm talking about ~30-40 clicks (1 click per task in the captcha grid)

not to mention when google puts you in captcha-hell-ban. often, after a few difficult ones, I realize I get stuck into the same 20 challenges. over and over. no matter if I get them rigth or not. We do run all browser in the office with figerprint protection on and run non-exit-tor-nodes in all offices. But those are hardly excuses. The hell bans happens more often on firefox for android, but I guess that is what you…

I have fingerprinting off too in firefox, and a lot times I now just ignore sites using captcha.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#215
post #36

Earlier quoted context omitted.

Mozilla devs seem to take this into account whenever adding new JS features, at least on their mailing lists. For example, this discussion of a new API for gamepads immediately turned to a discussion of its fingerprinting risks and how they can be mitigated: https://groups.google.com/d/msg/mozilla.dev.platform/75GrJSP...

The www has an API for gamepads. I need a moment.

I already had that moment when I heard about the "Web Bluetooth API"

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#216
post #159

Earlier quoted context omitted.

The problem is not the wall itself, but that Google uses it’s de-facto monopoly position to enforce tracking.

Plus creating image recognition training data for them. I am not interested in working for Google. Not paid, let alone for free.

Never thought about it from that perspective before

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#217
post #68

Earlier quoted context omitted.

> like to see more security around the data that is used for fingerprinting, such as user agent I think this is already available, just not enabled by default. In about:config one need to set privacy.resistFingerprinting to true. (be aware however that this setting causes problems with google captcha - the number of challenges that you will need to solve will drastically increase)

> this setting causes problems with google captcha - the number of challenges that you will need to solve will drastically increase No kidding. I'm talking about ~30-40 clicks (1 click per task in the captcha grid)

This is why I immediately close any page with google's captcha.

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#218
post #160
post #98

Earlier quoted context omitted.

Could you give some examples of things they do that you disagree with? I can't really think of any controversial non-firefox things they've done.

https://www.reddit.com/r/firefox/comments/7k8ved/mozilla_fac... https://jolt.law.harvard.edu/digest/mozilla-announces-resign... https://wiki.mozilla.org/Speaker_Series#Monday_Oct_1.2C_2018... https://twitter.com/datasociety/status/1093227579723730946 I could go on forever with Mozilla's connections to organizations promoting and facilitating politically motivated censorship.

Just to be clear: other than the Mr Robot promo your main criticism is that their politics don't align with yours?

Because I think when people ask about Mozilla controversies they're thinking about situations in which Mozilla has "broken character" by e.g. risking users' privacy, not activism that is absolutely in line with Mozilla's stated goals (whether you personally agree with them and their interpretation thereof or not).

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#219
post #81

Earlier quoted context omitted.

Imagine how powerful a paid browser could become on this front. As people slowly become more privacy-aware this might be feasible.

I have a hard time believing a paid browser would ever get big. People just do not care enough.

Opera started as a paid browser and nearly went bankrupt. They even had ads on the free version. Barely anyone paid for it and the ads killed adoption.

Heck, even Netscape Navigator started out as shareware. It was "personal use only" but most commercial users never bought a license. It was eventually defeated by Microsoft Internet Explorer, which was free for commercial use even before it shipped with the OS.

If there is any chance someone will attempt a paid browser again, it will most definitely be based on Chromium (or maybe Firefox) rather than written from scratch and no website will make any effort to test on it (just like barely anyone ever tested on Opera).

Re: Protections Against Fingerprinting and Crypto Mining in Firefox Nightly and Beta

#220
post #24

> In the coming months, we will start testing these protections with small groups of users and will continue to work with Disconnect to improve and expand the set of domains blocked by Firefox. We plan to enable these protections by default for all Firefox users in a future release. While lots of people here already have uMatrix or other blockers running, blocking fingerprinting and cryptomining domains by default wo…

Since you work on ads, may I ask why you support this? Won't this make most of your features ineffective?

Optimistic answer: working on ads doesn't mean you agree with the level of privacy violations analytics involve these days, making those invasions of privacy technically impossible or illegal means you can avoid them without having to defend your stance against business interests (e.g. "but our competitors are already doing this and not doing it puts us at a disadvantage").

Pessimistic answer: technical countermeasures don't prevent these invasions of privacy but they make them significantly harder, putting companies with less technical skills at a disadvantage. Anti-fingerprinting protections hurt the bottom feeders while larger companies like Google can likely work around them.

Pragmatic answer: this wasn't really about the fingerprinting but the crypto miners. Ad networks don't like crypto miners either but blocking them is difficult so browser vendors are really just solving the ad networks' problem for them.

Post reply on HN