Live data from Hacker News

Firefox lost 50M users since 2019

data.firefox.com

591–600 of 618 posts

Re: Firefox lost 50M users since 2019

#591

Earlier quoted context omitted.

And that's why I regard anti-trust laws as inconsistently applied cudgels and not as legal gospel. If tying (assuming there's a consistent definition of the word) is such a bad idea to begin with why does it matter whether it's done by a company at 90% or 10% of market? Equality under the law should be the measure.

> If tying (assuming there's a consistent definition the word) is such a bad idea to begin with why does it matter whether it's done by a company at 90% or 10% of market? Equality under the law should be the measure. There is nothing inherently wrong with tying, which you might also call "bundling." Quoting from the FTC's website: Offering products together as part of a package can benefit consumers who like the conv…

Like how Apple bundled iTunes and forced streaming competitors onto uneven playing fields with the 30% tax to dominate online music sales, bundled the App Store and banned competing stores to ensure no competition, bundled Safari and banned competing tech, bundled Podcasts to help outcompete others in an area they want more growth, etc

It's only anti-trust when companies people don't like do it.

Re: Firefox lost 50M users since 2019

#592

Earlier quoted context omitted.

> To my understanding there is no data sent from my Brave client to any Brave servers. That would be wrong. By Brave's own confession, there are 70 requests it sends "home" on startup [1]. Regardless of request payload, each of them contains your PII (IP address at the very least). There is plenty of opportunity for your data to be stored and used (not saying that it is). If and how is that data actually used, we do…

> By Brave's own confession, there are 70 requests it sends "home" on startup… "Confession" is a curious choice of words. You're correct that Brave issues requests on startup; this is necessary for a secure application. If your browser isn't updating its internal list of suspected-malicious domains and more, it isn't doing "security" properly. > There is plenty of opportunity for your data to be stored and used (not…

It looks like we are coming from two different sides of the table. So let's try to agree with this statement:

"A privacy respecting browser has no business sending data on its own anywhere without the user being OK with it first."

This is true by the very definition of what privacy is.

If you want to check for updates - let the user initiate/opt-into automatic updates. If you want to update your malicious domain list (is that useful at all?) - let the user initiate/opt-into it. And so forth.

If you want to make these choices on the behalf of the user, and enable this and other things you do in those 70 requests you do on startup - that is of course fine. But you lose the right to call yourself a privacy-respecting product because Brave client just sent data to Brave servers without user knowing/consenting to it.

> which also found Brave to be the "most private" browser tested

A statement like "Brave is most private of the tested browsers" implies that privacy is somehow an analogue measure between 0 and 1, where Brave is for example 0.6 and Chrome is 0.4 or something.

But privacy is a binary measure, you (company/product) are either respecting privacy of the user or you are not. You can not respect it 'a little'. You look at your friends the same way - one has propensity to leak information and the other one doesn't. There is no category for friends who leak 'a little' information. Either they do or they don't. And frankly being called 'most private' in the company of those browsers is like saying a dog is 'most likely to fly' in the company of an elephant, dinosaur and a rhino. Be cool and be a bird to begin with.

> An IP address is rather unavoidable. But whether or not an IP address constitutes PII is debatable.

Kahm. IP address is rather avoidable - just do not send data without user's consent. It is that simple. We are doing it, so I know.

It is also not that much of a debate whether IP address is PII. It is.

Multiple court rulings such as State vs Reid [1], and Breyer vs Germany [2] as well as California CCPA act of 2018 [3] define IP address to be PII (w/ or w/o caveats) or at least a part of PII.

> That said, we drop the IP address when and where possible.

I never implied otherwise. What I did was to state the fact that Brave client sends data to Brave servers and that we can not tell for sure what is being done with this data because Brave's server code is closed-source.

Is this potentially a concern for the users? Yes. Can it be avoided? Yes - just become zero-telemetry by default. No need for discussion then.

A good relevant example is that Google advertises Chrome as a privacy respecting browser. Do you believe that based on what they say? Why not? Are there ways you could believe this? Yes, if no data ever left Chrome to Google servers without user explicitly allowing it first (by 'allowing it' I do not count accepting Terms&Conditions as those are never read by anyone and do not count as explicit/informed consent in this context).

> do you not maintain a client-side list of suspected-malicious domains

No we do not (could change in the future, in which case it will be opt-in of course). These lists in the current form are arbitrary, this hardly counts as security feature and there is very little chance the user will end up on a malicious website intentionally. Plus browsing the web is the responsibility of the user. The job of the browser is to stay out of your way, not make arbitrary decisions for you.

> check for updates to patch zero-day vulnerabilities in the wild

In Orion, user can check for updates manually or opt-in into automatic updates. So the feature is there. The key is however in "opting-in" because we want to have the right to call Orion a privacy respecting browser.

Orion does not even set a default search engine - otherwise the moment you start typing into address bar you would be leaking information (including IP address) to the search engine provider for suggestions.

To recap, Orion sends zero data to our servers or anywhere else for that matter (unless user first opts-in into it), on the first run, on any run or ever really. We call this "zero-telemetry by default" and we invite Brave to adopt this. Privacy is a serious matter, so let's treat it seriously.

[1] https://en.wikipedia.org/wiki/State_v._Reid

[2] http://curia.europa.eu/juris/document/document.jsf?text=&doc...

[3] https://oag.ca.gov/privacy/ccpa

Re: Firefox lost 50M users since 2019

#593

Earlier quoted context omitted.

How do you know this is because of Chrome in the first place? Another explanation is that it could be Edge or even users moving to use mobile (browsers) more? Genuinely curious where the market share and total number of users in the market (broken down) has shifted.

It may also not exclusively be anticompetitive behavior from Chrome, but just Mozilla's stewardship of Firefox. They constantly manage to generate shitstorms around updates (how does this never happen with Chrome?) and then the plain disregard/making fun of user feedback [1] is just a kick in the teeth. For me at least, that's in large part why I moved to Chrome. [1]: https://web.archive.org/web/20200731211652/https:…

Ever seen this response? https://www.emilykager.com/writing/2021/02/10/mozilla.html#m...

Re: Firefox lost 50M users since 2019

#594

Earlier quoted context omitted.

> To my understanding there is no data sent from my Brave client to any Brave servers. That would be wrong. By Brave's own confession, there are 70 requests it sends "home" on startup [1]. Regardless of request payload, each of them contains your PII (IP address at the very least). There is plenty of opportunity for your data to be stored and used (not saying that it is). If and how is that data actually used, we do…

> Do not want to be harsh but I assume you didn't actually look into the Brave's source code. This is a weird assumption to make on HN. I have. I also didn’t say that viewing source code is the only part of understanding a browser’s security. It’s a useful portion. Network monitors are also good. I’m not talking about startup telemetry, I mean browsing history and activity. Chrome reports this, Brave doesn’t. I don’t…

Point taken. Since someone from Brave jumped in, I gave my (long) opinion on the topic as a reply to their comment.

Re: Firefox lost 50M users since 2019

#595
post #503

Earlier quoted context omitted.

You’ve been able to use ad blockers in Safari for years.

Ya I know I "can". Via app store, I know. Hence my comment: "hard" to install ad-blockers

maybe you should go back and read your own comment. Also, it's not terribly hard to install extensions through the App Store — what makes it more difficult than going through the Firefox/Chrome extension store?

Re: Firefox lost 50M users since 2019

#596

Earlier quoted context omitted.

In terms of "browsers that actually matter", there's just Chrome/chromium at a combined 70% and Safari at a little over 18%. Everything else is a side mention at best and as a browser at least, is basically irrelevant on the world stage. Even if the companies behind them aren't (e.g. Mozilla or Samsung). [1] They are of course highly relevant for their user bases, but in terms of "browsers that might break the Chrome…

> You'd need to pull a Microsoft IE-on-Windows on Google How about actually just making a good, competitive browser instead? Firefox is not failing because of Google's monopoly; it is failing because as a product it is unable to compete and beat Chrome where it matters. If not Mozilla, I am pretty sure somebody else will make such browser (and search engine, and email... ) eventually.

Currently you can't really compete with Google's/Alphabet's market and marketing power. If you get too close, product-wise, they can just throw more money at their own product in your field. It needs political market intervention to make a dent that would count enough for others even getting a theoretical chance of getting one step ahead again. While that might be true in little web standard pieces here and there for Firefox compared to Chrome (and it certainly is vice-versa), the much smaller teams will always play catch up.

Re: Firefox lost 50M users since 2019

#597

Earlier quoted context omitted.

> By Brave's own confession, there are 70 requests it sends "home" on startup… "Confession" is a curious choice of words. You're correct that Brave issues requests on startup; this is necessary for a secure application. If your browser isn't updating its internal list of suspected-malicious domains and more, it isn't doing "security" properly. > There is plenty of opportunity for your data to be stored and used (not…

It looks like we are coming from two different sides of the table. So let's try to agree with this statement: "A privacy respecting browser has no business sending data on its own anywhere without the user being OK with it first." This is true by the very definition of what privacy is. If you want to check for updates - let the user initiate/opt-into automatic updates. If you want to update your malicious domain list…

We are indeed seeing these topics from two very different perspectives. I applaud your efforts; it sounds like you're building a nice project for [power users]. Brave is built for all users, however. As such, asking users to opt-in to security is, IMHO, a bad idea.

> "…you lose the right to call yourself a privacy-respecting product…"

I obviously disagree here. The problem is not _requests_, but rather the nature of the requests. You can certainly choose to not make any requests, but I feel doing so puts your users at considerably higher risk. I'd be curious how consistent you can be with this too; does your operating system and router also issue no requests on their own? Are users supposed to be capable of tracking security threats on those fronts too, as well as locate and install updates?

> "It is also not that much of a debate whether IP address is PII. It is."

It can be. I don't think this is a legal question, but rather an engineering one. You and I both know that this space is complicated by networks, NAT routers, and more.

> "Brave client sends data to Brave servers and that we can not tell for sure what is being done with this data"

What data? I understand that you have limited visibility into the server-side of things, but you can see clearly what data is being sent to Brave's services to begin with. What sorts of concerns do you have with what is being transmitted today?

> [Re: security lists] "Plus browsing the web is the responsibility of the user."

This is where we diverge even more. It sounds as though you're targeting super users who are very technical, and comfortable with monitoring threats, applying patches, etc. That expectation works for niche software, but not for software intended for _all users_. Brave absolutely should protect users from known threats. As we saw this past week, malicious ads on Google's search engine results were sending users to malware sites. Fortunately, we were able to get those URLs added to the SafeBrowsing service, and protect users of Brave, Chrome, Edge, and more.

> "Orion does not even set a default search engine - otherwise the moment you start typing into address bar you would be leaking information (including IP address) to the search engine provider for suggestions."

You don't have to perform live lookups. Brave doesn't send keystrokes for this very reason; users have to opt-in to that. Firefox defers sending keystrokes until 2 characters have been input. Most others just send the keystrokes (or pasted content) behind the scenes—not cool.

> "Privacy is a serious matter, so let's treat it seriously."

Expecting your users to opt-in to basic privacy features suggests privacy takes a backseat, IMHO. But then again, we may be targeting very different demographics with our software. It sounds like you're targeting power users who are okay with elevated risk. We're building Brave for everybody.

Re: Firefox lost 50M users since 2019

#598

Earlier quoted context omitted.

To my understanding there is no data sent from my Brave client to any Brave servers. So my data are not stored or used by Brave servers, so I don’t care too much about their source. Of course, there’s nothing magical about open source that makes it more privacy respecting. It’s just that open source let’s me know what my browser is doing. For example, Chrome is reporting everything I do to Google. It’s possible to kn…

> To my understanding there is no data sent from my Brave client to any Brave servers. That would be wrong. By Brave's own confession, there are 70 requests it sends "home" on startup [1]. Regardless of request payload, each of them contains your PII (IP address at the very least). There is plenty of opportunity for your data to be stored and used (not saying that it is). If and how is that data actually used, we do…

I was going to download your browser (from https://browser.kagi.com/), but I realized 1) There is no Windows option, and 2) It requires me to submit a great deal of information via a Google Form before I can download.

Honestly, this is not what I expected from the "privacy respecting, zero-telemetry, browser" that you've been heralding here.

The Google Form alone is far more alarming than Brave's P3A (which is not connected to any Google Account, doesn't feed the data to a third-party, restricts user answers to category/range values, breaks up and temporally offsets delivery of feedback to prevent fingerprinting, etc.).

Re: Firefox lost 50M users since 2019

#599
post #593

Earlier quoted context omitted.

It may also not exclusively be anticompetitive behavior from Chrome, but just Mozilla's stewardship of Firefox. They constantly manage to generate shitstorms around updates (how does this never happen with Chrome?) and then the plain disregard/making fun of user feedback [1] is just a kick in the teeth. For me at least, that's in large part why I moved to Chrome. [1]: https://web.archive.org/web/20200731211652/https:…

Ever seen this response? https://www.emilykager.com/writing/2021/02/10/mozilla.html#m...

Thanks for linking.

For a "light hearted joke", that is a lot of effort, extremely unprofessional and very poorly worded. I still don't blame people for taking issue with it. The harrassment though is another story, that sucks and shouldn't have happened.

Re: Firefox lost 50M users since 2019

#600

I've been using Firefox daily for over 15 years now. My experience with Firefox over the last 2-3 years in particular leaves me very disappointed and frustrated. The constant nonsense UI redesigns that come about with every new update. The instability, and ridiculous resources consumption. The slowness and slugishness. I want a browser that works, respects my privacy, stays out of my way and lets me get shit done. A…

> Any suggestions for what to try next?

I'm in the same boat as you -- a Firefox user (and evangelist) from the beforetimes. But Firefox stopped meeting my needs when the revamp occurred.

I haven't really found a modern browser that is acceptable, though, but it's not for lack of looking. In the meantime, I stick with an older release of Waterfox.

Post reply on HN