Live data from Hacker News

Things to know about the GDPR, Mozilla and Firefox

blog.mozilla.org

61–70 of 103 posts

Re: Things to know about the GDPR, Mozilla and Firefox

#61
post #48

Earlier quoted context omitted.

> Great, so about:addons doesn’t use tracking Google Analytics cookies anymore? Or has a visible way to disable it (you need to enable DNT to get rid of this). I can imagine this being legitimate interest, can be disabled with DNT flag, and it's not personal data. Mozilla signed a legal contract with Google which prevents Google from using this information. > EDIT 3: See also https://www.mozilla.org/en-US/firefox/cha…

> I can imagine this being legitimate interest, can be disabled with DNT flag, and it's not personal data. Mozilla signed a legal contract with Google which prevents Google from using this information. Still it would require at least a cookie notice. > Options -> "Privacy & Security" > "Nightly Data Collection and Use" That does not disable all telemetry, there were a few discussions about this on the bugtracker, in…

> I can imagine this being legitimate interest, can be disabled with DNT flag, and it's not personal data. Mozilla signed a legal contract with Google which prevents Google from using this information.

Actually the do not track and tetemetry preferences do not work on the addon page.

Re: Things to know about the GDPR, Mozilla and Firefox

#62
post #48

Earlier quoted context omitted.

> Great, so about:addons doesn’t use tracking Google Analytics cookies anymore? Or has a visible way to disable it (you need to enable DNT to get rid of this). I can imagine this being legitimate interest, can be disabled with DNT flag, and it's not personal data. Mozilla signed a legal contract with Google which prevents Google from using this information. > EDIT 3: See also https://www.mozilla.org/en-US/firefox/cha…

> I can imagine this being legitimate interest, can be disabled with DNT flag, and it's not personal data. Mozilla signed a legal contract with Google which prevents Google from using this information. Still it would require at least a cookie notice. > Options -> "Privacy & Security" > "Nightly Data Collection and Use" That does not disable all telemetry, there were a few discussions about this on the bugtracker, in…

> Still it would require at least a cookie notice.

Fair enough, I'm actually somewhat curious why Mozilla doesn't provide a cookie notice. Not that it matters, because those notices are used everywhere and people ignore them.

Re: Things to know about the GDPR, Mozilla and Firefox

#63
post #48

Earlier quoted context omitted.

> I can imagine this being legitimate interest, can be disabled with DNT flag, and it's not personal data. Mozilla signed a legal contract with Google which prevents Google from using this information. Still it would require at least a cookie notice. > Options -> "Privacy & Security" > "Nightly Data Collection and Use" That does not disable all telemetry, there were a few discussions about this on the bugtracker, in…

> I can imagine this being legitimate interest, can be disabled with DNT flag, and it's not personal data. Mozilla signed a legal contract with Google which prevents Google from using this information. Actually the do not track and tetemetry preferences do not work on the addon page.

Do Not Track should work on addons page, if it doesn't, it's a bug.

Telemetry settings however don't work unfortunately :(.

Re: Things to know about the GDPR, Mozilla and Firefox

#64
post #41

Earlier quoted context omitted.

This brings up a interesting point: cookies are not just for user/session identification. Yes that's how the majority of the apps work but instead, it's totally possible to use cookies to customize a site's experience, feature by feature. A cookie for the theme, a cookie for the font prefs, etc. Yet most sites still insist on logging the user in to customize the experience, and rely on some central storage to determi…

This is a terrible use case for cookies. Any browser reset or change, new computer, your phone, etc, and you need to redo the whole experience every time. I'd rather login and customize once. Cookies get sent with most requests as headers so you're unnecessarily bogging down requests with data unrelated to the session.

100% exactly. Cookies are device and moment specific. Whereas a user account can easily save and transport the saved experience/setting anywhere the user wants to access them.

Re: Things to know about the GDPR, Mozilla and Firefox

#65
post #35

Earlier quoted context omitted.

They’re using Google Analytics, by default, in the browser UI and on their Websites, without opt-in or visible opt-out (it’s hidden in the tracking prevention settings of the browser itself, and chained to the DNT setting). That’s about as violating as it gets.

Are you accounting for the fact that Mozilla has a special contract with Google regarding the use of Analytics? https://bugzilla.mozilla.org/show_bug.cgi?id=697436#c14

Yes. That still requires at least a cookie notice in any case.

But Mozilla doesn’t have that, and merely has a tiny grey-on-grey 10px tall "Privacy Policy" link in about:addons.

Re: Things to know about the GDPR, Mozilla and Firefox

#66
post #52
post #23

Great, so about:addons doesn’t use tracking Google Analytics cookies anymore? Or has a visible way to disable it (you need to enable DNT to get rid of this). And Firefox Nightly does not track personally identifiable telemetry anymore? No. Mozilla still tracks every step I take. What the fuck, Mozilla? EDIT: Example. Go to If you go to view-source: https://addons.mozilla.org/en-US/firefox/ — In the code you’ll find G…

https://bugzilla.mozilla.org/show_bug.cgi?id=697436#c14 "GA also doesn't track IPs or store PII within the tool."

Still requires that they inform the user, with the Cookie Notice soft-consent (or whatever the new ePrivacy directive will replace that with soon).

Re: Things to know about the GDPR, Mozilla and Firefox

#67
post #35

Earlier quoted context omitted.

They’re using Google Analytics, by default, in the browser UI and on their Websites, without opt-in or visible opt-out (it’s hidden in the tracking prevention settings of the browser itself, and chained to the DNT setting). That’s about as violating as it gets.

Users are free to block third party cookies.

They need to know that third-party cookies exist for that, though.

Re: Things to know about the GDPR, Mozilla and Firefox

#68

Moreover, many EU companies don't need to update it either.

And a ton of non-EU companies don't, but are doing so for future purposes. Despite territorial scope, a company without any form of business in the EU, they can't entorce this against non-EU businesses.

FWIW while you're right, that's awfully shortsighted unless you're a mom & pop shop with no intent of ever expanding beyond your backyard.

A lot of devs hanging out on HN are working for companies that have at least some B2B aspect. Being GDPR non-compliant means these companies will have to avoid you too, because even if they're themselves not affected by GDPR they may have customers who are and need the compliance to be able to do business with those customers.

But that said, as an EU company, US companies are only an option if they're Privacy Shield certified and offer a Data Processing Agreement. And even then it's safer to go for a company in the EU or in an "adequate"[0] country. You don't want to be caught unaware when some court or orange person decides to blatantly violate the Privacy Shield guarantees and you have to treat it as a breach.

[0]: https://ec.europa.eu/info/law/law-topic/data-protection/data...

Re: Things to know about the GDPR, Mozilla and Firefox

#69
post #34

Earlier quoted context omitted.

Show me case law where an EU government fined a US company and how they enforced payment of that fine.

Microsoft for antitrust violations more than once is just an example, but that's the EU itself.

Just like the other two people that brought up the same thing:

Microsoft had a presence in the EU long before the antitrust violations came. I'm talking about a US company that has no presence in the EU. That's a harder example largely because it doesn't exist.

Re: Things to know about the GDPR, Mozilla and Firefox

#70
post #32
post #21

Earlier quoted context omitted.

When did I mention case law? Shouldn't you be asking me for proof of the accords I mentioned, which is what I'm actually talking about?

So where is the evidence of the accords? How will they enforce it?

You won't get a response. There aren't any accords and there's no way to enforce it. It's empty threats.
Post reply on HN