Live data from Hacker News

Firefox: Dark pattern consent dialog invites users to share their location

theregister.com

91–100 of 107 posts

Re: Firefox: Dark pattern consent dialog invites users to share their location

#91

No one as any insider info of how this kind of things is going on inside Firefox corp? I find it curious that privacy cautious OSS devs would not complain highly when asked to add shitty "feature" like that. And it is not the first one recently. So, is it like in a big corp where an asshole management executive push down such decision from the top?

What typically happens is that this stuff gets forced from the managers from on high and some developers complain and ultimately leave since their morale compass is being violated and those that can stand it stay. Then whoever they hire and retain fits with this new culture and the entire morale compass is very quickly shifted. What management wants always goes in the end they just slowly expel all those that disagree to implement it one way or the other.

Re: Firefox: Dark pattern consent dialog invites users to share their location

#92

Earlier quoted context omitted.

Google respects your privacy and Chrome tends to have more features than Firefox.

> Google respects your privacy Do you work there? I see no other way you could possibly think this. If not, do you have a source you can provide? > Chrome tends to have more features than Firefox This is true. Some features, I have no use for, some are outside of standards and thus lead to the same issue as years ago with IE, and some fall under both. Admittedly, me having no use for some doesn't mean they don't have…

>If not, do you have a source you can provide?

Unironically read Google's privacy policy page.

https://policies.google.com/privacy?hl=en-US

Re: Firefox: Dark pattern consent dialog invites users to share their location

#93

Earlier quoted context omitted.

If it's deleted, then why would you care? It no longer has anything to do with you.

If they have trained an ML system on it, they have acquired and exploited info about your private behaviour even if it is anonymized. So it is an invasion. The trope "not personally identifiable => not invasive" is self-serving and a non-sequitur and needs to die.

Why do you care that Google's improved one of their ML systems. Are you a competitor to them. It doesn't seem very nice to be against others improving their services.

Re: Firefox: Dark pattern consent dialog invites users to share their location

#94

Earlier quoted context omitted.

Maybe you should learn how to trust people / companies than always being paranoid.

As the saying goes, it's not paranoia if they really are out to get you.

Hint: For 99.9999% people "they" are not out to get you

Re: Firefox: Dark pattern consent dialog invites users to share their location

#95
post #89

Earlier quoted context omitted.

Because it's normal in marketing. Most web servers log your whole IP yet people don't freak out about that.

Is ought fallacy. Just because it is normal in marketing does not make it okay. I am increasingly of the point that marketing, by itself, is not okay. In my browser, it is certainly not okay. I attempt to practice memetic hygine, so I do not want to see ads. Not wanting to see ads, and having some actual privacy in the first place, is why I use Firefox.

>Is ought fallacy.

I am not trying to make a logical argument. That would require an agreement on a way to determine objectively whether something is okay or not. Unfortunately, humans are subjective beings. What they believe to be right and wrong is subjective.

>I am increasingly of the point that marketing, by itself, is not okay.

>I do not want to see ads.

You say this yet you end your post with marketing. You are adverting Firefox. Marketing happens everywhere and trying to escape all of it is a fool's errand.

Re: Firefox: Dark pattern consent dialog invites users to share their location

#96
How long until we get an " unmozillad Firefox"? I really think that Firefox is a great project with the unfortunate attribute of having Mozilla attached to it. Mozilla really seems like a cannonical in the making (which itself is a Microsoft in the making)

I don't think I can trust IT-conglomerates in the making anymore.

Re: Firefox: Dark pattern consent dialog invites users to share their location

#97
post #36

> Unfortunately, all major browsers now use a combined address and search bar. So, if you’re typing in the address of a sensitive website to go directly there, your keystrokes as you type will be sent to your default search engine and your search engine may be able to determine the website address you’re typing in manually. That's why it's a good idea to split the search box in the Firefox settings. Ctrl-l takes you…

You may also need/want to set keyword.enabled to false in about:config.

Re: Firefox: Dark pattern consent dialog invites users to share their location

#98

Earlier quoted context omitted.

If they have trained an ML system on it, they have acquired and exploited info about your private behaviour even if it is anonymized. So it is an invasion. The trope "not personally identifiable => not invasive" is self-serving and a non-sequitur and needs to die.

Why do you care that Google's improved one of their ML systems. Are you a competitor to them. It doesn't seem very nice to be against others improving their services.

A few years ago the NHS gave a load of confidential patient data to an insurance company to train their models. They claimed that it wasn't a problem because the data was deleted after training.

However, nobody knows (publicly) what kind of model it was. If they overfitted the data then when you ask for an insurance quote based on say, date of birth and postcode, the quote will be based on your actual medical details rather than on broader statistics. The result is no different from them having explicit access to your medical records before giving a quote, which is not permitted.

It is easy to build an ML system which for most queries provides the same answer as having access to the original data.

Re: Firefox: Dark pattern consent dialog invites users to share their location

#99

Does a serious alternative to Firefox exist? I mean an alternative that is what Firefox purports to be? I'm ready to make the switch. Been with Mozilla since Pheonix, but the user hostility has become too much.

LibreWolf is a fork of Firefox that removes telemetry, Pocket, and other unwanted stuff. You can use a copy of your existing Firefox profile, but be sure to go through LibreWolf's settings as its defaults err on the side of privacy and may be different than what you already have set up.

Re: Firefox: Dark pattern consent dialog invites users to share their location

#100

Earlier quoted context omitted.

> Google respects your privacy Do you work there? I see no other way you could possibly think this. If not, do you have a source you can provide? > Chrome tends to have more features than Firefox This is true. Some features, I have no use for, some are outside of standards and thus lead to the same issue as years ago with IE, and some fall under both. Admittedly, me having no use for some doesn't mean they don't have…

>If not, do you have a source you can provide? Unironically read Google's privacy policy page. https://policies.google.com/privacy?hl=en-US

Blow by blow breakdown time I guess. I skip portions of the policy here and there.

> We also collect the content you create, upload, or receive from others when using our services. This includes things like email you write and receive, photos and videos you save, docs and spreadsheets you create, and comments you make on YouTube videos.

So first up. User created data, this seems necessary ofc. Lower down, it says emails aren't used for advertising, but says nothing about using them for tracking.

> We collect information about the apps, browsers, and devices you use to access Google services, which helps us provide features like automatic product updates and dimming your screen if your battery runs low.

> The information we collect includes unique identifiers, browser type and settings, device type and settings, operating system, mobile network information including carrier name and phone number, and application version number. We also collect information about the interaction of your apps, browsers, and devices with our services, including IP address, crash reports, system activity, and the date, time, and referrer URL of your request.

We totally need to have your device information on hour servers so we can checks notes provide automatic screen dimming! Yup! Can't do that on device!

And then there's the sheer amount of other information they collect in this paragraph, especially the phone number, and "unique identifiers" - which have proven to pretty much always be trackable back to an individual if someone care's to look.

Pretty much the only thing here which doesn't violate privacy is the last sentence.

> We collect this information when a Google service on your device contacts our servers — for example, when you install an app from the Play Store or when a service checks for automatic updates.

Hm, that seems pretty frequent but whatever I guess. Maybe this is just with Android?

> If you’re using an Android device with Google apps, your device periodically contacts Google servers to provide information about your device and connection to our services. This information includes things like your device type, carrier name, crash reports, and which apps you've installed.

Nope, that gets it's own section. Oh, and look they get every. single. app. installed - regardless of it's from Play Store.

> We collect information about your activity in our services, which we use to do things like recommend a YouTube video you might like. The activity information we collect may include:

    Terms you search for
    Videos you watch
    Views and interactions with content and ads
    Voice and audio information when you use audio features
    Purchase activity
    People with whom you communicate or share content
    Activity on third-party sites and apps that use our services
    Chrome browsing history you’ve synced with your Google Account
> If you use our services to make and receive calls or send and receive messages, we may collect call and message log information like your phone number, calling-party number, receiving-party number, forwarding numbers, sender and recipient email address, time and date of calls and messages, duration of calls, routing information, and types and volumes of calls and messages.

Most of this seems reasonable, but "Activity on third-party sites and apps that use our services" boils down to "We take whatever we want if the domain isn't ours".

> We collect information about your location when you use our services, which helps us offer features like driving directions for your weekend getaway or showtimes for movies playing near you.

This is one of the few that has actual functionality requirements to collect, but the degree to which it is collected is problematic.

Also, this information is effectively PII, but last time I checked can be shared with "Unique Identifiers" as anonymized information.

Skipping the rest of the location section to:

> In some circumstances, Google also collects information about you from publicly accessible sources. For example, if your name appears in your local newspaper, Google’s Search engine may index that article and display it to other people if they search for your name. We may also collect information about you from trusted partners, such as directory services who provide us with business information to be displayed on Google’s services, marketing partners who provide us with information about potential customers of our business services, and security partners who provide us with information to protect against abuse. We also receive information from advertisers to provide advertising and research services on their behalf.

Stuff from publicly accessible sources seem fair.

Collecting from "trusted partners" means that "We didn't collect all that data not in the privacy policy, we bought it!". This applies to most of the bottom 2/3 of this paragraph.

> We use various technologies to collect and store information, including cookies, pixel tags, local storage, such as browser web storage or application data caches, databases, and server logs.

Yep, this is standard to get the information they're collecting. Uncalled for, but standard.

The whole "Provide personalized services, including content and ads" section is exactly what you would expect, though this section:

> We don’t show you personalized ads based on sensitive categories, such as race, religion, sexual orientation, or health.

is worrying. "We have this information, but Trust Us(tm), we won't abuse it :) !"

Also

> We don’t show you personalized ads based on your content from Drive, Gmail, or Photos.

"We won't show you ad's from this" - but not "We won't look at this."

Skipping into "Protect Google, our users, and the public"

> We use information to help improve the safety and reliability of our services. This includes detecting, preventing, and responding to fraud, abuse, security risks, and technical issues that could harm Google, our users, or the public.

Oh boy, time for Security Purposes(tm)!

> And we analyze your content to help us detect abuse such as spam, malware, and illegal content.

There's where Gmail, Drive, and Photo scanning are allowed.

> We may combine the information we collect among our services and across your devices for the purposes described above. For example, if you watch videos of guitar players on YouTube, you might see an ad for guitar lessons on a site that uses our ad products. Depending on your account settings, your activity on other sites and apps may be associated with your personal information in order to improve Google’s services and the ads delivered by Google.

We'll build a profile full of information about you, ready for taking for whichever relevant government, rogue employee, or anyone who breaks our system! But don't worry, it is very secure :) !

Skipping past "Privacy controls" - which having used as an end user I can confirm are full of false choices and dark patterns.

Skipping into "When Google shares your information"

> We provide personal information to our affiliates and other trusted businesses or persons to process it for us, based on our instructions and in compliance with our Privacy Policy and any other appropriate confidentiality and security measures. For example, we use service providers to help us with customer support.

Trust Us and Our Partners(tm). Google has already shown themselves untrustworthy, and they don't share who these partners are, so we have no way of vetting them.

> [We will share data to] Meet any applicable law, regulation, legal process, or enforceable governmental request. We share information about the number and type of requests we receive from governments in our Transparency Report.

We will share any and all data with whichever government is relevant! Glad we created a comprehensive picture of each individual user already!

> [We will share data to ]Protect against harm to the rights, property or safety of Google, our users, or the public as required or permitted by law.

Ah yes, Security Purposes(tm). "We'll do whatever we want with sharing, as permitted by law!"

That's an awful lot.

> We may share non-personally identifiable information publicly and with our partners — like publishers, advertisers, developers, or rights holders.

There's no such thing as non-personally identifiable information ( https://www.cs.princeton.edu/~arvindn/publications/browsing-... ), and looky there, it's getting shared with everyone.

---

Anyways, I don't think that was the source you were looking for. It boils down to "We collect everything, and Trust Us!"

Google has repeatedly shown themselves to not be trustworthy, so forgive me if I don't.

Edit: And keep in mind this is just what they admit to. In my experience, the larger the business the more "sensitive" actions there are.

Post reply on HN