3 ms·
I'm objecting to the fact that you are calling this a change and that it supposedly collects more data. My understanding is that it is the opposite. Much of the
by gcp 9y ago
I'm objecting to the fact that you are calling this a change and that it supposedly collects more data. My understanding is that it is the opposite. Much of the stuff that you list is the update check and the update checks for add-ons, CA revocation checking etc, all things that have always been on by default and that can now actually be disabled more easily.
I have no idea where you pull the "this seems to include what URL's you're browsing; this could be a security risk for apps like Dropbox and OneDrive" stuff from. The only place I know of that these could potentially be recorded is a crash report, and this has always been the case if you allow it to send crash reports back because they contain the stack contents.
- jamiesonbecker 9y agoYou claimed that I was spreading FUD; rather than resort to ad hominem responses, please counter with facts. I'm happy to apologize if I am incorrect, but it appears that your information appears to be out of date: Telemetry was previously only enabled by default in Nightly and Aurora: https://blog.theochevalier.fr/telemetry-enabled-by-default-on-firefox-nightly-and-aurora/ https://blog.theochevalier.fr/telemetry-enabled-by-default-o... The telemetry data includes a lot more than just update checks. You wouldn't need to send information to Mozilla to get an update or get CA revocation lists. For example, from the privacy policy[1]: Firefox features offered by Mozilla or our partners (such as *interaction with Firefox search features* and search partner referrals). [emphasis added] Many of your comments are about Firefox, development with Rust, etc. I didn't mean to offend you if you are closely aligned with Mozilla. A healthy browser ecosystem (and especially the great new rendering engine from Mozilla) benefit us all. 1. https://www.mozilla.org/en-US/privacy/firefox/ https://www.mozilla.org/en-US/privacy/firefox/
- gcp 9y agoplease counter with facts I already did. Much of the stuff you mentioned has always been enabled and had nothing to do with telemetry. This is most obvious with the update checks. And yes, you DO need to send information to know which add-ons to update. Probing every installed add-on to see if there's an update amounts to sending over the list of installed add-ons. Let's be forthright about that. I quoted an article from one of the Telemetry engineers explaining that now LESS data is collected by default. I think that's a good enough rebuttal to your claim that there has been a change of direction to collect more.
- jamiesonbecker 9y agoPersonally, I actually don't have any issue with any of the individual telemetry data, although it can certainly be used to fingerprint and for other nefarious purposes, or even if it's opt-out instead of opt-in, but collecting it by default is definitely a new change. In fact, your link explicitly explains that you cannot control the extent of data collection now. ("There is just one control for data upload for Firefox") It also explains that this is a new change ("which is on by default.") Trying to spin this or casting aspersions on casual users who noticed a change won't change the facts.
- mintplant 9y agoYou are spreading FUD. > (URL's? Form data?) > this telemetry does cover usage.. i.e., this seems to include what URL's you're browsing; this could be a security risk for apps like Dropbox and OneDrive. Back these claims up with something specific and concrete, otherwise they're just wild speculation. The search bit you're quoting refers to when you, say, search for something using Amazon via the Amazon search provider built into the browser search box, a piece of data is sent along with the request to Amazon to attribute Mozilla as the source. In aggregate this influences how much Amazon pays out to Mozilla for their default presence in Firefox. I'm happy to try to clarify any concerns about telemetry or other data collection you might have (in an individual capacity, not as a representative of Mozilla), but usually that should come before the flinging of damaging accusations over a public forum.
- jamiesonbecker 9y ago> You are spreading FUD I was pointing out that this is a new opt-in change. The links that were posted prove it. Is that FUD? > specific and concrete In the absence of specific information, should we not assume the worst? > data collection That sounds reasonable for normal users, but any of this data can be used for fingerprinting, data mining, etc. Do you disagree? One suggestion for improvement would be that the specifics of what data is collected and why would be a welcome addition to the Privacy Policy page, or perhaps a more detailed page that the PP links to. This would be something people could paste in public forums to refute incorrect statements... especially if the page was on mozilla.org instead of Medium.
- mintplant 9y agoI believe the information you're asking for is already all there on the privacy policy page, broken down by feature and with links to disable each, even. It also includes a link to the full technical docs on Firefox telemetry: https://firefox-source-docs.mozilla.org/toolkit/components/telemetry/telemetry/index.html https://firefox-source-docs.mozilla.org/toolkit/components/t... The wording of the search partnership disclaimer could be made clearer. Is there anything else that you find confusing or disconcerting?
- kbenson 9y ago> You wouldn't need to send information to Mozilla to get an update or get CA revocation lists. Any request to Mozilla is sending info to Mozilla, and thus should be covered under the privacy policy. Every check for an update likely also includes the current version running so they can send back info on whether the update is important/security related or not. Even if it was just a "list all versions" request, it still signifies that IP used the browser. Similarly, a CRL list update signifies that the IP used Firefox and that the conditions that trigger a CRL update were met (which might mean an HTTPS address was visited, or it might happen at startup). Any time Firefox implicitly requests data from Mozilla, that's something that they would likely cover in their Privacy policy. Chrome got a lot of flack a few years back for essentially the same problem, but with a twist. Every time it started it would download a binary blob from Google. It turns out it was the code to do voice recognition, which was executed after download. Fairly innocuous if you trust Google, but it was executing remote code from Google on every startup, so people were rightly disturbed by what they saw going on until an explanation was put forth.