6 ms·
Firefox Pioneer
- fwdpropaganda 8y agoCompanies like this data to improve their products. As long as it's opt-in, we should have no ethical issue with it. Doesn't surprise me that Mozilla is dealing with this ethically. One of the few organizations I trust.
- katerberg 8y agoYup. They screw up occasionally, but I trust that they do their best and mistakes made are going to be resolved in a way that I feel comfortable with.
- slater 8y ago$5 say their marketing dept will "accidentally" install/push something that will "accidentally" opt-in everyone.
- CJefferson 8y agoHow about $500, over the next.. 8 years (you have to stop a bet eventually). Or just $5 if you don't have the confidence in a mistake.
- joombaga 8y ago> The data you submit is encrypted in Firefox and not decrypted until it is on a server that is not connected to the wider internet. Okay, stupid question: How does it get there? Sneakernet?
- Frye 8y agoIt gets there encrypted via the internet
- jgtrosh 8y agoNot directly connected to the wider internet ? As in not referenced by DNS, but connected to machines which are ?
- kemitche 8y agoEither sneakernet, or the server is disconnected before the private key is attached, I assume. But sneakernet makes the most sense to me.
- scrollaway 8y agoUser's computer => Encrypted => Sent over the internet => Mozilla's public servers => Mozilla intranet gateway => Mozilla non-internet-facing server => Decrypted here It doesn't say the server is completely offline. It can be connected to through a server which can connect to both that server and the wider internet, but the machine in question cannot.
- mygo 8y agohopefully the server connected to the wider internet can only receive from the wider internet and not send anything to the wider internet. Otherwise it can just be used as a proxy to the server that’s not connected to the internet.
- joombaga 8y agoHmm. If I was describing a server behind a bastion host I'd feel dishonest saying it's "not connected to the wider internet".
- bashinator 8y agoI agree. A more honest and accurate way of putting it would be, “not accessible from the wider Internet.” On the other hand, with immutable servers, giving them no route to the wider Internet actually could be possible.
- Gaelan 8y agoEncrypted data is uploaded to some Mozilla server. From there, the the encrypted data is copied onto some sort of storage device (USB stick or DVD), which is then inserted into the non-connected machine where it is decrypted.
- Gaelan 8y agoCan't edit, but should add that this is speculation
- _verandaguy 8y agoMost likely they mean that it only gets decrypted after going through a bastion-like host that's connected to both the internet and one of their intranets. A sneakernet would be an option but it's fairly unlikely
- joombaga 8y agoHmm. If I was describing a server behind a bastion host I'd feel dishonest saying it's "not connected to the wider internet".
- CubicsRube 8y agoYou will send your data to publicly available server, which will forward it to other server available only through local network, hidden from the prying eyes, secured by firewall, routers, and/or some network configuration.
- benatkin 8y agoIt could store it on a network filesystem. The computer that writes it would be connected to the internet, and the computer that reads it would not. Or it could store it in a database.
- hartator 8y ago> Okay, stupid question: How does it get there? Sneakernet? Homing pigeon.
- deleted 8y ago[deleted]
- walid 8y agoYou're right. It's a stupid question. What are you doing on Hacker News?
- dang 8y agoPersonal attacks will get you banned here. Please don't do this again. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- deleted 8y ago[deleted]
- some_account 8y agoI have all kinds of anti tracking installed in Firefox but I'm going to sign up for this. Why? Because I want Firefox to be the best browser. Mozilla is not Google and not Microsoft. They have a very different view on privacy and how they would like the internet to evolve.
- fixermark 8y ago> Mozilla is not Google and not Microsoft. ... right now. How many years do you trust them to hold the data they harvest from you? Through how many CEO transitions? ;)
- kevingadd 8y agoIt may be helpful to understand how Mozilla's operations are structured: https://en.wikipedia.org/wiki/Mozilla_Foundation https://en.wikipedia.org/wiki/Mozilla_Foundation However, anything's possible with the way businessmen tend to bend the rules to make money, so it's certainly within the realm of possibility that within 10 years the Foundation will sell the Corporation to Amazon-Comcast-Warner LLC and then they'll monetize the data.
- fixermark 8y agoPrecisely. If one is concerned about not giving data like this to Google, MS, et. al. for privacy reasons, I wouldn't trust Mozilla's guarantees without actual contractual language declaring the lifetime of the data and under what circumstances the data will be destroyed (including but not limited to "company is purchased by another company").
- jopsen 8y ago> I wouldn't trust Mozilla's guarantees without actual contractual language... Then go read the fine print: https://addons.mozilla.org/en/firefox/addon/firefox-pioneer/privacy/ https://addons.mozilla.org/en/firefox/addon/firefox-pioneer/... But more importantly understand that this probably isn't for everybody. I think it's a fair guess to say they just want a small population, not something in the millions.
- sevensor 8y agoIsn't Shield the same system that pushed a marketing gimmick late last year? I'm still feeling sore about that fiasco. Not sore enough to stop using Firefox and switch to a worse-for-privacy alternative, but sore enough to be grumpy about signing up for their studies.
- mythmon_ 8y agoYes, this is using the same system as the Mr Robot marketing gimmick last December. That isn't very worrying to me though, since that platform is basically a generic "do something in the browser" capability, where "do", "something" and "the browser" are fairly loosely defined. Both the Mr Robot promotion and the Pioneer program could be done through other avenues. Shield is the most convenient mechanism currently available for this sort of fine-grained deployment.
- deleted 8y ago[deleted]
- JadeNB 8y ago> Once you’ve opted in, you may be enrolled in additional studies without potentially annoying prompts. Ha. "Once you've opted in, you will not have explicit control over enrollment in future studies" is a less sunny way of saying this.
- walid 8y agoCheck the "How do I opt out?" part of the article.
- JadeNB 8y agoIndeed, I didn't mean to suggest that it was a permanent decision; but rather that opting in to the program as a whole explicitly and clearly, but nonetheless perhaps undesireably, amounted to opting in to in to not just the present but also the future parts of it—perhaps such as, without any guarantee to the contrary, future stunts on the order of the Mr Robot promotion.
- dmix 8y ago> The data you submit is encrypted in Firefox and not decrypted until it is on a server that is not connected to the wider internet. This is a good approach.
- 8bitsrule 8y agoI see that this personal information, too, doesn't pay like what pioneers used to get paid ... in land, gold, animals. "if you meet the criteria." No. I don't.