5 ms·
You're making an assumption that their decision was based on data they collected. Not worth discussing data privacy with you over that-- they may have very well
by anon12413 8y ago
You're making an assumption that their decision was based on data they collected. Not worth discussing data privacy with you over that-- they may have very well done simple user testing or done it on a whim of a few users that put a good case forward.
- askvictor 8y agoFrom the article: > According to our telemetry data, the notifications prompt is by far the most frequently shown permission prompt, with about 18 million prompts shown on Firefox Beta in the month from Dec 25 2018 to Jan 24 2019. Not even 3% of these prompts got accepted by users. The decision seems very clearly based on the collected data.
- anon12413 8y agoNo it's not, they quoted some telemetry but the feature and decision may have been decided way before then. The data may only be a justification for it.
- zaarn 8y agoWell, there is little proof that they decided something and then went looking for data unless you can find some statement by mozilla that supports your theory?
- nindalf 8y ago> May have been That’s a huge assumption. I’m going with a smaller assumption that Mozilla wouldn’t publicly lie for no obvious gain.
- darkpuma 8y agoHe's also failing to acknowledge that using telemetry in a constructive way does not preclude using that telemetry in a malicious way as well.
- nindalf 8y agoFirefox’s source code is open. So is Visual Studio Code. Could you please tell us what is collected that could possibly be used maliciously? You can get started here - https://github.com/Microsoft/vscode-extension-telemetry https://github.com/Microsoft/vscode-extension-telemetry and https://github.com/Microsoft/vscode https://github.com/Microsoft/vscode
- darkpuma 8y agoI didn't say that I believe it's being used maliciously. I pointed out that "Second, Mozilla seems to use telemetry data responsibly and well." is an assumption that can't be justified by observing publicized uses of the telemetry. It presumes that published uses of telemetry encompass all uses of telemetry. I have no reason to look at Mozilla's source because their stated policy already admits they collect information that could be considered sensitive, under certain circumstances: > Category 3 “Web activity data”: Information about user web browsing that could be considered sensitive. Examples include users’ specific web browsing history; general information about their web browsing history (such as TLDs or categories of webpages visited over time); and potentially certain types of interaction data about specific webpages visited. > Pre-Release: May be eligible for default on data collection, provided there is an opt-out. > Release: Default off. On a case-by-case basis collections may be eligible to be "default on" if mitigations are identified. Mitigations may include UX changes that make users aware of additional risk, technical mechanisms that remove the risk, or a risk assessment done of a case-by-case basis that determines the risk is limited. So here we have mozilla admitting that their default-on telemetry in pre-release copies of Firefox may include browsing history. This is information that COULD be used improperly. That's not to say Mozilla is, but confirmation that they aren't would require independent audits of the organization and their security practices. Simply reviewing their press releases is not enough to conclude that they haven't misused sensitive information. (Frankly I don't give a damn about VSCode, at all.)
- codedokode 8y agoI think the important point is that software developers prefer to enable telemetry silently, without even notifying the user, let alone asking for a permission. If they think that telemetry is so useful, why not ask the user about it?