8 ms·
> Just try setting your Firefox browser to a blank page with no requests on startup and watching the Wireshark log if you think otherwise OK, so I just did thi
by 43920 8y ago
> Just try setting your Firefox browser to a blank page with no requests on startup and watching the Wireshark log if you think otherwise
OK, so I just did this, and I don't really see what the issue is. Looking at Wireshark, I see requests for:
* detectportal.firefox.com, which is used to detect whether you're connected to a captive portal network and need to sign in before you can connect to the internet. As far as I'm aware, no personal information is transmitted as part of this request, and there's apparently a pref to disable it [0]
* A couple of requests for OCSP certificate validation [1], which seems like a useful feature, and is also pretty easy to disable if you really don't want it.
* A request to download.mozilla.org and another one to download.cdn.mozilla.net, which looks like it's checking whether an update is available.
I don't really see a problem with any of these?
[0] https://bugzilla.mozilla.org/show_bug.cgi?id=1307867 https://bugzilla.mozilla.org/show_bug.cgi?id=1307867
[1] https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...
- aphextron 8y ago>I don't really see a problem with any of these? You seriously don't have an issue with being fingerprinted and tracked every single time you open an application on your computer? The point is that there should be zero. I should not have a single outgoing network request triggered by opening a web browser to a blank page until interacting in some way. The fact that we've lost this as a standard is terrifying to me.
- sanxiyn 8y agoYou can configure Firefox such that there is zero outgoing connection. That's better than everything else.
- deleted 8y ago[deleted]
- vesche 8y agoThe whole point of Firefox _is_ to make network requests. All of the features above aren't leaking your user data or fingerprinting you, they're assisting you in what the applications purpose is... to make network requests. Not to mention firefox is an open-source project, so you could go look at all the network communication it makes when it starts up. All of these options are configurable anyways. I think you're looking in the wrong direction. Try the closed-source (or partial closed source) operating systems you interact with on a daily basis: Windows, Android, macOS, iOS- that's where you'll find the "fingerprinted and tracked every single time you open" sort of thing you speak of. :)
- justinclift 8y ago> The whole point of Firefox _is_ to make network requests. Just to point out, that "the whole point of Firefox" is to make the network requests I want. eg from my perspective it's a tool like (say) cURL that has a specific purpose. It's a subtle difference, but an important one. :)
- deleted 8y ago[deleted]
- eridius 8y agoEvery one of the requests that 43920 listed in a request in service of you, the user. The first is to detect captive portals, which is something you'll find very important if you're behind a captive portal. The second is for OCSP certificate validation, which helps ensure your safety while browsing. The third is checking for updates, which again is for your benefit.
- justinclift 8y agoDon't get me wrong, I do agree with the 2nd two, though I haven't really thought through the first use case. :) I'm mainly just replying to the poster that attempted to say that since Firefox already makes network requests, ~anything should be ok.
- deleted 8y ago[deleted]
- damnyou 8y agoFirefox, like most mass market software, is designed for normal people.
- hombre_fatal 8y agoYeah, portal checking and update checking are surely things 99% of people appreciate. Captive portal popup seems like an obvious UX improvement for 99% of people. I wonder how many people on HN even know how to trigger it if the browser didn't try to do it for you. Update checking and over the air updates make obvious sense to me given that my mother and girlfriend will click "Remind me tomorrow" for years on the macOS update popup, and there's nothing user-friendly about making it so easy for users use old browser versions. The rare user can turn both off if they want, so what's the big deal?
- gpm 8y ago> I wonder how many people on HN even know how to trigger it if the browser didn't try to do it for you. For anyone wondering: Just try and open literally any http page (note: no s). I use groklaw.net.
- admax88q 8y agoThat's getting harder and harder as people add HSTS. There's still neverssl.com, but with the most popular pages using HSTS like Google Facebook and Reddit, captive portal detection is essential for your average user. Although I wish the IETF would make a standard for doing this at the network level as part of DHCP rather than the current ridiculousness we have. Captive portals are just the buggiest shit.
- who_what_why 8y agoHonestly you sound paranoid. What if a dev wants to add instrumentation to make sure a page is loaded? What if you have some weird OS version, CPU, or kernel that might crash 1% of app opens?
- techntoke 8y agoA web page is not an app. It is a sandboxed rendered template that should not be able to crash due to a web page nor care about what OS, CPU or kernel the user is running. If a user wants to give that information away, then they should be prompted.
- detaro 8y agoThe "app" is Firefox, not the web page.
- detaro 8y agoHow often do you open a web browser to then not interact with it? Does it make a meaningful difference if it instead slows down the first request triggered by you to make the captive portal and OCSP checks, and moves the update request to a random time?