12 ms·
When it comes to privacy, default settings matter
- Tepix 7y agoThis step is overdue and i applaud Mozilla for doing it. But: Why doesn‘t Firefox block all 3rd party cookies by default? That would be a huge win for privacy. Yes, some sites would break. But if Apple can do it with Safari, Mozilla can do it with Firefox. Be brave! Do it!
- ignoranceprior 7y ago[comment retracted]
- Tepix 7y agoIt‘s just cookies recognized to be tracking cookies, isn‘t it? These companies are earning money by tracking you. They have a strong incentive to bypass these mechanisms.
- ignoranceprior 7y agoOh, hmm, it looks like you're right ("known third party trackers"). That's what I get for headline reading.
- lucb1e 7y ago(Maybe put "Edit:" in your message, for a minute I thought this was your reply, implying that the parent comment should retract their statement or something, but given the replies to your comment, I'm guessing you want to indicate that you changed your mind.)
- folkrav 7y agoI get what you mean and yes, it would definitely be a good move in terms of showing the way to sane defaults, however I would have a hard time calling it a "huge win" considering Firefox + Safari make up <20% market share. Maybe I'm just being cynical.
- deleted 7y ago[deleted]
- Tepix 7y agoWell, i guess i meant a huge win for Firefox users who use default settings.
- folkrav 7y agoSeems like they're in for a treat then : https://www.bloomberg.com/news/articles/2019-06-04/firefox-follows-apple-in-blocking-third-party-cookies-online https://www.bloomberg.com/news/articles/2019-06-04/firefox-f...
- discreditable 7y agoAs of right now their UI to allow third-party cookies is pretty bad. Chrome shows an icon in the address bar for it. In Nightly there is a section in tracking prevention, but it's not in normal Firefox yet.
- dvfjsdhgfv 7y agoWell, there is a real danger the web would split into two groups: those who care about privacy and use Firefox - so are a threat to several business models that are en vogue in SV right now, and those who use Chrome and are therefore better candidates for milking. Website owners would do everything to discourage people from using their websites with Firefox. Instead of seeing your favorite website in Firefox, you would see "Welcome to Oath family" or similar bullshit.
- gregknicholson 7y agos/Firefox/Europe/g and this is already happening. I suspect we're just training people to click the Whatever button. As that's most “normal” people's response (I am not normal), the courts will eventually rule that a first-use roadblock doesn't produce informed consent, so doesn't excuse you under the GDPR. Hopefully, then, websites will stop performing a superficial impression of caring about privacy. (Explicit informed consent is the GDPR's last-resort excuse, which you only need if your use of personal data falls outside all of the GDPR's automatically-acceptable justifications for using and storing personal data.)
- cpeterso 7y ago> Yes, some sites would break. But if Apple can do it with Safari, Mozilla can do it with Firefox. Safari has enough market share that web developers must work within Apple's guidelines if they want their websites to work on iOS.
- SamuelAdams 7y agoPlus users do not have an alternative, at least on iOS. They all pass through webkit. On a desktop, if Firefox breaks, people will just switch to Chrome or something else. Plenty of people want things to "just work" out of the box. Maybe the better solution is to have a guided install process. When installing firefox, ask the user if they want it to "just work" or be "privacy conscious"? Warn them of the tradeoffs of both and let them decide once.
- user17843 7y agoGood question. It would have made everything so much easier. How much work was done on this selective cookie blocking implementation? Personally I always hoped they would simply copy Privacy Badger and develop an algorithm, instead of relying on a black list.
- yholio 7y agoI strongly agree. There is no legitimate functionality that can't be implemented without 3rd party cookies. Some sites will break at first until they are fixed, and we could have a whitelist for a while, while making it very cumbersome to be added to that list. New sites would simply need to workaround the lack of 3rd party cookies and accept that user tracking is technically illegal. The surveillance internet is something that was allowed to evolve by a lack of foresight from the standard authors in their desire to build a rich web. We should put an end to it as soon as possible. The browser should not leak unique identifiers in any situation and all standard browsers should be as finger-print resistant as the Tor Browser. In my view, if you leak data that is critical to the privacy of the user, it's as bad if not worse than an improper implementation of TLS. It takes only two, modestly skilled, collaborating webadmins (one site "shameful" and one used with authentication) to possibly destroy a person's life, reputation and family. A practical attack on SSL2.0 is orders of magnitude more difficult. Let's put responsibility for privacy back where it should be: on the browsers and web standard authors.
- svieira 7y agoI'm genuinely curious about your assertion. Let's say I have an application for my business and I want to embedded a report on one of my pages from a separate application. This other application is a SaaS application, so I can't just "mount" it at mydomain/some-sub-path. How do I have secure reports without third-party cookies? Store cookie-like stateless tokens in my wrapping app and send them in the URL?
- a1369209993 7y agoAssuming I'm understanding your question correctly, yes, you would have something like: <iframe src="https://saasapp.com/report?url= https://mydomain.com/data/1234.json%3F v%3D42%26auth%3D__79_Pv6-fj39vX08_Lx8A++"/> (spaces added for readability)
- tetraca 7y agoCool, if third party tracking cookies are "defeated", this will be the next step in the arms race.
- ianbicking 7y agoWhen sites break, people leave Firefox. No amount of explaining or media changes that: the number one (by far) reason people leave a browser is because a site is broken.
- smacktoward 7y agoYes, this. Anyone who was around for the launch of Windows Vista could see this effect in action. Vista's added security measures like UAC (https://en.wikipedia.org/wiki/User_Account_Control https://en.wikipedia.org/wiki/User_Account_Control) broke a lot of poorly coded Windows applications that didn't bother to follow the rules of the platform. Who did the users blame when those apps broke? Microsoft. Why? "It worked fine until I upgraded to Vista!" Sigh.
- fwip 7y agoFurther evidence: Windows 7 wasn't even that much of a change from Vista. The main differences were 1) software had adjusted to deal with UAC and 2) new laptops were more powerful. But most of the good new architectural features had premiered with Vista. I think they did improve the UAC situation with Vista SP1, if memory serves.
- autoexec 7y agoMS changed UAC for windows 7 so much in an effort to stop annoying window's users that people complained that defeated the point https://www.networkworld.com/article/2253987/microsoft--neutered--uac-in-windows-7--says-researcher.html https://www.networkworld.com/article/2253987/microsoft--neut...
- TazeTSchnitzel 7y agoThe main UAC change in Windows 7 was just that it didn't pop up for changing of settings. But UAC on settings wasn't the problem (in fact, macOS basically has this and it's a non-issue), UAC on legacy Windows apps only tested on Windows 9x or on administrator accounts on NT systems was.
- bzbarsky 7y agoSafari does not block all 3rd party cookies by default last I checked. It does something a lot more complicated that still allows 3rd party cookies in various cases.
- shirefaux 7y agoMozilla is always the after-child of chrome, it's cute that they're trying, but no sane person would use Firefox if they're not a masochist really
- shirefaux 7y agoYeah the Mozilla organization is a piece of shit since Jamie Zawinski, JWZ, cashed out. #lesszilla
- rolph 7y ago"Today marks an important milestone in the history of Firefox and the web. As of today, for NEW USERS who download and install Firefox for the FIRST TIME, Enhanced Tracking Protection will automatically be set on by default, protecting our users from the pervasive tracking and collection of personal data by ad networks and tech companies." this gives me the impression that Mozilla is trying to pull in a bunch of new recruits, also does this mean upgrades or repetitive DLs will not have this ~privacy by default?
- ellard 7y agoProbably. This is generally the correct way to handle an upgrade while minimizing breaking changes to the user. Changing a user's settings during an upgrade will erode users' trust in doing so in the future, even if it's "good" for them.
- Rusky 7y agoThe article covers this, they have further plans for existing installs.
- pbhjpbhj 7y agoSo they're killing the Google relationship? I mean something called "Enhanced Tracking Protection" would have to disable any sending of data to Google (or anyone, except the server as required to get the data requested), surely?!?
- roca 7y agoGoogle might not be happy about this move, but historically Google has paid Mozilla to be the default search engine in Firefox, which doesn't require Firefox sending any data to Google (apart from actual search queries, obviously).
- shirefaux 7y agoI'd eat Jamie Zawinski's tricks every day but I would never use Firefox.
- basscomm 7y ago> In fact, nearly 25% of web page loads in Firefox take place in a Private Browsing window. If Mozilla knows that, then Private Browsing Mode isn't as private as it could be.
- cremp 7y agoIt seems you're being downvoted just because it's negative against Firefox. I don't know what it is about the HN community, but knowing that figure throws out any argument for using Firefox as a daily driver. Change my mind.
- Wowfunhappy 7y agoI'm not particularly bothered by the idea that Firefox can see how often private browsing is used. If you don't know what features people use, you can't prioritize development resources. Mozilla doesn't know who is using private browsing, or what they are looking at. I can certainly respect that it bothers you—but may I ask what browser you intend to switch to? I'm skeptical that you'll find a better, usable option. That's a sad state of affairs for sure, but also the way of things right now.
- oneofthem 7y agoWhat if the numbers are based on opt-ins only, and extrapolated?
- la_barba 7y agoCan you explain how you know that Firefox collects the data versus just asking people in a survey?
- nsuser3 7y agoThe total amount of loaded pages in Private Browsing doesn't really have to be private?
- sp332 7y agoAs long as the data is aggregated and not tied to individual users, I'm ok with it.
- stemuk 7y agoWhen it comes to the greater public, default settings might as well be the only available setting. Apart from a few 'techies' most people will never even touch the default settings out of the naive belief that "the default setting is what's best for me". As an alternative approach I would suggest empty settings to begin with, forcing the user to think about their preferences on first use.
- selebrazin 7y agoThat would only work if every browser implemented it but for the average user, choosing between a blank-slate approach where they have to parse through terminology they don't understand, and an alternative offering "sensible" defaults, I suspect most users would just pick the easier latter option.
- mikro2nd 7y agoPerhaps there's a middle ground. Give users a range of options (say 3 to 5) that aggregate the settings, ranging from "I don't really care about privacy" to "I wear a tinfoil hat to bed", along with pointers to where and how they might wish to delve deeper into more detailed settings. It can't be that hard...?
- slavik81 7y agoIf you put a big scary decision as the first thing users see, many will just close the browser because they don't know what they should pick. When they open a different browser that doesn't present them with that choice, they may conclude that it's not a problem on that other browser.
- AsusFan 7y agoThe irony is strong with this one. By default, Firefox: - Collects a bunch of telemetry data via several mechanisms and ships them to Mozilla HQ - Provides Mozilla with remote code execution privileges on your machine via the shield (or normandy, or whatever they are calling it these days) mechanism, which can install and uninstall extensions and certificates, change browser settings, etc - Uses Google as the default search engine, and search suggestions leak private data to Google - Uses Google Location Services for their geolocation thingy, which - unsurprisingly - phones home to Google - Ships closed source third party add-ons - Comes with a bunch of "about:config" settings configured in sub-optimal ways, privacy wise - battery API enabled by default, accept all cookies by default and so on Sure, Chrome is worse, but bringing that up that is like arguing that your pile of manure is better because it doesn't smell as bad: in the end, you are still arguing about shit.
- wnevets 7y ago>- Uses Google as the default search engine, and search suggestions leak private data to Google Doesn't apple do the same thing?
- xvector 7y agoApple is not the one making a blog post about privacy-centric defaults.
- wnevets 7y agoThere's literally an article on the front page talking about how Apple is really a privacy as a service company based on all of their marketing talking points about privacy.
- xvector 7y agoStill, Apple did not make a blog post about sane defaults. Mozilla did. Apple is completely besides the discussion here.
- sciurus 7y agoThere's some discussion of how this ties into Mozilla's mission at https://blog.mozilla.org/blog/2019/06/04/the-web-the-world-needs-can-be-ours-again-if-we-want-it/ https://blog.mozilla.org/blog/2019/06/04/the-web-the-world-n...
- dantiberian 7y agoMozilla didn't mention this in the article, but the study they referenced had an astounding statistic proving their point about default settings. > Chrome and Safari are the two most prevalent browsers in our data, with Chrome being associated to about 43% of the ad transactions and Safari to about 38%. About 73% of the ads shown on a Safari browser do not have a cookie associated, whereas on Chrome this is the case about 17% of the time. > The difference is probably due to different default tracking settings across the two browsers, with Safari impeding, by default, third-party tracking cookies being set on the user’s machine (the user has to explicitly allow the usage of third-party cookies) https://weis2019.econinfosec.org/wp-content/uploads/sites/6/2019/05/WEIS_2019_paper_38.pdf https://weis2019.econinfosec.org/wp-content/uploads/sites/6/...
- blitmap 7y agoThe thing that absolutely pisses me off is how I try to be actively aware of what settings I disagree with and disable things I don't like - and then an unseen update resets things to default. HOW MANY TIMES MUST I UNCHECK WHAT TO SYNC TO MY ACCOUNT? YOU WOULD THINK THAT IS SAVED PERSISTENTLY. I think my qualify of life on Firefox would be improved greatly if a notice popped up saying some of my settings were reset to defaults because of breaking changes (or minor). Like they give a crap.
- nullandvoid 7y agoNot sure why the down votes that would sure piss me off. I'm very conscious of what I want synced and it only takes a single bug like that to throw away all the effort to keep things separated
- TAForObvReasons 7y agoDownvotes are coming from the Mozilla defenders on HN, of which there are many. Many valid criticisms of Mozilla or Firefox's practices are frequently downvoted hard and flagged, which is truly unfortunate
- setr 7y agoPerhaps you disabled settings sync ;)
- baroffoos 7y agoThis is a slightly difficult problem but it has been solved in other places. When I update my computer with linux sometimes I will get a message saying that upstream has changed a config file that I have also modified and it asks if I want to keep my version, keep upstreams version or open it in an editor.
- Despegar 7y agoI'm amused by this because when I called Mozilla out a few days ago, I got a bunch of downvotes [1]. Plus one of the top comments was a subtweet of mine. [1] https://news.ycombinator.com/item?id=20055322 https://news.ycombinator.com/item?id=20055322
- craftyguy 7y ago> Please don't comment about the voting on comments. It never does any good, and it makes boring reading. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- lotu 7y agoWARNING advertising SWE insider I don't like how the opening line of article exploits the fact the average person does not know cost of average online ad to make it appear like tracking has basically no value. >... data about you was transmitted to dozens or even hundreds of companies, all so that the website could earn an additional $0.00008 per ad. For the reader to be able to accurately understand how much money this is they need to know the percentages. Very roughly (this varies widely based on the country and websitem) the average online ad only costs ~$0.0005, so that insignificant $0.00008 is around 10-20%. If the article had presented the exact same information but instead framed it in the form of revenue available to pay employees at an online company dependent on advertising, this would sound very different while really conveying the same concept. Edit: I read the linked study and the data they used had an average cost per add of $0.001 putting the difference around 4%. This is smaller than I would have predicted. I would still rather they have lead with this number.
- zbraniecki 7y agoMy personal problem with the model is not how much they make, but rather the intentionally hidden relationship they develop with the user. If the relationship is - you get the article, we get to show you an ad that gives us a chance to sell you something and make money on it, which is ~$0.00008 - that would be clear. Even if the relationship was - you get the article, we get the above plus we'll collect some bits of information about you that we explicitly list. The ad itself will give us ~$0.00008, and the collected data another ~$0.000007 - that would be ethical imho. But the real model is - we give you an article, and in return you sign a blank document that allows us to collect all the possible data and try to maximize the amount of money we can make on it. You step into it today, but we are not comfortable putting any price point on this agreement because we bank on the idea that in the future we'll make more as we increase our grip over understanding of user behavior and improve our ability to monetize it in any, potentially unethical way. The reason companies hide the nature of the relationship is because their business models are built around the assumption that the data collection will generate increasing amount of revenue in the future. And since there's no way for you to understand the relationship, or step out of it, you're entering it with information disadvantage, and there's no turning back. I hope you can see how this approach is by design hostile to users and the Internet as a public plane.
- cromwellian 7y ago[Googler, but this is just my own musing] Here's a theoretical question, if all third party tracking cookies were blocked, wouldn't that strengthen Google's position in the ad market and weaken all of the third party ad networks? Google gets most of it's revenue (~70%) from it's first party sites, and stuff like AdSense could be made to work without cookies, and given Google's size in the market, people would switch to whatever ad embedding format they required. But smaller ad networks won't have that power, and don't have huge first party sites either. So in a way, if Google jumps onboard this bandwagon in Chrome, they could be accused of doing it to strengthen their own position, the same way adopting Apple's extension/ad blocking restrictions in Chrome, led people to accuse them they're trying to sabotage ad blockers, instead of trying to reign in a toxic hell stew malware from overly permissive extensions.
- scarface74 7y agoI am not a Googler and have been a long time critic of any business model that is not “I give you money and you give me stuff.” That being said, I defended Google’s choice of implementing ad blocking extensions using an approach similar to Apple’s because I inherently don’t trust random third party extension makers that can intercept all of my web browsing. I also don’t trust VPN providers to protect my privacy but that’s a rant for another day.
- jchw 7y agoI generally agree, though I do trust uBlock Origin with the coveted webrequest blocking API. It has some pretty powerful features that I don’t think could be implemented otherwise, block list limitations aside. I kind of hope Firefox does not get rid of the webrequest blocking API for that reason alone. (Usual disclaimer: Googler here, opinions are my own.)
- deleted 7y ago[deleted]
- sbov 7y agoI don't trust random third party extension makers either. That's why I don't go around randomly installing extensions.
- anordal 7y agoWhen it comes to everything, default settings matter.