7 ms·
I don't really know Vivaldi. They mention that they do not track you, but do they make some effort to avoid being tracked by others? For example: firefox reduc
by kuu 5y ago
I don't really know Vivaldi. They mention that they do not track you, but do they make some effort to avoid being tracked by others?
For example: firefox reduces the timestamp precision on your mouse events to prevent fingerprinting
Does Vivaldi do something similar?
- hulitu 5y ago> For example: firefox reduces the timestamp precision on your mouse events to prevent fingerprinting ... while sending all URLs you visit to google for "safe browsing".
- matsemann 5y agoDon't spread FUD.
- 1cvmask 5y agoI always find it funny when they accuse people who point out glaring flaws and obvious truths of whataboutism. People should freely point out incongruences and hypocrisy. There is no better way to fix things, or at least to be buyer aware.
- jmnicolas 5y agoDoes it happen even if Google isn't the default search engine? If yes, where do I disable it? Depending on your answer, this might be the last straw in my relationship with FF.
- jfk13 5y agoI don't believe the claim was at all accurate; see the other responses about how Safe Browsing works.
- judofyr 5y agoI thought that they downloaded the list and checked locally (ref https://feeding.cloud.geek.nz/posts/how-safe-browsing-works-in-firefox/ https://feeding.cloud.geek.nz/posts/how-safe-browsing-works-...). Has this been changed recently?
- abbe98 5y agoFirefox fetches URLs hashes from Google and then checks the URLs you visit against that list. Only if there is a match Firefox will send the hash(not the URL) to Google to verify that there isn't a hash conflict.
- EastOfTruth 5y agoI disable that feature even though I don't think that they send every URLs for this purpose.
- jmnicolas 5y agoIt's kind of gray: Privacy One of the most persistent misunderstandings about Safe Browsing is the idea that the browser needs to send all visited URLs to Google in order to verify whether or not they are safe. While this was an option in version 1 of the Safe Browsing protocol (as disclosed in their privacy policy at the time), support for this "enhanced mode" was removed in Firefox 3 and the version 1 server was decommissioned in late 2011 in favor of version 2 of the Safe Browsing API which doesn't offer this type of real-time lookup. Google explicitly states that the information collected as part of operating the Safe Browsing service "is only used to flag malicious activity and is never used anywhere else at Google" and that "Safe Browsing requests won't be associated with your Google Account". In addition, Firefox adds a few privacy protections: Query string parameters are stripped from URLs we check as part of the download protection feature. Cookies set by the Safe Browsing servers to protect the service from abuse are stored in a separate cookie jar so that they are not mixed with regular browsing/session cookies. When requesting complete hashes for a 32-bit prefix, Firefox throws in a number of extra "noise" entries to obfuscate the original URL further. On balance, we believe that most users will want to keep Safe Browsing enabled, but we also make it easy for users with particular needs to turn it off.
- bogwog 5y agoSo basically, it does send your URLs to Google. Maybe not all of them, but an unspecified amount of them. Also, Google pinky promises that the data they collect from this isn't used for tracking purposes.
- jfk13 5y ago> So basically, it does send your URLs to Google No, it downloads hashes from Google, and checks the URL locally against those. See https://feeding.cloud.geek.nz/posts/how-safe-browsing-works-in-firefox/ https://feeding.cloud.geek.nz/posts/how-safe-browsing-works-...
- bogwog 5y agoThanks for the link, that explains it much better than the snippet in the post I replied to. It seems like it actually is way more private than I thought. FF downloads the database of flagged sites from Google and stores it locally (only partial hashes of URLs though). Only when a match is detected in the local database, FF sends the full hash of the URL to Google to double check, since the local database only has partial hashes to save space (so false positives are likely). It also apparently sends extra noise as part of the payload, so that the request isn't obviously tied to a single URL (in case Google is able to reverse the hash to track your browsing habits, or something like that) That sounds pretty private to me. A side-by-side comparison of this implementation to the one in Chromium would be interesting. I wonder if browsers like Vivaldi go the extra mile like FF does? (not: that post is over 5 years old, so it's possible that the implementation may have changed since then)
- Shadonototra 5y agoI don't know but firefox sends what ever you type in your address bar to mozilla, that is concerning
- yoasif_ 5y agoNot really true - you can see my post for details https://www.quippd.com/writing/2021/10/10/firefox-suggest-an-anatomy.html#the-good-news https://www.quippd.com/writing/2021/10/10/firefox-suggest-an...
- mcintyre1994 5y agoYep, they have built in ad and tracking protection enabled by default.
- lmkg 5y agoVivaldi is pretty pro-privacy. Every time Chromium adds a new API with privacy implications, Vivaldi makes a blog post publicly committing to disable or remove it from the version they ship. E.g. the most recent update, the headline feature is disabling the Idle API by default: https://vivaldi.com/blog/vivaldi-gets-more-private-delivers-an-all-new-capture-pwa-support/ https://vivaldi.com/blog/vivaldi-gets-more-private-delivers-... They also had a pretty long post about why FLOC is bad, and I believe have committed to retaining Manifest v2 for extensions. Other prominent privacy or privacy-adjacent features include a built-in ad-blocker and heavy investment into on-device translation features. I'm not sure how much work they put into preventing fingerprinting techniques. I don't get the sense it's a high priority.
- merlinscholz 5y agoSadly, as long as they are closed source, there is no way to check their privacy guarantee.
- Ndymium 5y agoYou can find the source at https://vivaldi.com/source/ https://vivaldi.com/source/ and in addition to that is the HTML/JS UI which can be found in the installed browser data (though as minified JS files).