12 ms·
The CTO of Mozilla just posted on /r/firefox about this: https://old.reddit.com/r/firefox/comments/1e43w7v/a_word_about_private_attribution_in_firefox/ https:/
by eco 2y ago
The CTO of Mozilla just posted on /r/firefox about this:
https://old.reddit.com/r/firefox/comments/1e43w7v/a_word_about_private_attribution_in_firefox/ https://old.reddit.com/r/firefox/comments/1e43w7v/a_word_abo...
- lopis 2y agoI think this line is very important: > First, in the absence of alternatives, there are enormous economic incentives for advertisers to try to bypass these countermeasures, leading to a perpetual arms race that we may not win. It's very likely that this arms race will lead to DRM in web publications and video feeds (which Google is already experimenting with).
- CalRobert 2y agoI will begrudgingly admit he has a point here. In a few years I imagine almost all sites will refuse to serve anything without WEI, and the "open" web will be the preserve of a few hobbyists. Annoyingly you'll still need to use a compromised browser (or worse, app) to do anything with your bank, etc.
- DaoVeles 2y agoIt will be something like WEI or sites will just be a giant blob served via WebASM.
- deleted 2y ago[deleted]
- xk_id 2y ago> the "open" web will be the preserve of a few hobbyists. And maybe that will be the Web healing. If all the value extraction moves elsewhere, we might finally have a sane web of hypertext documents again.
- setopt 2y agoUnless that is labeled the new darkweb and blocked by the firewalls of ISPs and govs. I hope enough mainstream things remain on the open web for it to be unrealistic to fully block.
- CalRobert 2y agoMaybe, but I suspect it will be more like trying to access Usenet now. I dunno. Considering the balkanization of the web maybe I should get in to ham radio or something.
- JeremyNT 2y agoYes, the kneejerk reaction against FF here isn't really thinking things through. Mozilla has to walk this tight rope since ad companies own the web already. Realistically, the best outcome at this point is that enough users are willing to send enough data to advertisers so they allow the open web to continue. The alternative is that sites will eventually only work in Chrome or Safari on limited, locked down platforms (read: no Linux support at all).
- cynicalsecurity 2y agoDRM on a website = no search engine can scan the website = no users = the DRM website dies.
- deafpolygon 2y agoWhich is why it hasn't rolled out yet. Once this is solved, you bet your ass they will start rolling it out.
- hollow-moe 2y agogoogle is the owner of the DRM verification system, they add exception for google robots, website only appears on google, kills other search engines in the process
- doix 2y agoIf the DRM is coming from Google, I'm sure they'll take that into consideration when designing it. Feels ripe for an anti-trust lawsuit, but IANAL so who knows.
- awesomeMilou 2y agoWith that logic, wouldn't Widevine DRM already be ripe for an antitrust lawsuit? Genuine question.
- doix 2y agoWhen I wrote the comment I was imagining Google using the tech as a moat to stop other search engines from indexing DRM protected content. I guess if they shared it and "all" search engines could index the content, it would probably be fine? I'm guessing that's why Widevine is "fine". But like I said, I'm not a lawyer and have no idea what I'm talking about.
- account42 2y agoIt would be if antitrust regulators were not asleep.
- 2y ago
- rwmj 2y ago> leading to a perpetual arms race that we may not win So we're not even going to try.
- lopis 2y agoThis is an attempt to try. You don't win my being an immovable wall going against the biggest corporations. If the W3C manages to create a system that satisfies advertisers while preserving our privacy, that's how you win. There isn't a future where advertising will just disappear. I'm just being pragmatic here, as a user of ad blockers for 15 years.
- jeltz 2y agoMost advertisers will not be satisfied with that. The real question is if regulators will be and therefore can use this as a reason to clamp down on advertisers. If so this might work, but I am skeptical. And either way it was wrong of Mozilla to sneak this in as opt-out.
- deleted 2y ago[deleted]
- ninjin 2y agoI can see the economic argument, but I am not sure that I buy it. W3C could push this as a standard, but surely anything that is privacy preserving will by its very definition provide less data for advertisement targeting, no? With less data, the targeting is likely to be worse in terms of advertisement efficiency. Thus, the economic incentive even in an ideal situation as with a W3C standard will be pushing any advertiser to "betray" the system and fall back on the very arms race that Mozilla is arguing that they are trying to avoid, no? At best, politicians could jump on the "solution", but then why are Mozilla not already lobbying in that case? Why is the first party they are reaching out to the wolf in this drama? Regardless, Mozilla has lost me at this point as a user. This being opt-out is inexcusable and I will find ways to gravitate away from them as I should not need my poor package maintainers to be paranoid with their upstream code in the same way they have to be with Chrome in order to protect us from developer abuse like this. Will try Mull on mobile now, hopefully it is viable, and see how I solve the desktop situation when I can find the time.
- jillesvangurp 2y agoWhich will lead to counter moves by alterative browsers and websites and Google risking the loss of browser market share. If you think this is unthinkable, just look back at Microsoft's dominance of the browser market twenty years ago. Exactly like Google is doing they were pushing through all sorts of user hostile stuff via internet explorer. Before Chrome came along, Firefox was one of the few holdouts against them. Internet explorer users were dealing with all sorts of crap. Popups, popunders, all sorts of viruses, cross site scripting attacks, etc. Mostly that was just a mix of poorly designed features but there was also MS trying to get into search and advertising and they were trying to abuse their defacto monopoly to do that.
- doctor_eval 2y agoI don’t disagree with you in principle, but this history is not quite right. IIRC the IE6 team was shut down. Basically only Mozilla and Apple were building browsers at scale until Chrome came along. I might be misremembering?
- jillesvangurp 2y agoYes, you are definitely missing a decade here. The internet explorer/edge team was shut down long after Google grabbed most of the market share. Chrome was launched 2008; Safari had its first release in 2003. And I was using the early Phoenix builds (later the name change to Firefox happened) in 2001. The version of internet explorer around the time Chrome launched was v7. IE 6 was already old news by then. And IE 8 launched soon after the Chrome launch. 9, 10, and 11 followed. And then the switch to Edge happened; which was a complete rewrite of their browser engine. Only in 2020, MS announced switching to Chromium. So, that's about 12 years of MS trying to hold on before they finally gave up.
- CalRobert 2y agoHow will an alternative browser get people to use it when major sites all make it impossible to use a non-Chromium browser?
- anordal 2y agoYes, that line is important. This has happened before. Remember the critique against Encrypted Media Extensions (https://en.wikipedia.org/wiki/Encrypted_Media_Extensions https://en.wikipedia.org/wiki/Encrypted_Media_Extensions): Oh no, DRM in the browser! But remember that web video used to require Adobe Flash for the longest time, and even after a decade of HTML5 video, sites were still clinging onto Adobe Flash (and later also Microsoft Silverlight) for what turned out to be DRM purposes. At the time, these plagued proprietary blobs were not going anywhere. Except, after EME had widely supplanted this last holdout usecase, they were quietly allowed to die. The result is that we have much smaller-scoped proprietary blobs in the form of content delivery modules with a lot fewer bugs and portability issues.
- mort96 2y agoThe situation with Flash and Silverlight was better than the situation currently is with EME. Before, you could implement a standard-compliant open source web browser, you just may not be able to view certain non-web embeds. Now, web browsers need permission from Google to view certain kinds of web content, and they can't be open source.
- daveoc64 2y agoI agree with the other commenter. The current situation is worse. EME requires that the browser ship with a DRM library like Widevine. Flash used an industry standard plugin model and could work in any browser.
- mort96 2y agoThis move does not stop the arms race. Non-anonymous data is still better for the ad industry. Why give that up?
- pacifika 2y agoBecause browsers can clamp down on The non-anon data streams when there’s a working alternative.
- mort96 2y agoWait aren't browsers already trying to implement anti-tracking measures? Are you saying Mozilla has been holding back improving anti-tracking for the benefit of advertisers until now? Now that is evil
- marcosdumay 2y ago> Wait aren't browsers already trying to implement anti-tracking measures? Yes, and trackers are investing large sums of money into breaking those measures. If you give advertisers a lawful non-user-threatening way to measure their ads performance, a lot of that money may disappear. (Or it may not, or it may disappear either way. That one market is crazy and I know almost nothing about it. But the claim that the money may disappear is valid, and you have to provide a valid counter-claim if you want to contest it. Calling it evil doesn't cut it.)
- mort96 2y agoBut this is exactly what I wrote that I don't believe in my initial comment. There'll always be more money in more intrusive tracking. Why would they give that up? Surely Mozilla is selling out to advertisers based on something more substantive than "we hope that advertisers won't keep taking a mile if we give an inch"?
- deleted 2y ago[deleted]
- account42 2y agoAnd that DRM will likely come anyway and restric users of niche browsers like Firefox and operatings systems no matter what Mozilla does - just look how EME implementations and Websites using it treat Linux users not to mention non-x86/ARM architectures. So best is to push back now while we still can instead of giving them an inch.
- thinkingemote 2y agoSome might be interested in the discussion about that too https://news.ycombinator.com/item?id=40971247 https://news.ycombinator.com/item?id=40971247
- luke-stanley 2y agoKey comment replying to him there which gets no reply from him: "Opt-out is NOT a consent". This is very problematic, see my last comment: https://news.ycombinator.com/item?id=40966312 https://news.ycombinator.com/item?id=40966312
- close04 2y ago> doing something about [the massive web of surveillance] is a primary reason many of us are at Mozilla > we consider modal consent dialogs to be a user-hostile distraction from better defaults, and do not believe such an experience would have been an improvement here. You know what's user-hostile? Doing things without the user's knowledge or consent. The new tab page of Firefox after an update often advertises features of the release Mozilla sees important (their VPN offering, Firefox on mobile, etc.). This time the new tab page told me nothing about this change. Communicating it to me was "free" and they still actively refused to do it. "Doing something" about surveillance starts with transparency but if Mozilla's leadership doesn't see this as important they have no place leading such a company. Mozilla doesn't seem to wrap its head around the fact that their users use Firefox because they don't want the same kind of shady tactics Google or Microsoft keep pulling, they don't want their browser control to be handed over to some guy in a board room who needs a PR team to give a lengthy non-answer to the problem. I see a lot of words spent on why they came up with this technology but barely a mention about the biggest issue here especially from a company that presents itself as a champion of user rights: they pushed the change in the dead of night and took an actively hostile decision in the users' names by enabling a clearly controversial setting without any warning or communication. > we should have communicated more on this one This kind of PR speak for "we actively kept it hidden" is the best way to alienate the users who investigated and chose this browser for a reason.
- DaoVeles 2y agoThats just it, that they are doing this in a somewhat quiet manner is a sign that they know how this would go down.
- deleted 2y ago[deleted]
- worble 2y agoInteresting comment here: https://old.reddit.com/r/firefox/comments/1e43w7v/a_word_about_private_attribution_in_firefox/lddbeqh/ https://old.reddit.com/r/firefox/comments/1e43w7v/a_word_abo... If you have telemetry disabled, this feature is also disabled, even though that isn't represented in the UI and looks like it's turned on. It's not good that it exists and is on by default, but if you have already opted out of telemetry previously, you're opted out of this too.
- dist-epoch 2y agoTL;DR: sorry, we're not sorry. we will go ahead with it and explain it to you better why it's a good thing in your interest.
- BoredPositron 2y agoOh my... not exactly reassuring.
- tgv 2y agoThis phrase in particular: > I’ll do my best to address [your questions], though I’ve got a busy week so it might take me a bit. That means: I'll answer the easy ones, and ignore the hard ones, or ask the legal team to come up with some weasel words.
- nubinetwork 2y agoAnd nothing of value was posted.
- lukan 2y ago"The devil is in the details, and not everything that claims to be privacy-preserving actually is" Yeah, like Mozilla. This is not the first time they silently added tracking and avertisement. The toggle with "firefox shares basic telemetry with the adcompany Adjust" has been there activated by default since a while (among other stuff). This is just more tracking from them, while claiming to defend privacy. Another day, another scandal.
- latexr 2y ago> It’s clear in retrospect that we should have communicated more on this one What isn’t clear, in retrospect or otherwise, is why companies/apps/services need to keep learning this lesson. The user outcry was utterly predictable from even before the first web article was out. The fact that no one with decision power at Mozilla saw it coming is worrying: either they have zero understanding of people’s concerns for privacy or they don’t care. Neither is good.
- jeltz 2y agoEspecially since this is very similar to what happened with Cliqz and that there likely are many at Mozilla who were around when that happened too. And the Cliqz scandal hurt Mozilla's market share a lot in Germany.
- Klonoar 2y ago> The fact that no one with decision power at Mozilla saw it coming is worrying: either they have zero understanding of people’s concerns for privacy or they don’t care. Or the third option: they feel the tradeoff of HN & co's criticism style is not a big deal in the end. Criticism of Mozilla in general is very warranted right now, but the way(s) in which everyone is doing so just feels very out of touch with the actual situation. ;P They're - by their own words - trying to do something in a privacy preserving way because the ad industry is not going away. They might fuck it up at first, and that's why it's an experiment. It's also possible to disable it, it's not like you're trapped in it. This thread in general feels like it leaves Mozilla no room to experiment or find any form of growth. People want them to be "just a browser" but then also expect them to be stewards of the web - and then cry foul when they actually try to find a setup that fits into the current model of the web.
- pdimitar 2y ago> It's also possible to disable it, it's not like you're trapped in it. Or so they say, in order to make people be OK with it. They might play the waiting game and in a year or two will make the setting not do anything and still collect / send data, hoping that by that time people have forgotten.
- qwertox 2y ago> Most users just accept the defaults they’re given, and framing the issue as one of individual responsibility is a great way to mollify savvy users while ensuring that most peoples’ privacy remains compromised. Cookie banners are a good example of where this thinking ends up. The problem we currently have with cookie banners is thanks to the browser vendors not caring about it. An API could exist which a page can query, where the user has already pre-selected how they want to deal with cookies. For example reject all but the essential ones, reject none at all, reject some, according to certain criteria. Even more, the browser could check if the page is adhering to the user's expectations, and if it doesn't, block it for a period of time, like a week or a month, and publish the fact that they ignored the user's wishes. Possibly also give the user a signed document which claims that this page did not respect the user's privacy expectations, so that the user can use it in court. These should be solvable problems.
- cqqxo4zV46cp 2y agoWhat!? What’s the benefit of this from a site’s POV? Your technical solution is completely out of touch with real goals and incentives.
- qwertox 2y agoHe's talking about cookie banners. The issue with cookie banners are the dark patterns, but the end-goal is to obtain permission from the user to set cookies. This requirement to constantly ask the user while using these dark patterns is what makes normal people just give up and "accept". If the page is expected to ask the browser which preferences the user has set regarding the cookies, then this problem is gone, because the page no longer is expected to ask a person via a popup.
- remedan 2y agoThis was already tried with the Do Not Track header. Websites simply ignore it. They don't want an easy way to get the user's preference. Because they know that most users would set it to decline tracking. Sites would rather annoy every visitor for the chance that they click 'accept'.
- htiawe 2y agoWow, that really was a wall of text. Is it just me that sometimes get the feeling that when companies have to explain them selves with this amoubt of text, they actually know that they are doing something wrong but are trying to cover it up by these long and unnecessary explanations?
- pndy 2y ago> they are doing something wrong but are trying to cover it up That's what most of folks says in this sub-tree
- deskr 2y agoFirst there's a justification based on current anti-tracking system being bypassed: > "there are enormous economic incentives for advertisers to try to bypass these countermeasures" Then: > We’ve been collaborating with Meta on this Given Meta's track record with scooping up just about any personal data they can find, it's pretty obvious that this is just going to be yet another datapoint in Meta's collection.
- robertlagrant 2y agoI imagine Meta like this because most of their tracking is done behind a Facebook login anyway, and it reduces the fidelity of Google ads.
- Juliate 2y agoWhat is really concerning (and enlightening) is that it is the CTO that's posting, and not the CEO. It shows that the topic is merely now considered as a technical point, rather than a principal-based one.
- justinclift 2y agoThe Mozilla CEO would be very unlikely to receive a positive reception.
- JoosToopit 2y agoThat's just the most brain dead rot I've read in a while. Mozilla is a joke nowadays.
- Retr0id 2y agoWow. This represents a profound misunderstanding of the advertising industry. Data is their edge. It's how they compete with each other. The privacy "arms race" isn't just between the browser vendors and the trackers, it's also between tracker a and tracker b. Giving them a new data point (no matter how """privacy preserving""" it is) is just that, another data point. It's not going to make them give up on the others.
- raxxorraxor 2y agoTo be honest, I would have used a different approach and browsers would very well be capable to give erroneous data and contaminate data from tracking users. This would be going on the offensive, and I don't believe there are any legal barriers that prevent users from "ad fraud". I don't believe in cooperation with an industry that has shown no remorse with tracking users at all. That will not be successful. Advertisers will employ this and still track. And it is possible to not get tracked and deliver false data, even today.
- AlexandrB 2y agoMaybe I'm cynical, but the rationale given seems extremely naive. There's nothing stopping advertisers from using this new attribution mechanism and tracking users as much as possible. In fact that's probably exactly what they'll do since it's likely that not every browser will support this kind of attribution. The arms race will continue as it does today, but advertisers will have yet another avenue to exploit in the form of the attribution API.
- Zefiroj 2y agoIt shows that their interest is in a "sustainable ad-driven economy model with privacy deemed acceptable by Mozilla", and an "agent of the user". I suppose it shows who's paying Mozilla.