10 ms·
Have been using Firefox for a long time, no issues, though long ago when I had little memory, Chrome was using less of it. Firefox also has HTTPS-only mode, enc
by codedokode 2y ago
Have been using Firefox for a long time, no issues, though long ago when I had little memory, Chrome was using less of it. Firefox also has HTTPS-only mode, encrypted DNS without fallbacks, supports SOCKS and Encrypted Client Hello (although almost no website support it). However, it is better to just buy more memory (unless you are lucky to use Apple products).
Regarding analytics, I believe browsers should take user's side and do not cooperate with marketing companies; even better, they should implement measures to make user tracking and fingerprinting more difficult. There is no need to track user's browsing history; just make a product better than competitors (so that it gets first place in reviews and comparisons) and buy ads from influencers.
It would be great if browsers made fingerprinting more difficult, i.e.: not allowed to read canvas data, not allowed to read GPU name, enumerate audio cards, probe for installed extensions etc. Every new web API should guarantee that it doesn't provide more fingerprinting data or hides the data behind a permission.
Regarding 3rd party cookies: instead of shady lists like RWS browsers should just add a button that allows 3rd party cookies as an exception on a legacy website relying on them (which is probably not very secure). Although, there is a risk that newspaper websites, blog websites and question-answers websites will force users to press the button to see the content.
- lcnPylGDnU4H9OF 2y ago> Every new web API should guarantee that it doesn't provide more fingerprinting data or hides the data behind a permission. FWIW, it's practically impossible to provide that guarantee because the API necessarily provides at least the data point of, "Did they select an option in the permission notification?" ("If yes, what option was selected?" etc.) It's often said that the only solution to this is regulation and there seems to be a good case for that perspective.
- XlA5vEKsMISoIln 2y ago> API necessarily provides at least the data point of, "Did they select an option in the permission notification?" If a bird app (or, heck, pancake recipe site) asked for WebRTC or GPU access I would be rightfully suspicious. It's a shame these things don't happen.
- chgs 2y agoThey do ask for location data, and it tends to mostly work - sites like openstreetmap will ask for it when you press the right button for example, which makes sense. There is a risk that it ends up like cookie banners, and the adtech industry manages to brainwash the world into thinking that the government is the bad guy and they just want some harmless data to share with their 1,345 best friends and they are “forced” to show these. Despite there being no requirement at all to track data, and they break the law with it anyway so why bother.
- USiBqidmOOkAqRb 2y agoThis is a poorly explored avenue. I think a lot of these more advanced APIs ought to be permitted to "installed" PWAs. Maybe it could even look like permissions menu for apps in phone OSes. I was a bit dismayed when mozillians in the bugtracker dismissed the idea of requiring consent to initialize WebRTC. F'k it, scan the local network.
- SpaghettiCthulu 2y ago> FWIW, it's practically impossible to provide that guarantee because the API necessarily provides at least the data point of, "Did they select an option in the permission notification?" ("If yes, what option was selected?" etc.) Wrong. The status of permissions should not be visible to the page in most cases. Instead, fake data should be returned from them. That would be practical.
- paulryanrogers 2y agoI've heard that fake data, like from AdNausium, just becomes noise as the advertisers know the patterns to filter them out. Assuming that's true, it seems to waste everyone's time and bits to fake it instead of just not answering or a minimal denial.
- autoexec 2y ago> I've heard that fake data, like from AdNausium, just becomes noise as the advertisers know the patterns to filter them out. It's actually much worse. That fake data is dangerous because data brokers don't really care how accurate their data is. Even the fake data AdNausium stuffs into your dossier will be used against you eventually, just like the real data will be. If you get turned down for a job, or your health insurance rates go up, or you have to pay more for something than you would have otherwise, you won't even be told that it was because of data someone collected/sold/bought. You sure won't be told if it was fake or real data and you won't be given any opportunity to correct it.
- thescriptkiddie 2y agoOne solution to this is to have the option to feed the application fake but plausible data. Android (or maybe some Android fork I was using) used to have this option for dealing with apps that insist on asking for location permission for no reason.
- codedokode 2y ago> FWIW, it's practically impossible to provide that guarantee because the API necessarily provides at least the data point of, "Did they select an option in the permission notification?" ("If yes, what option was selected?" etc.) If 99% of users will have permission disabled then it has little value, and only those who enabled it can be tracked. I don't give permissions to sites so this will not apply to me. Also, the status of permission (1 bit) provides less information than API it protects (for example, list of installed fonts or GPU name) so it is a win.
- pndy 2y ago> Regarding analytics, I believe browsers should take user's side and do not cooperate with marketing companies https://news.ycombinator.com/item?id=40703546 https://news.ycombinator.com/item?id=40703546 - from 2 months ago
- noirscape 2y agohttps://news.ycombinator.com/item?id=40966312 https://news.ycombinator.com/item?id=40966312 - 20 days ago. In light of that acquisition, this also seems related. Firefox is the best choice but Mozilla is the biggest reason why people aren't using it and shit like this doesn't help.
- nine_k 2y agoBTW I don't understand the anti-tracking absolutism. I don't care about being profiled as long as the profile lands me in a group of thousands of people like me. Yes, I live in ${CITY}, identify as ${GEDNER}, am approximately ${AGE_RANGE} years old, run ${BROWSER} under set to ${LOCALE}. This does not allow to easily harm me. If it allows ad networks to target their ads, so be it, uBlock Origin still works well. But anything more precise would be uncomfortable.
- mbb70 2y agoHow do you feel about ${INCOME}, ${SEXUAL_PREFERENCE}, ${RACE}, ${WEIGHT}, ${RELIGION}? Those categories are at least as broad as the ones you mentioned and are absolutely profiled.
- nine_k 2y agoFine enough, if the ranges for each value are wide enough. Compare: - $120-140k, hetero, white, 190-220 lb, broadly Christian. - $137,500/y, prefers tall redhead females, Irishman originally from Cork, 197 lb, observant Catholic. The first one is too unspecific, while the second could suffice to identify a particular person in a neighborhood. What makes a butter knife safe is not that it's completely devoid of an edge, but that its edge is sufficiently blunt.
- deleted 2y ago[deleted]
- throwaway937474 2y agoNow substitute the first one for "gay", and you might get a death sentence in several parts of the world. Why does almost nobody on this site thinks about the wider world bedsides their own extremely privileged position? I would very much prefer for advertisers to not even be able to determine my city, for personal safety. Throwaway account for obvious reasons.
- nine_k 2y ago
- factormeta 2y ago>It would be great if browsers made fingerprinting more difficult, i.e.: not allowed to read canvas data, not allowed to read GPU name, enumerate audio cards, probe for installed extensions etc. Every new web API should guarantee that it doesn't provide more fingerprinting data or hides the data behind a permission. This should be what browser maker's #1 focus! Preventing fingerprinting of user's browser. Seems all this cookies talk the news and for policy makers are just limited hangouts.
- autoexec 2y ago> Regarding analytics, I believe browsers should take user's side and do not cooperate with marketing companies Browsers were supposed to act as agents working for the user. User-agents. These days it's getting harder and harder to find a browser that doesn't work for an ad company at the expense of the user. Chrome's entire reason for existing is data collection. Firefox can, for now at least, be hardened to work for the user (and prevent a lot of fingerprinting), but Mozilla is an ad-tech company too now. They've made their lack of respect for Firefox users clear by making Firefox spy on users by default so that Mozilla can sell that data to marketers. Currently, you can disable that spying in about:config by setting dom.private-attribution.submission.enabled to false (see https://news.ycombinator.com/item?id=41311479 https://news.ycombinator.com/item?id=41311479 and also https://web.archive.org/web/20240827185708/https://make-firefox-private-again.com/ https://web.archive.org/web/20240827185708/https://make-fire...). No idea how long that will continue to be an option or how often you'll have to go back and reset that back to false following updates though. We really need a new browser that actually works in the interest of the users.
- AyyEye 2y agoMozilla is a Google vassal and nothing more. Google analytics? Check. Firefox Safebrowsing sending your private tab traffic to google? Of course! https://spyware.neocities.org/articles/firefox https://spyware.neocities.org/articles/firefox Mozilla only has their Google billion$ in mind, not you. https://digdeeper.neocities.org/articles/mozilla https://digdeeper.neocities.org/articles/mozilla
- threeseed 2y ago> Have been using Firefox for a long time It allows long lived first party cookies so isn't that much better. Only Safari clears them after 7 days to prevent tracking.
- deleted 2y ago[deleted]
- Terr_ 2y agoAs far as I can tell from some quick searching around, that limit only applies to cookies set through JavaScript code, as opposed to through server headers. I assume it's because of situations where websites include JavaScript from a third party, and then that JS uses first party cookies as a state-keeping workaround while synchronizing tracking information in some other way.
- morjom 2y agoFirefox doesn't have ECH support (atleast not turned on by default) https://privacytests.org/ https://privacytests.org/ (Scroll down to Misc tests)
- codedokode 2y agoI observed Firefox sending ECH extension in ClientHello, maybe I just enabled it in the settings, so Firefox supports ECH (on by default since version 119). However, virtually no servers support ECH now. Not Google, not Hackernews, not Cloudflare etc. This seems to be a not very good comparison, and it looks like it cherry-picks convenient for a certain browser points and ignores others. Look at "fingerprint protection", for example, and see that it does not include features that provide most fingerprinting data: - preventing reading GPU name via WebGL debugging extension (does Brave block this?) - preventing reading back canvas data which is used to fingerprint browser and OS code responsible for rendering graphics and text - enumerating audio devices And if you read the issues in Brave github [1], then you'll notice that Brave developers refuse to block features providing important fingerprinting information under compatibility" reasons (including GPU vendor and model), although these features could be made blocked only in high security mode. So regarding fingerprinting, the comparison you refer to is pretty much worthless: it doesn't mention many important fingerprinting APIs. [1] https://github.com/brave/brave-browser/issues/35646 https://github.com/brave/brave-browser/issues/35646
- morjom 2y agoFair points. Ill try to educate myself on this more. FWIW the about section says this: "Each privacy test examines whether the browser, on default settings, protects against a specific kind of data leak." The maintainer is a Brave employee and this is a project they were already doing before joining Brave. I'm hoping that they aren't manipulating it in favor of Brave. I sent those three options as a feature request. Do you think the site is still useful in some capacity?
- codedokode 2y agoAs for fingerprinting, there are more APIs that leak data allowing fingerprinting, what I mentioned were the most known APIs. Also, I looked at Brave Github and they seem to have counter-measures for some of those APIs to randomize results. So adding more tests could also be benefitial to Brave. > Do you think the site is still useful in some capacity? Well, it is better than nothing although it would be better if there were more tests regarding fingerprinting.
- netdevnet 2y agotbh, many of the main browsers have marketing companies as their main customers
- TacticalCoder 2y ago> Have been using Firefox for a long time, no issues, though long ago when I had little memory, Chrome was using less of it. I'd say the only area where I still see Chrome leading a bit is for web development: when I run super-heavy JavaScript in dev mode, Chrome is faster than Firefox at executing all the JavaScript nonsense. Seen that there's no ecosystem with more turds, bloatedness and slowness than that horror that JavaScript-the-piece-of-crap is, having a browser a bit quicker at running JavaScript helps. Long story short: for Web development, I use Chromium (it ships with Debian). For the rest I use Firefox. > Firefox also has HTTPS-only mode... In doubt port 80 is blocked by the firewall too. > encrypted DNS without fallbacks, And Firefox has a relatively easy "corporate" setting too where you can force also DNS "in the clear" over port 53 UDP (well, it's 99.9999% of the time going to be UDP so you can even firewall port 53 TCP and things shall keep working: believe me I know: theory vs practice and all that) It's convenient if you run your own DNS resolver (which, itself, can then be forced to only use encrypted DNS). > supports SOCKS I confirm: a SOCKS5 proxy over ssh is always sweet. Firefox just works.
- MisterTea 2y ago> Regarding analytics, I believe browsers should take user's side and do not cooperate with marketing companies; even better, they should implement measures to make user tracking and fingerprinting more difficult. Kinda hard to enact when the leading browser is developed by an ad company. Worse, the same company is contributing to the firefox foundation and drives web "standards." Its all collusion and the simple fact that browsers are more complex than the OS they run on is deliberate in ensuring no scrappy team can disrupt them. My curmudgeonly solution is to avoid as much of the web as possible and focus on human scale computing.