1. Download installer from Mozilla from your home network - Mozilla now has your home IP and installer ID.
2. Transfer it via USB key to a secure, anonymous computer - one not linked to you, on a network not associated with you, such as public WiFi.
3. Install Firefox using that installer on said computer. It transmits the installer ID to Mozilla, which matches the one given to your home IP, thereby deanonymizing you.
4. Mozilla receives a warrant for this information, or it is hacked, or the organization is infiltrated by a single government or corporate spy.
Edit: It gets worse. Suppose a newspaper IT department takes care of providing Firefox and other trusted software installers to their reporters. Now Mozilla can determine who that newspaper helped with IT, such as journalists or sources. Or if you provide trusted software to your friends, Mozilla gets part of your social graph.
But stuff like this and other shenanigans in the past (like Mr.robot, misuse of funding, etc) is really off-putting sometimes. It really makes me feel naive and just drinking the support open-source kool-aid.
Firefox put a lot of effort into tracking download to install behavior. Maybe this is the only violation you know about. There's no reason to continue to believe in Mozilla's good faith. They've been captured, and are 90% dependent on Google revenue.
Discussion here: https://news.ycombinator.com/item?id=28954390
Firefox is dead. It's time to move past denial. It doesn't stand for anything you think it does. I'm sad, too. Time to bury the putrid, rotting corpse.
Firefox to my eye jumped the shark a long, long time ago, when they took to using deliberate deception during the install process to get people to sign up to a Mozilla account.
Pretty much everything they've introduced for years I've not wanted or disliked.
The saving grace has been that pretty much everything can be turned off in about::config.
I may be wrong, but I think Moz has become a typical larger company, wholly divorced from its users, unable to know what users want, let alone respond.
What Moz as a large company wants is really completely different to what users want, and a unique tracking ID is a shining example of this.
I'll be using Tor, but I my secondary browser now has to change, as this is intolerable.
The Apple’s icloud private relay should prevent Mozilla knowing the IP.
> 1. Download installer from Mozilla from your home network - Mozilla now has your home IP and installer ID.
Compile from source?
I've been working at Mozilla since its inception. And eventually left the company 2 years ago.
And I'm so mad.
Mozilla is not the Mozilla that was created almost 20 years ago. It's not the same people there. After the Firefox 4 nightmare, they started hiring product managers from big corp. We started seeing some ex-twitter, ex-microsoft, ex-amazon joining the company. People with more professional ambitions. We didn't know how to react to Google Chrome and the smartphone revolution. We all trusted the upper management, but upper management was slowly becoming non-mozillians.
And an absurd mechanic started: original engineer were busy writing difficult code. upper-management was morphing into some BS silicon valley gang. New young engineers were hired, and they thought the core of Mozilla values lied in these upper-management people. And slowly the original engineers started leaving, leaving behind this BS people with these young engineers.
Marketing became "how to show we're good people". LGBT, women right, etc etc. Who gives a shit about Mozilla standing for these values? It's all marketing. The real only value, the manifesto, burnt a long time ago.
Don't get me wrong, LGBT and such are important, but that's not the job of Mozilla.
The last blow: getting rid of Brendan. Maybe he didn't have the same values employees had about LGBT, but fuck this. People in the silicon valley *love* being offended. And that thing was just too good of a fight for them. Brendan was the last bastion standing.
I'm so so so mad.
Mitchell trusted the wrong people. We were seeing all these ambitious silicon-valley-puppets taking the position of PM, director, etc etc…
Got damn, all we wanted is to make Gecko amazing, light, in a lightweight simple browser. But all these stupid features that were landing on our head…
I'm so mad…
Rant over.
There was a funny story of a Hawthorn Experiment[1], which tried to find ways to boost productivity but at the end managed to state just that the very attempt to conduct an experiment boosts productivity. It seems to me that with Mozilla the effect has a opposite sign and any attempt to measure decreases the target variables of decision making. And therefore they need to find ways to measure "non-invasively", not to measure every little thing they can measure.
Spyware watchdog posted about this years ago. It's been in there at least since 2016, and every time you open Firefox (not start!) it will happily broadcast its geo position information to their geolocation backend. The same goes for the WebRTC related STUN servers, which are always connected to when Firefox starts.
I mean, come on folks. Never trust any software blindly. Use MITM proxy to verify. Use a host firewall like opensnitch.
For the moment the best alternative is ungoogled chromium with ublock origin, even though the CSP headers cannot influence the DNS resolver mechanics in the CEF code.
I am still busy forking webkit into retrokit and it's a shitload of work to remove these tracking features. [1] But a project like this needs more privacy like minded people.
I mean, even the TOR people kind of gave up on this. Just look at their codebase, trying to stub everything anew with upstream changes.
There's no point in trying to race against chrome in "whose browser has the most features", you can't win anyways. I don't care about WebGL or WebGPU, I don't care about WebRTC, I just want privacy back.
>One note, in case it's not already clear: The download token will be available in the telemetry environment, but all web session data that it is linked to will NOT ever be included in telemetry, it is being deliberately kept in a separate data set, and we will be limiting access to the ability to join these data sets to a small set of people.
Small set of people? Pls do tell me more
>> 9) If this data collection is default on, what is the opt-out mechanism for users?
>> Standard Telemetry Opt-Out
If you haven't installed it yet, how can you use the standard telemetry opt-out?
[1] https://bug1677497.bmoattachments.org/attachment.cgi?id=9195...
What value does Mozilla see in being able to do that?
Privacy is largely a mirage, where are our representatives to protect our privacy when the "free" market cannot, and indeed will not, do it for us?
That’s really not something they should spent much time puzzling over, much less implement tracking IDs for.
https://wiki.mozilla.org/Firefox/Stub_Attribution
https://bedrock.readthedocs.io/en/latest/stub-attribution.ht...
OK, however, are we completely sure that Chrome installer doesn't generate this token on launch and talk with the mothership?
This sounds like whitewashing Chrome just to increase the impact of the article or push Chrome or both.
Like Chrome is not tracking me in and out of the internet and in the kitchen making tea and noting its brand and reporting to Google.
Firefox users who prefer to download the browser without the unique identifier may do so in the following two ways:
Download the Firefox installer from Mozilla's HTTPS repository (formerly the FTP repository).
Download Firefox from third-party download sites that host the installer, e.g., from Softonic.
It's nuts and another indication Mozilla doesn't understand the reason they exist, but it's not that hard to get around... if you're one of the 0.1% that hears about this.As dry as German humor gets :)
And unfortunately, I can't help but admit that Firefox deserves to lose (not just from this, but from other terrible decisions added up), even if the consequences of a web monoculture are terrible.
It's like discovering there's ham in a vegetarian sandwich. When you ask them they look puzzled and say their focus group was clear it tastes a lot better that way, besides it's just a little bit and the bread is vegetarian and there's way more meat in a Big Mac.
This is why I keep insisting that we need a browser made in a jurisdiction which has at least minimal privacy rights. Having to explicitly opt-out of being tracked by a browser is not reasonable at all; browsers should only spy/track users who explicitly consent, not by default.
I was able to disable the ads with an about:config modification and I always get my installers from ftp.mozilla.org so this didn't even personally effect me, but still I feel betrayed.
If it's genuinely useful and you're a transparent organization then it should be an easy thing to write up. "See! We avoided this *catastrophic* thing!" Demonstrate that the data has a very defining role in decision making or just get rid of it. The demonstration of its usefulness needs to continue as long as the tracking does. What significant problem(s) is being solved here? Sated curiosity isn't that compelling.
> This data will allow us to correlate telemetry IDs with download tokens and Google Analytics IDs.
I invite everyone on a Mac to try and support Orion browser - zero telemetry by default.
[1]: https://download.mozilla.org/?product=firefox-latest&os=linu...
I figure at this point in history, browsers are so complex (25M+LOC) and important that it no longer makes sense to not use native browsers. There’s many advantages to them.
For me, daily usage of Edge and keeping Tor Browser installed has been great. I rarely use Tor, usually just when trying to get around IP bans or limitations, but I keep it installed out of principle. I wouldn’t rely on that small team to support a daily browser either.
> This data will allow us to correlate telemetry IDs with download tokens and Google Analytics IDs. This will allow us to track which installs result from which downloads to determine the answers to questions like, "Why do we see so many installs per day, but not that many downloads per day?"
So it's basically to spy on people and track who's redistributing the installer or installing Firefox multiple times.
As a software developer, I fail to see how this would help fix bugs or anything alike.
At least I'm sure the Firefox that comes in FreeBSD's package system doesn't do this. As with most Linux users. Another reason a FOSS OS is essential.