this post was submitted on 13 Jul 2024
56 points (93.8% liked)

Firefox

1058 readers
36 users here now

The latest news and developments on Firefox and Mozilla, a global non-profit that strives to promote openness, innovation and opportunity on the web.

You can subscribe to this community from any Kbin or Lemmy instance:

Related

Rules

While we are not an official Mozilla community, we have adopted the Mozilla Community Participation Guidelines as far as it can be applied to a bin.

Rules

  1. Always be civil and respectful
    Don't be toxic, hostile, or a troll, especially towards Mozilla employees. This includes gratuitous use of profanity.

  2. Don't be a bigot
    No form of bigotry will be tolerated.

  3. Don't post security compromising suggestions
    If you do, include an obvious and clear warning.

  4. Don't post conspiracy theories
    Especially ones about nefarious intentions or funding. If you're concerned: Ask. Please don’t fuel conspiracy thinking here. Don’t try to spread FUD, especially against reliable privacy-enhancing software. Extraordinary claims require extraordinary evidence. Show credible sources.

  5. Don't accuse others of shilling
    Send honest concerns to the moderators and/or admins, and we will investigate.

  6. Do not remove your help posts after they receive replies
    Half the point of asking questions in a public sub is so that everyone can benefit from the answers—which is impossible if you go deleting everything behind yourself once you've gotten yours.

founded 1 year ago
MODERATORS
 

121

Discussion

Right. I'm getting tired of seeing people dump on Firefox and Mozilla about this thing in the release notes:

Firefox now supports the experimental Privacy Preserving Attribution API, which provides an alternative to user tracking for ad attribution. This experiment is only enabled via origin trial and can be disabled in the new Website Advertising Preferences section in the Privacy and Security settings.

What is this? And why is it not something to get heated about?

Attribution is how advertisers know how to pay the right site owner when someone clicks on their ad. It's important for ad-supported sites that clicks get attributed.

Right now, attribution is basically incompatible with protecting privacy. Advertisers use every method of tracking you can name, and some you can't, to provide accurate attribution.

The Privacy Preserving Attribution API is an experimental way of informing an advertiser that someone clicked on an ad on a given site without leaking that it was you, specifically, who did that. Specifically, ads using the API ask Firefox to remember that they were seen, on what sites, and to what sites they lead. Then, when the user visits the destination site, the destination site asks Firefox to generate a report and submit it via a separate service that mixes your report with reports from other people and forwards these aggregated reports in large batches. Any traces that might be unique to you are lost in the crowd.

This is still experimental, being enabled by Mozilla on a site-by-site basis as developers request it. It's not a free-for-all yet, and I can only find one entry on Bugzilla of a site who's requested it.

top 22 comments
sorted by: hot top controversial new old
[–] [email protected] 27 points 4 months ago (2 children)

what I’ve seen so far is that the heat isn’t against the API, it’s against it being shipped enabled by default (opt-out rather than opt-in)

[–] Carighan 7 points 4 months ago (1 children)

That's a requirement of being usable however. It has to be the default.

[–] [email protected] 9 points 4 months ago (3 children)

@Carighan @cerement personal data slurping has to be opt in the EU however. So not sure how #noyb etc will feel.

[–] kuneho 6 points 4 months ago (1 children)

it's not personal, though. that's the point

[–] [email protected] 7 points 4 months ago (1 children)

@kuneho Meta is not inventing this out of the goodness of it's heart. Just like how Google privacy sandbox is a fruit of a poisoned tree, the idea should be treated with extreme caution. If not, well, the NSA have a great new encryption standard they'd love you to use too.

#paranoid

[–] kuneho 2 points 4 months ago
[–] [email protected] 4 points 4 months ago

This would very likely be considered anonymized data, which means it is not personal data and the GDPR does not apply.

[–] [email protected] 3 points 4 months ago

From my understanding this is only a value add in terms of privacy? It's basically just asking every site to use this more private form of attribution, so I don't believe there's any more personal data being collected, it's just trying to send it in a more anonymized way if a given site supports it.

[–] [email protected] 6 points 4 months ago (1 children)

Itd be useless opt-in though, why would companies adopt somehting that only a small minority

[–] [email protected] 14 points 4 months ago

You're just supporting the point.

[–] [email protected] 20 points 4 months ago (1 children)

If it's such a great thing for users, why isn't Mozilla shouting from the rooftops how they've improved things, instead of it being enabled automatically?

[–] [email protected] 5 points 4 months ago (2 children)

Because its not really ready yet, im sure theyll talk more about it once they get big websites on board

[–] friend_of_satan 11 points 4 months ago (1 children)

Wait, it's not ready yet, so they enable it by default? That's not how experimental feature development happens.

[–] [email protected] 3 points 4 months ago

The feature is ready in the browser, but its not ready because no websites use it, thats what i meant

[–] [email protected] 1 points 4 months ago

What you're saying is that they're not vaporwaring their feature while it's still in beta, if I get you.

This is a positive, if so, and I have Mozilla for what they did with .. well, mozilla.exe .

[–] kerthale 17 points 4 months ago

What blows my mind is how people are crapping on Mozilla just constantly. Yeah sure they can do better. But also it’s the only real alternative to total domination from Chrome and all the dozens if not hundreds of rebuilds/ripoffs/reskins. It’s bizarre that they providing such a negative perspective on the basically the last bastion of an open web.

This constant negative attitude just boggles my mind. I’m happy with Firefox and Thunderbird with the functionality and features. Most of all the internet desperately needs diversity in the browser space.

For what it’s worth. I’m also skeptical of what they’re doing in the ad space. But I’m willing to give them the benefit of the doubt because the internet sadly runs on ads for the vast majority of it. If they’re trying to at least bring something ethical to that space they have my support. Once they have a fair chunk of the market and don’t rely on the Google antitrust protection racket to survive we’ll talk about how to do better.

[–] 0oWow 6 points 4 months ago

It does not matter how you feel about Googzilla. Spyware is spyware. And this is just one of many aspects of spyware built into and sneakily added by Googzilla.

That's why there are forks like LibreWolf that remove that nonsense, because people aren't sitting back and letting Googzilla run it into the ground.

[–] kuneho 5 points 4 months ago

sounds reasonable

[–] [email protected] 5 points 4 months ago (1 children)

So you won't even notice this if:

  • you don't click, or block, ads, or
  • you never visit a website that's part of the origin trial.
[–] [email protected] 7 points 4 months ago (1 children)

Exactly, ans it REPLACES traditional, more invasive ads for those sites

[–] [email protected] 0 points 4 months ago

Well, that depends on the website, I assume?

Of course, Firefox already partitioned (and can block, if you enable Strict Tracking Protection and accept some extra breakage) cookies, so those more invasive ads were already neutered. Unlike e.g. Chrome, whose Topics API proactively reports characteristics about you before you click an ad, and does so while third-party cookies are still allowed too.

[–] DeadNinja 3 points 4 months ago* (last edited 4 months ago)

This seems to assume that advertisers don't want our identifying information, and are clamoring for an alternative to tracking that lets them measure ad performance anonymously, which is just not true. Being able to uniquely identify users and target them is a feature, and getting more data points from the browser just helps add to their profiles.