I tried to be unbiased in the submission title and it's probably late enough that this will be buried, but here are some my thoughts:
> They don't plan on collecting URLs, just (eTLD+1).
This is true as of right now, but can change at any time in the future. From the post:
> What we plan to do now is run an opt-out SHIELD study [6] to validate our
implementation of RAPPOR. This study will collect the value for users’ home
page (eTLD+1) for a randomly selected group of our release population
This test consists of collecting domains, indeed, but that doesn't say anything about what will happen in the future.
> Note: "planning" means "reaching out for feedback about".
Planning means planning. Today they're reaching for feedback, and the plans might change or not.
> Hello, Redditors...
This is my fault, I suppose, for posting the link here :). Many of the angry comments are uninformed, but the users, educated or not, are stakeholders here and Mozilla should be prepared for the fallout. There have been situations in the past (Pocket, Google Analytics) where well-formulated feedback from users was raedily dismissed.
> One recurring ask from the Firefox product teams is the ability to collect more sensitive data, like top sites users visit and how features perform on specific sites. Currently we can collect this data when the user opts in [...].
Does anyone know what this is about? Telemetry? Because I will disable it if so.
> What we plan to do now is run an opt-out SHIELD study [6] to validate our implementation of RAPPOR.
This still sounds bad enough to forever poison "SHIELD" for me. It's also terribly named because it doesn't "protect" anyone.
> No telemetry, no data collection.
Without telemetry it would be almost impossible for the developers to figure out what works or not, and what's fast or not in Firefox. There's a whole spectrum here from "no telemetry" to "creepy". Please don't ignore this.
> Now they are killing Privacy.
Please try to get informed. A Mozilla employee in this thread (alexrs95) posted a series of tweets about what's being proposed: https://twitter.com/Alexrs95/status/896366072240144385. It's short enough, so please read at least that before complaining.
> What's your favorite open-source browser?
Firefox :).
> I've removed all URLs from about:config and replaced them with localhost (search for "http"). This should help with privacy-related issues as long as no API endpoint is hardcoded.
Beware of SHIELD, as Mozilla may still have the ability to push extensions to the browser.
> He said there are math theorem to prove that it's sufficiently anonymize.
I've not dug deep enough into the RAPPOR paper, but they do consider in passing the possibility of an attacker that has access to all of the collected data (think https://en.wikipedia.org/wiki/National_security_letter).
> Everyone else
Please be kind.
EDIT: Looks like this post might have been pushed back from the front page by a moderator. I'm not sure I'm fine with that.
Indeed, that might have been better. The thing was that many arguments ideas I took issue with were repeated by different people and I didn't want to spam all those comment threads.
My reasoning is that people might search for my comment (I sometimes do when others post), but by the time I wrote the it the first comment page was full and it ended up on the second one.
> They don't plan on collecting URLs, just (eTLD+1).
This is true as of right now, but can change at any time in the future. From the post:
> What we plan to do now is run an opt-out SHIELD study [6] to validate our implementation of RAPPOR. This study will collect the value for users’ home page (eTLD+1) for a randomly selected group of our release population
This test consists of collecting domains, indeed, but that doesn't say anything about what will happen in the future.
> Note: "planning" means "reaching out for feedback about".
Planning means planning. Today they're reaching for feedback, and the plans might change or not.
> Hello, Redditors...
This is my fault, I suppose, for posting the link here :). Many of the angry comments are uninformed, but the users, educated or not, are stakeholders here and Mozilla should be prepared for the fallout. There have been situations in the past (Pocket, Google Analytics) where well-formulated feedback from users was raedily dismissed.
> One recurring ask from the Firefox product teams is the ability to collect more sensitive data, like top sites users visit and how features perform on specific sites. Currently we can collect this data when the user opts in [...].
Does anyone know what this is about? Telemetry? Because I will disable it if so.
> Allow Firefox to install and run studies
This is from the Nightly settings page but is pointing to https://support.mozilla.org/en-US/kb/shield, which doesn't exist (yet?). For anyone interested, there's a wiki page about them https://wiki.mozilla.org/Firefox/Shield/Shield_Studies.
> What we plan to do now is run an opt-out SHIELD study [6] to validate our implementation of RAPPOR.
This still sounds bad enough to forever poison "SHIELD" for me. It's also terribly named because it doesn't "protect" anyone.
> No telemetry, no data collection.
Without telemetry it would be almost impossible for the developers to figure out what works or not, and what's fast or not in Firefox. There's a whole spectrum here from "no telemetry" to "creepy". Please don't ignore this.
> Now they are killing Privacy.
Please try to get informed. A Mozilla employee in this thread (alexrs95) posted a series of tweets about what's being proposed: https://twitter.com/Alexrs95/status/896366072240144385. It's short enough, so please read at least that before complaining.
> What's your favorite open-source browser?
Firefox :).
> I've removed all URLs from about:config and replaced them with localhost (search for "http"). This should help with privacy-related issues as long as no API endpoint is hardcoded.
Beware of SHIELD, as Mozilla may still have the ability to push extensions to the browser.
> He said there are math theorem to prove that it's sufficiently anonymize.
I've not dug deep enough into the RAPPOR paper, but they do consider in passing the possibility of an attacker that has access to all of the collected data (think https://en.wikipedia.org/wiki/National_security_letter).
> Everyone else
Please be kind.
EDIT: Looks like this post might have been pushed back from the front page by a moderator. I'm not sure I'm fine with that.