Privacy? What is it doing? Explanation needed. #5907
Replies: 12 comments 83 replies
|
Well that was a fast-fail. Is there a Firefox fork that does NOT connect to Google by default? Like even LibreWolf had (still does?) an issue where it would connect to Google servers for "push" notifications, and when somebody filed a bug against it, they said it wasn't a problem. Like how hard can it be: you stripped all of the connect-to-Google from the browser, but you insist on leaving that one feature in by default. But then I'm supposed to trust you on everything else. |
|
Yeah and the telemtry is not disabled either. If you go into the about:config page it all there with urls and some are enabled including pings. Seems like the privacy marketing is just that, marketing. Its not privacy focused at all. Ungoogled chrormium or maybe Orion browser seems like an option though the latter is not open source. I also raised an issue about these questions a while ago and got no response from the devs about this. So I dont trust that the developers truly are privacy focused here. Id stay away from this browser |
|
Looked into it a little bit, and some of these are due to: Some wifi stuff - probably good if you're on wifi that has a login portal before you can use it. Geo location - not sure why it needs my geo location before any site has asked for it. Firefox push services (Notifications) - again, not sure why it's enabled/sharing my data with mozilla/firefox before any site has even asked to send notifications. Login breach information This one is interesting because I've never used firefox monitor, and I do not have any of the "security"/"block dangerous content" stuff enabled. Yet it's still enabled and sharing data with mozilla/Firefox. There was another one related to firefox profiles (?) and Sync. Again, i don't use profiles, no sync, nothing so I don't know why it talks to mozilla/firefox and shares data. This list is not complete. |
|
There appears to be a lot more features that would cause firefox to make connections, and they are transparent about it. Here's what I found: https://support.mozilla.org/en-US/kb/how-stop-firefox-making-automatic-connections |
This comment was marked as off-topic.
This comment was marked as off-topic.
|
Just my last 2c on this topic. You guys have a built a nice browser and there is a real opportunity to build a private browser with manifest v2 support since mozilla will be keeping support for it. Ungoogled chromium now has a big discussion going on about what to do. You guys dont have that problem. If you take the approach they did however of completely stripping on out telemtry and any relation to mozilla from the browser I think you may have a a lot more people using this browser to continue using plugins like Ublock origin. I dont doubt it wont be easy or a lot of work but you guys promote and sell the browser as privacy conscious but it lacks a lot on that front. I hope you see the opportunity that exists here and go down that route. |
|
Just to add here, @mauro-balades or someone from the moderators of the zen browser subreddit removed a similar post on reddit This is the kind of response and suppression of information that is being raised here. Its very concerning. Rather than have an open discussion on this topic they just want to hide it yet still claim the browser is secure |
|
While I think theres quite a few valid concerns raised in this thread, the tone has gotten a bit out of hand in my opinion. This is a browser being made largely by one dude who open sourced the whole thing. Being privacy conscious is important, and is something I very much am, but accusing the maintainer of fraud because they expect a different level of privacy is not only rude but ineffective - if people are hoping to convince the maintainer to change things, insulting them is not an effective strategy. Im also a tad concerned about these connections being made, but I'm assuming no malintent. It would be great, however, if we could get a more full response - an explanation of the connections made, why they are made, and what data if any could even theoretically be transferred through them. This would increase transparency and hopefully ease concerns a little. This whole thread has become an argument but it should be a discussion to make things better. |
|
The amount of shit-flinging in this thread, and elsewhere, is frankly absurd. As someone who's been coding professionally for well over a decade, I see no reason to assume malpractice or malice on part of the maintainers. Inexperience, perhaps, but that does not justify a tenth of the vitriol that's been spilled in this thread. First, the idea that Firefox is "spying" on you or "selling your data" is ridiculous. You don't have to trust me on that - there are great resources from far more reputable individuals explaining exactly why they were forced to change their terms (tl;dw - the state of California decided to redefine what the verb "to sell" means). There are valid criticisms of this change, but to imply that something substantial has changed in the past 6 months about Mozilla's actions is disingenuous at best, and wilful ignorance at worst. Second, and I can't believe I have to mention this in the discussion forum of a GitHub project to a community of alleged developers, if you do not want Google to know what you are doing on the internet, turn off your router. The majority of services you connect to are hosted at Google's, Amazon's or Microsoft's data centres. When you load a page it downloads fonts from Google and JavaScript from Microsoft's CDN. If you truly cared about this, instead of performative outrage at an indie dev you would have already null-routed all of these hostnames in your PiHole. Now. Should Zen auto-load X the everything app, Notion and Discord on a fresh install? No, including those tabs by default is an understandable but silly decision. Should Zen devs have noticed the remote-control thing earlier before it was pointed out in a PR? Maybe, though calling it a backdoor is likewise disingenuous. But, you should never assume security from alpha/beta software, and the issue was remedied a long time ago. Should the Zen maintainers be better at communicating issues and stating exactly what their policies are? Maybe, but you all know very well that we are talking about a handful of nerds making a Firefox mod for free that blew up over night, not a large corporation that can afford a PR team and a team of lawyers at the standby. And guess what? The code is right here. You have the agency to go into the code base, make a change, and say "hey, I noticed this issue, here's a PR that fixes it". I bet that you would be thanked and that you'd walk away happy knowing you improved the experience for everyone. Instead, you choose to be bitter and assume malice on the maintainers part. Do better. |
|
The only "privacy-focused" (your words) thing is like mozilla telemetry being disabled by default? Or am I missing something? There's countless connections sharing your data without interaction as soon as you start the browser. For example: Geo location: It's on by default and sharing your data OCSP Push notifications: For some reason this one connects and shares data with mozilla before you even let any site send push notifications. I don't need their extensions blocklists. I don't want to share my data with mozilla. These are just a few examples off the top of my head. At the very least, opt-out during install / first run before any automatic connections are made would be nice. You have the potential to be the only browser in the world with zero automatic connections when starting up on a blank page! Other concerns like google being default search is less of an issue to me, since you can change it before your data is shared with them if you want to. Keep up the good work! |



Uh oh!
There was an error while loading. Please reload this page.
Why does Zen connect to multiple google IPs, Akmai IPs, and GitHub IPs upon startup, and remains connected to them throughout the session.
I thought this browser was privacy focused, no telemetry?
Just started browser, no tabs open, no extensions.
Query OCSP servers off.
Block dangerous and deceptive content off.
Check for updates off.
I just don't understand what feature I have enabled that warrants these connections.
What is it doing and why? Please clarify and be specific.
And can I turn it off somehow?
Example:
https://i.imgur.com/EPGrCjZ.png
https://i.imgur.com/NmVcMh5.png
https://i.imgur.com/tqwNDXw.png
Sample IP list:
34.107.243.93
34.149.100.209
184.51.252.197
34.107.221.82
34.107.243.93
184.51.252.176
185.199.111.153
34.107.221.82
All reactions