Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

1. X sniffs my connection. 2. X learns my address uses Firefox on Linux. 3. X sells the data to Y, whom I never visit. 4. Y correlates the IP with Z's subscriber data, and adds Linux to my shadow profile.

As the sibling said, the burden of proof is on them. They are the ones who push that on users when there's no technical need.



Surely that same information is made available by visiting any website, no?


Yes, except the attacker gets it without visiting the attacker's web site.


You lost me. Why can an attacker do this to Firefox's telemetry, but not when I visit https://google.com/?


If you decide to visit google, that's your problem. Visiting mozilla should be optional too. Otherwise it creates attack surface area that wasn't there before.


Okay, so in conclusion, the attack vector from analytics that people spill dozens of comments on in every Mozilla thread is not unique to Firefox but rather shared with every website on the planet.


Yes. Except in most cases people aren't sent to $website unless they request it. That Mozilla does this is an opsec failure for anyone using it.


If any network request will result in this vulnerability, then why do you have an Internet connection at all? This isn't a Mozilla problem.


I can decide to connect only to trusted hosts. Having an automatic connection breaks that limitation.

You ask for a real attack, but you don't seem to accept the example that you were given. I'm not sure what your point is.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: