Firefox and Thunderbird phone home daily


Recommended Posts

http://blogs.zdnet.com/hardware/?p=2143

Several of you have emailed me to let me know of a Firefox and Thunderbird feature that you might not be aware of - both applications phone home on a daily basis.

Here?s the info as posted on Reddit:

I found this out a few days after I decided to start using Thunderbird and created strict firewall rules as a precaution.

I noticed that Thunderbird would, for no reason at all, sometimes try to contact a server over SSL. I looked up the ip address 63.245.213.32 and found it belonged to Mozilla.

On researching the problem further I found that the cause of the connection is a feature that cannot be disabled from any menu, only the about:config configuration page.

Look up extensions.blocklist.enabled for more information. It?s present in Firefox also and is enabled even if all the options are disabled through the menus.

What this tells Mozilla each day:

- IP address

- What time you were using the product

- What exact version number you were using

- If you are using any of the plugins or addons sent in the disabled list

- Total number of active users of their software

Firefox = Spyware:D :D

Seriously please stop using the internet if you are worried. It probably "Phones Home" as the term is given to check for updates. Also to verify the sites you browse in the Phishing filter. The information given is actually a given. Please tell me a site that doesn't know your IP address when you visit it. As for the rest of the information it sends its hardly anything personal is it. But then again Firefox will be branded as spyware as some idiots out there *sighs*

Most of this is explained in their KB:

- IP address: Pretty obvious why this is sent along

- What time you were using the product: Not sure about this one, but seems harmless.

- What exact version number you were using: http://support.mozilla.com/fr/kb/Firefox+m...update_checking

- If you are using any of the plugins or addons sent in the disabled list: http://support.mozilla.com/fr/kb/Firefox+m...cklist_updating

- Total number of active users of their software: Not sure why they would need this, although it does seem harmless.

And the Captain Obvious of the Day Award goes to...

People who don't know the how their web bound software works and why it's necessary for some of them to phone home, and are concerned by that, should just get and stay offline. One would think that it's bloody obvious that checking for updates, be it manually or automatically, will involve phoning home.

i predict lots of "does it really matter" type replies... but if it was a microsoft app it would be like "omgz uninstall teh spywarez and sue micro$$$oft!1!111!!"

The reason for that is that Firefox is open-source whereas Microsoft programs are not. When one can look at the source code and find out exactly what information is being transmitted, it's easier to accept the behaviour because nothing is kept secret and, if it comes down to it, you can always just hack that part out of the source code and recompile. Compare this to the "black box" paradigm of Microsoft (and Adobe and Macromedia and Autodesk and Apple and Intuit and...) software and you need, at the minimum, a packet sniffer to figure out what's being sent, and sometimes cryptanalysis tools on top of that.

It's a matter of openness and transparency. Firefox has it. Microsoft products do not.

Firefox is open source anyway. If they are that concerned somebody could surely make a branch that removes the whole IP sending etc...

There are things like GhostFox, TorPark, etc.

I also am wondering about things like Debian Iceweasel or GNU IceCat that run on Linux and are based on Firefox. Oh, right... Those are updated via a package manager, a convenience that Windows doesn't have... They don't need to "phone home". :p

Funny how the person who posted this has an Internet Explorer 7 avatar. :laugh:

Actually doesn't Windows phone home to enable Windows Update to work? Is Windows Spyware? Ubuntu also 'phones home' to get updates, is it spyware.

Load of rubbish.

My guess is that they need to know the time of use of the product is probably to see the time from when the request was given for the updates and the time the either No Updates Available or that their is an update available. Possibly the addons in use is for the updates for them... not to mention if they have updates.

So... how else exactly is Firefox/Thunderbird supposed to check for updates without 'phoning home'??
Agreed. What are people doing that they're so afraid of this information being reported back to Mozilla?

They don't. And that's kind of the point (read: bitch) of some people?* If you had read the quote on the blog entry it says: It's present in Firefox also and is enabled even if all the options are disabled through the menus.

The user does not want to automatically check for updates for $app, $addon, $searchengine. The application respects that (unless there's some restriction on either side or something...).

If your application is dealing with updates and statistics (total number of active users? lolwut), then it should prompt a dialog during the installation and inform the user of its intentions and the information that will be sent to the company and how it will be sent, and then the users chooses whether or not to allow it.

The entry is hardly moronic. The author is just blogging about a situation that is actually happening (doubts?) on which people emailed (read: bitched) him about; quotes what they are saying; provides information on how to probably solve the situation and doesn't really give a crap about the whole deal and asks for your comment. Hardly controversy bait.

The OP forgot to quote the last part of the blog entry: Personally, I’m not too fussed about this feature, but I can understand why some folks are getting hot under the collar*. Thoughts?

Funny how the person who posted this has an Internet Explorer 7 avatar. :laugh:

Actually doesn't Windows phone home to enable Windows Update to work? Is Windows Spyware? Ubuntu also 'phones home' to get updates, is it spyware.

You have to blame Ballmer on this, obviously. :p

And if I'm not mistaken, doesn't Windows and Ubuntu only "phone home" with the permission of the user? Ubuntu probably has setup as default to perform daily checks on (recommended/security) updates and only notifies. I think that the statistical part (used in the popularity section of the Add/Remove Application)is by default turned off? Correct me if I'm wrong.

There's a good post about it in the original fire, it seems:

I see your point and I wholeheartedly agree. However, there is a difference, even if it's only an ethical one, between willingly sending non-confidential data for a necessary service (over HTTP or any remote service) and having a software sending without notifying you or letting you know in any way the same data to the mother land.

All that being said, this is absolutely not a good reason to dust off your tinfoil hats people.

- IP address

- What time you were using the product

- What exact version number you were using

- If you are using any of the plugins or addons sent in the disabled list

- Total number of active users of their software

Firefox downloads the list, then blocks them client side, it's easier than on the server than a back and forth "Is this ok?" "yes" "Is this ok?" "no" "Is this ok?" "yes"

Even if it does report back you're using a disabled extension, the only ones disabled at the moment are plugins that cause crashes, extensions that cause crashes, and that 3rd party language pack that had remnants of ads in it.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • $80 or 90%, anything else would be financial suicide one way or another.
    • Or... just use Bitwarden. Free, and has on-prem option as well. Works both on desktop and mobile, wherever you are. The age of local password files is over.
    • Thanks
    • I actually got to use one of those so called "backup codes" once. It was for a customer, I choose the backup code option, and by the grace of god, they actually hade them printed out. Imagine my surprise, when after using the backup code, Google then told use we had to enter a code they just sent to the gmail address we currently did not have access to. I was not amused, Google backup codes should be the end all get out of jail free card, because you had to have access to the account to even get them.
    • On the topic of being locked out of a service. Recently two different friends of mine got locked out of their Google accounts. Both were hack attempts and one of them is waiting 30 days before he can get back in. He had backup codes and MFA but not a passkey. It was a browser token hack. Anyhow he has to wait 30 days for the dispute or whatever to end. The other person only had a password and is screwed losing all of the email, docs and years of photos. Google won’t help her at all. Her fault because she had no backup/recovery setup. Enable passkeys if possible. Also do NOT use browser based password managers. If using a cloud service make sure it is one you can fully sync to one of your devices so you can back it up. Like a PC or Mac with some backup drive plugged into it. Google is the worst to use IMHO. You can’t sync your photos at all. You have to use the “Take Out” service which is manual and takes days. That service strips the meta data from your photos. Also Google Docs synced to a device are useless without a Google accounts. MS Office/Libre Office is not going to open a link to a Google doc to a dead account.
  • Recent Achievements

    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
    • One Month Later
      Genuinetonerink- Dubai earned a badge
      One Month Later
    • Week One Done
      Genuinetonerink- Dubai earned a badge
      Week One Done
    • One Year In
      hhgygy earned a badge
      One Year In
    • Week One Done
      AMV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      513
    2. 2
      +Edouard
      164
    3. 3
      PsYcHoKiLLa
      88
    4. 4
      Steven P.
      74
    5. 5
      Michael Scrip
      73
  • Tell a friend

    Love Neowin? Tell a friend!