Firefox and Thunderbird phone home daily


Recommended Posts

http://blogs.zdnet.com/hardware/?p=2143

Several of you have emailed me to let me know of a Firefox and Thunderbird feature that you might not be aware of - both applications phone home on a daily basis.

Here?s the info as posted on Reddit:

I found this out a few days after I decided to start using Thunderbird and created strict firewall rules as a precaution.

I noticed that Thunderbird would, for no reason at all, sometimes try to contact a server over SSL. I looked up the ip address 63.245.213.32 and found it belonged to Mozilla.

On researching the problem further I found that the cause of the connection is a feature that cannot be disabled from any menu, only the about:config configuration page.

Look up extensions.blocklist.enabled for more information. It?s present in Firefox also and is enabled even if all the options are disabled through the menus.

What this tells Mozilla each day:

- IP address

- What time you were using the product

- What exact version number you were using

- If you are using any of the plugins or addons sent in the disabled list

- Total number of active users of their software

Firefox = Spyware:D :D

Seriously please stop using the internet if you are worried. It probably "Phones Home" as the term is given to check for updates. Also to verify the sites you browse in the Phishing filter. The information given is actually a given. Please tell me a site that doesn't know your IP address when you visit it. As for the rest of the information it sends its hardly anything personal is it. But then again Firefox will be branded as spyware as some idiots out there *sighs*

Most of this is explained in their KB:

- IP address: Pretty obvious why this is sent along

- What time you were using the product: Not sure about this one, but seems harmless.

- What exact version number you were using: http://support.mozilla.com/fr/kb/Firefox+m...update_checking

- If you are using any of the plugins or addons sent in the disabled list: http://support.mozilla.com/fr/kb/Firefox+m...cklist_updating

- Total number of active users of their software: Not sure why they would need this, although it does seem harmless.

And the Captain Obvious of the Day Award goes to...

People who don't know the how their web bound software works and why it's necessary for some of them to phone home, and are concerned by that, should just get and stay offline. One would think that it's bloody obvious that checking for updates, be it manually or automatically, will involve phoning home.

i predict lots of "does it really matter" type replies... but if it was a microsoft app it would be like "omgz uninstall teh spywarez and sue micro$$$oft!1!111!!"

The reason for that is that Firefox is open-source whereas Microsoft programs are not. When one can look at the source code and find out exactly what information is being transmitted, it's easier to accept the behaviour because nothing is kept secret and, if it comes down to it, you can always just hack that part out of the source code and recompile. Compare this to the "black box" paradigm of Microsoft (and Adobe and Macromedia and Autodesk and Apple and Intuit and...) software and you need, at the minimum, a packet sniffer to figure out what's being sent, and sometimes cryptanalysis tools on top of that.

It's a matter of openness and transparency. Firefox has it. Microsoft products do not.

Firefox is open source anyway. If they are that concerned somebody could surely make a branch that removes the whole IP sending etc...

There are things like GhostFox, TorPark, etc.

I also am wondering about things like Debian Iceweasel or GNU IceCat that run on Linux and are based on Firefox. Oh, right... Those are updated via a package manager, a convenience that Windows doesn't have... They don't need to "phone home". :p

Funny how the person who posted this has an Internet Explorer 7 avatar. :laugh:

Actually doesn't Windows phone home to enable Windows Update to work? Is Windows Spyware? Ubuntu also 'phones home' to get updates, is it spyware.

Load of rubbish.

My guess is that they need to know the time of use of the product is probably to see the time from when the request was given for the updates and the time the either No Updates Available or that their is an update available. Possibly the addons in use is for the updates for them... not to mention if they have updates.

So... how else exactly is Firefox/Thunderbird supposed to check for updates without 'phoning home'??
Agreed. What are people doing that they're so afraid of this information being reported back to Mozilla?

They don't. And that's kind of the point (read: bitch) of some people?* If you had read the quote on the blog entry it says: It's present in Firefox also and is enabled even if all the options are disabled through the menus.

The user does not want to automatically check for updates for $app, $addon, $searchengine. The application respects that (unless there's some restriction on either side or something...).

If your application is dealing with updates and statistics (total number of active users? lolwut), then it should prompt a dialog during the installation and inform the user of its intentions and the information that will be sent to the company and how it will be sent, and then the users chooses whether or not to allow it.

The entry is hardly moronic. The author is just blogging about a situation that is actually happening (doubts?) on which people emailed (read: bitched) him about; quotes what they are saying; provides information on how to probably solve the situation and doesn't really give a crap about the whole deal and asks for your comment. Hardly controversy bait.

The OP forgot to quote the last part of the blog entry: Personally, I’m not too fussed about this feature, but I can understand why some folks are getting hot under the collar*. Thoughts?

Funny how the person who posted this has an Internet Explorer 7 avatar. :laugh:

Actually doesn't Windows phone home to enable Windows Update to work? Is Windows Spyware? Ubuntu also 'phones home' to get updates, is it spyware.

You have to blame Ballmer on this, obviously. :p

And if I'm not mistaken, doesn't Windows and Ubuntu only "phone home" with the permission of the user? Ubuntu probably has setup as default to perform daily checks on (recommended/security) updates and only notifies. I think that the statistical part (used in the popularity section of the Add/Remove Application)is by default turned off? Correct me if I'm wrong.

There's a good post about it in the original fire, it seems:

I see your point and I wholeheartedly agree. However, there is a difference, even if it's only an ethical one, between willingly sending non-confidential data for a necessary service (over HTTP or any remote service) and having a software sending without notifying you or letting you know in any way the same data to the mother land.

All that being said, this is absolutely not a good reason to dust off your tinfoil hats people.

- IP address

- What time you were using the product

- What exact version number you were using

- If you are using any of the plugins or addons sent in the disabled list

- Total number of active users of their software

Firefox downloads the list, then blocks them client side, it's easier than on the server than a back and forth "Is this ok?" "yes" "Is this ok?" "no" "Is this ok?" "yes"

Even if it does report back you're using a disabled extension, the only ones disabled at the moment are plugins that cause crashes, extensions that cause crashes, and that 3rd party language pack that had remnants of ads in it.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I'd say the first one failed to be as popular as Apple anticipated, but the easy adjustment here is to make fewer of them next time around. It would only be a "flop" if it isn't possible for Apple to recover the design and factory tooling costs given the number of units sold, which I doubt would be the case. It isn't like no one bought them; it just failed to become the new hot phone of the year.
    • You're right that it does not follow the plain meaning of the word, but in this context, it is a legal term defined in 49 U.S.C. Kind of how "wire fraud" laws apply even if a physical wire was not used. Given that it is codified in law, and it isn't just automotive journalists that don't understand evolving technology, I highly doubt congress would change a well understood term just because technology makes the term slightly less actuate.
    • This is exactly why I keep saying we are not ready for human free self-driving. These little "bugs" are may seem like random one-offs. There was also the Waymo that drove between police with drawn weapons and the suspect they were pointing them at. From a software perspective it is easy to understand how those extremely rare situations may not have been programed for, but that is the point. If AI needs to be told to watch out for every possible contingency, then it can never be successful. There will always be the possibility of a first encounter that the AI needs to understand to avoid.
    • TeraCopy 4.0 Final by Razvan Serea TeraCopy is a compact program designed to copy and move files at the maximum possible speed, also providing you with a lot of features. Copy files faster. TeraCopy uses dynamically adjusted buffers to reduce seek times. Asynchronous copy speeds up file transfer between two physical hard drives. Pause and resume transfers. Pause copy process at any time to free up system resources and continue with a single click. Error recovery. In case of copy error, TeraCopy will try several times and in the worse case just skips the file, not terminating the entire transfer. Interactive file list. TeraCopy shows failed file transfers and lets you fix the problem and recopy only problem files. Shell integration. TeraCopy can completely replace Explorer copy and move functions, allowing you work with files as usual. TeraCopy is free for non-commercial use only. For commercial use you need to buy a license. The paid version of the program includes the following features: Copy/move to your favorite folders. Save reports as HTML and CSV files. Select files with the same extension/folder. Remove the selected files from the copy queue. Download: TeraCopy 4.0 | 14.6MB (Freeware, paid upgrade available) View: TeraCopy Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
    • First Post
      BizSAR earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      586
    2. 2
      +Edouard
      187
    3. 3
      Michael Scrip
      74
    4. 4
      PsYcHoKiLLa
      72
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!