Firefox and Thunderbird phone home daily


Recommended Posts

I do not see what the fuss is over the fact that Mozilla products report back to the company in this regard. If it weren't for software "phoning home", there would be no such thing as "update checks" or "automatic updates". If you have a problem with this behavior, stop using the software or block the outbound traffic on your firewall/router/tinfoil hat and call it a day.

I am sure if Microsoft did this, people would be following random guides on disabling this feature. Because it is firefox, no one really cares... double standard.

in the end.. who cares. It checks for updates, and that is good enough.

I've actually dealt with this "feature" on OS X. In order to comply with some absurd legal requirements for public-accessible kiosks, I've had to route all browser traffic through a proxy which requires Kerberos authentication. After disabling automatic updates to Firefox, addons, and extensions, Kerberos prompts continued to spawn. I went into about:config and replaced all instances of external addresses with http://127.0.0.1/, which seemed to fix it.

And the Captain Obvious of the Day Award goes to...

People who don't know the how their web bound software works and why it's necessary for some of them to phone home, and are concerned by that, should just get and stay offline. One would think that it's bloody obvious that checking for updates, be it manually or automatically, will involve phoning home.

Off-topic: Your display pic is dancing in perfect time to my music, it really freaked me out lol.

On-topic: Countless apps do this for updates, this isn't news

The reason for that is that Firefox is open-source whereas Microsoft programs are not. When one can look at the source code and find out exactly what information is being transmitted, it's easier to accept the behaviour because nothing is kept secret and, if it comes down to it, you can always just hack that part out of the source code and recompile. Compare this to the "black box" paradigm of Microsoft (and Adobe and Macromedia and Autodesk and Apple and Intuit and...) software and you need, at the minimum, a packet sniffer to figure out what's being sent, and sometimes cryptanalysis tools on top of that.

It's a matter of openness and transparency. Firefox has it. Microsoft products do not.

You are right. But admit it, hundreds of users who would never thought about what you just said would blame Microsoft all day long for this, just for the lulz of being inconvenient.

How do people think software will check for updates without hitting a server (the easiest way)? Would you rather run a small p2p so you phone an ANONYMOUS person for updates?

Software isn't really magic, just because you don't see them those bits don't appear on your computer out of nowhere :) and being a Microsoft platform developer, I absolutely LOVE firefox. It has it's own small problems, but it's a brilliant piece of software.

So... how else exactly is firefox/thunderbird supposed to check for updates without 'phoning home'??

I think people should actually try read through that article before posting comments like this.

that guy explicitly said "the cause of the connection is a feature that cannot be disabled from any menu, only the about:config configuration page."

and automatic updates can be disabled from the menu.

So it sounds like completely different things to me.

People who don't know the how their web bound software works and why it's necessary for some of them to phone home, and are concerned by that, should just get and stay offline. One would think that it's bloody obvious that checking for updates, be it manually or automatically, will involve phoning home.

And the user of a web bound software should be able to easily config the said software to access the web only when he/she wants it to. It's bloody obvious that when the automatic update is disabled, and when the user is not manually checking for updates, and when all apparent options that'll "phone home" get disabled, then it should not phone home.

The reason for that is that Firefox is open-source whereas Microsoft programs are not. When one can look at the source code and find out exactly what information is being transmitted, it's easier to accept the behaviour because nothing is kept secret and, if it comes down to it, you can always just hack that part out of the source code and recompile.

Out of the 26+ millions people who have downloaded Firefox 3 up to now, I bet there are less than 1000 who are even remotely capable of hacking the source code. Heck I do programming everyday to make a living for more than half a decade already, and even I'd think twice before trying to go through that overwhelming bloat mess called Mozilla/Gecko.

The add-on blocklist update is there for the security and integrity of the browser and it's not something you want to make a menu entry for and risk that a novice user or even grandma will disable it. That person might then end up downloading a bad extension which ruins his/her experience with Firefox, ends up blaming Mozilla, and never uses Firefox again.

Considering this isn't really something that would be smart to disable, I think Mozilla made the right choice and made it an about:config option that hopefully only advanced users with a reason to do so would change.

IP Address - Required

The time and date - Required for SSL

Version Number - Required

Checking if any of your extensions match the blocklist - Required

Total number of active users of their software - I assume this means it checks for multiple profiles so it can run all of them against the blocklist. Probably Required.

I don't see Mozilla doing anything in there that would be considered farming data.

The add-on blocklist update is there for the security and integrity of the browser and it's not something you want to make a menu entry for and risk that a novice user or even grandma will disable it. That person might then end up downloading a bad extension which ruins his/her experience with Firefox, ends up blaming Mozilla, and never uses Firefox again.

Considering this isn't really something that would be smart to disable, I think Mozilla made the right choice and made it an about:config option that hopefully only advanced users with a reason to do so would change.

IP Address - Required

The time and date - Required for SSL

Version Number - Required

Checking if any of your extensions match the blocklist - Required

Total number of active users of their software - I assume this means it checks for multiple profiles so it can run all of them against the blocklist. Probably Required.

I don't see Mozilla doing anything in there that would be considered farming data.

oh I didn't realise time/date was needed for ssl, I stand corrected (from my previous post) then.

Even if the time and date wasn't required for SSL, they could get the time and date just from when the packet is being sent out, and the # of active users could just be derived from how many different IP addresses ask for updates. That leaves only two things it's actually sending: the version number and your extensions... which is pretty much required if you are asking to see if there are any updates to the software.

The add-on blocklist update is there for the security and integrity of the browser and it's not something you want to make a menu entry for and risk that a novice user or even grandma will disable it. That person might then end up downloading a bad extension which ruins his/her experience with Firefox, ends up blaming Mozilla, and never uses Firefox again.

Funny that Firefox 3 has easily accessible options to disable Anti-Malware and Anti-Phishing features, which are arguable more dangerous than disabling the add-on blocklist (since the novice user or grandma is more likely to stumble upon bad sites than install add-ons themselves, if the grandma even knows what "add-ons" are about).

And that's why there are settings under tabs called "Security" and "Advanced". When there's a menu entry to disable automatic update of the browser itself, which is arguably far more important to the browser's security and integrity, the excuse of "no option for disabling add-on blocklist update because it's too risky" is simply ridiculous.

Edited by wellofsouls

I have no reason to defend Firefox and Tunderbird, but I'm going to anyway.

Even before I knew this, I kind of assumed that's what the programs did anyway. There's nothing personal enough for me to care about in that little bit of information, and it helps the team make their programs better. If it were anything I had to pay for I'd be a little miffed because most of the time, pay-for programs only "phone home" to make sure you aren't pirating their software. I guess I just hate being thought of as a criminal before I've done anything wrong.

And not only does this little bit of information help the team, but it is also probably used in helping Firefox figure out if it needs an update or not.

I guess a little disclaimer box telling you the information it will be sending would be nice (sort of like what Winamp and a lot of other programs use), but this is something so trivial I really don't care.

Funny that Firefox 3 has easily accessible options to disable Anti-Malware and Anti-Phishing features, which are arguable more dangerous than disabling the add-on blocklist (since the novice user or grandma is more likely to stumble upon bad sites than install add-ons themselves, if the grandma even knows what "add-ons" are about).

And that's why there are settings under tabs called "Security" and "Advanced". When there's a menu entry to disable automatic update of the browser itself, which is arguably far more important to the browser's security and integrity, the excuse of "no option for disabling add-on blocklist update because it's too risky" is simply ridiculous.

Add-ons integrate into the browser itself and affect it's core functionality. A user made add-on messing up their application is something any company should be worried about. The add-on blocklist gives them some limited control over their browser being contaminated with a bad extensions. As I'll say again, only an advanced user should have a reason to disable this. What is so hard about going into about:config and changing an entry anyway? I would consider that easily accessible for an advanced user.

Anything that is website related should have an easily accessible option to disable. Why should Mozilla care if you want to give away your personal information to a phishing website or download malware to your computer? The browser is doing what it is designed to do. You can't say as much for add-ons.

Add-ons integrate into the browser itself and affect it's core functionality. A user made add-on messing up their application is something any company should be worried about. The add-on blocklist gives them some limited control over their browser being contaminated with a bad extensions. As I'll say again, only an advanced user should have a reason to disable this. What is so hard about going into about:config and changing an entry anyway? I would consider that easily accessible for an advanced user.

and the browser itself is integrated into the... well, browser itself. By your logic, disabling automatic updates should be worried much more than disabling add-on blocklist. There's nothing hard about going into about:config, but any excuse trying to rationalize not having an option for disabling add-on blocklist update out of fear for some supposed "risk", while there are "Advanced" options for disabling the whole browser update, is simple ridiculous.

only an advanced user should have a reason to disable this.

And why there's an option tab named "Advanced"? um, I guess it means exactly for "Advanced" users.

Anything that is website related should have an easily accessible option to disable. Why should Mozilla care if you want to give away your personal information to a phishing website or download malware to your computer? The browser is doing what it is designed to do. You can't say as much for add-ons.

oh, and the add-on blocklist is related to the addons.mozilla.org website. And Firefox browser is designed to be extensible with add-ons, so if the users choose to install add-ons that has security risks, they should have the same freedom as going to some phishing sites, and the Firefox browser is just doing what it's designed for. At least for Firefox, I can surely say as much for installings add-ons as for browsing websites.

and the browser itself is integrated into the... well, browser itself. By your logic, disabling automatic updates should be worried much more than disabling add-on blocklist. There's nothing hard about going into about:config, but any excuse trying to rationalize not having an option for disabling add-on blocklist update out of fear for some supposed "risk", while there are "Advanced" options for disabling the whole browser update, is simple ridiculous.

You shouldn't force people to automatically upgrade their software. Unlike you, I see nothing wrong with keeping a blocklist of bad extensions up to date which should be completely invisible to the user.

oh, and the add-on blocklist is related to the addons.mozilla.org website. And Firefox browser is designed to be extensible with add-ons, so if the users choose to install add-ons that has security risks, they should have the same freedom as going to some phishing sites, and the Firefox browser is just doing what it's designed for. At least for Firefox, I can surely say as much for installings add-ons as for browsing websites.

They do have the same freedom, it's just made harder on purpose. I wasn't really arguing about security risks as much as the integrity of the browser. Websites might be blocked on accident or the user might have other protections in place to protect them from phishing schemes or malware and don't like being bothered. Are they a bit similar, sure, but I make a distinct separation between accessing websites and software integrity.

And why there's an option tab named "Advanced"? um, I guess it means exactly for "Advanced" users.

There isn't much "Advanced" about the "Advanced" option tab. If I say "Only expert users..." would that make you happy? Or is there an "Expert" option tab somewhere I'm missing as well. :rolleyes:

The reason there isn't an option is because none of the developers must of thought there was a good enough reason to add such an option to the gui and to keep it as uncluttered as possible. As you seem to care so much about it, why don't you file a bug on Bugzilla (and get a bunch of people to support you so the change is made) or write an extension to add this option you care so much about to the options dialog. If they decided to add the option to the GUI, I wouldn't have a problem with it but personally I don't think it's really needed.

Lets just agree to disagree. :yes: We each have our own opinions and neither is more right than the other. I can see where you're coming from about not liking your information being sent without permission and why someone with your point of view would want an easily accessible option to disable. If you are unable to see why Mozilla would do what it did with no malicious intent in mind then I have no reason to debate with you over this any longer.

Edited by cyberbeing
IE does this; it's called Windows Updates. :)

It comes down to risk and trust, or maybe just caring. Any program that informs you of updates has to check the internet. As someone said, the nice thing about open source is you, or someone knowledgeable if you dont know, can tell what is being sent by looking at the code. This means you can't really have open source spyware.

I use Ubuntu Linux and let it call the repo every day to check for updates to my software. I can set it for once a week or turn it off entirely if I want though. This is sort of like Windows update but for all the software on the system at once. I trust Ubuntu when they say they keep these records anonymous. If you trust Microsoft, then that is fine too.

Ubuntu also has the following option (disabled is the default):

ubqmb.png

I used to use Firefox but now use Opera as the new version is so cool but I know I am giving up the chance of knowing exactly what is going on behind the scene with my web browser because Opera is closed source. It is a risk I'll take in this case. :)

You shouldn't force people to automatically upgrade their software. Unlike you, I see nothing wrong with keeping a blocklist of bad extensions up to date which should be completely invisible to the user.

If you shouldn't force people to automatically update their software, then you shouldn't force people to automatically update add-on blocklist inside the software, which is a "software update" itself.

Unlike me what? I never said whether it's wrong or not, or maybe you are seeing things that I myself have not seen from my own posts? :rolleyes: I just said that what the article has described is actually not about the automatic software update option in the menu.

They do have the same freedom, it's just made harder on purpose. I wasn't really arguing about security risks as much as the integrity of the browser. Websites might be blocked on accident or the user might have other protections in place to protect them from phishing schemes or malware and don't like being bothered. Are they a bit similar, sure, but I make a distinct separation between accessing websites and software integrity.

And software updates is what software integrity is about. Again, like what I have said multiple times already, when there's option to turn off software updates, saying not having an option to turn off add-on blocklist updates at the same place is because of some "software integrity" concerns is completely ridiculous.

There isn't much "Advanced" about the "Advanced" option tab. If I say "Only expert users..." would that make you happy? Or is there an "Expert" option tab somewhere I'm missing as well. :rolleyes:

Nope, whether it's "Expert" or "Advanced" is completely irrelevant here, my point is that, there are options that shouldn't be casually turned off in the "Security" and "Advanced" tabs, just like the add-on blocklist option. So not having the options to turn off the add-on blocklist update at those places have absolutely nothing to do with whatever supposed "software integrity" risk involved :rolleyes: If you think there isn't much "Advanced" about the "Advanced" tab, then you should tell that to Mozilla, not me :laugh:

The reason there isn't an option is because none of the developers must of thought there was a good enough reason to add such an option to the gui and to keep it as uncluttered as possible.

Now we are getting to something, yes that's a good reason I can agree with, instead of some illogical nonsense about it having something to do with "security", "software integrity", or whatever :yes:

As you seem to care so much about it, why don't you file a bug on Bugzilla (and get a bunch of people to support you so the change is made) or write an extension to add this option you care so much about to the options dialog. If they decided to add the option to the GUI, I wouldn't have a problem with it but personally I don't think it's really needed.

Now you shouldn't put words in other's mouth. I have never said anything about adding it to the GUI. And I personally have no problem with Firefox "phone home" at all.

Lets just agree to disagree. :yes: We each have our own opinions and neither is more right than the other. I can see where you're coming from about not liking your information being sent without permission and why someone with your point of view would want an easily accessible option to disable. If you are unable to see why Mozilla would do what it did with no malicious intent in mind then I have no reason to debate with you over this any longer.

I think you should try read my posts before replying, or are you only seeing things you wish to see? Nope, I have nothing against firefox sending some data back home to get updates. My point of view regarding this "phone home" stuff is I don't care.

My posts here are just replying to some other posts in this thread regarding the following issues :

1. The article is NOT talking about the automatic software update options that can be disabled in the options menu, which is what a lot of people here seem to think without properly reading through the article itself.

2. The article is talking about Firefox "phone home" after disabling all apparent menu options.

3. The excuse of "Firefox is open-source so you can hack its code yourself" is not applicable to most of its users.

4. The excuse of "Firefox hides the option for disabling add-on blocklist updates because of concerns with security/software integrity/whatever risk" is completely ridiculous and illogical when it has easily accessible options to turn off its anti-phishing/anti-malware/auto-update feature.

and now,

5. I can agree that firefox may have hidden such an option in the about:config in order to avoid GUI cluttering, or, I may even say, maybe they just think this option isn't important enough to warrant a place in the options menu.

So you'd better first understand what my posts are saying before deciding what to "agree to disagree". I have nothing against Firefox phone home for some automatic updates, I just don't agree with some people seeing only what they want to see and ignoring what the article here is really about. Or pulling out some ridiculous excuses to rationalize certain Mozilla decisions in some strange illogical ways :shifty:

  • 2 weeks later...
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The quantum search for Time's origin had an equally mind-boggling conclusion by Sayan Sen Image by Steve Johnson via Pexels A theoretical study from researchers at the University of Surrey suggested that the direction of time may not be fundamentally fixed in certain quantum systems. The work, published in Scientific Reports, examined how the “arrow of time” could emerge from microscopic physics and found that time-reversal symmetry can remain intact even in models used to describe processes such as energy loss and thermalisation. The arrow of time refers to the observed one-way direction from past to future in everyday life. In macroscopic processes, this is easy to see. Spilled milk spreads across a table and does not gather back into a glass, and heat flows from hotter objects to colder ones. These processes shape the common sense idea that time moves in a single direction. However, at the level of fundamental physics, many equations do not prefer a direction of time. Time-reversal symmetry means that the same physical laws can describe a system whether time moves forward or backward. This has made it difficult to explain why irreversible behaviour appears in the large-scale world even when the underlying rules do not require it. Dr Andrea Rocco, Associate Professor in Physics and Mathematical Biology at the University of Surrey, described this contrast: "One way to explain this is when you look at a process like spilt milk spreading across a table, it's clear that time is moving forward. But if you were to play that in reverse, like a movie, you'd immediately know something was wrong – it would be hard to believe milk could just gather back into a glass. However, there are processes, such as the motion of a pendulum, that look just as believable in reverse. The puzzle is that, at the most fundamental level, the laws of physics resemble the pendulum; they do not account for irreversible processes. Our findings suggest that while our common experience tells us that time only moves one way, we are just unaware that the opposite direction would have been equally possible." The study focused on open quantum systems, which are quantum systems that interact with a surrounding environment. This environment, often described as a heat bath, can exchange energy and information with the system. The researchers used this framework to study how a direction of time might appear even when the underlying physics does not enforce one. A key part of the analysis involved the Markov approximation. This is a simplification used in many models where the system is assumed not to retain memory of its past states. The idea is that changes depend only on the current state, not on earlier history. This is commonly used when studying thermalisation, which is the process where a system settles into equilibrium with its environment. The study also used concepts such as master equations, including the Lindblad and Pauli equations, which describe how probabilities of different quantum states change over time. Another related model discussed was quantum Brownian motion, which describes the random-like movement of a quantum particle interacting continuously with its environment. In these descriptions, a “memory kernel” can appear, which is a mathematical term that accounts for how past states influence current behaviour. The researchers found that applying the Markov approximation did not break time-reversal symmetry. Even when the system interacted with an effectively infinite heat bath, the resulting equations of motion remained symmetric in time. This meant that the same mathematical description could, in principle, run forward or backward in time without contradiction. The study further showed that standard frameworks used in open quantum systems, including quantum Brownian motion and master equations like the Lindblad and Pauli forms, could be written in a time-symmetric way. These equations are typically used to describe processes that look irreversible, such as dissipation and thermalisation, but the results suggested they can also be interpreted as allowing evolution in both time directions. Thomas Guff, Research Fellow in Quantum Thermodynamics, said: "The surprising part of this project was that even after making the standard simplifying assumption to our equations describing open quantum systems, the equations still behaved the same way whether the system was moving forwards or backwards in time. When we carefully worked through the maths, we found that this behaviour had to be the case because a key part of the equation, the "memory kernel," is symmetrical in time. We also found a small but important detail which is usually overlooked – a time discontinuous factor emerged that kept the time-symmetry property intact. It’s unusual to see such a mathematical mechanism in a physics equation because it's not continuous, and it was very surprising to see it appear so naturally." The researchers also noted that deriving a one-way arrow of time from time-reversal symmetric microscopic dynamics remains an open problem across fields such as thermodynamics, statistical mechanics, particle physics, and cosmology. Their results suggested that some standard descriptions of irreversible behaviour in open quantum systems may be better understood using a time-symmetric formulation of Markovianity. According to the study, processes such as thermalisation, which are usually treated as irreversible, could in theory be described in a way that allows evolution in either time direction under the same rules. This does not imply that time reversal occurs in everyday life, but rather that the underlying equations do not strictly enforce a single direction. Overall, the findings suggested that the perceived direction of time may emerge from how physical systems are modelled and approximated, rather than from a fundamental asymmetry in the laws themselves. The researchers noted that this perspective could have implications for ongoing work in quantum mechanics, thermodynamics, and cosmology on the origin of time’s arrow. Source: University of Surrey, Nature This article was generated with some help from AI and reviewed by an editor. Under Section 107 of the Copyright Act 1976, this material is used for the purpose of news reporting. Fair use is a use permitted by copyright statute that might otherwise be infringing
    • A bit premature... 100% Marketing. Bizarre.
    • A $300 price hike is insane! No one is going to want to pay that much!
    • Since the 1st one flopped, there is really no reason to make another one. It's just losing money left and right.
  • Recent Achievements

    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      581
    2. 2
      +Edouard
      182
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      73
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!