Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There's a gap in the market for a simple and fast browser that takes privacy seriously.


Firefox with extensions ?


Firefox has the code that secretly sends a hash of every file you download, with your IP and computer fingerprint, to Google for "verification". I only found out after a post about it here on HN.

But I'm interested, what Firefox extensions are good for privacy?


BetterPrivacy to manage Flash Cookies

Cookie Monster to manage regular cookies

HTTPS Everywhere

DNSSEC/TLSA Validator

RequestPolicy Continued to control third-party requests

NoScript for selectively allowing first-party JS, and keeping third-party scripts blocked when other third-party requests are allowed through RequestPolicy, and for its other always-on features like XSS protection, permanently forcing encryption for cookies set over HTTPS, etc.

µMatrix has apparently been available for Firefox for a few months now, and is probably a viable substitute for RequestPolicy, but not a complete replacement for NoScript.


Links to each of the mentioned (and available) add-ons below. Note that they each require a restart.

- BetterPrivacy https://addons.mozilla.org/en-US/firefox/addon/betterprivacy...

- Cookie Monster https://addons.mozilla.org/en-US/firefox/addon/cookie-monste...

- HTTPS Everywhere - https://www.eff.org/files/https-everywhere-latest.xpi

- DNSSEC/TLSA Validator - https://addons.mozilla.org/en-US/firefox/addon/dnssec-valida...

- RequestPolicy Continued ??? https://addons.mozilla.org/en-US/firefox/addon/requestpolicy...

- NoScript Suite - https://addons.mozilla.org/en-US/firefox/addon/noscript/

- µMatrix - couldn't find a Firefox version



I think if you uncheck the "block reported forgeries/attacks" options in security settings it won't make the requests.


are you referring to this? https://news.ycombinator.com/item?id=9779440

this is the first I've heard of this, could you be more specific?


This: https://support.mozilla.org/en-US/kb/how-does-phishing-and-m...

It sends a hash of the file to Google with your IP/print. Worded like it's anonymous and one way, it's not. The hash is unique to the file, if your file-hash database is large enough (like Googles) you can cross reference to get the details of the original file. From this hash, you can then see the exact file the person is downloading. Great if you want to make a list of who is downloading an unallowed file, like say, a list of missing Chinese citizens or anything from wleaks.


pretty sure you're misunderstanding how firefox handles that, it downloads to local and checks against it, not the other way around


Only if it's signed by a known good publisher. Is that file you downloaded from Github signed by a known good publisher? Nope, then it's getting sent to Google for logging. Oh, it was a list of detained journalists? Well, no more gov contract work for you and you'll never know why.


Nothing on that page mentions a hash. There is absolutely nothing misleading in the page you linked.


The metadata sent to Google includes a hash of the file. That's what the metadata part means.


No, the metadata means the URL (not hashed). The protocol is linked from the page you posted. It's clear as day, and the only person who would be misled is somebody who didn't read the page at all and claimed it said things it doesn't say.


There is nothing secret about it.


I'd suggest it's purposefully obfuscated. It's certainly not clear this is being done and many users are surprised it exists. Such a possibility would be in line with Mozillas recent actions and allegations made against them.


Epic?


Not open source, so it needs to be asked, what's their business model?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: