TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Firefox built-in spyware that cannot be disabled

60 点作者 gamertime超过 1 年前
Looking at about:networking I can see connections to pocket (despite me disabling pocket in about:config) as well as connections to &quot;firefox.settings.services.mozilla.com&quot;.<p>And after research, it appears some of these are hard-coded into the source code on purpose for &quot;security reasons&quot; which is ridiculous.<p>Mind you, my browser is hardened to it&#x27;s best.. just felt like sharing this for anyone unaware that even if you harden Firefox, even if you go the extra 10 miles and edit about:config, it will still spy on you!

10 条评论

k8svet超过 1 年前
I swear there must be one person at Mozilla with power and a massive sunk cost complex surrounding their pocket acquisition. <i>if</i> they actually cared, it wouldn&#x27;t be built-in and so offensively un-disableable.
评论 #39174995 未加载
评论 #39179467 未加载
logicprog超过 1 年前
This is why I use LibreWolf, which is a patched version of Firefox that removes pocket and stuff like this entirely, instead of regular Mozilla Firefox with something like arkenfox to harden it. There&#x27;s only so much a config, no matter how extensive, can really do for you against what&#x27;s been hard-coded into a program itself, and configs need personal maintenance, whereas a patch version of a piece of software can pull things out at the root, and will generally be maintained by people other than me. Yes, since it&#x27;s a patched version there is some delay in receiving updates from upstream, but it&#x27;s very small and they&#x27;re extremely consistent about keeping up with new Firefox versions, since I believe most of their system is automated and it&#x27;s basically the same set of patches every time. So it&#x27;s no more of a risk than using a distro packaged version of Firefox instead of a Flatpak version, since distro packages add the same sort of patching by a third party delay. And most people are fine with distro packages for browsers, so there&#x27;s no reason to balk here either.
评论 #39168871 未加载
评论 #39175577 未加载
评论 #39167135 未加载
CTOSian超过 1 年前
I am on firefox 122 , binary from Mozilla, not from my distro&#x27;s repos (debian) and I don&#x27;t see any connection to pocket - at least some domain that has the name &#x27;pocket&#x27; on it.
LinuxBender超过 1 年前
I noticed this as well and blocked it in my local DNS. I also disable DoH.<p><pre><code> grep firefox &#x2F;etc&#x2F;unbound&#x2F;override&#x2F;combined.conf local-zone: &quot;firefox-settings-attachments.cdn.mozilla.net&quot; always_nxdomain local-zone: &quot;firefox.settings.services.mozilla.com&quot; always_nxdomain</code></pre>
评论 #39168403 未加载
评论 #39166900 未加载
评论 #39167148 未加载
punkybr3wster超过 1 年前
Is pocket actually spyware &#x2F; telemetry or is this just conjecture?
评论 #39173360 未加载
nequo超过 1 年前
For those wondering like me, this is Mozilla’s official documentation page about network connections made by Firefox:<p><a href="https:&#x2F;&#x2F;support.mozilla.org&#x2F;en-US&#x2F;kb&#x2F;how-stop-firefox-making-automatic-connections" rel="nofollow">https:&#x2F;&#x2F;support.mozilla.org&#x2F;en-US&#x2F;kb&#x2F;how-stop-firefox-making...</a>
ilikenwf超过 1 年前
Here&#x27;s your solution<p><a href="https:&#x2F;&#x2F;librewolf.net&#x2F;" rel="nofollow">https:&#x2F;&#x2F;librewolf.net&#x2F;</a><p>Keeps version parity but removes all the nastiness with a lot of other beneficial config changes...and the ability to further customize in persistent js files.<p>Cachy Browser in CachyOS&#x2F;Archlinux is more or less Librewolf with some other tweaks to make it faster.
评论 #39172009 未加载
FractalHQ超过 1 年前
I wonder how much hidden telemetry is in Brave browser, if any. Has anyone with wireshark chops looked into it?
rasz超过 1 年前
Mozilla CEO needs this for that sweet Google payout. This is how you prove to advertisers number of active installs.
评论 #39179690 未加载
评论 #39174625 未加载
hknmtt超过 1 年前
yes, ff does a ton of background connections. use wireshark to see what it is doing. i tried to block all that crap once but after a while i just gave up.<p>it is still my primary browser because it is now the only alternative to google&#x27;s monopoly(even though mozilla is de facto living off of google&#x27;s money).
评论 #39168794 未加载