Windows 10 reached EOS (end of support) on October 14, 2025. If you are on Windows 10, see this article.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More
Open

mozilla products phoning home all the time, violating privacy and security policy

mozspyware

I've noticed that Mozilla products (firefox, thunderbird etc) all phone home all the time, which is a violation of both my security as well as privacy policy. In the firewall one can observe persistent, periodic, repeated connections to various non-sanctioned sites and services, apparently run by Mozilla. These include, but are not limited to:

firefox-portal-detection.com etc.

Specifically, there are persistent, periodic and repeated connection attempts to (just copy/pasting from the first page of firewall report; there are many more as well as similar connection attempts from thunderbird as well): firefox-settings-attachments.cdn.mozilla.net:443 assets-prod.sumo.prod.webservices.mozgcp.net:443 content-signature-2.cdn.mozilla.net:443 push.services.mozilla.com:443 etc

These begin at the startup of the browser/mua and continue throughout the session. Given that none of the sites actually browsed have anything to do with mozilla per se, and given that various privacy-violating features such as DNS-over-HTTPS (yes, that's a not a privacy-enhancing feature but the opposite - it just shifts the surveillance point from the ISP to the DoH provider) and other similar "features" are disabled in-browser, there should be no user/browser connections attempted to mozilla servers.

Also, by setting up a local security MITM proxy in order to observe and analyze the content sent to and received from these services and configuring the browser to connect via the proxy, the browser seems to *stop* trying to connect to these services, which indicates *active* measures by the browser/mua to avoid it's browser-fingerprinting and location-revealing content from being intercepted and analyzed.

This is especially concerning as Mozilla actively brands and markets it's products as privacy-respecting, as for-user-rights and as away-from-big-tech-dominated. Consequently I perceive this as complete breach of trust. Even by just *attempting* such phone-home connections a leak of metadata occurs, identifying the IP, the browser and consequently the user and user's location, sometimes actively (such as was the case with now apparently discontinued location.services.mozilla.net). Combined with whatever content these connections carry, this constitutes a serious breach. And there seems to be no way for the user to configure the browser to stop making these connections, other than by using an external application firewall.

And to top it off, with Firefox version 155.0.1, the browser now outright refuses to connect to *any* sites at all if firefox.settings.services.mozilla.com:443, firefox-settings-attachments.cdn.mozilla.net:443, firefox-portal-detection.com:80 and content-signature-2.cdn.mozilla.net:443 are *externally* blocked, at least on that profile (which worked just fine prior to upgrade to 155.0.1), showing a spinner and waiting indefinitely (not even timing out). These are the *only* connections it even attempts, completely ignoring the actual site that it was told to connect to. So that's at least 4 privacy-violating, security-policy-violating phoning-home connection attempts and a complete disregard for user's actual, sanctioned connection request.

I've noticed that Mozilla products (firefox, thunderbird etc) all phone home all the time, which is a violation of both my security as well as privacy policy. In the firewall one can observe persistent, periodic, repeated connections to various non-sanctioned sites and services, apparently run by Mozilla. These include, but are not limited to: *.mozgcp.net *.services.mozilla.net firefox-portal-detection.com etc. Specifically, there are persistent, periodic and repeated connection attempts to (just copy/pasting from the first page of firewall report; there are many more as well as similar connection attempts from thunderbird as well): firefox-settings-attachments.cdn.mozilla.net:443 assets-prod.sumo.prod.webservices.mozgcp.net:443 content-signature-2.cdn.mozilla.net:443 push.services.mozilla.com:443 etc These begin at the startup of the browser/mua and continue throughout the session. Given that none of the sites actually browsed have anything to do with mozilla per se, and given that various privacy-violating features such as DNS-over-HTTPS (yes, that's a not a privacy-enhancing feature but the opposite - it just shifts the surveillance point from the ISP to the DoH provider) and other similar "features" are disabled in-browser, there should be no user/browser connections attempted to mozilla servers. Also, by setting up a local security MITM proxy in order to observe and analyze the content sent to and received from these services and configuring the browser to connect via the proxy, the browser seems to *stop* trying to connect to these services, which indicates *active* measures by the browser/mua to avoid it's browser-fingerprinting and location-revealing content from being intercepted and analyzed. This is especially concerning as Mozilla actively brands and markets it's products as privacy-respecting, as for-user-rights and as away-from-big-tech-dominated. Consequently I perceive this as complete breach of trust. Even by just *attempting* such phone-home connections a leak of metadata occurs, identifying the IP, the browser and consequently the user and user's location, sometimes actively (such as was the case with now apparently discontinued location.services.mozilla.net). Combined with whatever content these connections carry, this constitutes a serious breach. And there seems to be no way for the user to configure the browser to stop making these connections, other than by using an external application firewall. And to top it off, with Firefox version 155.0.1, the browser now outright refuses to connect to *any* sites at all if firefox.settings.services.mozilla.com:443, firefox-settings-attachments.cdn.mozilla.net:443, firefox-portal-detection.com:80 and content-signature-2.cdn.mozilla.net:443 are *externally* blocked, at least on that profile (which worked just fine prior to upgrade to 155.0.1), showing a spinner and waiting indefinitely (not even timing out). These are the *only* connections it even attempts, completely ignoring the actual site that it was told to connect to. So that's at least 4 privacy-violating, security-policy-violating phoning-home connection attempts and a complete disregard for user's actual, sanctioned connection request.

All Replies (1)

Hi

You can read about the captive portal detection at:

https://support.mozilla.org/en-US/kb/captive-portal

And the DNS over HTTPS functionality at:

https://support.mozilla.org/en-US/kb/firefox-dns-over-https

The people who answer questions here, for the most part, are other users volunteering their time (like me), not Mozilla employees or developers. When a Mozilla employee jumps into a discussion, you'll see the Mozilla Staff label next to their name.

If you wish, you can leave feedback for developers on the Mozilla Connect website. Click the Firefox Menu Fx89menuButton button in the toolbar, click Help and select Share ideas and feedback…. Alternatively, you can use this link. Your feedback is collected by a team that reads it and gathers data on the most common issues.

You can also file a bug report or feature request. See File a bug report or feature request for Mozilla products for details.

Ask a question

You must log in to your account to reply to posts. Please start a new question, if you do not have an account yet.