Вы просматриваете вопросы по теме:
Вы просматриваете вопросы с метками:

mozilla products phoning home all the time, violating privacy and security policy

I've noticed that Mozilla products (firefox, thunderbird etc) all phone home all the time, which is a violation of both my security as well as privacy policy. In the fire… (читать ещё)

I've noticed that Mozilla products (firefox, thunderbird etc) all phone home all the time, which is a violation of both my security as well as privacy policy. In the firewall one can observe persistent, periodic, repeated connections to various non-sanctioned sites and services, apparently run by Mozilla. These include, but are not limited to:

firefox-portal-detection.com etc.

Specifically, there are persistent, periodic and repeated connection attempts to (just copy/pasting from the first page of firewall report; there are many more as well as similar connection attempts from thunderbird as well): firefox-settings-attachments.cdn.mozilla.net:443 assets-prod.sumo.prod.webservices.mozgcp.net:443 content-signature-2.cdn.mozilla.net:443 push.services.mozilla.com:443 etc

These begin at the startup of the browser/mua and continue throughout the session. Given that none of the sites actually browsed have anything to do with mozilla per se, and given that various privacy-violating features such as DNS-over-HTTPS (yes, that's a not a privacy-enhancing feature but the opposite - it just shifts the surveillance point from the ISP to the DoH provider) and other similar "features" are disabled in-browser, there should be no user/browser connections attempted to mozilla servers.

Also, by setting up a local security MITM proxy in order to observe and analyze the content sent to and received from these services and configuring the browser to connect via the proxy, the browser seems to *stop* trying to connect to these services, which indicates *active* measures by the browser/mua to avoid it's browser-fingerprinting and location-revealing content from being intercepted and analyzed.

This is especially concerning as Mozilla actively brands and markets it's products as privacy-respecting, as for-user-rights and as away-from-big-tech-dominated. Consequently I perceive this as complete breach of trust. Even by just *attempting* such phone-home connections a leak of metadata occurs, identifying the IP, the browser and consequently the user and user's location, sometimes actively (such as was the case with now apparently discontinued location.services.mozilla.net). Combined with whatever content these connections carry, this constitutes a serious breach. And there seems to be no way for the user to configure the browser to stop making these connections, other than by using an external application firewall.

And to top it off, with Firefox version 155.0.1, the browser now outright refuses to connect to *any* sites at all if firefox.settings.services.mozilla.com:443, firefox-settings-attachments.cdn.mozilla.net:443, firefox-portal-detection.com:80 and content-signature-2.cdn.mozilla.net:443 are *externally* blocked, at least on that profile (which worked just fine prior to upgrade to 155.0.1), showing a spinner and waiting indefinitely (not even timing out). These are the *only* connections it even attempts, completely ignoring the actual site that it was told to connect to. So that's at least 4 privacy-violating, security-policy-violating phoning-home connection attempts and a complete disregard for user's actual, sanctioned connection request.

Открытый 14

Clarification on "Firefox security for Linux" article

Firefox security features warning on Linux doesn't explain what kind of file to add to apparmor.d/firefox-local. Is it a .txt file, or something else? … (читать ещё)

Firefox security features warning on Linux doesn't explain what kind of file to add to apparmor.d/firefox-local. Is it a .txt file, or something else?

Открытый 2

Publisher guidance for uncommon-download warning on signed private installer

I publish NinePane Connector at https://ninepane.com. On September 12, 2026, a Firefox test on Windows displayed NinePane-Connector-Setup-0.8.56-Windows-x64.exe as not co… (читать ещё)

I publish NinePane Connector at https://ninepane.com. On September 12, 2026, a Firefox test on Windows displayed NinePane-Connector-Setup-0.8.56-Windows-x64.exe as not commonly downloaded, with Remove file and Allow download controls. I have two matching Firefox screenshots of the warning.

The intended release candidate is distributed through our private authenticated test route. These screenshots do not establish the exact final download URL or completed bytes. The exact Firefox version and capture-time Windows build were not recorded, so I have not guessed them in this form.

The intended local candidate was independently checked as validly Authenticode signed by NINEPANE STUDIO with a timestamp. That identifies the signed local file; it is not proof of safety or of the blocked browser copy's exact bytes. We are not asserting malware detection or requesting a way to bypass the warning.

Which official publisher-support or assessment route applies to Firefox's uncommon-executable warning? Is there a supported way to obtain classification or remediation guidance without publishing a private installer or sharing login credentials? We have already reported the related Chrome warning to Google; should a publisher take any separate Firefox-specific action?

No installer, credentials, session data or unrelated browser diagnostics are included.

Открытый

I have fear of being hacked can someone help me with running a diagnosis in my daily activities please.

I am using a local library and it comes to me that I find some activities that occur whilst working on my daily tasks and wonder, I would really like to run a diagnosis i… (читать ещё)

I am using a local library and it comes to me that I find some activities that occur whilst working on my daily tasks and wonder, I would really like to run a diagnosis in my tasks and activities and check if there are no spams running me dry.

Открытый