TheTwelveYearOld

joined 1 year ago
 

A Mozilla employee recently released a Firefox addon to change the user agent to Chrome on sites the user enables it on.

 

I tried looking for lists but didn't find any.

The Work Number is US-specific and where your employers input your salary data for future employers to see. You can opt out here: https://employees.theworknumber.com/employee-data-freeze/.

 

I tried looking for lists but didn't find any.

The Work Number is US-specific and where your employers input your salary data for future employers to see. You can opt out here: https://employees.theworknumber.com/employee-data-freeze/.

 

I tried looking for lists but didn't find any.

The Work Number is US-specific and where your employers input your salary data for future employers to see. You can opt out here: https://employees.theworknumber.com/employee-data-freeze/.

 

I'm actually pissed. I and many other users on the forum got an email from Chris Hayes on this:

Hello,

This is a friendly email to make you aware that your personal email address is currently visible to the whole internet via Mozilla's Discourse forum. It will show up in Google Search results. The affected email is the one that this email was sent to.

Many users may not be aware that their email address is publicly visible and Mozilla has not done anything about it in the 4 years it has been known, so I've taken this into my own hands to inform you.

What can you do?

You can update your profile name to be something else (actually, profile name is completely optional, so you can leave it blank if you want).

Steps to update profile name:

  1. If you search for "Mozilla Discourse forum" it should be one of the first results.
  2. Login. (Top-right)
  3. Click on your profile picture at the top right.
  4. Then, click on your username, at the top of the dropdown menu.
  5. Click on the "Preferences" button.
  6. Change the "Name" field, and click "Save Changes".

How did this happen?

There's a misconfiguration with Mozilla's Discourse forum that when you sign up with your Firefox account, it will by default use your personal email address as your profile's public name.

This is not a new issue, and has been known since 2020. The Mozilla Discourse forum is not actively maintained by Mozilla, so this has yet to be fixed.

You are one of 4,630 other users impacted by this privacy issue. It impacts 19% of all forum users, and 28% of new users.

More information:

There's a Discourse discussion about this problem here: https://discourse.mozilla.org/t/email-is-displayed-by-default-for-the-new-account/92266

If you have connections to Mozilla, please help escalate this issue to the right people. This is a serious and long-standing privacy issue at an organization that should value "Privacy by default".

Sincerely,@chrisA fellow Mozillian

I am not Mozilla: This is not an official Mozilla email, I do not represent or work for Mozilla. This is an email from a fellow community member spreading awareness of this unaddressed privacy issue.

 

One example would be state disability programs, they already need my real name and identity to work with me. Are there any downsides to sharing a simplelogin alias containing my real name vs no containing my real name? I just think it would be easier record keeping for them.

 

One example would be state disability programs, they already need my real name and identity to work with me. Are there any downsides to sharing a simplelogin alias containing my real name vs no containing my real name? I just think it would be easier record keeping for them.

 

One example would be state disability programs, they already need my real name and identity to work with me. Are there any downsides to sharing a simplelogin alias containing my real name vs no containing my real name? I just think it would be easier record keeping for them.

 

I just tried changing my email on studentaid.gov to a simplelogin alias (using SL is a habit at this point) and I got notifications that emails from it were bounced while trying to verify the email change with sent codes. I looked it up and found a bunch of Reddit posts about issues with SL and iCloud.

 

I just tried changing my email on studentaid.gov to a simplelogin alias (using SL is a habit at this point) and I got notifications that emails from it were bounced while trying to verify the email change with sent codes. I looked it up and found a bunch of Reddit posts about issues with SL and iCloud.

 

I just tried changing my email on studentaid.gov to a simplelogin alias (using SL is a habit at this point) and I got notifications that emails from it were bounced while trying to verify the email change with sent codes. I looked it up and found a bunch of Reddit posts about issues with SL and iCloud.

[–] [email protected] 4 points 2 months ago (1 children)

I got it after make 5 aliases for 5 Reddit accounts.

[–] [email protected] 7 points 2 months ago

This is on my paid account.

[–] [email protected] 29 points 2 months ago (5 children)

SimpleLogin premium, with their domain. But I can't blame them for not wanting to ruin the simplelogin.com domain

[–] [email protected] -1 points 2 months ago* (last edited 2 months ago)

I just tried it on the Tor Browser and I still get the error, I'm gonna wait a day to see if its just a rate limit, because I've prolly created dozens of aliases today as I've been changing all my account emails.

I don't use Tor as my default browser because the Tor circuits are slower and not necessary for my threat model.

[–] [email protected] 1 points 2 months ago (2 children)

How does it work though, does it use tracker lists like uBlock origin does?

[–] [email protected] 7 points 2 months ago (4 children)

I'd definitely wanna block embedded trackers though

[–] [email protected] 2 points 2 months ago (4 children)

But couldn't the JS runtime track which objects and variables interact with such information, so if they make any HTTP requests with the info after getting it and maybe processing it then it could be rejected?

[–] [email protected] 3 points 2 months ago (1 children)

But would it not be easy for a user to catch when the app is using the mic or camera when it's not supposed to? the lights are an iOS feature that can't be disabled.

[–] [email protected] 5 points 2 months ago

You're absolutely right micro-optimization, I found that I did too much of that in 2022 and 23 and really cut down on that this year, I found that doing so is basically never worth it. I'm not gonna do that with privacy either, I'm focusing on what actions I can take that will make big improvements to my privacy rather than tweak every little thing.

[–] [email protected] 2 points 2 months ago (1 children)

Firefox changes the capacity dynamically, I set browser.cache.disk.capacity to false in about:config and browser.cache.disk.capacity to 1024000 (the storage amount in MBs)

[–] [email protected] 4 points 2 months ago (2 children)

I have UBlock Origin, I assume that one that one is good?

view more: ‹ prev next ›