floc
mozilla-vpn-client
floc | mozilla-vpn-client | |
---|---|---|
92 | 31 | |
928 | 429 | |
- | 1.9% | |
1.1 | 9.8 | |
about 1 year ago | 2 days ago | |
Makefile | C++ | |
GNU General Public License v3.0 or later | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
floc
-
Google starts trialing its FLoC cookie alternative in Chrome.
Draft: https://github.com/WICG/floc
- Chrome vulnerability reported for 3.2 billion users
-
[D] Google FLoC and Topics API suspiciously similar.
"The browser uses machine learning algorithms to develop a cohort based on the sites that an individual visits. The algorithms might be based on the URLs of the visited sites, on the content of those pages, or other factors. The central idea is that these input features to the algorithm, including the web history, are kept local on the browser and are not uploaded elsewhere — the browser only exposes the generated cohort." Source: https://github.com/WICG/floc
-
Will a VPN help me? And is Kape Technologies ruining everything?
Google (or other third-party tracking) is also not effected by VPN. These groups use cookie syncing to assign you a unique ID and then collect this ID again as you browse the internet. That buyerID can then be cross-referenced (even with other buyerIDs) to generate all sorts of different demographic/psychographic information and used to fingerprint your online life for audience targeting. Google actually is in the works to take this a step forward with the FloC experiment. FloC (Federated League of Cohorts) actually deprecates the Set-Cookie header in favor of in-browser history scanning. Basically, in a year or two they plan to incorporate Chrome into their adtech stack and have it report your history/behavior to Google (regardless of whether you save history or not). Here is some good info on that: https://github.com/WICG/floc
-
Google Play Services now lets you delete your advertising ID when you opt out of ad personalization
Instead they propose new standards, like HTML Imports or FLoC, and the W3C decides as a whole whether or not they become official standards.
-
Google considers switching FLoC to a topic-based approach
With cross-site cookies, adnetwork.com has full information about what sites you've visited (among sites that incorporate their cookies). This isn't good either! But generally speaking, an individual site using adnetwork.com for advertising won't have or want access to that vector of your interests; many site operators don't even have visibility into what ads win real-time bidding, just that they're receiving money for providing their inventory. Certainly there are players that can provide demographic targeting metadata to site operators, but to my knowledge they are less widely known and certainly not cheap, and I imagine (or hope) any players with wide enough cookie reach would be discouraged from maintaining a database that could associate metadata with PII.
With FLoC, though, the idea was that the browser would provide document.interestCohort() and the individual site's JS could react accordingly: https://github.com/WICG/floc . This means that any site, regardless of its contracts with ad networks, could immediately identify your cohort and associate it with your activity. Web developers working in good faith would be encouraged to have user.cohort or user.topic fields from day one "just so you have it" - imagine all the ways someone could use this in bad faith. Inevitably this data would leak (or be intentionally leaked) and could trivially become a target list for doxxing closeted people. It's a dangerous, dangerous proposal.
-
Trying to understand Addressability (for native mobile, and in general)
You can't find any info about this because there isn't really any. Josh Karlin, who is the maintainer of the FLoC working document, said at an event that it might make sense to swap to topics. It's essentially just reducing the entropy of the cohorts and giving them a more comprehensible (and probably less useful) taxonomy. That's all the info there is.
-
Apple's Plan to "Think Different" About Encryption Opens a Backdoor to Your Private Life
https://github.com/WICG/floc explains the overall goals.
- Firefox Users Continue to Decrease Despite Proton Update
-
Amazon is blocking Google’s FLoC
It's pretty complicated and my understanding could be wrong and definitely not an expert. All the stupid CIA-style names that keep changing don't help. Turtledove, fledge, sparrow lol.
But from what I think I know that's kind of right technically, but kind of not in terms of actual real privacy.
Yes, the actual browsing data, e.g. for the basic floc cohorts only what amazon product page you visited, is no longer 'sent' to ad networks (that's a pretty big oversimplification of how ad networks track you but for brevity). That data is parsed in your browser to generate a cohort ID for you.
But this cohort ID is exposed to the world document.interestCohort() and is what's used for targeting and tracking.
To me it seems that the cohorts are so small "thousands of people" + IP or UA it's basically the same as a semi-long lasting uuid.
Here's an image from google's site.
https://web-dev.imgix.net/image/80mq7dk16vVEg8BBhsVe42n6zn82...
It also seems like Chrome/google might be still defaulting browser settings to give themselves even more data just like they currently do?
https://github.com/WICG/floc#qualifying-users-for-whom-a-coh...
BUT when you layer on the other proposals (Fledge/Turtledove/Dovekey or whatever) - which I don't understand that much maybe someone else can explain - it seems like it basically collect this page/product level data and makes it available to DSP etc for tracking/ad serving (again if not technically 1:1 basically in consequence given the sizes of these groups).
Like one of the proposals talks about a 'trusted' key/value server which doesn't seem that different from what already happens? The original proposal wanted to move the entire ad bid/target/serve process into the browser.
mozilla-vpn-client
- What is a proper way to support Firefox?
-
Mozilla VPN: CVE-2023-4104: vpndaemon wrongly implements Polkit authentication
The summary seems to ignore upstream.
They did infact
removed polkit : https://github.com/mozilla-mobile/mozilla-vpn-client/pull/70...
refactor auth using D-Bus: https://github.com/mozilla-mobile/mozilla-vpn-client/pull/71...
These are why author's PR was dropped.
-
Compiling Mozilla VPN (Tumbleweed)
git clone https://github.com/mozilla-mobile/mozilla-vpn-client.git cd mozilla-vpn-client git submodule update --init
-
Enabling IPv6 support for IPv4 only apps on Linux
RTNETLINK answers: Network is unreachable
So I intentionally decided not to have IPv4 connectivity system wide to catch apps with issues in IPv6 only environment and then carefully evaluate issues and report them to authors: https://github.com/mozilla-mobile/mozilla-vpn-client/issues/... https://github.com/signalapp/Signal-Desktop/issues/4121
Dual stack setups tend to hide IPv6 implementation issues and may create illusion that app is IPv6 compatible but in reality it's not.
Clearly my setup is too hostile for home users but as developer I enjoy it a lot.
-
I almost always ignore the pop-ups from browsers, but that one time I clicked, it tells me to... "Join the Waitlist?" They seem to go hard on talking about their VPN, why can't I "just download it"? What's the problem? Why Waitlist? Is this scam?
Mozilla VPN is still in "beta testing" mode, and while everyone works out issues with clients, subscriptions, and all the other fun, it's better to limit the scope of a test. Mozilla VPN will roll out into more countries over time, and if yo want to know when, there's a "join the waitlist"-button on https://vpn.mozilla.org/.
- Most websites dont load on ubuntu
-
is mozillavpn cli friendly?
A CLI is available - never used it in a headless environment yet. Hope that helps :) https://github.com/mozilla-mobile/mozilla-vpn-client/blob/main/docs/Command-line-interface.md
- Mozilla bundles its VPN and email relay services for $7 per month
-
Firefox Private Network (only $2.99 a month)
No. The Firefox Private Network browser extension offers set and forget network protection while you shop, bank, and browse in Firefox. It’s lightweight and simple. A VPN is a more robust software application that allows location switching. It’s a separate app you install to secure everything on your device that connects to the internet, including all browsers, social media apps, and banking apps. Learn more if you’re interested in our VPN.
-
Firefox and fingerprinting
Having said that, people can only track you if you make connections to their domains. If you don't even want the owner of a site you visit directly to know you visit it, use Mozilla VPN (if available in your country) or a slower free alternative like Tor or VPN Gate.
What are some alternatives?
bypass-paywalls-chrome - Bypass Paywalls web browser extension for Chrome and Firefox.
multi-account-containers - Firefox Multi-Account Containers lets you keep parts of your online life separated into color-coded tabs that preserve your privacy. Cookies are separated by container, allowing you to use the web with multiple identities or accounts simultaneously.
ungoogled-chromium-archlinux - Arch Linux packaging for ungoogled-chromium
network-manager-wireguard - NetworkManager VPN Plugin: Wireguard
uBlock - uBlock Origin - An efficient blocker for Chromium and Firefox. Fast and lean.
ungoogled-chromium - Google Chromium, sans integration with Google
chromium - The official GitHub mirror of the Chromium source
dns-adblock - Ad, tracker, adult content and gambling blocking for our DNS blocking service [Moved to: https://github.com/mullvad/dns-blocklists]
AmIUnique - Learn how identifiable you are on the Internet
openvpn3-linux - OpenVPN 3 Linux client
brave-browser - Brave browser for Android, iOS, Linux, macOS, Windows.
Fenix - ⚠️ Fenix (Firefox for Android) moved to a new repository. It is now developed and maintained as part of: https://github.com/mozilla-mobile/firefox-android