Feeds

Mozilla explains user-tracking proposal for Firefox

Telemetry has no UUID, Metrics Data Ping might

3 Big data security analytics techniques

In a story published yesterday your humble Reg writer wrongly confused Mozilla's Telemetry project with the open-source outfit's so-called Metrics Data Ping proposal. Mozilla has been in touch to clear things up.

The org's global privacy and policy boss Alex Fowler kindly explained the differences between the two systems to us.

"The Metrica Data Ping proposal is not Telemetry. Telemetry is a component of Firefox that collects anonymous browser performance data for around 200 data points. It's voluntary, doesn't include a universally unique identifier (UUID), and is under the user's control," he said.

As we noted in our earlier piece, the Telemetry project that transmits data via secure encryption was slotted into Mozilla's browser, Firefox 7, in September last year.

Fowler continued:

The Metrics Data Ping is currently a proposal under consideration to understand usage statistics. The proposal is to begin collecting a limited data set of fewer than 30 non-personal data elements in a statistically valid approach.

The current thinking is for the ping to be opt-out and introduce a UUID to enable longitudinal analysis. Users would be provided notice of the data collection and how it will contribute to the stability and performance of Firefox, the ability to view the non-personal data collected, and also to opt-out of the collection.

In addition, the team is developing other privacy-enhancing sampling techniques to further limit the collection wherever possible.

Mozilla works in the open and we are under active discussions about various approaches to determine how to measure Firefox usage so that we can improve the features and performance for all users.

As with any Mozilla project or offering we will make sure that if the proposal is integrated into Firefox, it's in accordance with the Mozilla's Privacy Principles and gives users complete control over their data.

Our original story wrongly suggested that a proposal had been put forward for Telemetry to have the longitudinal analysis UUID loaded into it. However, it is in fact being mulled over for use with Mozilla's Metrics Data Ping.

Thanks to those readers who got in touch to point out the errors in that story, and we sincerely hope this piece clarifies Mozilla's current position on tracking users online.

The outfit's privacy policy is here, while the public and sometimes fiery discussion about the Metrics Data Ping proposal can be viewed here.

It's a debate well worth getting stuck into. ®

SANS - Survey on application security programs

More from The Register

next story
Android engineer: We DIDN'T copy Apple OR follow Samsung's orders
Veep testifies for Samsung during Apple patent trial
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Batten down the hatches, Ubuntu 14.04 LTS due in TWO DAYS
Admins dab straining server brows in advance of Trusty Tahr's long-term support landing
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
Half of Twitter's 'active users' are SILENT STALKERS
Nearly 50% have NEVER tweeted a word
Internet-of-stuff startup dumps NoSQL for ... SQL?
NoSQL taste great at first but lacks proper nutrients, says startup cloud whiz
Windows 8.1, which you probably haven't upgraded to yet, ALREADY OBSOLETE
Pre-Update versions of new Windows version will no longer support patches
Microsoft TIER SMEAR changes app prices whether devs ask or not
Some go up, some go down, Redmond goes silent
Red Hat to ship RHEL 7 release candidate with a taste of container tech
Grab 'near-final' version of next Enterprise Linux next week
Ditch the sync, paddle in the Streem: Upstart offers syncless sharing
Upload, delete and carry on sharing afterwards?
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.