Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 324347 - mozilla-firefox: mozilla google-search rls and moz:distributionID are privacy issues
Summary: mozilla-firefox: mozilla google-search rls and moz:distributionID are privacy...
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High normal with 1 vote (vote)
Assignee: Mozilla Gentoo Team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-06-16 17:09 UTC by niogic
Modified: 2010-12-30 23:08 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description niogic 2010-06-16 17:09:24 UTC
This bug was originally discovered in debian (bugs.debian.org/405370).
That bug is obsolete (because google parameters changed), but the problem is the same.

I'm wondering: why do "/usr/portage/eclass/mozcoreconf-2.eclass" contain
mozconfig_annotate gentoo [...] --with-distribution-id=org.gentoo

That eclass applies to both xulrunner and mozilla-firefox.
Maybe there could be a "privacy" useflag to let the user choose if to expose it's distro name (like apache has its ServerTokens config option).

For example that information is used in "/usr/lib/mozilla-firefox/searchplugins/google.xml"
<Param name="rls" value="{moz:distributionID}:{moz:locale}:{moz:official}"/>

That line could be completely dropped.


I personally suggest to remove --with-distribution-id flag and to create a patch to the default google.xml search plugin.
Comment 1 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-06-16 17:21:47 UTC
This feels a little over-paranoid. There are lots of ways others (including Google) could find out what distro you use, ripping stuff out here is really just an unneeded a drop in the bucket imo. So -1 from me.

mozilla?
Comment 2 Jory A. Pratt gentoo-dev 2010-06-16 21:38:34 UTC
your way to paranoid. not gonna change in main tree
Comment 3 niogic 2010-06-25 01:45:49 UTC
If you say the world "hey i'm using gentoo" (in the useragent.vendor), then they will fingerprint you.
Because it restricts a lot the pool of configurations and very little entropy is enough to identify you univocally.

If you have a look in mozilla bugzilla there are a lot of bugs about fingerprinting.
They don't RESOLVE INVALID.


This bug is distribution-level so it should stay here.
Comment 4 Jory A. Pratt gentoo-dev 2010-12-29 04:52:52 UTC
When firefox-4.0 rolls out you will get your wish, I am not gonna make a change to the tree before then, any then only reason is due to fact that id has been drop'd completely from upstream.
Comment 5 niogic 2010-12-30 23:08:30 UTC
To all who said I was paranoid

:-P