Bug 27348 - Firefox: [privacy, compliance] External content loaded by default on startpage
Summary: Firefox: [privacy, compliance] External content loaded by default on startpage
Status: REOPENED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: All Packagers
QA Contact:
URL:
Whiteboard:
Keywords: Triaged
Depends on:
Blocks: 28788
  Show dependency treegraph
 
Reported: 2020-10-02 22:00 CEST by Hartmut Goebel
Modified: 2021-07-12 11:32 CEST (History)
2 users (show)

See Also:
Source RPM: firefox-78.3.0-1.mga7.src.rpm
CVE:
Status comment:


Attachments
startpage show the compromising section (270.53 KB, image/png)
2020-10-02 22:01 CEST, Hartmut Goebel
Details
screenshot from Mageia 8 (226.91 KB, image/png)
2021-07-12 11:30 CEST, Hartmut Goebel
Details

Description Hartmut Goebel 2020-10-02 22:00:31 CEST
Description of problem:

The "Firefox Startpage" by default contains a section "Recommended by Pocket". In this section external content is loaded from Pocket.

This section shall be OFF by default, as is leak personal identifiable data to Pocket/Mozilla without prior explicit consent. Thus this setting does not comply to GDPR.

Version-Release number of selected component (if applicable):


How reproducible:
Start Firefox with default setting.


What I'd expect:

Since Mozilla most probably will not fix this issue any time soon, Mageia should difable this section my default. This can be done by setting as default:

"browser.newtabpage.activity-stream.feeds.section.topstories = false"
Comment 1 Hartmut Goebel 2020-10-02 22:01:32 CEST
Created attachment 11898 [details]
startpage show the compromising section
Comment 2 Aurelien Oudelet 2020-10-03 13:27:57 CEST
Hi, thanks reporting this.

This should really reported upstream and link provided here.
We are really concerned by GDPR / Privacy use with Mageia operating system.

Assigning to recent commiters on Firefox to look at this.
Packager: Please set the status to 'assigned' if you are working on it.

Meanwhile, there is a UI toggle in Preferences -> Welcome pane.

CC: (none) => ouaurelien
Keywords: (none) => Triaged

Aurelien Oudelet 2020-10-03 13:29:24 CEST

Assignee: bugsquad => nicolas.salguero

Comment 3 Morgan Leijström 2020-10-03 14:21:34 CEST
If this really is against GDPR, Mozilla should be interested to fix this.

@Hartmut, please search for / file upstream bug.

CC: (none) => fri

Comment 4 Hartmut Goebel 2020-10-03 14:45:57 CEST
This clearly is against GDPR, which requires explicit consent *prior* to transmitting personal identifiable data. Se criteria listed at https://gdpr.eu/article-6-how-to-process-personal-data-legally/.
Nicolas Salguero 2021-01-20 15:39:42 CET

Assignee: nicolas.salguero => pkg-bugs

Aurelien Oudelet 2021-04-16 13:20:43 CEST

Blocks: (none) => 28788

Morgan Leijström 2021-04-16 18:12:55 CEST

Summary: [privacy, compliance] External content loaded by default on startpage => Firefox: [privacy, compliance] External content loaded by default on startpage

Comment 5 Aurelien Oudelet 2021-07-06 13:15:31 CEST
Mageia 7 is EOL since July 1st 2021.
There will not have any further bugfix for this release.

You are encouraged to upgrade to Mageia 8 as soon as possible.

@reporter, if this bug still apply with Mageia 8, please let us know it.

@packager, if you work on the Mageia 7 version of your package, please check the Mageia 8 package if issue is also present. In this case, please fix the Mageia 8 version instead.

This bug report will be closed OLD if there is no further notice within 1st September 2021.
Comment 6 Hartmut Goebel 2021-07-07 17:19:52 CEST
This very issue ("top-sites by pocket") is gone.

Status: NEW => RESOLVED
Resolution: (none) => OLD

Comment 7 Hartmut Goebel 2021-07-12 11:30:13 CEST
(In reply to Hartmut Goebel from comment #6)
> This very issue ("top-sites by pocket") is gone.

Sorry, I was wrong; This is *not* solved in Mageia 8, see attached new screenshot.

Resolution: OLD => (none)
Version: 7 => 8
Status: RESOLVED => REOPENED

Comment 8 Hartmut Goebel 2021-07-12 11:30:55 CEST
Created attachment 12857 [details]
screenshot from Mageia 8
Comment 9 Hartmut Goebel 2021-07-12 11:32:12 CEST
Proposed solution:

Change default setting of 

"browser.newtabpage.activity-stream.feeds.section.topstories = false"

Note You need to log in before you can comment on or make changes to this bug.