- Mozilla has launched a paid subscription service called Mozilla Monitor Plus, which monitors and removes personal information from over 190 sites where brokers sell data.
- The service is priced at $8.99 per month and is an extension of the free dark web monitoring service Mozilla Monitor (previously Firefox Monitor).
- Basic Monitor members receive a free scan and one-time removal sweep, while Plus members get continual monthly data broker scans and removal attempts.
Archive link: https://archive.ph/YdY3R
How can they know it’s your data without first collecting your data to compare it?
“Give us your personal information so we can ask others to delete your personal information” just doesn’t sound like a trustworthy offer.
Unless you trust Mozilla. I’m unaware of another organization that is more trustworthy, despite the haters mad that CEOs make money.
The CEO is making an inordinate amount of money. $6.9 million is excessive.
You can argue that Mozilla should be held to the same low standard as every other corporation, but if you do that, you have to take into account that the Mozilla CEO got a huge pay raise in a year where other CEOs got less money.
$6.9MM is a perfectly reasonable compensation package for a $500MM organization and is probably low to attract a significant number of quality candidates.
It’s better when it’s in their hands, because:
- It’s Mozilla - one of the more trusty organizations out there.
- They don’t get your information in some sneaky way from some source that was never supposed to be available to them.
- You know exactly how they make money from your data.
I can also see the irony. But I can’t imagine another way to do it at any scale. Do you know of another option?
Something akin to haveibeenpwned.com password hash partial match? Can that even be done with this data?
Edit: You goofs know you can calculate the hash locally and submit it for review without actually exposing your password to them right? That’s how bitwarden does it’s check. https://www.troyhunt.com/ive-just-launched-pwned-passwords-version-2/#cloudflareprivacyandkanonymity
Ah, but Mozilla isn’t even trying to do anything cool like that. They just use onereap and those fuckers look shady. Quotes from their privacy policy: https://onerep.com/privacy-policy#what-data-we-collect-and-how-we-do-that
We use your Personal Information for a number of purposes, which may include the following:
[snip]
- To display advertisements to you.
- To manage our Affiliate marketing program.
There will be times when we may need to disclose your Personal Information to third parties. We may disclose your Personal Information to:
[snip]
- Third-party service providers and partners who assist us in the provision of the Services and Website, for example, (a) those who support delivery of or provide certain features in connection with the Services and Website (e.g. Stripe, a payment services provider; Sendgrid, an email delivery service; HubSpot, a CRM platform, and Sentry, a crash reporting platform); (b) providers of analytics and measurement services (e.g. Google Analytics, ProfitWell etc.); © providers of technical infrastructure services (e.g. Microsoft Azure, Google Cloud, and Amazon AWS); (d) providers of customer support services (e.g. Zendesk); (e) those who facilitate conduct of surveys (e.g. Hotjar); (f) those who help to advertise, market or promote our Services and Website (e.g. Mautic, Facebook Ads, Google Ads, Linkedin Ads, Reddit Ads, and Microsoft Ads);
The bastards
No, because you are asking the data broker to do something with your data that they possess. It is not possible for them to delete your data without knowing which are your data.
The only alternative is fully banning this kind of data collection. Which would be nice, but isn’t happening anytime soon.
The front page there is literally: “Give us your email, so we can find leaks of your email.” It’s exactly the same thing.
No. If your name is Dave Jones they have to look around those broker sites for Dave Jones. If those sites were using hashes then they could use hashes too.
This is no different than any credit or identity monitoring service. The need to give them basic information should be obvious, people have to decide if the company is trustworthy or not.