611
  • Mozilla has launched a paid subscription service called Mozilla Monitor Plus, which monitors and removes personal information from over 190 sites where brokers sell data.
  • The service is priced at $8.99 per month and is an extension of the free dark web monitoring service Mozilla Monitor (previously Firefox Monitor).
  • Basic Monitor members receive a free scan and one-time removal sweep, while Plus members get continual monthly data broker scans and removal attempts.

Archive link: https://archive.ph/YdY3R

all 40 comments
sorted by: hot top controversial new old
[-] Feathercrown@lemmy.world 94 points 2 years ago

God bless the Mozilla foundation

[-] Rodeo@lemmy.ca 80 points 2 years ago* (last edited 2 years ago)

How can they know it's your data without first collecting your data to compare it?

"Give us your personal information so we can ask others to delete your personal information" just doesn't sound like a trustworthy offer.

[-] Steve@communick.news 108 points 2 years ago* (last edited 2 years ago)

I can also see the irony. But I can't imagine another way to do it at any scale. Do you know of another option?

[-] Static_Rocket@lemmy.world 13 points 2 years ago* (last edited 2 years ago)

Something akin to haveibeenpwned.com password hash partial match? Can that even be done with this data?

Edit: You goofs know you can calculate the hash locally and submit it for review without actually exposing your password to them right? That's how bitwarden does it's check. https://www.troyhunt.com/ive-just-launched-pwned-passwords-version-2/#cloudflareprivacyandkanonymity

Ah, but Mozilla isn't even trying to do anything cool like that. They just use onereap and those fuckers look shady. Quotes from their privacy policy: https://onerep.com/privacy-policy#what-data-we-collect-and-how-we-do-that

We use your Personal Information for a number of purposes, which may include the following:

[snip]

  • To display advertisements to you.
  • To manage our Affiliate marketing program.

There will be times when we may need to disclose your Personal Information to third parties. We may disclose your Personal Information to:

[snip]

  • Third-party service providers and partners who assist us in the provision of the Services and Website, for example, (a) those who support delivery of or provide certain features in connection with the Services and Website (e.g. Stripe, a payment services provider; Sendgrid, an email delivery service; HubSpot, a CRM platform, and Sentry, a crash reporting platform); (b) providers of analytics and measurement services (e.g. Google Analytics, ProfitWell etc.); (c) providers of technical infrastructure services (e.g. Microsoft Azure, Google Cloud, and Amazon AWS); (d) providers of customer support services (e.g. Zendesk); (e) those who facilitate conduct of surveys (e.g. Hotjar); (f) those who help to advertise, market or promote our Services and Website (e.g. Mautic, Facebook Ads, Google Ads, Linkedin Ads, Reddit Ads, and Microsoft Ads);

The bastards

[-] Bitrot@lemmy.sdf.org 62 points 2 years ago* (last edited 2 years ago)

No. If your name is Dave Jones they have to look around those broker sites for Dave Jones. If those sites were using hashes then they could use hashes too.

This is no different than any credit or identity monitoring service. The need to give them basic information should be obvious, people have to decide if the company is trustworthy or not.

[-] Peer@discuss.tchncs.de 4 points 2 years ago

They could just look for names, then hash those names and compare them to your hashed name. So technically that don’t need to store your data, just hashes.

[-] Lmaydev@programming.dev 7 points 2 years ago* (last edited 2 years ago)

I'm all for privacy but worrying about giving one of the most trustworthy companies around your name seems a bit much.

You'd also have to give them your card details to pay for it.

This would also require searching and indexing the entire system as opposed to searching it.

[-] fruitycoder@sh.itjust.works 1 points 2 years ago

Need a Moreno payment system

[-] Lmaydev@programming.dev 3 points 2 years ago

Tbf if someone logged that you were paying for this service that data would get removed anyway haha

[-] Steve@communick.news 23 points 2 years ago

The front page there is literally: "Give us your email, so we can find leaks of your email." It's exactly the same thing.

[-] Bitrot@lemmy.sdf.org 15 points 2 years ago

They are talking about the password lookup: https://haveibeenpwned.com/Passwords

But, it's the same deal. You have to trust they are actually doing what they say. Mozilla uses haveibeenpwned for their basic Monitor service too.

[-] Nyfure@kbin.social 14 points 2 years ago

To be fair, you can check the code they run or just use the API.
The hash is calculated locally, cut-off and then send, the server returns all hashes it found which start with your one and then you can check if yours in in the list locally.

[-] ambrosiaforest 1 points 2 years ago

ah yes. type your password in here we totally wont steal it

[-] claudiop@lemmy.world 9 points 2 years ago

Y'know that you can see the requests your browser makes, right? Mind putting in here a screenshot of HIBP uploading your password or any complete hash of it?

Failing to provide that grants you the "talking shit out of ya ass" award.

[-] admiralteal@kbin.social 14 points 2 years ago

No, because you are asking the data broker to do something with your data that they possess. It is not possible for them to delete your data without knowing which are your data.

The only alternative is fully banning this kind of data collection. Which would be nice, but isn't happening anytime soon.

[-] TrickDacy@lemmy.world 39 points 2 years ago

Unless you trust Mozilla. I'm unaware of another organization that is more trustworthy, despite the haters mad that CEOs make money.

[-] Neato@ttrpg.network 34 points 2 years ago

Likely you must provide Mozilla with basic identifying data like name and birth date. Which isn't all that radical since you're giving them quite a bit more by paying them.

[-] AeonFelis@lemmy.world 32 points 2 years ago

It's better when it's in their hands, because:

  1. It's Mozilla - one of the more trusty organizations out there.
  2. They don't get your information in some sneaky way from some source that was never supposed to be available to them.
  3. You know exactly how they make money from your data.
[-] Defaced@lemmy.world 20 points 2 years ago

It's ironic yeah, but if trust is the only way to implement something like this, then Mozilla is probably the one company I would trust considering they're a non-profit org.

[-] pineapplelover@lemm.ee 2 points 2 years ago

The way I see it, if you're asking for data removal, it's because your identity is public online already, the company has nothing else to gain maybe other than the payment information and you can get a new card if they just happened to be untrustworthy.

[-] subignition@kbin.social 48 points 2 years ago

There are already plenty of companies that sell managed data removal like this, Mozilla claims to be doing it better and perhaps they are incrementally more trustworthy than the smaller no name ones

[-] TheIllustrativeMan@lemmy.world 8 points 2 years ago

Discover does it for free, but they only do so on a handful of sites.

[-] Sabata11792@kbin.social 29 points 2 years ago

Decided to try it out, 489 request in progress vs the 10 from a year with Discovers free takedowns.

[-] TheIllustrativeMan@lemmy.world 3 points 2 years ago

I think it was only 3 when I first signed up, so that's an improvement. They probably hit the ones most likely to honor takedown requests, but yeah 190 sites is more than 10. $9 is more than $0 too though, so it's a balance.

I wonder how many sites like this actually exist. Probably over a thousand would be my guess.

[-] maccentric@sh.itjust.works 5 points 2 years ago

I just tried to enable it, they want $15/month.

[-] TheIllustrativeMan@lemmy.world 1 points 2 years ago

Sounds like you're looking at their identity theft bullshit? The data removal is free, but only for 10 sites.

[-] maccentric@sh.itjust.works 1 points 2 years ago

Probably so. How do you sign up for the data removal?

[-] jqubed@lemmy.world 35 points 2 years ago

If I’m reading this correctly, are they basically just reselling the Onerep service ($14.95/monthly or $99.96/annually) for $8.99/month?

[-] LWD@lemm.ee 19 points 2 years ago* (last edited 1 month ago)
[-] irreticent@lemmy.world 10 points 2 years ago

And there are other alternatives besides.

If you have a Discover card they'll do the monitoring/removal for free.

[-] Bitrot@lemmy.sdf.org 26 points 2 years ago

Discover only removes it from ten sites.

[-] irreticent@lemmy.world 7 points 2 years ago

Oh, thanks. I didn't know.

[-] autotldr@lemmings.world 18 points 2 years ago

This is the best summary I could come up with:


For $8.99 a month under its annual subscription, Mozilla says it will automatically keep a lookout for your information at over 190 sites where brokers sell information they’ve gathered from online sources like social media sites, apps, and browser trackers, and when your info is found, it will automatically try to get it removed.

Mozilla Monitor product manager Tony Cinotto told The Verge in an email that Mozilla partners with a company called Onerep to perform these scans and subsequent takedown requests.

Mozilla will keep trying, he added, but will also give Plus members instructions for attempting removal themselves.

Basic Monitor members will get a free scan and one-time removal sweep, plus continual monthly data broker scans afterward, Mozilla says.

Mozilla says its data broker scans can find details online like your name and current and previous home addresses but adds that it could go as deep as criminal history, hobbies, or your kids school district.

Services like this are fairly common, but they’re not all that well known to most people and searching for them is as likely to turn up sketchy scam sites as it is legitimate service providers like, for instance, DeleteMe.


The original article contains 325 words, the summary contains 195 words. Saved 40%. I'm a bot and I'm open source!

[-] ares35@kbin.social 17 points 2 years ago

services like this rely upon the data harvesters and brokers to honor removal requests. honest ones would. but there's tons of them that aren't legit, so it's like using a straw to empty lake superior.

[-] ohlaph@lemmy.world 5 points 2 years ago

Exactly. I trust Mozilla, but I absolutely do not trust the broker sites to actually honor a request to remove data.

[-] thehatfox@lemmy.world 4 points 2 years ago

Even for the “honest” data collectors I’m sceptical any of these services really work. Privacy and data protection laws are weak in many places, and even the countries that have enacted better legislation in this regard often have fairly toothless enforcement. Data is the new oil and is far too valuable for companies to want to part with. There seems little real incentive for companies to truthfully cooperate with these schemes.

[-] TheDarkKnight@lemmy.world 4 points 2 years ago

We need chain of custody data laws. If FB sells your data they’re responsible for keeping a chain of custody as to who they sold it to and requests for removal need to follow that chain down with regular audits and stiff fines for noncompliance.

[-] SeekPie@lemmy.world 17 points 2 years ago

Almost got a heart attack when I read that they made a subscription service.

[-] OscarRobin@lemmy.world 10 points 2 years ago

If they added automatic online account collation and mass deletion I'd pay them $100 on the spot to wipe the hundreds of random accounts I have on sites/services I never use and often have never used.

this post was submitted on 06 Feb 2024
611 points (100.0% liked)

Technology

73698 readers
4128 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS