this post was submitted on 06 Mar 2025
417 points (98.8% liked)

Open Source

33927 readers
180 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 5 years ago
MODERATORS
 

Thought this was interesting and worth knowing about

you are viewing a single comment's thread
view the rest of the comments
[–] Zerush@lemmy.ml 43 points 3 days ago* (last edited 3 days ago) (3 children)

Thunderbird May Disclose Information To: Mozilla Affiliates: Thunderbird is a project of MZLA Technologies Corporation, a subsidiary of Mozilla Foundation and an affiliate of Mozilla Corporation, and as such, shares some of the same infrastructure. This means that, from time to time, your data (e.g., crash reports, and technical and interaction data) may be** disclosed to Mozilla Corporation and Mozilla Foundation**. If so, it will be maintained in accordance with the commitments we make in this Privacy Notice.

DNS servers, Standard Autoconfiguration URIs, and Mozilla's Configuration Database: To simplify the email set-up process, Thunderbird tries to determine the correct settings for your account by contacting Mozilla’s configuration database as well as external servers. These include DNS servers and standard autoconfiguration URIs. During this process, your email domain may be sent to Mozilla's configuration database, and your email address may be disclosed to your network administrators.

Amazon Web Services: Thunderbird uses Amazon Web Services (AWS) to host its servers and as a content delivery network. Your device’s IP address is collected as part of AWS’s server logs.

Email address providers (Desktop Only Legacy): Prior to version 128, Thunderbird partnered with Gandi.net and Mailfence to allow you to create a new email address through Thunderbird. If you choose to use this feature, your email address search terms are sent to Gandi.net and Mailfence to return available addresses. In addition, your country location is also shared to provide the correct prices. You can learn more about Gandi.net’s and Mailfence’s data practices by reading their privacy notices.

Always good to read TOS and PP of an service.

[–] TheOctonaut@mander.xyz 20 points 2 days ago (2 children)

I'm always confused when people are surprised by something like an account sync meaning that the operators have to store your data

Makes me wonder if they understand how Lemmy works...

[–] Zerush@lemmy.ml 2 points 1 day ago (1 children)

Yes, naturally to create an account for Sync, they have to store your data. But it's not the same if they also share these with third parties.

[–] TheOctonaut@mander.xyz 1 points 1 day ago (2 children)

If third parties means AWS, then every website you've accessed this year shares your data with third parties. This is why the GDPR exists.

[–] Zerush@lemmy.ml 0 points 1 day ago* (last edited 1 day ago) (1 children)

Yes, but this is a different thing. It's clear that you are not private, even using TOR, if you use Google for search, post on Fakebook or use another page/service which logs and profile your activity, but it's different if the browser itself or/and its company is tracking you, sharing it with third parties. That is the point. GDPR limit this to an minimum, but don't avoid it completely. More than ever is important that you ALWAYS read TOS and PP of every app/service before using it. A good rule is: longer and more written in a legal jargon, difficult to understand and many external links, it is a sign that the app or service is trying to hide its activities and dark patterns by boring the user. A honest app/service don't need this tricks, using a short and clear text.

[–] TheOctonaut@mander.xyz 1 points 1 day ago (1 children)

Are you under the impression that what you quoted is a long or unclear text?

[–] Zerush@lemmy.ml 1 points 20 hours ago

That of Mozilla is enough clear, although not much better with several external links that must be checked separately. But in general it is a fairly valid rule that the site has things to hide if it puts a very long legal text. A normal user does not bother to read a text of 2 or more pages in a difficulty legal jargon.

Honest sides don't need to do it, good examples are the PPs of the SSuite (the shortest ever) or Andisearch, which are between the bests I know.

[–] Legume5534@lemm.ee 1 points 1 day ago

Depends. Every hostname accessed? Sure. Every full URL? Not with https being everywhere these days.

[–] anzo@programming.dev 4 points 2 days ago

Not a counterpoint, but to extend a bit on how it could be done: encrypted data. Or, self-hosting server part available, like Mozilla's (i.e. GarduaLinux has a fork of Librewolf/ Floorp, called Firedragon which uses their own firefox server for account sync)

[–] Xeroxchasechase@lemmy.world 10 points 3 days ago (1 children)
[–] greywolf0x1@lemmy.ml 1 points 2 days ago (1 children)

your network administrators

What does network administrators mean in this context? Your ISP?

[–] ILikeBoobies@lemmy.ca 1 points 1 day ago

The person who manages your router