From 92d754fb6b4e0d49095bdd73d90dec87018b3339 Mon Sep 17 00:00:00 2001 From: anonymouse Date: Tue, 31 May 2022 23:19:48 -0400 Subject: [PATCH] Updated Waterfox, Opera and Vivaldi articles --- articles/opera.html | 127 ++++++++++----------------- articles/vivaldi.html | 42 ++++----- articles/waterfox_classic.html | 11 +-- guides/files/spyware.asc | 51 +++++++++++ images/PowerISO7-x64_1.png | Bin 39459 -> 43791 bytes images/PowerISO7-x64_2.png | Bin 29598 -> 36160 bytes images/activelink.png | Bin 4115 -> 5104 bytes images/badwolf.png | Bin 8046 -> 8642 bytes images/bg.jpg | Bin 3041 -> 3267 bytes images/bing_logo.png | Bin 2411 -> 3260 bytes images/blackbg.jpg | Bin 1012 -> 1402 bytes images/bleachbit_logo.png | Bin 53649 -> 41237 bytes images/blocklist.png | Bin 1592 -> 2712 bytes images/brave/brave-cert.png | Bin 11642 -> 13029 bytes images/brave/brave-dict.png | Bin 10380 -> 11437 bytes images/brave/brave-extensions.png | Bin 44220 -> 53769 bytes images/brave/brave-gstatic.png | Bin 46718 -> 45327 bytes images/brave/brave-static.png | Bin 36408 -> 43920 bytes images/brave/brave_logo.png | Bin 8479 -> 9444 bytes images/brave/custom-headers.png | Bin 20163 -> 60208 bytes images/brave/google-brave.png | Bin 43715 -> 58652 bytes images/cc0.png | Bin 991 -> 1900 bytes images/ccleaner_logo.png | Bin 15753 -> 16184 bytes images/ccleaner_privacy.png | Bin 67275 -> 75380 bytes images/cdex_bundling.png | Bin 25478 -> 27847 bytes images/cdex_logo.png | Bin 18443 -> 18746 bytes images/chrome_logo.png | Bin 11531 -> 11868 bytes images/chromium_logo.png | Bin 9908 -> 10391 bytes images/clementine.png | Bin 19027 -> 19994 bytes images/ddg_logo.png | Bin 16204 -> 17862 bytes images/discord_2.png | Bin 16469 -> 26565 bytes images/discord_data.png | Bin 9661 -> 13490 bytes images/discord_logo.png | Bin 2450 -> 4987 bytes images/discord_process_logging.png | Bin 44834 -> 59889 bytes images/discord_verify.png | Bin 17770 -> 22914 bytes images/dissenter_ext_ph.png | Bin 39731 -> 49958 bytes images/dissenter_logo.png | Bin 1592 -> 3951 bytes images/dissenter_phone_home_1.png | Bin 45201 -> 56388 bytes images/dissenter_safebrowsing.png | Bin 1956 -> 2446 bytes images/example_logo.png | Bin 1616 -> 3434 bytes images/falkon_firstrun.png | Bin 2704 -> 3423 bytes images/falkon_logo.png | Bin 13869 -> 14520 bytes images/firefox_logo3.png | Bin 17302 -> 17911 bytes images/fpseek.png | Bin 2867 -> 4428 bytes images/google_logo.png | Bin 4055 -> 5249 bytes images/gzdoom_logo.png | Bin 25511 -> 23221 bytes images/hexchat_logo.png | Bin 5916 -> 7771 bytes images/icecat_logo.png | Bin 29019 -> 27061 bytes images/icecat_phones_home.png | Bin 43671 -> 58538 bytes images/ie_logo.png | Bin 15869 -> 16533 bytes images/ig_logo.png | Bin 15726 -> 16154 bytes images/ig_sshot.png | Bin 184307 -> 198729 bytes images/iridium_disablesb.png | Bin 33442 -> 45755 bytes images/iridium_logo.png | Bin 10201 -> 13837 bytes images/iridium_request.png | Bin 15835 -> 27465 bytes images/iron_bing.png | Bin 6680 -> 14768 bytes images/iron_connections.png | Bin 24890 -> 30556 bytes images/iron_spyware.png | Bin 811811 -> 997126 bytes images/itunes_logo.png | Bin 140320 -> 195223 bytes images/itunes_spyware1.png | Bin 3745 -> 6230 bytes images/ksp_logo.png | Bin 12961 -> 12827 bytes images/librewolf.svg | 26 ++---- images/logo.png | Bin 22261 -> 28494 bytes images/lynx_logo.png | Bin 129025 -> 131669 bytes images/netsurf.png | Bin 12993 -> 15547 bytes images/opera_firstrun.png | Bin 698 -> 0 bytes images/opera_geo.png | Bin 617 -> 0 bytes images/opera_geolocation_spyware.png | Bin 0 -> 18312 bytes images/opera_logo.png | Bin 8544 -> 9037 bytes images/opera_partner_content.png | Bin 966 -> 0 bytes images/opera_partner_spyware.png | Bin 0 -> 155667 bytes images/opera_sitecheck.png | Bin 1525 -> 0 bytes images/opera_sitecheck_spyware2.png | Bin 0 -> 60982 bytes images/opera_spyware.png | Bin 0 -> 600882 bytes images/osw.jpg | Bin 1995 -> 1986 bytes images/otter_browser_logo.png | Bin 22977 -> 23828 bytes images/paintnet_logo.png | Bin 5398 -> 5608 bytes images/palemoon_logo.png | Bin 24778 -> 25326 bytes images/piso_extension.png | Bin 52897 -> 67420 bytes images/piso_installer_phone_home.png | Bin 24139 -> 80448 bytes images/piso_scripts.png | Bin 8901 -> 13300 bytes images/pm_analytics.png | Bin 74312 -> 114071 bytes images/pm_hp.png | Bin 16657 -> 19231 bytes images/pm_ud.png | Bin 19699 -> 23694 bytes images/poweriso_logo.png | Bin 8728 -> 18842 bytes images/qutebrowser_logo.png | Bin 7928 -> 10978 bytes images/razer_logo.png | Bin 9740 -> 15443 bytes images/realplayer_logo.png | Bin 19037 -> 19631 bytes images/redshell_logo.png | Bin 8002 -> 10715 bytes images/request.png | Bin 697 -> 1002 bytes images/request2.png | Bin 1634 -> 2548 bytes images/safe_browsing.png | Bin 2793 -> 7287 bytes images/seamonkey/SeaMonkey.svg | 77 ++++++++-------- images/seamonkey/seamonkey.png | Bin 164087 -> 195031 bytes images/self_repair.png | Bin 5811 -> 10237 bytes images/sheilds_blocking.png | Bin 23149 -> 35562 bytes images/sj_cloud.png | Bin 5600 -> 6966 bytes images/sj_google_BITS.png | Bin 10240 -> 14488 bytes images/sj_google_BITS_2.png | Bin 17539 -> 23688 bytes images/sj_google_BITS_3.png | Bin 11034 -> 17486 bytes images/sj_google_requests.png | Bin 20840 -> 27872 bytes images/slimjet_logo.png | Bin 27870 -> 28584 bytes images/snapchat_logo.png | Bin 6648 -> 8126 bytes images/sphere_homepage.png | Bin 9642 -> 14266 bytes images/sphere_logo.png | Bin 3996 -> 7560 bytes images/sphere_tracking.png | Bin 20463 -> 30584 bytes images/srware_logo.png | Bin 43528 -> 44619 bytes images/steam_logo.png | Bin 6878 -> 9275 bytes images/surf_logo.png | Bin 261 -> 431 bytes images/telegram_logo.png | Bin 7930 -> 9225 bytes images/theevidence.png | Bin 74233 -> 132149 bytes images/thunderbird.png | Bin 16256 -> 16782 bytes images/tor_browser_logo.png | Bin 11751 -> 12369 bytes images/unity_analytics.png | Bin 16608 -> 22210 bytes images/unity_logo.png | Bin 16395 -> 17003 bytes images/utorrent_logo.png | Bin 18944 -> 19528 bytes images/vivaldi_logo.png | Bin 3403 -> 5095 bytes images/vivaldi_piwik.png | Bin 6897 -> 0 bytes images/vivaldi_safebrowsing.png | Bin 1865 -> 0 bytes images/vivaldi_spyware2.png | Bin 0 -> 603098 bytes images/vivaldi_spyware3.png | Bin 0 -> 633133 bytes images/vivaldi_threatlist.png | Bin 559 -> 0 bytes images/vivaldi_update.png | Bin 3663 -> 0 bytes images/vlc_logo.png | Bin 18410 -> 20103 bytes images/vlc_privacy_policy.png | Bin 13165 -> 17948 bytes images/w3c_logo.png | Bin 3930 -> 5224 bytes images/waterfox_classic_spyware.png | Bin 0 -> 491131 bytes images/waterfox_logo.png | Bin 5300 -> 10465 bytes images/wd1.jpg | Bin 72106 -> 67045 bytes images/wd2.jpg | Bin 55579 -> 51586 bytes images/wd3.jpg | Bin 109082 -> 99344 bytes images/wd4.jpg | Bin 52264 -> 49445 bytes images/wd5.jpg | Bin 114273 -> 103612 bytes images/wd6.jpg | Bin 119419 -> 108146 bytes images/wd7.jpg | Bin 64495 -> 62000 bytes images/wd8.jpg | Bin 77821 -> 74178 bytes images/wd9.jpg | Bin 76383 -> 73262 bytes images/web_browser_logo.png | Bin 8094 -> 11965 bytes images/webdiscover_logo.png | Bin 4978 -> 7070 bytes images/yahoo_logo.png | Bin 3453 -> 4338 bytes images/youtube_logo.png | Bin 3535 -> 3784 bytes misc.html | 2 +- style.css | 16 ++-- 143 files changed, 173 insertions(+), 179 deletions(-) create mode 100644 guides/files/spyware.asc delete mode 100644 images/opera_firstrun.png delete mode 100644 images/opera_geo.png create mode 100644 images/opera_geolocation_spyware.png delete mode 100644 images/opera_partner_content.png create mode 100644 images/opera_partner_spyware.png delete mode 100644 images/opera_sitecheck.png create mode 100644 images/opera_sitecheck_spyware2.png create mode 100644 images/opera_spyware.png delete mode 100644 images/vivaldi_piwik.png delete mode 100644 images/vivaldi_safebrowsing.png create mode 100644 images/vivaldi_spyware2.png create mode 100644 images/vivaldi_spyware3.png delete mode 100644 images/vivaldi_threatlist.png delete mode 100644 images/vivaldi_update.png create mode 100644 images/waterfox_classic_spyware.png diff --git a/articles/opera.html b/articles/opera.html index 300c408..d47fdf8 100644 --- a/articles/opera.html +++ b/articles/opera.html @@ -1,86 +1,53 @@ - + - - - + + + Opera — Spyware Watchdog + - Opera logo -

Opera

-

- A web browser made by Opera Software, using the Blink engine. Has some interesting features like mouse gestures, a built-in ad blocker and VPN. It is the sixth most popular browser. But how does it look like in terms of privacy? -

-

Spyware Level: EXTREMELY HIGH

-

- Opera makes 55 unsolicited requests upon its first run. By default, it spies on all your browsing history. Works closely with advertisers and trackers. Is integrated with Facebook, one of the biggest privacy violators in the world. Has Google as the default search engine. Closed source. -

- -

Geolocation

- -

The first request Opera makes is the geolocation request: which includes your country and the precise timestamp.

- -

Homepage request

- -

If this is the first time you run Opera, it makes this request: which will redirect you to their homepage. Then, that homepage will make a bunch of other requests, including to google analytics, facebook (if you're logged in, they now know who you are), and even yandex.ru. The yandex request will set a uniquely identifying cookie.

- -

Cxense analytics

- -

Later, it will make a few requests to cxense.com. What is Cxense?

- -

We are Cxense. We help hundreds of leading publishers and marketers across the globe transform their raw data into their most valuable resource. Built on the premise of 1:1 analytics and communication; allowing you to both gain unprecedented insight about your individual customers, and to action this insight real-time in all your marketing and sales channels.

- -

This request seems to include a unique ID

- -

Search engines

- -

Opera will also download a list of search engines, which you cannot delete, only add new ones (at least from the GUI). Apparently, there are some convoluted methods of deleting the search engines, but I haven't confirmed them. Of course, the default search engine is the anti-privacy Google.

- -

OCSP querying

- -

Opera will query OCSP servers (ocsp.comodoca.com) to check if SSL certificates expired. - -

Malware / Phishing protection

-

Anytime you visit a website, Opera will make a request like this: to check if it is malicious. So it is literally spying on your whole browsing history. Fortunately, this can be turned off.

- -

Other requests

- -

Other requests include ones to googletagmanager, google ads specific for your country, more requests to yandex (these include your screen size, encoding, and the page you came from), more geolocation, etc. Together, Opera made 55 unsolicited requests in my first run of it. Analyzing them all would probably take a book.

- -

Facebook integration

- -

Opera has a Facebook chat button on the sidebar, and Facebook is one of the most anti-privacy organizations out there.

- -

Opera's "Partners"

-

Opera has a list of "partners" — those are the websites that are in the Speed Dial by default. If you click on one of them from there, they will know you visited from Opera's Speed Dial. Those requests also include unique user IDs. - What happens if you close Opera and run it again? The websites in the Speed Dial will change to the ones from your country! And the same rule about them knowing where you came from applies.

- -

Opera is closed source

-

And it will stay that way. From their FAQ (the message used to be there in 2017, they must have deleted it somewhere in 2018):

- -

Opera has not officialy open sourced its browser. However, leaks of the Presto web engine Opera used have appeared on the internet.

- -

Even with that however, there could still other spyware might be hiding in there.

-
-
-

Credits

-

- This article was written by digdeeper.neocities.org
- Formatting changes were done by the site maintainer. -

-
-

- This article was last edited on 6/8/2018 -

-

- This article was created on 11/25/2017 -

-

- If you want to edit this article, or contribute your own article(s), visit us at the git repo on Codeberg. All contributions must be licensed under the CC0 license to be accepted. -

- CC0 License -

Back to catalog

-
- +
+ +
+ Opera logo +

Opera

+

A web browser made by Opera Software, using the Blink engine. Has some interesting features like mouse gestures, a built-in ad blocker and VPN. It is the sixth most popular browser. But how does it look like in terms of privacy?

+

Version tested: 87.0.4390.36

+

Spyware Level: EXTREMELY HIGH

+

Opera makes about 83 unsolicited requests on its first run:

+ +

By default, it spies on all your browsing. Works closely with advertisers and trackers. It is integrated with Facebook/Meta, one of the biggest privacy violators in the world. Has Google as the default search engine. Closed source.

+

Geolocation

+

Opera makes geolocation requests:

+ +

Malware / Phishing protection

+

Anytime you visit a website, Opera will make a request like this to check if it is malicious. So it is literally spying on your whole browsing history:

+ +

This can be turned off in the settings ("Privacy & Security" → "Privacy" → "Protect me from malicious sites").

+

Facebook, Instagram and WhatsApp integration

+

Opera has a Facebook Messenger, WhatsApp and Instagram button on the sidebar, and Facebook/Meta (which owns WhatsApp and Instagram) and is one of the most anti-privacy organizations out there.

+

Opera's "Partners"

+

Opera has a list of "partners" — those are the websites that are in the Speed Dial by default.

+ +

If you click on one of them from there, they will know you visited from Opera's Speed Dial. Those requests also include unique user IDs.

+

Opera is closed source

+

And it will stay that way. From their FAQ (the message used to be there in 2017, they must have deleted it somewhere in 2018):

+

Opera has not officialy open sourced its browser. However, leaks of the old Presto web engine Opera used to use have appeared on the internet.

+

Even with that however, there could still other spyware might be hiding in there.

+
+ +
+
+ diff --git a/articles/vivaldi.html b/articles/vivaldi.html index ced0efd..4445df2 100644 --- a/articles/vivaldi.html +++ b/articles/vivaldi.html @@ -13,43 +13,33 @@
vivaldi logo

Vivaldi

-

Vivaldi is a feature-full, customizable web browser made by some of Opera's old developers (since they were dissatisfied with the direction Opera was heading). But how does it look in terms of privacy? Versions 1.15 and 2.0 were tested to make this article. Program used for testing requests: Mitmproxy.

-

Spyware Level: Medium

-

Vivaldi makes a bunch of requests to Google upon startup and after (malware protection requests can be turned off, but extension updates don't appear to?). Phones home every 24 hours with a unique ID using Piwik, an analytics service. Anti-privacy Bing as the default search engine. Not fully open source. Connects to an analytics platform that spies on its users.

-

Vivaldi's developers do not respect your privacy

-

Vivaldi connects to the analytics platform Piwik[1] that it uses to spy on its users, which is discussed in greater detail in other sections of this page. What is most notable about this is the attitude of Vivaldi's developer team: Developers that belittle privacy concerns, and insult their users further when they speak out about being spied on, are not developers you can trust. Below is an anti-privacy rant from a moderator on Vivaldi's forums:

-

@dib_ Stop spreading FUD. Piwik as employed by Vivaldi is not "spyware." Piwik is not a "spyware company" (unless Google, Facebook, Yahoo, TVGuide, Microsoft, Apple, NYT, Huffpo, Ancestry.com, WaPo, CenturyLink and McAfee are "spyware companies" — in which case just disconnect your computer and go to bed). It is irresponsible and malicious of you to lie about Vivaldi in this fashion. If you want to know what a connection does, ask. But don't sling around reckless accusations.[2]

-

Addon updates

- Vivaldi Update -

These are the Chrome webstore requests, supposed to update your extensions. But with a new Vivaldi install, you don't have any, so they only accomplish spying. And the first request includes "x-googleupdate-appid" which is most likely uniquely identifying. Can't be disabled.

-

Google Safe Browsing

- Vivaldi SafeBrowsing - Vivaldi Threatlist -

Vivaldi is downloading the lists for Google's Malware and Phishing protection, which is enabled by default, but can be disabled from the Settings menu.

-

Phoning home

-

From Vivaldi's privacy policy: "When you install Vivaldi browser ('Vivaldi'), each installation profile is assigned a unique user ID that is stored on your computer. Vivaldi will send a message using HTTPS directly to our servers located in Iceland every 24 hours containing this ID, version, CPU architecture, screen resolution and time since last message. We anonymize the IP address of Vivaldi users by removing the last octet of the IP address from your Vivaldi client then we store the resolved approximate location after using a local geoip lookup. The purpose of this collection is to determine the total number of active users and their geographical distribution.". So they (claim to) delete "the last octet" of your IP. How generous of them. This is the full request:

- Vivaldi Piwik -

Anti-privacy search engine by default

-

The default search engine is Bing, whose privacy policy states: "Microsoft will collect the search or command terms you provide, along with your IP address, location, the unique identifiers contained in our cookies, the time and date of your search, and your browser configuration.". To make it worse, that data is shared with third parties: "We share some de-identified search query data, including voice queries, with selected third parties for research and development purposes." (you have no proof it has been "de-identified", by the way). Vivaldi has other engines preinstalled, and you can easily change it, but still, the default is all we can judge it by.

-

New tab sites

-

By default, Vivaldi contains some websites in its new tab page that have a lot of spyware in them, but does not automatically make any connection, and those sites can easily be deleted.

+

Vivaldi is a feature-full, customizable web browser made by some of Opera's old developers (since they were dissatisfied with the direction Opera was heading). Just like modern Opera, it is based on Chromium.

+

Version tested: 5.2.2623.48

+

Spyware Level: High

+

Vivaldi makes about 119 requests on startup, and continues to make unsolicited connections after. Anti-privacy Bing is the default search engine.

+ +

Even if you disable everything under "Google Services" and "Google Extensions" under "Privacy" in settings, it will still make automatic connections to Google. Also makes connections after first start up to mirmir.vivaldi.com and downloads.vivaldi.com.

+

Vivaldi's web pages are Cloudflared

+

You will be blocked if using Tor, and be connected to hcaptcha.cloudflare.org. You can disable this by simply changing the homepage.

+ +

Vivaldi Assigns you a unique ID

+

From the Privacy Policy: "When you install Vivaldi browser (“Vivaldi”), each installation profile is assigned a unique user ID that is stored on your computer. Vivaldi will send a message using HTTPS directly to our servers located in Iceland every 24 hours containing this ID, version, cpu architecture, screen resolution and time since last message. We anonymize the IP address of Vivaldi users by removing the last octet of the IP address from your Vivaldi client then we store the resolved approximate location after using a local geoip lookup. The purpose of this collection is to determine the total number of active users and their geographical distribution".[1]

Cannot be built from source code

-

"However, it is only our Chromium work that is found on https://vivaldi.com/source. If you were to build it and run it, nothing will display as the HTML/CSS/JS UI is missing. This UI is only available as part of our end user packages, which is covered by the EULA (in which we also bundle with a compiled version of our modified Chromium)."[3]

+

"However, it is only our Chromium work that is found on https://vivaldi.com/source. If you were to build it and run it, nothing will display as the HTML/CSS/JS UI is missing. This UI is only available as part of our end user packages, which is covered by the EULA (in which we also bundle with a compiled version of our modified Chromium)."[2]