Closed Bug 946894 Opened 12 years ago Closed 12 years ago

Privacy-Policy Review: Firefox Updates Add-on Hotfix

Categories

(Privacy Graveyard :: Product Review, task, P1)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: tdowner, Assigned: ahua)

References

Details

(Whiteboard: privacy feedback provided)

Attachments

(1 file, 4 obsolete files)

Initial Questions: Project/Feature Name: Firefox Updates Add-on Hotfix Tracking ID:928173 Description: We are going to be developing and launching an add-on hotfix that will attempt to both help fix and find more details on the reasons that prevent Firefox users from updating to the latest version. This hotfix will do two things: 1. Prompt all users of Firefox version 10 and up (excepting current version and ESR) that their version of Firefox is out of date and give them the ability to download the full installer to workaround any updater bugs. 2. Ask users if they would like to privde a copy of their update logs to mozilla for us to analyze. The files will be (Quoting from Bug 928173): "In the update directory, active-update.xml, updates.xml, updates/backup-update.log, updates/last-update.log, and updates/0/update.log if they exist for the updater." Additional Information: Key Initiative: Firefox Desktop Release Date: TBD Project Status: active Mozilla Data: Yes Mozilla Related: Separate Party: No Is there a privacy policy for this new feature/product?: no What assistance do you need from the privacy team (if any)?: We want to make sure that the data we are requesting from users falls within our privacy guidelines. This will be a fully Opt-In data gathering effort, users will have to actively click a checkbox to give us their logs, and there shouldn't be any personally identifiable information in the logs.
Hi Tyler - I will reassign this to Alina, since it's product related. In general, opt-in and no personal info sounds like a good plan. Some questions that come to mind are: Do you have a list of the data they would be sharing (what's included in the update log files)? What's the purpose of providing the files? Do you have the opt-in text written, that we could review? It would be great to see the user experience flow.
Assignee: smartin → ahua
Status: NEW → ASSIGNED
Whiteboard: privacy feedback provided
Priority: -- → P1
Hi Tyler, could you answer stacy's questions in comment 1? Is this project still live?
Flags: needinfo?(tdowner)
Cc'ing Rob onto this bug to provide the technical answers for what data is going to be collected and how those files will be used. I am currently on PTO, but I will come back next week with opt-in text and more information but yes, this project is very much live and in progress.
Flags: needinfo?(tdowner)
Attached file updates.xml (obsolete) —
Attached file last-update.log (obsolete) —
These four attachments are the files we want.
Regarding "What's the purpose of providing the files?" They provide troubleshooting information in this instance.
There is a username in two of the log files, can that be scrubbed? How long with the data be retained and is there any other meta data (e.g. email address to get back in contact with the user)?
I don't need the username so if whatever method is used to collect these files can scrub that I'm fine with it. This data will be evaluated for possible issues as time permits so retention is unknown. I have no idea what the plan for other meta data (e.g. email address) is.
I don't believe we will be collecting any other meta data, we have no real need for comments, e-mail addresses, etc. There are two different approaches we are considering for this, one is as originally proposed, having one hotfix to both gather data and prompt for an update, and the second is to split these two tasks into separate hotfixes, with the data gathering one significantly earlier than the update prompt. Either way, we will be using something along the lines of: "We notice that your Firefox is out of date. We would like your help in investigating this issue. If you would like to send some non-personally identifiable information from your installation of Firefox about your updater please check the checkbox below" We will then have a link to a page on support.mozilla.org that we will write to show what is in these files for users who want to learn more.
Another File that may be interesting would be about:support, perhaps there are certain add-ons or other issues that we can correlate to update bustage.
Group: mozilla-employee-confidential
Things have changed a bit since this bug was filed. A new example of an uploaded log is available at https://bug1014194.bugzilla.mozilla.org/attachment.cgi?id=8439576. I'll upload an example JSON payload from the client shortly.
Attached file hotfix-payload.json
A file similar to this is uploaded from clients that have completed a hotfix upgrade. This "forensics payload" is only uploaded if the user has Telemetry or FHR enabled. The payload contains some basic metrics along with two logs: the log from the hotfix itself and the log from the installer. We have made an effort to ensure the log produced by the hotfix does not log PII or anything typically viewed as sensitive. Both these text-based logs are sanitized and stripped of values such as the profile directory (which may contain a user or real name). This particular example does not contain a fully sanitized installer log. Please see the link in the previous comment. Please needinfo? me if you have any questions. bsmedberg would like to ship the hotfix ASAP. A prompt privacy review would be appreciated.
Attachment #8390095 - Attachment is obsolete: true
Attachment #8390096 - Attachment is obsolete: true
Attachment #8390097 - Attachment is obsolete: true
Attachment #8390100 - Attachment is obsolete: true
I've been reviewing the data we're actually sending, so I think this is fine.
Status: ASSIGNED → RESOLVED
Closed: 12 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: