Controversy over Mozilla’s anti-data broker service

Martin Shelton

Principal Researcher

Electronic Frontier Foundation. (CC BY 2.0)

It’s the Digital Security Training team at Freedom of the Press Foundation (FPF), with security news that keeps you, your sources, and your devices safe. If someone has shared this newsletter with you, please subscribe here.

In the news

We recently shared news of Mozilla’s partnership with data removal service Onerep. Through a service it calls Mozilla Monitor Plus, Onerep is designed to automatically scan for personal information on data broker websites — services that aggregate and sell data about private individuals, such as addresses, phone numbers, names of family members, and even purchase histories. But journalist Brian Krebs has found evidence that the founder of Onerep, purveyor of anti-data broker services, himself created dozens of data broker services. Read more.

What you can do

  • It’s pretty disappointing to hear this news, especially having highlighted the service earlier. But it’s also an opportunity to talk about how not to take the promises or histories of any particular tool as gospel. While I wish every time I mentioned a tool it just stayed unproblematic, the reality is that we learn more about services in our security toolkit all the time. The services will change, we will learn more about them, and we will assess if they have become more or less reliable for our needs. So we hope journalists will use examples like this to understand the changing nature of the security space and find the tools that work best at the moment those tools are needed.
  • OK, I just gave you advice about not being married to any one service. All the same, an anti-data broker service that works well right now in about a dozen countries is DeleteMe, which allows you to have personal data removed from data brokers. It’s not cheap though — roughly $129 each year.
  • Also, you can manually remove yourself (for free!) from a variety of data brokers by following instructions listed in Yael Grauer's Big Ass Data Broker Opt-Out List.

Updates from my team

We are always ready to assist journalists with digital security concerns. Reach out here, and stay safe and secure out there.

Best,
Martin

Donate to support press freedom

Your support is more important than ever.

Read more about Digital Security Digest

Apple warns iPhone users of targeted malware

On April 10, Apple sent users in 92 countries warning of mercenary malware attacks targeting the iPhone. The notification did not provide details about the identities of the attackers. According to TechCrunch, Apple warned, “This attack is likely targeting you specifically because of who you are or what you do. Although it’s never possible to achieve absolute certainty when detecting such attacks, Apple has high confidence in this warning — please take it seriously.”

Preparing for election-related security issues

Throughout this year, our digital security training team will share our thoughts on navigating security issues during the 2024 election season. Elections around the world experience distinct security issues that may change from year to year, but in the U.S. we look to 2020 for lessons on how to get ahead of likely issues, from surveillance of our sensitive communications to perennial phishing attacks and harassment for political reporting.

Google to delete old Chrome Incognito data

Following a class-action lawsuit over Google’s handling of user data in its Chrome browser’s “Incognito” private browsing mode, the search company will expunge “billions of event-level data records that reflect class members’ private browsing activities” improperly collected before January 2024. It also updated its Incognito landing page to highlight that even Google can discern your activities in private browsing mode. Additionally, the company will be required to delete data that makes users’ private browsing data personally identifiable, such as IP addresses.