Privacy/Reviews/AndroidSystemStorage: Difference between revisions

Jump to navigation Jump to search
no edit summary
No edit summary
Line 164: Line 164:
In this section, the privacy champion will identify areas of user data risk and recommendations for minimizing the risk.
In this section, the privacy champion will identify areas of user data risk and recommendations for minimizing the risk.


==Risks==
== User History/Bookmarks/etc. ==
* Possibility of syncing user data to Google, unexpectedly or undesirably to the user
 
* No option to not use system storage planned for initial Firefox for Android Native UI release
''The Risk'' is the possibility of syncing user data to Google unexpectedly or undesirably to the user, via storing bookmarks, history, etc in the Android system store
 
''Requirement:'' There must be explicit messaging that users may need to take action to opt out of having their Firefox for Android data synced to Google (if they have their phone configured to sync data to Google, which many users will - the change to using system storage and its implications must be communicated loudly and clearly to avoid user surprise
 
''Recommendation:'' Option to store data apart from the global store.  That is, do not use the global system services to store history, bookmarks, and passwords.  But instead, hide them from the rest of the phone and discourage data sharing on the device. Have this separate data store be the default storage for Firefox for Android and have users opt in to using system storage


= Alignment with Privacy Operating Principles =
= Alignment with Privacy Operating Principles =
Line 176: Line 180:
====Principle: Transparency / No Surprises====
====Principle: Transparency / No Surprises====
Users are going to be upgraded from the previous release of Firefox to the Native UI/Birch release.  
Users are going to be upgraded from the previous release of Firefox to the Native UI/Birch release.  
If they have enabled Google sync, they will be opted in without notice to having their data from
If they have enabled Google sync, they will be opted in without notice to having some of their data from
Firefox for Android browsing synced to Google. Users also may be using Firefox to avoid using system
Firefox for Android browsing synced to Google. Users also may be using Firefox to avoid using system
storage, and will be opted in to using it when upgraded to the Birch release.
storage, and will be opted in to using it when upgraded to the Birch release.


Additionally, it may happen that users will sync their Firefox data from Mozilla Sync, this data would then
Additionally, it may happen that users will sync their Firefox data from Mozilla Sync, this data would then
be stored in the system store and then possibly synced to Google - violating the guarantees that Mozilla Sync
be stored in the system store and then possibly synced to Google - breaking expectations of where and how
makes about data not being accessible by anyone else, even Mozilla.
sync'd data is shared


''Recommendations'': (what can be improved)
''Recommendations'': (what can be improved)
Line 189: Line 193:


* Option to store data apart from the global store.  That is, do not use the global system services to store history, bookmarks, and passwords.  But instead, hide them from the rest of the phone and discourage data sharing on the device.
* Option to store data apart from the global store.  That is, do not use the global system services to store history, bookmarks, and passwords.  But instead, hide them from the rest of the phone and discourage data sharing on the device.
* If users are going to be essentially opted-in to the new UI and using system storage, there must be explicit messaging that they may need to take action to opt of having their Firefox for Android data synced to Google (if they have their phone configured to sync data to Google, which many users will).


====Principle: Real Choice====
====Principle: Real Choice====
Confirmed users
197

edits

Navigation menu