Live data from Hacker News

Firefox 59 to strip path information from referrer values for 3rd parties

blog.mozilla.org

171–180 of 236 posts

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#171
post #151

Whoah, TIL that > EFF researchers discovered this leak of personal health data from healthcare.gov to DoubleClick It blows my mind that a site such as healthcare.gov would include 3rd party trackers. You guys in the US really don't care about privacy at all.

This is largely the part of independent contractors and subcontractors. Contracts go to the companies good at winning contracts, not necessarily the best company to do the job. The contractor takes an obscene profit for providing no value and then subcontracts the project to various subcontractors who may or may not employ actually qualified and skilled engineers. The government employees managing the contract typica…

> (as no one needs to run their own data center).

That can be extraordinarily expensive once it leaks out that classified government data is in the hand of uncertified third-party cloud in some other nation, and you have to rush and pay twice or three times more in order for the contract to be changed and now have local certified supplier. This is what happened here in Sweden in equivalent departments for the DMV, which later implicated a further 40 different government department which used the same practice.

When the cost go up by 200%-300%, suddenly the idea of running your own data center sounds much cheaper. It ended up being the highest single cost the departments had, excluding salaries and rent. you can get quite a nice data center for those billions.

https://simple.wikipedia.org/wiki/Swedish_Transport_Agency%2...

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#172
post #146

Earlier quoted context omitted.

Nooo! Pleasee don't! It will be like these useless cookie warnings in EU all over www. I voluntary enable this path info if you spare me more popups.

Don't worry, the cookie warnings (actually third-party tracking warnings) will soon (May) become not useless at all. From May on sites have to offer yes/no, they may only track you if you choose yes, and if you choose no they may not ask again, and may not refuse access either. Which is what was originally intended all this time, and which all good websites offered anyway.

I'm very curious about this. How will you keep track of a user who has opted out without using a cookie? That's my understanding of the issues - websites keep asking not because they think they can browbeat you into accepting cookies, but because they can't tell the difference between a user who has opted out of cookies and a first time user.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#173
post #151

Whoah, TIL that > EFF researchers discovered this leak of personal health data from healthcare.gov to DoubleClick It blows my mind that a site such as healthcare.gov would include 3rd party trackers. You guys in the US really don't care about privacy at all.

This is largely the part of independent contractors and subcontractors. Contracts go to the companies good at winning contracts, not necessarily the best company to do the job. The contractor takes an obscene profit for providing no value and then subcontracts the project to various subcontractors who may or may not employ actually qualified and skilled engineers. The government employees managing the contract typica…

> Contracts go to the companies good at winning contracts, not necessarily the best company to do the job.

This is worth a deeper explanation. "Good at winning contracts" involves a lot of things that have nothing to do with the ability to do the job. From legislated preferences for "minority- and women-owned" businesses (which is usually a farce), to kickbacks to the bureaucrats who award the contracts, there are a LOT of reasons why government hiring "private" companies to do work goes wrong.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#174
post #154

Earlier quoted context omitted.

I get what you're saying and I agree but it is a bit more nuanced. Say you want to read a certain news article, and if you get referred to it by Google you can read it, otherwise not. Now, lets say you've been finding news articles to read that way via Google the past years. Suddenly, with Firefox 59, this no longer works. Without even informing the user. That is not user-friendly.

Sites should be penalized for giving preference to one kind of link over another. Why should Google have even more of an upper hand than they already have? To me this is a super good illustration of why we probably should get rid of the 'Referer' (sic) header altogether.

Agreed, but the short-term loser of this change is the non-technical customer who's workflow is suddenly broken, and only in Firefox, and only in version 59.

Apparently only in Private Mode though which makes my use case probably less common.

Thing is, do you remember the uproar about addons being broken in Firefox 57? It was for good (security) reasons but many non-technical users don't understand or respect the pros and cons. All they see is their workflow being broken.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#175
post #121

Earlier quoted context omitted.

Good marketing does please users by delivering them products tailored to them that they may have never knew even existed.

If I can go through your underpants drawer then I'll know the right kind of underpants to try and sell you. That means it's OK, right?

(Tangent, but I’ve never found this particular example compelling. All that’s in my underwear drawer is underwear... and I don’t find that particularly embarrassing? I think I’m missing some cultural context for it)

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#176

Earlier quoted context omitted.

Don't worry, the cookie warnings (actually third-party tracking warnings) will soon (May) become not useless at all. From May on sites have to offer yes/no, they may only track you if you choose yes, and if you choose no they may not ask again, and may not refuse access either. Which is what was originally intended all this time, and which all good websites offered anyway.

I'm very curious about this. How will you keep track of a user who has opted out without using a cookie? That's my understanding of the issues - websites keep asking not because they think they can browbeat you into accepting cookies, but because they can't tell the difference between a user who has opted out of cookies and a first time user.

There was never a blanket prohibition against cookies, that was a misconception (pushed purposefully by some, I suspect). Cookies which are "strictly necessary" in order to provide the service don't need to be approved. A cookie to remember that you don't want unnecessary cookies seems to fall well under that exception.

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#177

Earlier quoted context omitted.

Don't worry, the cookie warnings (actually third-party tracking warnings) will soon (May) become not useless at all. From May on sites have to offer yes/no, they may only track you if you choose yes, and if you choose no they may not ask again, and may not refuse access either. Which is what was originally intended all this time, and which all good websites offered anyway.

I'm very curious about this. How will you keep track of a user who has opted out without using a cookie? That's my understanding of the issues - websites keep asking not because they think they can browbeat you into accepting cookies, but because they can't tell the difference between a user who has opted out of cookies and a first time user.

They could use local storage? As local storage isn't sent to the server, the server will not know whether the user opted out. (User opt in will be a cookie still.)

Alternatively, the legal definition of tracking cookie can differ from the technical definition of cookie. It wouldn't be the first time...!

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#178
post #151

Whoah, TIL that > EFF researchers discovered this leak of personal health data from healthcare.gov to DoubleClick It blows my mind that a site such as healthcare.gov would include 3rd party trackers. You guys in the US really don't care about privacy at all.

They were specifically using a monitoring tool (Floodlight, for tracking conversions) that happens to be provided by an ad company. To my view, it's more of a security issue than a privacy issue, as DoubleClick was prohibited by TOS from using the data for advertising.

In this era, if it comes from an ad company it almost certainly is a privacy issue and should generally be considered a security problem

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#179

Earlier quoted context omitted.

I'm very curious about this. How will you keep track of a user who has opted out without using a cookie? That's my understanding of the issues - websites keep asking not because they think they can browbeat you into accepting cookies, but because they can't tell the difference between a user who has opted out of cookies and a first time user.

They could use local storage? As local storage isn't sent to the server, the server will not know whether the user opted out. (User opt in will be a cookie still.) Alternatively, the legal definition of tracking cookie can differ from the technical definition of cookie. It wouldn't be the first time...!

"Cookie law" is an informal name, the Directive itself refers generally to "stor[ing] information on the equipment of a user".

Re: Firefox 59 to strip path information from referrer values for 3rd parties

#180
#1 this should be on by default. I might be missing something, but do sites really need the referrer? What would break if the browser sent the same page as referrer, or google.com/ or something similar? Is there any value in the referrer to the client? The host can use it for a whole range of reasons - but apart from helping the host, what is the immediate benefit to the client?

#2 Won't this be possible to bypass simply by encoding more in the domain part of the url than in parameters? So you switch from a.b.tld/foo?p=123 to 123.a.b.tld/foo ?

Post reply on HN