Live data from Hacker News

Facebook Container for Firefox

mozilla.org

241–250 of 406 posts

Re: Facebook Container for Firefox

#241
post #225

Third party cookies, and any way to fingerprint a specific user starting from high entropy user agents to screen resolution, font fingerprinting or canvas data, should be considered a breach of the browser security model. All sites should run in containers and no advertiser should be able to track you across sessions. When I want 3rd party interaction, I should need to opt in and connect the current site with Faceboo…

Exactly. Why aren't all websites run in containers by default (personally I'm envisioning per-domain containers)? What benefit do we get from full-coverage containerization not being the default?

While micro-sites and CDNs could still be brought under the same SLD. The biggest blocker as is OAuth. I'd want to make a UX call to see if browser could elegantly prompt the user for a 3rd party interaction.

While we are at it, I keep wondering (in a strictly SSL world) if it would be a good idea to restrict CORS calls only to sites using the same certificate as the webpage. Would make life easier for folks like facebook.com making CORS to fb-blablabla.fbcdn.com.

Re: Facebook Container for Firefox

#242
post #230
post #225

Earlier quoted context omitted.

Exactly. Why aren't all websites run in containers by default (personally I'm envisioning per-domain containers)? What benefit do we get from full-coverage containerization not being the default?

In short: site breakage. We're so deep in this that a first party isolation would break almost every single website. In a cooperation with Tor, Mozilla actually ported the first-party isolation feature in mainstream Firefox (available in Nightly, don't know about stable), but since it would break almost every single website, there are no plans to turn it on by default. You can, of course, enable it yourself by turnin…

It would break some sites (certainly not every site, I'm browsing this site right now with it enabled) because 3rd party cookies are an entrenched, standardized feature of the web, you can't simply turn them off tomorrow. Developers are using them to create benign functionality, for example spread an application across multiple domains owned by the same publisher.

What I proposed above is that we introduce an opt-in feature: before the browser is allowed to connect to 3rd parties (in the tracking and cookie sense), the user needs to opt-in, for example by clicking in a notice window displayed at the corner of the browser window. Instead of nagging every user of every site that "This site is using cookies", developers should nag only when connecting to other applications, using a standardized browser API. After sometime from standardization, you can roll out this functionality to all users and nothing legitimate would break.

There should be no presumed used consent - because there really is none, the outcry against Facebook and advertiser tracking shows people don't expect the web to work the way it does.

Re: Facebook Container for Firefox

#243

Third party cookies, and any way to fingerprint a specific user starting from high entropy user agents to screen resolution, font fingerprinting or canvas data, should be considered a breach of the browser security model. All sites should run in containers and no advertiser should be able to track you across sessions. When I want 3rd party interaction, I should need to opt in and connect the current site with Faceboo…

The security model of the internet is whack. Javascript should be opt-in, especially from 3rd party sources. "This website wants/requires javascript for an enhanced viewing experience [allow/deny]". Instead not only will any stock browser gladly run anything thrown at it, it will also accept any cookies and now run WebGL code, trigger DRM engines and various other things. All that because the engineers who wrote the standards had enough hubris to think that a turing complete language with access to such a large API surface (from the DOM to the GPU to threads to a lot of the browser state) could be successfully sandboxed.

The web is a lost cause as far I'm concerned, it was under-engineered at the start and as a result people kept pilling mounds of crap on top to make up for it. What started as a way to display basic markup and images has been arm wrestled into handling complex web applications and videogames. The thing is so complex that it would probably take me less time to write a basic operating system and run Firefox on it than implementing my own browser from scratch on Linux. And despite all of this you end up having to use a billion of 3rd party javascript libraries to do anything remotely complex in the browser, things that have been standard in Qt or GTK since forever with a fraction of the code base and memory footprint.

And now people seem to enjoy reimplementing all the internet protocols on top of HTTP. The world has gone mad. I'm going to get a "gopher should've won" tatoo and live in as an hermit on some nearby mountain.

I'm glad that there appears to be a lot of discussion surrounding internet privacy lately, including in the mainstream. However I think that focusing all the discussion of Facebook is becoming counter-productive. Facebook exploited the weaknesses of the web very successfully but it only exploited tools that existed long before it was created. I have absolutely no illusion that Google & friends are doing pretty much the same thing, and if you have an Android phone the amount of info Google can harvest is nothing short of terrifying when you think about it from an Orwellian perspective. Don't miss the forest for the Facetree.

Assuming that internet giants will adhere to some "code of conduct" is naive at best. "Do no evil", yeah right. We let them have to tools to do these things, we need to pry some of them away from their hands through technology and regulation (probably in that order).

Re: Facebook Container for Firefox

#244
post #130

Earlier quoted context omitted.

Twitter mobile. Scroll down for a screen, full page "Log in/Sign up" popup. Every single page.

Tragically, this is most probably by design, to encourage sign-ups. Whoever implemented that should not feel any better than a telemarketer or a spammer.

And then when you decide to create a sacrificial account just to keep them happy, they won't let you unless you give them your mobile number...

Re: Facebook Container for Firefox

#245
post #66
post #27

I used Firefox's containers for about a day, and then I discovered the privacy.firstparty.isolate option (in about:config), which effectively gives every site its own container with no user effort. That, combined with Cookie AutoDelete, seems to work well.

My use case is multiple Google accounts. I can log in to multiple Google accounts at the same time in different containers and answer emails very easily.

Why don't you use Thunderbird for multiple mail accounts? I cannot imagine using web interface for multiple email accounts, too much effort, taking my browser tab space. Thunderbird is right tool for it...

Re: Facebook Container for Firefox

#246

Earlier quoted context omitted.

How about just whitelist the good guys?

That's what I do on Android, except I use Brave instead of Chrome/Firefox. I change the default settings to block all JavaScript by default, and then use the Brave button to whitelist sites I trust and actually want to use. Browsing the web (especially news sites) on my Android has gone from "a complete nightmare" to "tolerable" because of this.

Same approach, but I prefer firefox beta + noscript, which allows more fine-grained control (so I can permanently or temporarily enable js from e.g. reddit.com and redditstatic.com, but not googletagservices, amazon-adsystem, etc. .. on the same page.)

Re: Facebook Container for Firefox

#247
post #180

Earlier quoted context omitted.

I don't know if you've come across i.reddit e.g. [0], I only heard about it a few weeks ago, but it's an old mobile site from reddit with nice simple styling and all the shite taken out. No popups for the stupid app. I don't understand the drive to force people to use the app. Medium trys similar but less annoying tactics. Either way you get eyeballs on your site. Perhaps there's better tracking that they can get hol…

https://i.reddit.com and https://old.reddit.com both avoid this ... until you hit an internal reddit link to a different host (www, np, etc.,) in which case you're back to base and fucked. The inconsistency of intra-reddit links (that is, links within the Reddit app) is ... one of the more annoying elements of the site, and long has been.

You could try a browser extension to rewrite [www|np].reddit.com to i.reddit.com [0]

But yeah when ever you don't follow the path that the major sites want you to go down you have to keep jumping around

Similar with Gmail, all links in the email go via Google tracking so you have to do a right-click and get the link then open a separate tab and paste it (obviously a signal for me that I shouldn't be using Gmail in the first place).

[0]: https://stackoverflow.com/questions/1891738/how-to-modify-cu...

Re: Facebook Container for Firefox

#248
post #31

We're going from cold war to all-in. Not just a privacy question. Reddit nags me every time I hit the front page, even returning from a story, asking me to log in. For most sites I need to create ublock filters to prevent pop-ups with useless "we use cookies", subscription requests, ads or social media bars that fills half the screen, etc. etc. etc. Every newspaper I read has decided that autostarting video and strea…

> I'm giving up on the web They said, while posting on a web forum

> a web forum

which, to be fair, is accessible via numerous 3rd party apps: https://news.ycombinator.com/item?id=14684105

Re: Facebook Container for Firefox

#249
post #243

Third party cookies, and any way to fingerprint a specific user starting from high entropy user agents to screen resolution, font fingerprinting or canvas data, should be considered a breach of the browser security model. All sites should run in containers and no advertiser should be able to track you across sessions. When I want 3rd party interaction, I should need to opt in and connect the current site with Faceboo…

The security model of the internet is whack. Javascript should be opt-in, especially from 3rd party sources. "This website wants/requires javascript for an enhanced viewing experience [allow/deny]". Instead not only will any stock browser gladly run anything thrown at it, it will also accept any cookies and now run WebGL code, trigger DRM engines and various other things. All that because the engineers who wrote the…

Spot on. And most of website should not even need javascript but some simple extension to xhtml to allow interactive websites in a declarative fashion rather than having a Turing-complete language.
Post reply on HN