Earlier quoted context omitted.
Giving it up for work is not possible. But for entertainment it's different the gp not only mentions Reddit, but other news sites and specifically the ones linked from HN. It's a general trend that almost everybody does, probably because "everybody is doing it". There are good alternatives like reading books, watching movies or going out. Web sites are shooting themselves in their feet. Blockers end up being too much…
I regularly browse HN and click through to articles. I run firefox / noscript on both mobile and desktop. I occasionally have to enable or temp-enable some stuff in noscript to be able to read articles, but it's a small minority of cases, and probably smaller if I wasn't so prone to temp-enabling rather than enabling. For sessions where I know I want js to "just work", like online shopping from a set of presumed-trus…
Facebook Container for Firefox
271–280 of 406 posts
Re: Facebook Container for Firefox
#272Third party cookies, and any way to fingerprint a specific user starting from high entropy user agents to screen resolution, font fingerprinting or canvas data, should be considered a breach of the browser security model. All sites should run in containers and no advertiser should be able to track you across sessions. When I want 3rd party interaction, I should need to opt in and connect the current site with Faceboo…
Indeed. Safari blocks 3rd party cookies by default, I see no reason why Firefox can't do the same. The fact that they don't is a direct contradiction to their claims that they care about user privacy. The only explanation I have is that they do not want to anger their long-time money sources Google and other advertisers.
Apple can do this, because they have a limited yet consistent market share that mostly consists of their own customers.
But Firefox? If they block third-party cookies and Chrome does not, they might just end up losing even more users.
Re: Facebook Container for Firefox
#273Third party cookies, and any way to fingerprint a specific user starting from high entropy user agents to screen resolution, font fingerprinting or canvas data, should be considered a breach of the browser security model. All sites should run in containers and no advertiser should be able to track you across sessions. When I want 3rd party interaction, I should need to opt in and connect the current site with Faceboo…
Ever encountered Google ReCaptcha when you've turned off third party cookies or while in incognito/private mode? It's a nightmare, even if you're logged into a Google account. You can be shown upto 7-8 challenges, painfully slow loading images and Google's insistence that they encountered malicious traffic from your IP when attempting to use the audio version. What's even worse is they track your mouse movements and…
Re: Facebook Container for Firefox
#274- Every website (domain) should get its own container by default. I don't want to configure stuff when visiting a new domain.
- If I want domains to share a container, then I don't mind having to configure that.
- When clicking a link inside a container that points to a different domain, then the link should open in the container for the domain pointed to.
- When clicking a link, I should have the opportunity to edit the link before opening it, to avoid information leakage from one container to another.
- Cookies may be saved per container (default). But I should be able to turn cookies off for a specific container.
- Containers should work against fingerprinting, i.e. by perturbing browser characteristics slightly. This should work by default per container and per session. It should be configurable.
- If some well-known websites only work with multiple domains, then that is ok. These domains can be grouped into one container. Firefox can distribute a "whitelist" for such configurations. Please don't bother me with the specifics, but enable me to figure out what the settings are for a container, and to change those settings.
- Container settings should be synced over my devices. Needless to say, containers should work on all platforms.
Re: Facebook Container for Firefox
#275Re: Facebook Container for Firefox
#276Third party cookies, and any way to fingerprint a specific user starting from high entropy user agents to screen resolution, font fingerprinting or canvas data, should be considered a breach of the browser security model. All sites should run in containers and no advertiser should be able to track you across sessions. When I want 3rd party interaction, I should need to opt in and connect the current site with Faceboo…
Ever encountered Google ReCaptcha when you've turned off third party cookies or while in incognito/private mode? It's a nightmare, even if you're logged into a Google account. You can be shown upto 7-8 challenges, painfully slow loading images and Google's insistence that they encountered malicious traffic from your IP when attempting to use the audio version. What's even worse is they track your mouse movements and…
Re: Facebook Container for Firefox
#277Earlier quoted context omitted.
Exactly. Why aren't all websites run in containers by default (personally I'm envisioning per-domain containers)? What benefit do we get from full-coverage containerization not being the default?
In short: site breakage. We're so deep in this that a first party isolation would break almost every single website. In a cooperation with Tor, Mozilla actually ported the first-party isolation feature in mainstream Firefox (available in Nightly, don't know about stable), but since it would break almost every single website, there are no plans to turn it on by default. You can, of course, enable it yourself by turnin…
Re: Facebook Container for Firefox
#278Third party cookies, and any way to fingerprint a specific user starting from high entropy user agents to screen resolution, font fingerprinting or canvas data, should be considered a breach of the browser security model. All sites should run in containers and no advertiser should be able to track you across sessions. When I want 3rd party interaction, I should need to opt in and connect the current site with Faceboo…
The security model of the internet is whack. Javascript should be opt-in, especially from 3rd party sources. "This website wants/requires javascript for an enhanced viewing experience [allow/deny]". Instead not only will any stock browser gladly run anything thrown at it, it will also accept any cookies and now run WebGL code, trigger DRM engines and various other things. All that because the engineers who wrote the…
I wonder why you say that. I concede that web has evolved from no-security in the 90s, when random applets and ActiveX controls were 1-click away from rooting your machine, through faulty security in 2000s, where stack smashing IE was a hobby of mine, and up to the current era of sandboxes. Which do work, sandbox evasion zero days have become very rare and remote execution has largely ceased to be an infection vector against the masses.
The problem with 3rd party tracking is not technological, the web was deliberately engineered to work in this manner. The browsers work exactly as specified, and that specification is the problem. It's compounded then as a political problem, where major browser investment are controlled by advertising companies that have a massive conflict of interest regarding the users privacy, and are likely to promote bandaids like "Do not track" instead of the fundamental privacy re-engineering the web urgently requires.
> The world has gone mad. I'm going to get a "gopher should've won" tatoo and live in as an hermit on some nearby mountain.
When I'm thinking like this is usually a sign of age. Hang in there buddy, we'll be fine. There is a promised land just around the corner with rich, secure web applications and strong privacy. If only everybody agreed we want it.
Re: Facebook Container for Firefox
#279Re: Facebook Container for Firefox
#280Earlier quoted context omitted.
https://i.reddit.com and https://old.reddit.com both avoid this ... until you hit an internal reddit link to a different host (www, np, etc.,) in which case you're back to base and fucked. The inconsistency of intra-reddit links (that is, links within the Reddit app) is ... one of the more annoying elements of the site, and long has been.
You could try a browser extension to rewrite [www|np].reddit.com to i.reddit.com [0] But yeah when ever you don't follow the path that the major sites want you to go down you have to keep jumping around Similar with Gmail, all links in the email go via Google tracking so you have to do a right-click and get the link then open a separate tab and paste it (obviously a signal for me that I shouldn't be using Gmail in th…
More: https://www.reddit.com/r/dredmorbius/comments/8avwul/open_th...