Live data from Hacker News

Facebook Container for Firefox

mozilla.org

301–310 of 406 posts

Re: Facebook Container for Firefox

#302
post #289

Earlier quoted context omitted.

I agree, but blocking third-party cookies does break a whole lot of sites. Apple can do this, because they have a limited yet consistent market share that mostly consists of their own customers. But Firefox? If they block third-party cookies and Chrome does not, they might just end up losing even more users.

Sure you can argue that way. But it's not as big of a problem as you think it is. The fact that Apple does it is enough proof for that. Websites can be changed to work without third party cookies. I'm blocking cookies since years and I have come across less than 10 sites that require it. When that happens, most of the time I just go elsewhere or I'll send them an email.

I’ve been blocking third party cookies for as long as Safari has had that option, and I’ve never noticed an issue. I only get Google’s annoying recaptchas when my search string is too specific for their tastes.

Re: Facebook Container for Firefox

#303
post #220

Earlier quoted context omitted.

Indeed. Safari blocks 3rd party cookies by default, I see no reason why Firefox can't do the same. The fact that they don't is a direct contradiction to their claims that they care about user privacy. The only explanation I have is that they do not want to anger their long-time money sources Google and other advertisers.

I agree, but blocking third-party cookies does break a whole lot of sites. Apple can do this, because they have a limited yet consistent market share that mostly consists of their own customers. But Firefox? If they block third-party cookies and Chrome does not, they might just end up losing even more users.

What sites are broken by Safari because of its default cookie options? I haven't encountered any.

Re: Facebook Container for Firefox

#304
post #231

Earlier quoted context omitted.

Ever encountered Google ReCaptcha when you've turned off third party cookies or while in incognito/private mode? It's a nightmare, even if you're logged into a Google account. You can be shown upto 7-8 challenges, painfully slow loading images and Google's insistence that they encountered malicious traffic from your IP when attempting to use the audio version. What's even worse is they track your mouse movements and…

This is what finally made me switch my default search engine away from Google. I will put up with a lot of crap, but I'm not going to spend 60s to solve a CAPTCHA every time I do a search.

Bear in mind that Google might be correctly identifying your IP address as a botnet source. If you start seeing lots of CAPTCHAs, it's worth it to take a look around your network for open ports or weak ssh passwords etc., or just look at a traffic monitor to see if there's a lot of egress from your net.

Re: Facebook Container for Firefox

#305
post #243

Third party cookies, and any way to fingerprint a specific user starting from high entropy user agents to screen resolution, font fingerprinting or canvas data, should be considered a breach of the browser security model. All sites should run in containers and no advertiser should be able to track you across sessions. When I want 3rd party interaction, I should need to opt in and connect the current site with Faceboo…

The security model of the internet is whack. Javascript should be opt-in, especially from 3rd party sources. "This website wants/requires javascript for an enhanced viewing experience [allow/deny]". Instead not only will any stock browser gladly run anything thrown at it, it will also accept any cookies and now run WebGL code, trigger DRM engines and various other things. All that because the engineers who wrote the…

Javacript running automatically is a decision made at the user agent level, it isn't really part of the "internet" security model. If browsers didn't run scripts automatically I think that would be the #1 support question, "How do I turn off those prompts!?".

Re: Facebook Container for Firefox

#306

Earlier quoted context omitted.

I agree, but blocking third-party cookies does break a whole lot of sites. Apple can do this, because they have a limited yet consistent market share that mostly consists of their own customers. But Firefox? If they block third-party cookies and Chrome does not, they might just end up losing even more users.

What sites are broken by Safari because of its default cookie options? I haven't encountered any.

Any site which iframes in another site where you're expected to be logged in. For example, Disqus comments, Facebook like buttons, Youtube embeds (which work, but show ads even if you've paid for no ads).

There are also lots of one-off cases where developers split functionality across multiple domains in ways that were fine at the time but now get blocked. These are all fixable, unlike the iframing case, but it's still a lot of sites.

Re: Facebook Container for Firefox

#307
post #230
post #225

Earlier quoted context omitted.

Exactly. Why aren't all websites run in containers by default (personally I'm envisioning per-domain containers)? What benefit do we get from full-coverage containerization not being the default?

In short: site breakage. We're so deep in this that a first party isolation would break almost every single website. In a cooperation with Tor, Mozilla actually ported the first-party isolation feature in mainstream Firefox (available in Nightly, don't know about stable), but since it would break almost every single website, there are no plans to turn it on by default. You can, of course, enable it yourself by turnin…

We ran a breakage study near the end of last year.

First-Party Isolation (FPI) did have the highest breakage scores: ~18-19% of users reported problems with it, and 9-10% of FPI users disabled the study.

Those are low relative numbers, but at entire-market scale, they are big absolute numbers. :/

https://blog.mozilla.org/data/2018/01/26/improving-privacy-w...

Re: Facebook Container for Firefox

#308
post #230
post #225

Earlier quoted context omitted.

Exactly. Why aren't all websites run in containers by default (personally I'm envisioning per-domain containers)? What benefit do we get from full-coverage containerization not being the default?

In short: site breakage. We're so deep in this that a first party isolation would break almost every single website. In a cooperation with Tor, Mozilla actually ported the first-party isolation feature in mainstream Firefox (available in Nightly, don't know about stable), but since it would break almost every single website, there are no plans to turn it on by default. You can, of course, enable it yourself by turnin…

In my experience with Brave browser I had to enable third-party cookies only for very few sites. In most cases that was to support some external login mechanism that the site used, not to access the site after a login. So I doubt the claim about breakage on most sites.

Re: Facebook Container for Firefox

#309
post #181

Earlier quoted context omitted.

That the targeted advertising and profiling will still come to you. Live with a person who joins fb mommy groups and buys diapers online? Prepare for a barrage of relevant ads. The main point is that the combination of relationship-inference and geolocation can undo probably 70% of your own privacy protection measures, through ignorant ordinary use of the fb app by friends, family and coworkers. Then combine that wit…

Putting in my year of birth to 1911 (but the same month/day so half friends don't send me wishes on the wrong day) used to mostly destroy their targeted advertising. It was all adverts for arthritis medication. They're steadily figuring it out, but it's taken them about 10 years.

I'm also enjoying completely meaningless ads as I lie to them about my gender.
Post reply on HN