Live data from Hacker News

First-party isolation in Firefox: what breaks if you enable it?

ctrl.blog

1–10 of 120 posts

Re: First-party isolation in Firefox: what breaks if you enable it?

#2
I've been running at home and at work with first-party isolation enabled for a few months now. Google login works fine for me, as does login with Google. It's broken a few internal tools, especially when people do things like hotlink across internal systems (which would have been broken at least some of the time for most people anyway, until they realise that to view _this_ page properly they need to log in over _there_). Also breaks PlayStation Network.

All in all, insufficiently broken for me to be bothered enough to turn it back off :). I do wish there was a "view from alternate origin" feature though, to let me load a site as if it were loaded in an iFrame -- that would let me work around the issues with my internal sites.

Re: First-party isolation in Firefox: what breaks if you enable it?

#4

> I’m not sure whether that is because Mozilla consider it unsafe, unpractical, or don’t want to commit to maintain the feature in future releases. I imagine it was implemented for the container tabs.

The main problem I see with account containers — still — is that you can't say "this container can only have certain websites in it". For example, if you put reddit in a "social" container, but click on links to the stories, then you have all of your cookies and stuff polluting the social container.

Re: First-party isolation in Firefox: what breaks if you enable it?

#5

I've been running at home and at work with first-party isolation enabled for a few months now. Google login works fine for me, as does login with Google. It's broken a few internal tools, especially when people do things like hotlink across internal systems (which would have been broken at least some of the time for most people anyway, until they realise that to view _this_ page properly they need to log in over _the…

The best strategy is to not use Google however. It's not like you need to in 2018 anymore. There are better services for almost anything out there, although you may have to pay a few dollars for some of them.

Well worth it since they are superior to Google. For email, Fastmail is king.

Re: First-party isolation in Firefox: what breaks if you enable it?

#7

> I’m not sure whether that is because Mozilla consider it unsafe, unpractical, or don’t want to commit to maintain the feature in future releases. I imagine it was implemented for the container tabs.

The main problem I see with account containers — still — is that you can't say "this container can only have certain websites in it". For example, if you put reddit in a "social" container, but click on links to the stories, then you have all of your cookies and stuff polluting the social container.

The Temporary Containers plugin is very nice. It can be configured to keep all tabs completely isolated, as if they were their own browser.

And you can set it to isolate subdomains or not, which is very useful when you need multiple tabs and want the same session in them.

Re: First-party isolation in Firefox: what breaks if you enable it?

#9
post #8

I guess trackers will just ask websites to route analytics traffic through their own infrastructure. Would it be enough for example.com to setup a dns alias pointing tracking.example.com to tracking.com?

This is a possible work-around, but it adds a lot of complexity to get HTTPS and stuff worked-around. Either the third-party must handle HTTPS for their partners who setup CNAMEs, or the first-party must handle HTTPS and proxy the requests back to the third-party. It’s doable but it will significantly slow things down to the point where even shitty websites would consider it unacceptable.

Re: First-party isolation in Firefox: what breaks if you enable it?

#10

I've been running at home and at work with first-party isolation enabled for a few months now. Google login works fine for me, as does login with Google. It's broken a few internal tools, especially when people do things like hotlink across internal systems (which would have been broken at least some of the time for most people anyway, until they realise that to view _this_ page properly they need to log in over _the…

The best strategy is to not use Google however. It's not like you need to in 2018 anymore. There are better services for almost anything out there, although you may have to pay a few dollars for some of them. Well worth it since they are superior to Google. For email, Fastmail is king.

I use “alternative search engines” daily. However, I have to crawl back to Google if I want to find things that were published in the last two weeks. Even Microsoft Bing can’t keep up with all the content that appears on the web every day.
Post reply on HN