Earlier quoted context omitted.
Webmasters should have thought of that before littering their website with hundreds of off-site scripts and packaging all data and behavior and sending it off to dozens of tracking companies. "great products". Yeah, websites used to be much, much better before loading every bit of text with a remote javascript. Here's a behavioral data point: Go back to making good websites and stop leaking private data everywhere. T…
My website is broken by this feature [1]. It does not leak private data, as Mozilla devs said here [2] > According to the original screenshot in the thread, your web page is sending an HTTP request to https://www.reddit.com/api/v1/access_token . If the user has previously visited reddit.com, this request will include the user's reddit cookies normally. Also, the HTTP request I mentioned before has a Referer header th…
Firefox Now Available with Enhanced Tracking Protection by Default
201–210 of 278 posts
Re: Firefox Now Available with Enhanced Tracking Protection by Default
#202Earlier quoted context omitted.
No, Profiles are an entirely separate feature that Firefox also has. Setting up separate profiles for every major site could achieve something similar, but that would obviously be unimaginably inconvenient. Containers are like sandboxed virtual browser instances that nullify most methods of cross-site tracking, while also enabling you to conveniently stay logged in to all of your sites. Switching between the containe…
How so? This is exactly what personal profiles do. Keeping a separate cookie jar, local storage, history, extensions. Basically only the browser version and OS related stuff is left to track you. Ok, except if Google tracks browser usage directly. I've been using separate profile for each of the evil websites I have to use, no cookie leaking.
Re: Firefox Now Available with Enhanced Tracking Protection by Default
#203Earlier quoted context omitted.
Webmasters should have thought of that before littering their website with hundreds of off-site scripts and packaging all data and behavior and sending it off to dozens of tracking companies. "great products". Yeah, websites used to be much, much better before loading every bit of text with a remote javascript. Here's a behavioral data point: Go back to making good websites and stop leaking private data everywhere. T…
>loading every bit of text with a remote javascript. This update is only about a select list of "bad" domains, though. I don't think most users would want to block literally all third party scripts (Source: I use uMatrix set to do that, and every other site I visit requires a complicated ritual of unblocking layers of scripts, frames, and XHR. Don't even get me started on static sites that display blank without scrip…
Re: Firefox Now Available with Enhanced Tracking Protection by Default
#204This feature breaks hundreds of websites listed in a 5 year old issue [1] The last descriptive update was 4 years ago, > As the list is increasingly managed according to policy, breakage is a feature, not a bug. [1] https://bugzilla.mozilla.org/show_bug.cgi?id=1101005 Among the broken websites is one I just completed, revddit, "removeddit for user pages": https://revddit.com/user/rhaksw
https://www.reddit.com/user/revddit/
Creating a bot to spam your own website is obviously against the site rules. I see most of your posts on Hacker News are similarly promotional.
Re: Firefox Now Available with Enhanced Tracking Protection by Default
#205Earlier quoted context omitted.
My website is broken by this feature [1]. It does not leak private data, as Mozilla devs said here [2] > According to the original screenshot in the thread, your web page is sending an HTTP request to https://www.reddit.com/api/v1/access_token . If the user has previously visited reddit.com, this request will include the user's reddit cookies normally. Also, the HTTP request I mentioned before has a Referer header th…
I don't get it. The Mozilla dev explained, as you quoted, that the API access sends the reddit cookie to reddit while not being on reddit. That's leaking private data. "In other word, Reddit will be able to see the user's browsing history, as if they had access to the user's computer." You know who owns reddit, right?
A few things,
(1) Why does it matter in this case? Under what scenario can you imagine reddit abusing the knowledge that certain users are reading metadata about reddit accounts off-site?
(2) It seems to me Firefox could selectively choose not to send cookies and the referrer header in this case, rather than rendering entire sites broken. In that manner, sites accessing social media APIs can function, no data leaks, and everyone is happy.
(3) Hundreds of sites are broken like this. An issue tracking them has been open for 5 years [1]. The list used to identify "tracking" websites is huge and not maintained by Firefox [2].
(4) Due to this list, it is virtually impossible to build a web service that queries any social media site and runs on Firefox under default settings, significantly handicapping apps that can be built. Devs' recommendation was for me to move the code to a server, which would be expensive to maintain and would limit usefulness to users by obscuring code and introducing per-IP rate limits from the external API, in this case reddit's.
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=1101005
[2] https://github.com/disconnectme/disconnect-tracking-protecti...
Re: Firefox Now Available with Enhanced Tracking Protection by Default
#206Re: Firefox Now Available with Enhanced Tracking Protection by Default
#207Hopefully Mozilla will have funding and manpower to improve this.
Thanks for the work nonetheless.
Re: Firefox Now Available with Enhanced Tracking Protection by Default
#208Re: Firefox Now Available with Enhanced Tracking Protection by Default
#209This feature breaks hundreds of websites listed in a 5 year old issue [1] The last descriptive update was 4 years ago, > As the list is increasingly managed according to policy, breakage is a feature, not a bug. [1] https://bugzilla.mozilla.org/show_bug.cgi?id=1101005 Among the broken websites is one I just completed, revddit, "removeddit for user pages": https://revddit.com/user/rhaksw
Are you the one that created this bot on reddit? https://www.reddit.com/user/revddit/ Creating a bot to spam your own website is obviously against the site rules. I see most of your posts on Hacker News are similarly promotional.
The bot itself only responds once per user or thread, and I've already blacklisted some subreddits per suggestions [1]. Feel free to pm me at u/rhaksw if you would like to discuss it further.
Re: Firefox Now Available with Enhanced Tracking Protection by Default
#210Unpopular opinion on HN - Majority regular net users don't care about tracking and the FF focus on privacy will not give them the browser landscape they are losing daily. They should be focused on giving a better smooth UI, make it faster, remove unwanted extensions like pocket, make all the sites work. Let's see how valid this comment is in couple of years.
Those are all things which do not differentiate Firefox from Chrome. They're focusing on that as well, but Chrome will never be able to copy their privacy-enhancing features, because that's Google's business model.