Live data from Hacker News

Firefox Now Available with Enhanced Tracking Protection by Default

blog.mozilla.org

201–210 of 278 posts

Re: Firefox Now Available with Enhanced Tracking Protection by Default

#201
post #190
post #106

Earlier quoted context omitted.

Webmasters should have thought of that before littering their website with hundreds of off-site scripts and packaging all data and behavior and sending it off to dozens of tracking companies. "great products". Yeah, websites used to be much, much better before loading every bit of text with a remote javascript. Here's a behavioral data point: Go back to making good websites and stop leaking private data everywhere. T…

My website is broken by this feature [1]. It does not leak private data, as Mozilla devs said here [2] > According to the original screenshot in the thread, your web page is sending an HTTP request to https://www.reddit.com/api/v1/access_token . If the user has previously visited reddit.com, this request will include the user's reddit cookies normally. Also, the HTTP request I mentioned before has a Referer header th…

I don't get it. The Mozilla dev explained, as you quoted, that the API access sends the reddit cookie to reddit while not being on reddit. That's leaking private data. "In other word, Reddit will be able to see the user's browsing history, as if they had access to the user's computer." You know who owns reddit, right?

Re: Firefox Now Available with Enhanced Tracking Protection by Default

#202

Earlier quoted context omitted.

No, Profiles are an entirely separate feature that Firefox also has. Setting up separate profiles for every major site could achieve something similar, but that would obviously be unimaginably inconvenient. Containers are like sandboxed virtual browser instances that nullify most methods of cross-site tracking, while also enabling you to conveniently stay logged in to all of your sites. Switching between the containe…

How so? This is exactly what personal profiles do. Keeping a separate cookie jar, local storage, history, extensions. Basically only the browser version and OS related stuff is left to track you. Ok, except if Google tracks browser usage directly. I've been using separate profile for each of the evil websites I have to use, no cookie leaking.

I've edited the comment to clarify, but you're right that they're functionally similar. I was talking mainly in terms of user experience, though. Setting up multiple separate profiles with much the same options and extensions, and then having to actively fire them up for every time you want to use a major site that also employs trackers seems massively inconvenient and redundant to me. With containers, mapping specific sites to specific containers that first time is all you have to do. Containers also share local storage, history, and extensions with the rest of the browser, which is a blessing, as there's no need to install the same set of extensions five different times for as many different profiles, for no added security or privacy benefit whatsoever, and you can access local data in consolidated form, without having to deal with them being fragmented across multiple profiles.

Re: Firefox Now Available with Enhanced Tracking Protection by Default

#203
post #106

Earlier quoted context omitted.

Webmasters should have thought of that before littering their website with hundreds of off-site scripts and packaging all data and behavior and sending it off to dozens of tracking companies. "great products". Yeah, websites used to be much, much better before loading every bit of text with a remote javascript. Here's a behavioral data point: Go back to making good websites and stop leaking private data everywhere. T…

>loading every bit of text with a remote javascript. This update is only about a select list of "bad" domains, though. I don't think most users would want to block literally all third party scripts (Source: I use uMatrix set to do that, and every other site I visit requires a complicated ritual of unblocking layers of scripts, frames, and XHR. Don't even get me started on static sites that display blank without scrip…

What good is blocking google tracking subdomains while neatly packaging the exact same data and sending it off to google cdn and tagmanager?

Re: Firefox Now Available with Enhanced Tracking Protection by Default

#204
post #185

This feature breaks hundreds of websites listed in a 5 year old issue [1] The last descriptive update was 4 years ago, > As the list is increasingly managed according to policy, breakage is a feature, not a bug. [1] https://bugzilla.mozilla.org/show_bug.cgi?id=1101005 Among the broken websites is one I just completed, revddit, "removeddit for user pages": https://revddit.com/user/rhaksw

Are you the one that created this bot on reddit?

https://www.reddit.com/user/revddit/

Creating a bot to spam your own website is obviously against the site rules. I see most of your posts on Hacker News are similarly promotional.

Re: Firefox Now Available with Enhanced Tracking Protection by Default

#205
post #201
post #190

Earlier quoted context omitted.

My website is broken by this feature [1]. It does not leak private data, as Mozilla devs said here [2] > According to the original screenshot in the thread, your web page is sending an HTTP request to https://www.reddit.com/api/v1/access_token . If the user has previously visited reddit.com, this request will include the user's reddit cookies normally. Also, the HTTP request I mentioned before has a Referer header th…

I don't get it. The Mozilla dev explained, as you quoted, that the API access sends the reddit cookie to reddit while not being on reddit. That's leaking private data. "In other word, Reddit will be able to see the user's browsing history, as if they had access to the user's computer." You know who owns reddit, right?

> the API access sends the reddit cookie to reddit while not being on reddit.

A few things,

(1) Why does it matter in this case? Under what scenario can you imagine reddit abusing the knowledge that certain users are reading metadata about reddit accounts off-site?

(2) It seems to me Firefox could selectively choose not to send cookies and the referrer header in this case, rather than rendering entire sites broken. In that manner, sites accessing social media APIs can function, no data leaks, and everyone is happy.

(3) Hundreds of sites are broken like this. An issue tracking them has been open for 5 years [1]. The list used to identify "tracking" websites is huge and not maintained by Firefox [2].

(4) Due to this list, it is virtually impossible to build a web service that queries any social media site and runs on Firefox under default settings, significantly handicapping apps that can be built. Devs' recommendation was for me to move the code to a server, which would be expensive to maintain and would limit usefulness to users by obscuring code and introducing per-IP rate limits from the external API, in this case reddit's.

[1] https://bugzilla.mozilla.org/show_bug.cgi?id=1101005

[2] https://github.com/disconnectme/disconnect-tracking-protecti...

Re: Firefox Now Available with Enhanced Tracking Protection by Default

#207
Going back to Firefox nightly since the google ad issue. I'm sad to say, Firefox UI still lags 2x more than Chromium (even abused with 40+ tabs) on my old machine to the point of being a noticeable annoyance.

Hopefully Mozilla will have funding and manpower to improve this.

Thanks for the work nonetheless.

Re: Firefox Now Available with Enhanced Tracking Protection by Default

#209
post #185

This feature breaks hundreds of websites listed in a 5 year old issue [1] The last descriptive update was 4 years ago, > As the list is increasingly managed according to policy, breakage is a feature, not a bug. [1] https://bugzilla.mozilla.org/show_bug.cgi?id=1101005 Among the broken websites is one I just completed, revddit, "removeddit for user pages": https://revddit.com/user/rhaksw

Are you the one that created this bot on reddit? https://www.reddit.com/user/revddit/ Creating a bot to spam your own website is obviously against the site rules. I see most of your posts on Hacker News are similarly promotional.

Promotion through censorship is what I meant to tackle when building the site, so I'm sorry if you feel the bot or citing it on HN is too promotional. Isn't this the place for sharing such work? If not here, where?

The bot itself only responds once per user or thread, and I've already blacklisted some subreddits per suggestions [1]. Feel free to pm me at u/rhaksw if you would like to discuss it further.

[1] https://www.reddit.com/wiki/bottiquette

Re: Firefox Now Available with Enhanced Tracking Protection by Default

#210
post #155

Unpopular opinion on HN - Majority regular net users don't care about tracking and the FF focus on privacy will not give them the browser landscape they are losing daily. They should be focused on giving a better smooth UI, make it faster, remove unwanted extensions like pocket, make all the sites work. Let's see how valid this comment is in couple of years.

> They should be focused on giving a better smooth UI, make it faster, remove unwanted extensions like pocket, make all the sites work.

Those are all things which do not differentiate Firefox from Chrome. They're focusing on that as well, but Chrome will never be able to copy their privacy-enhancing features, because that's Google's business model.

Post reply on HN