Live data from Hacker News

Firefox 85 cracks down on supercookies

blog.mozilla.org

321–330 of 786 posts

Re: Firefox 85 cracks down on supercookies

#321

Earlier quoted context omitted.

Can you elaborate on your setup?

I'm not OP, but I have my browser setup to block trackers only, nothing that's billed as an ad-blocker. I use Firefox with Strict Enhanced Tracking Protection [0] and Privacy Badger [1] as an extra layer of protection. Some sites, mostly news orgs, complain that I'm blocking ads, but inevitably these are the sites Privacy Badger reports 20+ trackers blocked. I'm happy to see ads online, I'm just not willing to sacrif…

Why not just block ads, too? Do you really think advertising is ethical at any level? Because I do not. If I want to buy something, I seek it out. Anything else is like junk snail mail: a waste of my time and your money.

Re: Firefox 85 cracks down on supercookies

#322

Use uBlock Origin, Multi Account Containers, Privacy Badger, Decentraleyes and CookieAutoDelete with Firefox. Make sure you aggressively clear cache, cookies, etc., periodically (with CookieAutoDelete). You’ll probably load the web servers more and also add more traffic on your network, but it will help protect your privacy since most websites don’t care about that. When websites are user hostile, you have to take pr…

Doing this will make it trivially easy to fingerprint and track you on the web, as the set of people who use non-defaults like this list is 0.000001% of the total possible user space for their area, and your IP address probably only changes rarely or never

A better way to protect yourself is to use a browser with tracking protections on by default, and leave the settings alone. You may see a few more ads but you’ll be a lot less tracked as a result.

If personal convenience is the priority, then of course Adblock and so on to your heart’s content, but if not being tracked is the priority, reset your browser settings to default and remove weird addons that your neighbors don’t use.

Re: Firefox 85 cracks down on supercookies

#323
post #31

Are there any plans for complete partitioning? I'd like to see a point where browsing on two different websites are treated as a completely different user. Embeds, cookies, cookies in embeds, etc.

This is called First-Party Isolation, a key principle of the Tor Browser and an optional preference in Firefox.

Re: Firefox 85 cracks down on supercookies

#324
post #28

Tracking has become so bad that it seems like users have to spend money (more bandwidth) to protect themselves from it. Crazy and sad to see where we've come :\

Which one more annoying for you between today's tracker and early 2000ish popup on top IE?

Or remember adware on windows XP and how many antivirus tools advertised to eradicate that.

* they're hilarious comparison but I found it amusing.

Re: Firefox 85 cracks down on supercookies

#325
post #18

"In the case of Firefox’s image cache, a tracker can create a supercookie by “encoding” an identifier for the user in a cached image on one website, and then “retrieving” that identifier on a different website by embedding the same image." Clever. And so frustrating that optimisations need to be turned off due to bad actors.

I'm curious how bad disabling this caching feature would be. Specifically, how often do you load the same image on two different domains?

Re: Firefox 85 cracks down on supercookies

#326

These advertising networks are destroying web performance. Most of these "Supercookies" are optimizations to improve performance. By abusing them, advertisers have turned what should be a great performance tool into a liability. I know FF suggests this won't significantly affect most websites performance, but web advertising and trackers are already responsible for a huge chunk of performance issues already. Of cours…

We're trying to build an ad network that doesn't track users: https://www.ethicalads.io/ We talked a little bit about how these ads still work, even without tracking you. You might be losing 10-15% of revenue, but if you never had that revenue to start with, you don't miss it: https://www.ethicalads.io/blog/2018/04/ethical-advertising-w... I think the real secret is just to not become dependent on the additive revenu…

To me, there is no such thing as an “ethical ad”. You are trying to steal my attention, my time. You don’t get to do that. My time on Earth is limited and you don’t get a millisecond of it if I can help it.

If I want to buy something, I seek it out. Anything else is a waste of my time and a waste of the advertisers money.

I long ago decided to throw out every piece of physical ad mail I receive without even glancing at it more than long enough to recognize it as an advertisement.

I don’t know why you expect me to treat your digital ads any differently?

You can call my perspective extremist, but is it any more extreme than the methods used by advertising networks to steal my attention?

Re: Firefox 85 cracks down on supercookies

#327
post #199

Earlier quoted context omitted.

I wonder how many people reading this comment are thinking, "what's a fax machine?" :o) I like the analogy, but I wonder how effective it is on anyone under the age of what, 35?

My bank still accepts fax documents. All I would have to do is find a fax machine ...

There are quite a few multifunction printers with fax.

Re: Firefox 85 cracks down on supercookies

#328
post #239
post #215

Earlier quoted context omitted.

Sorry, I didn't mean their _own_ servers, I just meant hard-coding 8.8.8.8 into the DNS settings, for example. I wonder if you could hijack those requests at your router and send them back to your Pi-Hole? But then they just switch to DNS over TLS...

I just have my network block outgoing DNS queries that aren’t from the gateway. But you’re so right that DoH is going to throw a wrench in this.

If an ad can use DoH to sidestep a firewall, so can an employee. If Google and Facebook were cunning (and nefarious, but that much is presumed), they would be aggressively developing a product that solves this problem for corporate networks, but at an enormous cost. Otherwise, when corporate networks solve this (and they will), home users who hate ads will just follow whatever pattern they settle on.

Re: Firefox 85 cracks down on supercookies

#329

Earlier quoted context omitted.

I switched in late 2017 when they released quantum or neutrino or whatever they called it, a huge performance release. As a backend dev and security focused eng I have little reason to test drive changes in all browsers. FF has been smooth and stable for me across desktop OSs. Having no reason to alternate between that and Chrome, I’ve been confused by people saying it’s slow. It’s been, to my memory, a flawless expe…

I've had a similar experience. My only gripe is that the Facebook Container extension / Multi-Account Containers[0] stopped working for some reason, and I haven't been able to get them working again. I love that I was able to sequester all of Google's real estate from all of Amazon from all of my work tabs, and so on. [0] https://support.mozilla.org/en-US/kb/containers

The FB container is working Ok on my side. It's not helpful tho

May be try on new profile to isolate the issue.

Re: Firefox 85 cracks down on supercookies

#330
post #216

The partitioning thing is terrible for people with slow/unstable connections, despite the security gains. Is there a way to disable it? Or should I better think about installing a caching proxy to avoid the redundant traffic?

I think you’re overestimating the impact of this. Most web site content these days are served from the web site owner’s own domain. It’s only if a.com and b.com have (for example) the exact same image URL (c.com/img123.jpg) embedded, and you visit both sites, that this cache partitioning will make a difference. In essence, there’s very little legitimate Internet traffic that would be effected by this change, but lots…

What about JS libraries or CSS hosted by a CDN? I'm thinking jQuery, Bootstrap, etc etc. I learned that using a common CDN was the way to go because the content would likely already be in the user's cache and often not need to be loaded.
Post reply on HN