Live data from Hacker News

Firefox 85 cracks down on supercookies

blog.mozilla.org

421–430 of 786 posts

Re: Firefox 85 cracks down on supercookies

#421

Earlier quoted context omitted.

Doing this will make it trivially easy to fingerprint and track you on the web, as the set of people who use non-defaults like this list is 0.000001% of the total possible user space for their area, and your IP address probably only changes rarely or never A better way to protect yourself is to use a browser with tracking protections on by default, and leave the settings alone. You may see a few more ads but you’ll b…

I don't see how using containers in Firefox or auto-deleting cookies would have any negative effect here. None of the cache deletion/isolation addons should inject any Javascript into the page or alter headers in any way, so they shouldn't be detectable to sites you visit. So in terms of unique behavior, all that site isolation means is that you're going to hit caches more often and be missing cookies. I mean, sure,…

Auto-deleting cookies or other content in a way that doesn't resemble Safari ITP would indicate that a device at your IP address is constantly losing tracking cookies in an uncommon manner, theoretically increasing your trackability.

Websites can only make inferences based on the absence of unique cross-site cookies if you are configuring your browser in non-default ways. If all Firefox 85+ users are partitioning, then any inferences drawn from that behavior do not increase your trackability — and it could well decrease it, as those Firefox 85+ users will be joining the swarm of Safari users whose browser has already done the same sort of partitioning for a couple years.

Multi Account Containers are an oddity, and alone they would not be particularly distinguishable from a multi-user computer (which, at a home residence, could be unusual; many people don't have User Accounts on a shared device). However, when combined with cross-container tracking infection (such as URL parameter tags designed to survive a transition to another container, e.g. fbclid or utm_*), it's possible to identify that a user is using containers, which is a very rare thing and not available by default, thus increasing risk of being tracked.

UBlock Origin allows far too much customization for me to prepare any clear reply there. I imagine it is possible to run UBO with a ruleset that only interferes with requests to third-party adservers, without letting the first-party know that this is occurring. I doubt, however, that a majority of UBO users are running in such a circumspect mode. Adblocking often requires interfering with JavaScript in ways that are easily visible to the first-party (who has a vested interest in preventing ad fraud).

Fingerprinting is a known defense against fraudulent clicks, so there's a lot to puzzle over there. But I definitely don't like to take active steps to make myself stand out from others. I'm annoyed that I'm tracked a little on the web, but I'm indistinguishable from the general pool of "users with default browser settings" today. That's a type of protection that addons can't provide. I'm not wholly certain what I think yet, but happily the browsers continue advancing the front of protection forward, so maybe by the time I decide it won't matter anymore. YMMV.

ps. I'm glad to see your much more nuanced consideration of this balance, and I wish that more took your careful approach here when recommending "privacy" setups to others.

Re: Firefox 85 cracks down on supercookies

#422
post #18

"In the case of Firefox’s image cache, a tracker can create a supercookie by “encoding” an identifier for the user in a cached image on one website, and then “retrieving” that identifier on a different website by embedding the same image." Clever. And so frustrating that optimisations need to be turned off due to bad actors.

Note that the root of all evil here is Javascript being opt-out instead of opt-in (and effectively mandatory for a big chunk of the internet these days).

Letting any website and their friends (and the friends of their friends) run turing complete code on the client PC probably sounded reasonable when the web was created but it seems incredibly naive in hindsight. It's not as bad as ActiveX and other plugins, but it's pretty close.

Re: Firefox 85 cracks down on supercookies

#423
post #75

Earlier quoted context omitted.

That's not true; they respect the sciences. But only sufficiently "hard" ones like chemistry and biology.

You seem to think that the meaning of "STEM" includes anything that anyone applied the word "science" to. But no, the "science" part is precisely the "hard" sciences. E.g. psychology, economics and theology aren't included in STEM.

I thought it was STEM instead of HSTEM. Silly me.

Sarcasm aside, not all natural sciences are treated equally. There are differing attitudes towards astronomy, oceanography, and climatology, for example.

Re: Firefox 85 cracks down on supercookies

#424
post #375

Earlier quoted context omitted.

I am really confused by this position. How do you propose that companies should promote their products and services, if not through advertising? Are you somehow suggesting that they should just sit there and hope that people who have never heard of their product independently decide they happen to want or need that product and seek it out, unprompted? You say "people part with their money for things they wouldn't thi…

> Are you somehow suggesting that they should just sit there and hope that people who have never heard of their product independently decide they happen to want or need that product and seek it out, unprompted? Yeah, it's even got a name: shopping.

And how do you know about the existence of a product to go shop for in the first place, if not through advertising and promotion?

Or do you have infinite time to go browse every single store in your city on the odd chance that you'll see something you want?

Re: Firefox 85 cracks down on supercookies

#425
post #341

Earlier quoted context omitted.

I had to use a Fax machine in 2018. In the United States. As the only acceptable way to submit certain documents. I should also point to non-Unitedstatians that checks (that physical paper worth as much money as you write and sign on it) are still in use in the USA.

Checks still in use in Canada as well. I had a person today tell me they had 3 checks stolen and cashed and my response was “people still use checks?”.

Still in us but much less than the US. Interac bank transfer has cut on a lot of that usage.

Re: Firefox 85 cracks down on supercookies

#426

Earlier quoted context omitted.

We're trying to build an ad network that doesn't track users: https://www.ethicalads.io/ We talked a little bit about how these ads still work, even without tracking you. You might be losing 10-15% of revenue, but if you never had that revenue to start with, you don't miss it: https://www.ethicalads.io/blog/2018/04/ethical-advertising-w... I think the real secret is just to not become dependent on the additive revenu…

There is no such thing as an ethical ad. Advertising is a cynical deployment of our knowledge of crowd wisdom, media manipulation, and statistics to make people part with their money for things they wouldn't think they needed. Our economy can't handle this kind of reckless consumerism anymore. Worse yet, we don't need advertising to bolster our media. Unfortunately, the media execs don't realize this yet. All your me…

I like what that guy is doing, but I still have to agree with you. To me ads are just money focused propaganda, abusing human psychology to make people spend money they on crap they don't need.

Re: Firefox 85 cracks down on supercookies

#427
post #325
post #18

"In the case of Firefox’s image cache, a tracker can create a supercookie by “encoding” an identifier for the user in a cached image on one website, and then “retrieving” that identifier on a different website by embedding the same image." Clever. And so frustrating that optimisations need to be turned off due to bad actors.

I'm curious how bad disabling this caching feature would be. Specifically, how often do you load the same image on two different domains?

Good question. I'd guess that the chance of that happening is very small. But if that optimization exists maybe it's not that uncommon?

Re: Firefox 85 cracks down on supercookies

#428
post #221

Earlier quoted context omitted.

25-33% of requests? Or is this a percentage of bytes? Because I wonder what percentage of bandwidth (in terms of bytes) trackers/banners/ads account for. Need to set up a pi-hole ... just too many other projects....

How would you measure bytes if the requests are blocked?

Run the same requests throught different end points. Each through pihole & unfiltered, while monitoring the traffic on both.

Re: Firefox 85 cracks down on supercookies

#429
post #422
post #18

"In the case of Firefox’s image cache, a tracker can create a supercookie by “encoding” an identifier for the user in a cached image on one website, and then “retrieving” that identifier on a different website by embedding the same image." Clever. And so frustrating that optimisations need to be turned off due to bad actors.

Note that the root of all evil here is Javascript being opt-out instead of opt-in (and effectively mandatory for a big chunk of the internet these days). Letting any website and their friends (and the friends of their friends) run turing complete code on the client PC probably sounded reasonable when the web was created but it seems incredibly naive in hindsight. It's not as bad as ActiveX and other plugins, but it's…

No no no. The problem isn't JavaScript or web capabilities here. It's the companies and people who use them in evil ways. I would rather handle that even if it's much much harder.
Post reply on HN