We need to acknowledge also that recognising the user as he moves across pages and domains is sometimes needed to provide valuable services to the user. Therefore, I believe, browsers have to provide a volunteer "tracking" functionality - when a web page reqests 3rd party cookies, a popup is shown to the user with the cookie values, description (as set by the owning domain), the list of domains already permitted to a…
Firefox 85 cracks down on supercookies
551–560 of 786 posts
Re: Firefox 85 cracks down on supercookies
#552We need to acknowledge also that recognising the user as he moves across pages and domains is sometimes needed to provide valuable services to the user. Therefore, I believe, browsers have to provide a volunteer "tracking" functionality - when a web page reqests 3rd party cookies, a popup is shown to the user with the cookie values, description (as set by the owning domain), the list of domains already permitted to a…
The "problem" with that solution is that users are very willing to click any button necessary to achieve their goal, and in any dialog that prompts to allow tracking in order to achieve something else, most people will click allow. Personally I don't think this is a problem, and people should be allowed to make that choice. But most of HN seems to disagree with me there, and feels that users need to be protected from…
Re: Firefox 85 cracks down on supercookies
#553We need to acknowledge also that recognising the user as he moves across pages and domains is sometimes needed to provide valuable services to the user. Therefore, I believe, browsers have to provide a volunteer "tracking" functionality - when a web page reqests 3rd party cookies, a popup is shown to the user with the cookie values, description (as set by the owning domain), the list of domains already permitted to a…
That is when you have sign in and communication on the server side, not place data in the browser for tracking.
Re: Firefox 85 cracks down on supercookies
#554Earlier quoted context omitted.
> The latest casualty was podcasts. It's revolting. Hmm? Yes, there are adverts on all the podcasts I listen to. Many of my favorites offer members only ad-free versions. Usually I suffer through the ad supported versions because the adverts are easy enough to skip. Some podcasts have too many adverts or annoyingly inserted advertising. Those are pretty 1 and done. No point listening to them. IMO the (current) podcas…
I absolutely don't respect having my weir podcast-friendship relationship with the host exploited by fully integrated ad pieces whispered to me in a trusted voice. That. Is. Sick.
Do you feel people should volunteer their time gratis to entertain you?
What Hacker News does with adverts slipped into the newsfeed is essentially the same as what podcasters do.
Re: Firefox 85 cracks down on supercookies
#555Earlier quoted context omitted.
In Javascript how are they able to retrieve something from the cache? Local, session, and cookies are domain locked.
I think that they put the user information in the image using something like this[1]. [1]. https://github.com/subc/steganography
Re: Firefox 85 cracks down on supercookies
#556Is there any reason to keep the Same Origin Policy after this change? I mean, shouldn't this change defeat CSRF attacks?
All this does is create a separate cache for each site, so that they can't infer that a user has already been to another site. It makes no changes to POST/PUT/PATCH requests to an endpoint. They will still be going there.
Re: Firefox 85 cracks down on supercookies
#557From a purely web browsing experience the first iPad 'should be' powerful enough to browse ANYTHING out there these days. But it can't. The last few models will increasingly have the same issues as the sheer volume of muck and cruft that's included with the advertising gack just continues to explode. I'm definitely of the opinion that our web browsing devices are marketing tools that we are allowed to use for media c…
Re: Firefox 85 cracks down on supercookies
#558"In the case of Firefox’s image cache, a tracker can create a supercookie by “encoding” an identifier for the user in a cached image on one website, and then “retrieving” that identifier on a different website by embedding the same image." Clever. And so frustrating that optimisations need to be turned off due to bad actors.
Note that the root of all evil here is Javascript being opt-out instead of opt-in (and effectively mandatory for a big chunk of the internet these days). Letting any website and their friends (and the friends of their friends) run turing complete code on the client PC probably sounded reasonable when the web was created but it seems incredibly naive in hindsight. It's not as bad as ActiveX and other plugins, but it's…
Re: Firefox 85 cracks down on supercookies
#559Earlier quoted context omitted.
That is when you have sign in and communication on the server side, not place data in the browser for tracking.
How do you suggest implementing "sign in" without setting a cookie?
Re: Firefox 85 cracks down on supercookies
#560Earlier quoted context omitted.
A lot of people accept that which is beyond their control. That doesn't mean they are Ok with it, just that they don't know how to do anything about it or often that it's even happening.
Wasn't there an article about paying with your face around here just a bit ago? People clearly don't just tolerate this, but embrace it. Only people from places where it's too late to go back (like China) are aware of the dangers of these systems, but they can hardly warn the rest of us and when they do, we generally don't listen as "something like that surely wouldn't happen in my free country". It would seem that p…
There's not much risk to 'pay with your face' for Apple/Google/Samsung pay given it's all on-device biometrics that never leave the phone, but a similar situation is when Google paid $5 to people willing to submit their face to help with facial recognition training in the then-upcoming Pixel 4 phone.
https://gadgets.ndtv.com/mobiles/news/google-pixel-4-usd-5-f...