Live data from Hacker News

Firefox 85 cracks down on supercookies

blog.mozilla.org

641–650 of 786 posts

Re: Firefox 85 cracks down on supercookies

#641

Earlier quoted context omitted.

> it seems incredibly naive in hindsight Oh stop with the dramatics, please. JS has brought us an immense amount of innovation on the web. It has lowered the barrier of entry to programming and introduced tens of millions of people to the world of development. If you're on HN the odds are that directly or indirectly, JS is one of the reasons you have a job today, and that you can execute it remotely. And today specif…

I agree with simias. What does JS have to do with my VPN? What was wrong with Skype? Still beats the pants off others for quality. I cannot think of much good agressive whitespace, hamburger menus, infinite scrolling, HID hijacking, copy-paste preventing, trackers etc, etc etc, has brought us, besides into the world of Aggressive Ad Arbitrage. Need https://motherfuckingwebsite.com/ be mentioned? The real powerhouse w…

So .. because you don't like design trends, you're saying JS is useless?

That's like saying wool is useless because you don't like modern fashion.

Re: Firefox 85 cracks down on supercookies

#642
"Trackers and adtech companies have long abused browser features to follow people around the web."

Is this a confesion.

Browsers, including Mozilla, have continually designed and kept those features enabled by default, even when they are aware of the abuse.[1]

Mozilla is nearly 100% funded by a deal with Google.

I try to forget these facts every time I read some public communication coming from Mozilla, but they just keep coming back.

1. Mozilla, or any of us (yeah, right), could rip out some of the fetaures that advertisers abuse and create a more "advertising-proof" version of Firefox. Heck, we could create much smaller and faster Firefoxes. But no, there can be only one. Because reasons.

Take out that search bar and they would probably have to kiss the money from Google goodbye.

Getting rid of ads and tracking is not Mozilla's highest priority. Keeping online advertising alive is the highest priority because obvious reasons.

There is nothing in the contract we have with our ISP that says we must support online ads. That is the benefit of paying for something. There are actually terms and the possibility for enforcement.

Mozilla's ad-supported web has no terms. None that web users can enforce. Internet subscribers using "the web" have no power. Advertisers call the shots.

Re: Firefox 85 cracks down on supercookies

#643
post #496
post #318

Earlier quoted context omitted.

Whitelist/blacklist have their origins in terms from the 1400s and nothing to do with race (they have to do with criminality). Twisting their etymology to fit some kind of racial bias is sort of weird. And throwing aside 600 years of clarity for "basic manners" also seems rather weird. Sort of like banning the word "engender" because a small minority might find that to be offensive. It isn't clearer to use a differen…

For a while, people were getting in trouble for using the word, "niggardly," even though it had nothing to do with the offensive term that it sounds like. https://en.wikipedia.org/wiki/Controversies_about_the_word_n...

The difference being that the controversy around white/blacklist only appeared after someone said it was a controversy in 2018, which is extremely recent, and the wording doesn't contain any phonetic similarity to a term from slavery. Being able to be misheard is more of a problem when phonetics clash.

Should all terms for the colour-that-is-somewhat-the-absence-of-colour now be banned? Is Vanta Black now racist?

Manufactured controversy leads you down a path of absurdism. It isn't helpful to the people it purports to help, whilst granting the vocal group the ability to say they're being helpful whilst actively ignoring any actual problems.

Re: Firefox 85 cracks down on supercookies

#644

Earlier quoted context omitted.

> it seems incredibly naive in hindsight Oh stop with the dramatics, please. JS has brought us an immense amount of innovation on the web. It has lowered the barrier of entry to programming and introduced tens of millions of people to the world of development. If you're on HN the odds are that directly or indirectly, JS is one of the reasons you have a job today, and that you can execute it remotely. And today specif…

That's an entirely different question to whether it should be on by default for random sites, which is what GP is actually talking about. I would go farther and say that there was never a time that it looked reasonable.

Don't you think JS being so available is part of what made it so popular, and thus what made it accessible, and what brought programming to millions who wouldn't have done it otherwise?

Re: Firefox 85 cracks down on supercookies

#645

"Trackers and adtech companies have long abused browser features to follow people around the web." Is this a confesion. Browsers, including Mozilla, have continually designed and kept those features enabled by default, even when they are aware of the abuse.[1] Mozilla is nearly 100% funded by a deal with Google. I try to forget these facts every time I read some public communication coming from Mozilla, but they just…

Uhm... Tor Browser? Already exists, based on Firefox, with features merged upstream?

Re: Firefox 85 cracks down on supercookies

#646
post #508

Earlier quoted context omitted.

And how would you address this problem?

I browse in firefox with javascript turned off, in ublock, with a bunch of other restrictions [0], and temporary containers. I make exceptions for a couple dozen sites, like my bank, open street maps, etc. Youtube is my only soft spot here, the rest of google I keep blocked. I can make one-off exceptions to read a tab in front of me, but that's not routine, it's not hard to find sites that support this. [0] https://g…

How do you use the internet with JS turned off? Every time I try doing this, I undo it five seconds later because of so many sites breaking instantly. (I sometimes browse the web with w3m; sites blocking you because of no JS happens often)

Re: Firefox 85 cracks down on supercookies

#647

Earlier quoted context omitted.

I don't see how using containers in Firefox or auto-deleting cookies would have any negative effect here. None of the cache deletion/isolation addons should inject any Javascript into the page or alter headers in any way, so they shouldn't be detectable to sites you visit. So in terms of unique behavior, all that site isolation means is that you're going to hit caches more often and be missing cookies. I mean, sure,…

Auto-deleting cookies or other content in a way that doesn't resemble Safari ITP would indicate that a device at your IP address is constantly losing tracking cookies in an uncommon manner, theoretically increasing your trackability. Websites can only make inferences based on the absence of unique cross-site cookies if you are configuring your browser in non-default ways. If all Firefox 85+ users are partitioning, th…

> Websites can only make inferences based on the absence of unique cross-site cookies if you are configuring your browser in non-default ways.

But if the defaults don't block those cookies, then the alternative is that you have unique cross-site cookies, which are an instant game over. Having a site make inferences about you is preferable to having a unique cross-site cookie set that can perfectly identify you across multiple websites.

> [...] and I wish that more took your careful approach here when recommending "privacy" setups to others.

Similarly, I appreciate your approach and concerns, and you are correct that browser uniqueness is a valid concern, one that many people don't consider. But I fully stand by my advice. Your first priority as a user who cares about privacy needs to be blocking unique cross-site cookies. If you have them set, it's just game over, it doesn't matter whether or not someone is fingerprinting you somewhere else.

Your priority list should be:

A) block cookies and persistent storage that can track you across sites.

B) block tracking scripts from ever executing at all.

C) keep your browser from standing out.

D) etc...

uBlock Origin is the easiest, simplest way that you can make progress towards addressing A and B. To your overall points about stuff like advertising networks looking to prevent fraud, this is exactly why it's important to block advertising networks; they're the low hanging fruit that's most likely to be trying to fingerprint you at any given moment. To your point about it standing out that you don't have certain query params set, those query params are unique identifiers and referrers. If you don't delete them it's game over, you have been identified. You can't blend into the crowd if you have a tracker attached to you.

There are very few one-size-fits-all approaches to security/privacy, but I fully stand by the belief that virtually every single person running Chrome or Firefox should have uBlock Origin installed. I don't have much nuance or any caveats to add to that statement: block unique identifiers first, worry about fingerprinting second. You don't need to worry as much about your browser standing out if you block the majority of tracking scripts from reaching your browser in the first place, and in most (not all, but most) cases you should be more worried about 3rd-party tracking on the web than 1st-party tracking. That's just where the current incentives are right now, and it's important that we calibrate our threat models accordingly.

Re: Firefox 85 cracks down on supercookies

#648
post #18

"In the case of Firefox’s image cache, a tracker can create a supercookie by “encoding” an identifier for the user in a cached image on one website, and then “retrieving” that identifier on a different website by embedding the same image." Clever. And so frustrating that optimisations need to be turned off due to bad actors.

Ads are frustrating but this can lead to even more irrelevant and therefore more frustrating ads.

Re: Firefox 85 cracks down on supercookies

#649

Earlier quoted context omitted.

That idea of having JS files hosted elsewhere always struck me as a Girardian scam (e.g. "everybody else does it") and always getting voted down when I showed people the reality factor. Nobody seemed to think it was hard to host a file before this came along, just as nobody thought it was hard to have a blog before Medium. Of course this creates the apocalyptic possibility that one of these servers could get hacked (…

Browsers can check "subresource integrity" to guard against hacks of third-party services. https://developer.mozilla.org/en-US/docs/Web/Security/Subres...

Yeah but you, the developer, need to provide the hash of the script being downloaded, work that’s easy to miss.
Post reply on HN