Live data from Hacker News

Firefox rolls out Total Cookie Protection by default to all users

blog.mozilla.org

71–80 of 339 posts

Re: Firefox rolls out Total Cookie Protection by default to all users

#71

Cool. Just a heads' up that I had to disable it on Zendesk and Asana so they could talk to each other - you might experience similar issues.

When I was blocking 3rd-party cookies on Chrome, I couldn't log into the IRS site. I figure that might happen here, too.

Re: Firefox rolls out Total Cookie Protection by default to all users

#72
post #57
post #37

Before anyone jumps to why Chrome doesn't block third-party cookies, some context: Regulators did warn Google NOT TO block third-party cookies before they provide a replacement, UK CMA accepted the latest proposal from Google: https://www.gov.uk/government/news/cma-to-keep-close-eye-on-... Apple's tracking rules also raised a lot of anti-trust concerns, giving advertisement in App Store unfair advantages among other…

they can still track you based on your account (e.g. Gmail, Hotmail, iCloud) Really? I don't think so. How would that work? If you visit www.somesite.com - how would javascript on that site identify you via Gmail?

Because Google's, Apple's and Microsoft's accounts specifically are tied to their particular browser and/or OS, not just the websites you're on.

So are Firefox accounts but they probably don't have the numbers to engage in any particularly egregious behavior.

Re: Firefox rolls out Total Cookie Protection by default to all users

#74
post #37

Before anyone jumps to why Chrome doesn't block third-party cookies, some context: Regulators did warn Google NOT TO block third-party cookies before they provide a replacement, UK CMA accepted the latest proposal from Google: https://www.gov.uk/government/news/cma-to-keep-close-eye-on-... Apple's tracking rules also raised a lot of anti-trust concerns, giving advertisement in App Store unfair advantages among other…

Just to clarify, Total Cookie Protection in Firefox is not the same as blocking third-party cookies. Firefox will accept third-party cookies and send them back, but only on this particular site. So third parties (read ad networks) will be able to track you on any site, but not across sites (without some other means of tracking).

If you don’t want Firefox to do even that, you can go to Settings, click on Privacy & Security, then choose the Strict option. It’ll warn you that it might break sites, but you can always turn it off on a site-specific level by clicking on the shield in the address bar and turning off the toggle.

Re: Firefox rolls out Total Cookie Protection by default to all users

#75
post #19

Earlier quoted context omitted.

It shouldn't. SSO doesn't typically work by sharing cookies, which have always been limited to a single domain in the first place.

I'm not sure about that. It depends on where the boundaries of the "cookie jar" are (through redirects and such). And I suspect it will effect it, in order to accomplish it's purpose. After all, what is tracking but a sort of "SSO" you don't know about. (OK, technically tracking is less powerful than SSO, since only the third-party needs to know your "single" identity, the first-party website doesn't actually know it…

Those work by redirect you on top level domain (the url you see in url bar) shouldn't be affected. They don't even share cookie directly anyway. (Which is just.... standard oauth)

Those work by enbedded into pages (iframe) or popups may.

The biggest offender of this kind of usage is probably facebook comment / disqus comment.

Re: Firefox rolls out Total Cookie Protection by default to all users

#76
post #59

It's nice, but is that so hard for Mozilla to tell in which version it will appear? Is it the current version or is it the next 102 version (which releases in 2 weeks, but then why they say it "rolls out"?)

Mozilla occasionally rolls out features in the current release via remote mechanisms. So it's rolling out to existing v101 installs now. I would assume that v102 will also ship with it on by default.

Re: Firefox rolls out Total Cookie Protection by default to all users

#77
post #57
post #37

Before anyone jumps to why Chrome doesn't block third-party cookies, some context: Regulators did warn Google NOT TO block third-party cookies before they provide a replacement, UK CMA accepted the latest proposal from Google: https://www.gov.uk/government/news/cma-to-keep-close-eye-on-... Apple's tracking rules also raised a lot of anti-trust concerns, giving advertisement in App Store unfair advantages among other…

they can still track you based on your account (e.g. Gmail, Hotmail, iCloud) Really? I don't think so. How would that work? If you visit www.somesite.com - how would javascript on that site identify you via Gmail?

[deleted]

Re: Firefox rolls out Total Cookie Protection by default to all users

#79

Earlier quoted context omitted.

Yeah, which is why sites are all requiring logins nowdays, so they can use server-side ID syncs.

> so they can use server-side ID syncs Does this only work if you use the same email across multiple sites? If so it's yet another reason to use a different email address with every site you sign up at.

Which incidentally Mozilla also has a product for: https://relay.firefox.com

(Disclosure: I work on Firefox Relay :) And yes, I know some people also have their own domain with unlimited email addresses.)

Re: Firefox rolls out Total Cookie Protection by default to all users

#80
I wonder if there's anyone from any advertising/ad-targeting companies on HN who can shed some light on if/how much this change may affect their "product".

Asking this since I know friends working at companies that were DRASTICALLY affected by the Apple advertising changes in terms of user targetability (and hence revenue) and I'm wondering if this change will be similar.

Post reply on HN