Live data from Hacker News

Firefox getting smarter about third-party cookies

blog.mozilla.org

31–40 of 103 posts

Re: Firefox getting smarter about third-party cookies

#31
post #28
post #15

Earlier quoted context omitted.

Give me an example where sending a Referer is essential to providing me as a user with a better experience. There are no such cases, period. Also, with an exception of dumb content protection schemes (anti-hot-linking), Referrers are used exclusively for tracking purposes and carry zero positive benefits for the users. If Mozilla is in fact "passionate about putting its users first", these headers must go. It is as s…

Referrers are used exclusively for tracking purposes and carry zero positive benefits for the users. This is short sighted. Sites can respond to referrers by improving themselves and better adapting to what users are looking for.

Sure, in theory.

Re: Firefox getting smarter about third-party cookies

#32

Earlier quoted context omitted.

First, there are already multiple Firefox extensions that will let you totally control the Referer header. (In general, if there's something that you want to change about Firefox, you should search https://addons.mozilla.org to find a solution, because somebody's probably already created an extension that does what you want.) I think one such extension is called "RefControl." I also brought up the issue on Mozilla's…

FWIW, I just followed your advice, searching Firefox Addons for "Referer". The results were not helpful at all for the goal abcd_f mentioned of blocking cross-site referrers. [Edit: Sorry, it looks like I mistyped "Referer". There is at least one promising addon on the first page.] Also FWIW, I agree that this is indeed becoming a significant privacy issue. I too don't see why Google or Typekit or some widely used CD…

> Is this because some of the third party resources are only authorised for use by certain sites and rely on Referer to establish whether a given request qualifies? Given that there is no security or verification for Referer headers, that seems like a rather broken model to start with.

It's just a first-order approximation to defend against hotlinking. Disabling referes wholesale has mostly worked out for me (via about:config, not an extension), but very rarely I have to turn them back on or switch to a backup browser profile or whatever.

Re: Firefox getting smarter about third-party cookies

#33

Earlier quoted context omitted.

FWIW, I just followed your advice, searching Firefox Addons for "Referer". The results were not helpful at all for the goal abcd_f mentioned of blocking cross-site referrers. [Edit: Sorry, it looks like I mistyped "Referer". There is at least one promising addon on the first page.] Also FWIW, I agree that this is indeed becoming a significant privacy issue. I too don't see why Google or Typekit or some widely used CD…

> Is this because some of the third party resources are only authorised for use by certain sites and rely on Referer to establish whether a given request qualifies? Given that there is no security or verification for Referer headers, that seems like a rather broken model to start with. It's just a first-order approximation to defend against hotlinking. Disabling referes wholesale has mostly worked out for me (via abo…

But if you're linking to an image on your own site from your own site, the proposal not to send Referer headers across domains to third parties wouldn't do any harm.

In other words, if your interest is in blocking unauthorised hotlinking, can't you just assume anyone who doesn't include a Referer is equivalent to someone sending a Referer from a malicious site and decline the request?

Re: Firefox getting smarter about third-party cookies

#34

Earlier quoted context omitted.

FWIW, I just followed your advice, searching Firefox Addons for "Referer". The results were not helpful at all for the goal abcd_f mentioned of blocking cross-site referrers. [Edit: Sorry, it looks like I mistyped "Referer". There is at least one promising addon on the first page.] Also FWIW, I agree that this is indeed becoming a significant privacy issue. I too don't see why Google or Typekit or some widely used CD…

Is this not what you want? Third search result: https://addons.mozilla.org/en-US/firefox/addon/smart-referer...

Sorry, you're right. I think I forgot to misspell "referrer" the first time I searched.

Re: Firefox getting smarter about third-party cookies

#35
Finally. Third party cookies provide almost zero value for users. Only use case is for log in on iframe-embedded apps such as Discus comment boards, but the ones you use yourself can be counted on one hand so adding exceptions isn't such a big issue. Adding some UI that shows that you are logged in to Discus on a particular web page would just good imo. I think the "From visited" option is an excellent trade off as a transition period until a better option for embedded authentication is available.

Re: Firefox getting smarter about third-party cookies

#36
post #14
post #4

Earlier quoted context omitted.

> Users of this build of Firefox must directly interact with a site or company for a cookie to be installed on their machine. There are not many users that don't interact with google. While I don't expect the chrome team to add this to their feature list (even as optional), if they did, it would not really hurt google. It would actually hurt all the other "smaller" players.

>It would actually hurt all the other "smaller" players Exactly. But it's not neccesary a bad thing though. What all the "smaller players" in emerging retracking field - where 3rd party cookies are used in the first place - are doing now is nothing conceptually different from "ah, you've added iPhone to shopping cart at shopX! Now we'll show you iPhone ads for a week on every site you visit!". And user is beating her…

You're right that these retargeting shops have a stupid thesis and can only exist because marketers' metrics haven't evolved enough yet (and that's changing). Highest purchase % doesn't mean you changed intent or created business, you just won the bidding war to show an ad to someone who was already going to buy, or maybe already bought.

But users will never manually enable 3rd party cookies, even if they agreed with you that the ads were adding value (which odds are they never will either).

Content has to be monetized in some way -- if not ads, then how?

All that blocking 3rd party cookies will accomplish is put most of the less technically-mature shops out of business while the smart ones figure out a way to route around using the exact same data science for targeting.

Re: Firefox getting smarter about third-party cookies

#38
post #4

Google is in the ad business making it tougher for them to go in this direction. Go Firefox

> Users of this build of Firefox must directly interact with a site or company for a cookie to be installed on their machine. There are not many users that don't interact with google. While I don't expect the chrome team to add this to their feature list (even as optional), if they did, it would not really hurt google. It would actually hurt all the other "smaller" players.

It could very easily be seen as a monopolistic move on their part if they were to move in that direction oddly enough.

Re: Firefox getting smarter about third-party cookies

#39
post #4

Google is in the ad business making it tougher for them to go in this direction. Go Firefox

> Users of this build of Firefox must directly interact with a site or company for a cookie to be installed on their machine. There are not many users that don't interact with google. While I don't expect the chrome team to add this to their feature list (even as optional), if they did, it would not really hurt google. It would actually hurt all the other "smaller" players.

This change will hurt small players in web advertising, but I suspect they are more likely to use shady tracking tactics than the big players. So fewer players consolidates user information, but I hope it makes those advertisers easier to track and regulate.

Re: Firefox getting smarter about third-party cookies

#40
post #24

Does this affect Google Analytics (or any analytics software for that matter)? if so: How would a webmaster deal with that?

Google Analytics javascript runs on your domain and the cookies it uses are on your domain. So it should count as "first party" here.

Interesting. Isn't the website just telling to load the script from a Google server (which could count as 3rd party) and execute it?
Post reply on HN