Live data from Hacker News

Firefox getting smarter about third-party cookies

blog.mozilla.org

1–10 of 103 posts

Re: Firefox getting smarter about third-party cookies

#2
Excellent. I know you, Mozilla guys, are on HN, so a question.

Any ETA for allowing to block Referer header from being included in cross-origin requests? If I'm on the page that pulls down something from Google Fonts, I see no reason why I should be sharing with Google the URL of the page I'm visiting.

Re: Firefox getting smarter about third-party cookies

#4

Google is in the ad business making it tougher for them to go in this direction. Go Firefox

> Users of this build of Firefox must directly interact with a site or company for a cookie to be installed on their machine.

There are not many users that don't interact with google. While I don't expect the chrome team to add this to their feature list (even as optional), if they did, it would not really hurt google. It would actually hurt all the other "smaller" players.

Re: Firefox getting smarter about third-party cookies

#5
post #2

Excellent. I know you, Mozilla guys, are on HN, so a question. Any ETA for allowing to block Referer header from being included in cross-origin requests? If I'm on the page that pulls down something from Google Fonts, I see no reason why I should be sharing with Google the URL of the page I'm visiting.

But a request is still a request. It might not make sense to include referer data in the case you mentioned but that does not mean every cros request will fit that description.

Re: Firefox getting smarter about third-party cookies

#7
post #4

Google is in the ad business making it tougher for them to go in this direction. Go Firefox

> Users of this build of Firefox must directly interact with a site or company for a cookie to be installed on their machine. There are not many users that don't interact with google. While I don't expect the chrome team to add this to their feature list (even as optional), if they did, it would not really hurt google. It would actually hurt all the other "smaller" players.

Chrome will probably never make this the default, unfortunately. But, this is an option in Chrome.

Settings > Show Advanced > Privacy > Content settings... > Block third-party cookies and site data.

It's not exactly obvious, of course. :-)

Re: Firefox getting smarter about third-party cookies

#8
post #4

Google is in the ad business making it tougher for them to go in this direction. Go Firefox

> Users of this build of Firefox must directly interact with a site or company for a cookie to be installed on their machine. There are not many users that don't interact with google. While I don't expect the chrome team to add this to their feature list (even as optional), if they did, it would not really hurt google. It would actually hurt all the other "smaller" players.

It is my understanding that Google uses separate domains like doubleclick.net for serving ads, not google.com, so they won't gain any particular advantage there. Of course, that could change.

Re: Firefox getting smarter about third-party cookies

#9
post #7
post #4

Earlier quoted context omitted.

> Users of this build of Firefox must directly interact with a site or company for a cookie to be installed on their machine. There are not many users that don't interact with google. While I don't expect the chrome team to add this to their feature list (even as optional), if they did, it would not really hurt google. It would actually hurt all the other "smaller" players.

Chrome will probably never make this the default, unfortunately. But, this is an option in Chrome. Settings > Show Advanced > Privacy > Content settings... > Block third-party cookies and site data. It's not exactly obvious, of course. :-)

This isn't exactly the same as blocking third-party cookies, and Firefox was capable of that since forever.

Firefox is going to accept third-party cookies only from sites that you already browsed before, kinda like Safari does it now.

Post reply on HN