Live data from Hacker News

Firefox rolls out Total Cookie Protection by default to all users

blog.mozilla.org

101–110 of 339 posts

Re: Firefox rolls out Total Cookie Protection by default to all users

#102
post #57
post #37

Before anyone jumps to why Chrome doesn't block third-party cookies, some context: Regulators did warn Google NOT TO block third-party cookies before they provide a replacement, UK CMA accepted the latest proposal from Google: https://www.gov.uk/government/news/cma-to-keep-close-eye-on-... Apple's tracking rules also raised a lot of anti-trust concerns, giving advertisement in App Store unfair advantages among other…

they can still track you based on your account (e.g. Gmail, Hotmail, iCloud) Really? I don't think so. How would that work? If you visit www.somesite.com - how would javascript on that site identify you via Gmail?

Okay:

1) you visit to www.somesite.com

2) it serves an ad 3) your browser does a request to google. It sends:

a) your login cookie from your gmail session (or ...)

b) the referrer header tells it which site to serve the ad on

c) any information the site itself wants to attach to the request

4) Google/Microsoft/Apple store this information and can provide advertisers with your identity, all sites you visit that have their ads, the "flow" (what you visited in what order, e.g. how far did you get in an ordering funnel) and any information those sites share about your account on their site.

Re: Firefox rolls out Total Cookie Protection by default to all users

#103

Why weren't separate cookie jars the default in the first place? I know that browsers other than Firefox have no real incentive to protect your privacy, but I'm wondering why cookies were designed to be shared among different pages in general

There are legit cross-domain use cases. A good example is how someone here mentioned (comment seems deleted though) account sessions being shared between Atlassian products like JIRA and BitBucket. The problem with that is domains are a poor way of representing ownership that can be trusted. If the web was rebuilt from scratch, a better approach might be to allow cookies to be shared between secure sites using the sa…

There are also legit use cases for leaving all your doors unlocked. But they usually aren't really worth considering when you are installing your doors/locks.

Re: Firefox rolls out Total Cookie Protection by default to all users

#104

This will only further entrench the big players (google, facebook, etc) while making it impossible for new & small players to compete. All of the services the big players offer effectively make working without universal cookies trivial. For the small players though, without massive ad-supported service offerings like Gmail, Facebook (as a platform), etc, this will screw them completely. Mind you, I'm a HUGE privacy a…

Do we want anyone tracking us? I don't really care about the size of something that is tracking me - I care about the tracking itself.

Re: Firefox rolls out Total Cookie Protection by default to all users

#106
post #37

Before anyone jumps to why Chrome doesn't block third-party cookies, some context: Regulators did warn Google NOT TO block third-party cookies before they provide a replacement, UK CMA accepted the latest proposal from Google: https://www.gov.uk/government/news/cma-to-keep-close-eye-on-... Apple's tracking rules also raised a lot of anti-trust concerns, giving advertisement in App Store unfair advantages among other…

>Total Cookie Protection creates a separate cookie jar for each website you visit.

Means third parties win't be able to identify you qccriss sites through cookies. Means the Google Ads cookie or Floc ID will be different for each site you visit.

Re: Firefox rolls out Total Cookie Protection by default to all users

#108
post #79

Earlier quoted context omitted.

> so they can use server-side ID syncs Does this only work if you use the same email across multiple sites? If so it's yet another reason to use a different email address with every site you sign up at.

Which incidentally Mozilla also has a product for: https://relay.firefox.com (Disclosure: I work on Firefox Relay :) And yes, I know some people also have their own domain with unlimited email addresses.)

Is there any plans to support naming my different relay addresses? :)

The service is awesome but it's quite confusing to know which one to use on which websites and which one to delete etc

Re: Firefox rolls out Total Cookie Protection by default to all users

#110
post #93

Earlier quoted context omitted.

Because Google's, Apple's and Microsoft's accounts specifically are tied to their particular browser and/or OS, not just the websites you're on. So are Firefox accounts but they probably don't have the numbers to engage in any particularly egregious behavior.

What kind of mechanic are you describing? Are you saying the browser is phoning home, telling Google which sites you visit?

Well, Chrome obviously does if you’re ‘signed in’ to Google and haven’t turned off their sync settings… which I imagine is the most common end user path, and chrome is the most popular browser. https://www.google.com/chrome/privacy/
Post reply on HN