Live data from Hacker News

Firefox rolls out Total Cookie Protection by default to all users

blog.mozilla.org

171–180 of 339 posts

Re: Firefox rolls out Total Cookie Protection by default to all users

#171

I know Firefox has a small market share, but this is the sort of feature other browsers may adopt. Maybe not the big boys like Chrome or Edge, but I could see all the niche privacy focused browsers implementing it and maybe even Safari given Apples claims to support user privacy. If a certain percentage of browsers started to use similar functionality I could tracking companies starting to develop countermeasures. In…

> Maybe not the big boys like Chrome or Edge

Firefox has essentially the same market share as Edge.

Re: Firefox rolls out Total Cookie Protection by default to all users

#172

Earlier quoted context omitted.

> Everyone should use FF. Wouldn't simply installing an ad/tracking blocker like uBlock Origin be just as effective, if not moreso?

Isn't it better to remove the different root problems isntead of having plugins working around?

Personally, I use uBlock Origin more to block obnoxious ads than to block the tracking.

I'm not sure I really care that much about tracking, honestly. So what if reddit knows I bought a toaster on Amazon recently? What are they going to do with that data, show me toaster ads? I'm going to be blocking that ad. Sell the fact that I bought a toaster? Whatever. It's all going to be so advertisers can personalize ads...which I will be blocking.

Re: Firefox rolls out Total Cookie Protection by default to all users

#173
post #92

Earlier quoted context omitted.

It's not that one site is seeing another site. It's that multiple sites will serve content (ads, Javascript libraries, like buttons) from a common site (eg an ad network) that uses its own domain. That domain is allowed to get the cookie for itself because it is referenced by multiple site, that's how this type of tracking works. If you go to bbc.com, it still won't be able to see cookies from cnn.com, but say if adv…

> Everyone should use FF. Wouldn't simply installing an ad/tracking blocker like uBlock Origin be just as effective, if not moreso?

Not with Google hamstringing extensions w/ Manifest v3, no.

Re: Firefox rolls out Total Cookie Protection by default to all users

#174
post #134

Earlier quoted context omitted.

given that Electron is really just a featureless browser shouldn't it be straightforward to make your own browser now? That's not what Electron is but there are piles of fork-ish browser projects out there statistically nobody uses. This also answers the second question in the negative - it is not straightforward to make your own browser that's as useful as the browser you're likely using.

> > given that Electron is really just a featureless browser [...] > That's not what Electron is I mean...isn't it? Forget the idea of what it's used for and just look at how it works. It's a framework for making apps that uses Chromium for rendering and a Node backend. Strip off the Node backend and you're left with Chromium. And Chromium on its own is a web browser. Electron just doesn't show the controls for it. A…

a backend added

That's a huge change which allows for things like turning XSS into RCEs. It's a bit like 'why can't you make your own street legal sports car by removing the rear spoiler and replacing it with a jet engine'.

Re: Firefox rolls out Total Cookie Protection by default to all users

#175
post #115

Earlier quoted context omitted.

Surprised it's even that high, I tried to switch to Firefox the other month for privacy but gave up because it crashed on me it-least once a day. Edit: thanks for the downvotes, I would have preferred if it worked but it didn't. I tried basic troubleshooting, disabling extensions etc. but didn't find it usable on macOs Monterey, think it doesn't play well with youtube.

I have used Firefox for 7 years and never had it crash once.

I have also used Firefox for a similar time and although I can't say it has never crashed for me, it has at least proven to be a bit more stable than my experience with Chrome.

Re: Firefox rolls out Total Cookie Protection by default to all users

#176

It would be nice to allow users to create "trusted tuples" to list small groups of domains that are allowed to share their cookies. For instance: Zendesk, Asana, Jira, etc. But have each tuple listed still be isolated from the other, only domains listed together in a single list could share a cookie container.

...as opposed to 'nested tuplets'? /fz

Re: Firefox rolls out Total Cookie Protection by default to all users

#177

Privacy wins aside, can anyone please help educate if third party single sign ons will still continue to work?

This feature protects domains, not sessions. SSO relies on passing tokens over redirects, not cookies. As long as your redirected, the SSO uses their own first party cookies. You would be logged in to the SSO provider no matter who redirected you there.

Re: Firefox rolls out Total Cookie Protection by default to all users

#178
post #118

Why weren't separate cookie jars the default in the first place? I know that browsers other than Firefox have no real incentive to protect your privacy, but I'm wondering why cookies were designed to be shared among different pages in general

> Why weren’t separate cookie jars the default in the first place? Tracking today is an interaction between cookies and pages, not really because cookies were designed to be shared between domains. Because of that, ads on web pages are a reason that information gets shared across sites. Any ad or other iFramed content that’s served on a site can get the domain name of where it’s be served from and then access the iFr…

The solution still seems to be to:

1. Use Firefox, block .js by default, and selectively allow.

2. Set browser to block cross-site cookies, and to purge all cookies when closing browser.

3. Avoid tabbed browsing, and restart browser after using a website.

I've been doing this since about 2006. It's inconvenient, but gives some peace of mind.

Re: Firefox rolls out Total Cookie Protection by default to all users

#179

Is this better or worse than Safari's "Prevent cross-site tracking" feature? https://support.apple.com/guide/safari/prevent-cross-site-tr... It appears Safari is just blocking the cookies, while Firefox is isolating the cookies. I guess Safari has to keep track of who to block while Firefox just isolates everybody. Are there other benefits to the Firefox approach? Frankly, I have a hard time understanding why this Co…

Sites that use cross site resource will still work. Except the cross domain resource provider will always see the same domain coming to get resource. For example, if you are on Site A and use cross site resource from Site C. The site C will get a cookie C('A) And in another day, you visited a Site B that also use resource from Site C. The site C get a cookie C('B). And C('A) != C('B) Although these cookie are both is…

Thanks. In case anyone is interested, I looked around a bit more and found these descriptions of Safari's (Webkit) intelligent tracking prevention starting from 2017 (in reverse chronological order):

Safari Tracking Prevention background:

https://webkit.org/tracking-prevention/#intelligent-tracking...

Blog posts about tracking prevention updates:

https://webkit.org/blog/11545/updates-to-the-storage-access-...

https://webkit.org/blog/10218/full-third-party-cookie-blocki...

https://webkit.org/blog/9521/intelligent-tracking-prevention...

https://webkit.org/blog/8613/intelligent-tracking-prevention...

https://webkit.org/blog/8311/intelligent-tracking-prevention...

https://webkit.org/blog/8142/intelligent-tracking-prevention...

https://webkit.org/blog/7675/intelligent-tracking-prevention...

Here is their tracking prevention policy definition:

https://webkit.org/tracking-prevention-policy/

Re: Firefox rolls out Total Cookie Protection by default to all users

#180
post #159

It would be nice to allow users to create "trusted tuples" to list small groups of domains that are allowed to share their cookies. For instance: Zendesk, Asana, Jira, etc. But have each tuple listed still be isolated from the other, only domains listed together in a single list could share a cookie container.

Probably that is the use-case for the official multi-account containers plugin.

I tend to agree, but as someone who uses this plugin a LOT, I have some complaints.

If I decide I want, say, an Azure Portal container then I cannot have login.microsoftonline.com assigned to a different container -and- configured to automatically open in that container.

If I do that, I need to have a combined Azure + Office 365 + anything-I-need-to-authenticate-to-Azure-AD-for container.

It’s a good solution but with its lack of flexibility I find it’s too far in the direction of security versus convenience.

Post reply on HN