Live data from Hacker News

Firefox rolls out Total Cookie Protection by default to all users

blog.mozilla.org

191–200 of 339 posts

Re: Firefox rolls out Total Cookie Protection by default to all users

#191
post #152

Earlier quoted context omitted.

Ciphertext leaks information via its size and its presence / absence.

yeah and so? how is this information useful? if the actual useful information is encrypted, then size is meaningless as it is just random text until decrypted. presence/absence? you have a cookie or you don't?

You say the size is meaningless. But sometimes it may actually be meaningful. And presence/absence is information also. Not much, but it definitely exists.

Re: Firefox rolls out Total Cookie Protection by default to all users

#192

Is that basically the PrivacyBadger plugin integrated into Firefox? Can I uninstall it now?

Hi, Privacy Badger dev here.

Total Cookie Protection helps by keeping all third-party cookies isolated to the site they were set on. This means tracker domains will no longer get their cookie identifiers persisted across different sites.

However, tracking isn't limited to cookies. If unblocked, trackers can still use techniques like browser fingerprinting and cookie syncing. They could also just track you via your IP address, or, most likely, via some combination of different techniques.

Trackers can also collect sensitive information such as your email address, or even become vectors for delivering malware.

Outside of privacy/security concerns, unblocked trackers can slow down websites and waste your bandwidth.

To learn about how Privacy Badger works, visit https://privacybadger.org/#faq

Re: Firefox rolls out Total Cookie Protection by default to all users

#194
post #115

Earlier quoted context omitted.

Firefox has a sub 8% market share, so I doubt this will make a drastic change to how they operate.

Surprised it's even that high, I tried to switch to Firefox the other month for privacy but gave up because it crashed on me it-least once a day. Edit: thanks for the downvotes, I would have preferred if it worked but it didn't. I tried basic troubleshooting, disabling extensions etc. but didn't find it usable on macOs Monterey, think it doesn't play well with youtube.

care to share what sites were causing your "crashing"?

no? then hello downvote for just making unsubstantiated claims that goes totally against the grain of typical experience.

Re: Firefox rolls out Total Cookie Protection by default to all users

#195
post #59

It's nice, but is that so hard for Mozilla to tell in which version it will appear? Is it the current version or is it the next 102 version (which releases in 2 weeks, but then why they say it "rolls out"?)

Looks like it's already in v101.0.1. It's under the Settings | Privacy and Security tab with a new checkbox to allow you to "Test Pilot our newest..." It is not automatically checked for me.

I think the change might just be they will be setting that checkbox to on now? Although I don't remember seeing this option until now.

Re: Firefox rolls out Total Cookie Protection by default to all users

#196
post #92

Earlier quoted context omitted.

It's not that one site is seeing another site. It's that multiple sites will serve content (ads, Javascript libraries, like buttons) from a common site (eg an ad network) that uses its own domain. That domain is allowed to get the cookie for itself because it is referenced by multiple site, that's how this type of tracking works. If you go to bbc.com, it still won't be able to see cookies from cnn.com, but say if adv…

> Everyone should use FF. Wouldn't simply installing an ad/tracking blocker like uBlock Origin be just as effective, if not moreso?

[deleted]

Re: Firefox rolls out Total Cookie Protection by default to all users

#197
post #160

Earlier quoted context omitted.

Firefox really needs to implement two features: 1. Cookie Auto-Delete (see https://github.com/Cookie-AutoDelete/Cookie-AutoDelete/wiki/... ), where cookies and local data are automatically deleted some time after closing the tab. You can, of course, whitelist Websites to exclude them. 2. Firefox multi-container extension, to assign some websites (domains and subdomains) to a container by default so that you can visit…

(1) totally exists, that's always how I configure all my FF installs. You also can add exceptions, although I don't use this feature.

Unless I'm missing something, this only triggers on browser close. I sort of agree with the proposed tab closer with timer trigger idea, since I almost never close the browser on my main machine.

Re: Firefox rolls out Total Cookie Protection by default to all users

#198

Why weren't separate cookie jars the default in the first place? I know that browsers other than Firefox have no real incentive to protect your privacy, but I'm wondering why cookies were designed to be shared among different pages in general

Why didn’t cars have safety belts in the first place?

Re: Firefox rolls out Total Cookie Protection by default to all users

#200

It would be nice to allow users to create "trusted tuples" to list small groups of domains that are allowed to share their cookies. For instance: Zendesk, Asana, Jira, etc. But have each tuple listed still be isolated from the other, only domains listed together in a single list could share a cookie container.

> small groups of domains that are allowed to share their cookies

Could you explain how this could be beneficial to the user?

Post reply on HN