Live data from Hacker News

Firefox rolls out Total Cookie Protection by default to all users

blog.mozilla.org

201–210 of 339 posts

Re: Firefox rolls out Total Cookie Protection by default to all users

#201

Does this obviate the need for [Facebook Container]( https://addons.mozilla.org/en-US/firefox/addon/facebook-cont... )?

Facebook Container is a stricter form of protection for Facebook specifically, so no, you should continue using it if you're interested in isolating Facebook.

Total Cookie Protection is about isolating third party cookies/web storage, without breaking as much of the web as simply blocking third party cookies does.

Re: Firefox rolls out Total Cookie Protection by default to all users

#202

It would be nice to allow users to create "trusted tuples" to list small groups of domains that are allowed to share their cookies. For instance: Zendesk, Asana, Jira, etc. But have each tuple listed still be isolated from the other, only domains listed together in a single list could share a cookie container.

> small groups of domains that are allowed to share their cookies Could you explain how this could be beneficial to the user?

for non-dark pattern use cases where it is beneficial from a usability standpoint to share cookies across domains

Re: Firefox rolls out Total Cookie Protection by default to all users

#203
post #115

Earlier quoted context omitted.

Firefox has a sub 8% market share, so I doubt this will make a drastic change to how they operate.

Surprised it's even that high, I tried to switch to Firefox the other month for privacy but gave up because it crashed on me it-least once a day. Edit: thanks for the downvotes, I would have preferred if it worked but it didn't. I tried basic troubleshooting, disabling extensions etc. but didn't find it usable on macOs Monterey, think it doesn't play well with youtube.

Been using firefox for multiple years now with no crashing issues, pretty much ever.

Re: Firefox rolls out Total Cookie Protection by default to all users

#204
post #159

Earlier quoted context omitted.

Probably that is the use-case for the official multi-account containers plugin.

I tend to agree, but as someone who uses this plugin a LOT, I have some complaints. If I decide I want, say, an Azure Portal container then I cannot have login.microsoftonline.com assigned to a different container -and- configured to automatically open in that container. If I do that, I need to have a combined Azure + Office 365 + anything-I-need-to-authenticate-to-Azure-AD-for container. It’s a good solution but wit…

I use multi-account containers too, and I like it. This is exactly my point, instead of mapping each domain into a single container, any domain could exist in one or more "trusted tuples"

Maybe another way to think of it is like a one-to-many join. A domain would not "belong" to a single container, but have tags to associate with 1+ containers.

Re: Firefox rolls out Total Cookie Protection by default to all users

#205

Earlier quoted context omitted.

> small groups of domains that are allowed to share their cookies Could you explain how this could be beneficial to the user?

for non-dark pattern use cases where it is beneficial from a usability standpoint to share cookies across domains

Well, what are those use-cases? That is what I asked.

Re: Firefox rolls out Total Cookie Protection by default to all users

#206

Privacy wins aside, can anyone please help educate if third party single sign ons will still continue to work?

It depends on the specific third party login service. Some rely on third party storage-sharing, and there are web compatibility measures built into Total Cookie Protection to allow those to keep working.

One is that the login service can request access from the user using a new web API (requestStorageAccess). Another is heuristics which apply when the user interacts with the page in a way which implies a login might be taking place.

In these cases, specific third parties can be granted access to allow the login. There are some more details here: https://developer.mozilla.org/en-US/docs/Web/Privacy/Storage...

Re: Firefox rolls out Total Cookie Protection by default to all users

#208

Earlier quoted context omitted.

> small groups of domains that are allowed to share their cookies Could you explain how this could be beneficial to the user?

for non-dark pattern use cases where it is beneficial from a usability standpoint to share cookies across domains

Yes, I think there are some cases where a user might want to opt-in and allow cookies to be shared across a specific set of domains. The main reason I could think of it to allow cross-site business integration to continue to work as (currently) designed.

Re: Firefox rolls out Total Cookie Protection by default to all users

#209

Cool. Just a heads' up that I had to disable it on Zendesk and Asana so they could talk to each other - you might experience similar issues.

Zendesk has been like this for me since forever. Every time I need to use it to talk to a vendor, I roll my eyes for 2 seconds and open my backup browser which does not have 3rd party cookie restriction.

Re: Firefox rolls out Total Cookie Protection by default to all users

#210
post #193

When will the browsers take care of handling the cookie options for all the sites, so I can declare my preferences once and everyone stops putting up a popup? Surely this is already in the works?

Right, the consent window should have been a browser thing so that it is always the same and so that it follows the laws and cant involve dark patterns.

By reading this message you agree with it.

Post reply on HN