Earlier quoted context omitted.
It's not possible to block browser fingerprinting since it's a range of techniques and heuristics based on numerous features. There's no "turn off fingerprinting" button you can just press.
Whonix says hello. https://www.whonix.org/ I was planning to use it exclusively when I was working on a system to fight cartels, so I got pretty deep into these kinds of questions. Whonix has its own problems but it's the best solution available. The communities are interesting too. One fellow was trying to download map data, which confused me initially. Why was he so fixated on maps? It's because if you're in the mi…
Firefox rolls out Total Cookie Protection by default to all users
241–250 of 339 posts
Re: Firefox rolls out Total Cookie Protection by default to all users
#242Re: Firefox rolls out Total Cookie Protection by default to all users
#243Why weren't separate cookie jars the default in the first place? I know that browsers other than Firefox have no real incentive to protect your privacy, but I'm wondering why cookies were designed to be shared among different pages in general
> Why weren’t separate cookie jars the default in the first place? Tracking today is an interaction between cookies and pages, not really because cookies were designed to be shared between domains. Because of that, ads on web pages are a reason that information gets shared across sites. Any ad or other iFramed content that’s served on a site can get the domain name of where it’s be served from and then access the iFr…
Won't this break some basic features like being logged in to Facebook (or similar services, e.g. Disqus) for the purpose of embedded comment sections on other sites? They don't use cookies only for tracking buttons after all. It would be… annoying… for every site to require a separate login.
Re: Firefox rolls out Total Cookie Protection by default to all users
#244Is this better or worse than Safari's "Prevent cross-site tracking" feature? https://support.apple.com/guide/safari/prevent-cross-site-tr... It appears Safari is just blocking the cookies, while Firefox is isolating the cookies. I guess Safari has to keep track of who to block while Firefox just isolates everybody. Are there other benefits to the Firefox approach? Frankly, I have a hard time understanding why this Co…
I believe this is part of the "Prevent cross-site tracking" feature. I do know that Webkit/Safari has had this feature for a while now, under the name "Partitioned storage." Safari has a handful of other policies under the "Intelligent Tracking Prevention" banner, like blocked or ephemeral cookies for non-first-party domains. Firefox is playing catch-up with this feature. The announcement says "...making Firefox the…
Re: Firefox rolls out Total Cookie Protection by default to all users
#245Why not abolish third-party cookies altogether? There are very few good uses for them.
(at least MS accounts just don't work)
Re: Firefox rolls out Total Cookie Protection by default to all users
#246Why not abolish third-party cookies altogether? There are very few good uses for them.
You can turn them off. However, most single-sign-on stuff will break without them :/ (at least MS accounts just don't work)
> You can turn them off.
Of course I did, long ago. The issue is that they're on by default. And defaults matter a lot because most people don't change them.
Re: Firefox rolls out Total Cookie Protection by default to all users
#247Earlier quoted context omitted.
The solution still seems to be to: 1. Use Firefox, block .js by default, and selectively allow. 2. Set browser to block cross-site cookies, and to purge all cookies when closing browser. 3. Avoid tabbed browsing, and restart browser after using a website. I've been doing this since about 2006. It's inconvenient, but gives some peace of mind.
The solution is political action. You're describing a workaround that only a few of the most concerned people will be willing to use.
In my defense, I don't see it as a workaround - I wouldn't use it any other way.
There was a time when one didn't need to do this, but the internet has become more cumbersome to use. Easy-breezy... just make it muscle memory, and don't look back!
Re: Firefox rolls out Total Cookie Protection by default to all users
#248Earlier quoted context omitted.
> And no one saw the privacy invading potential at the time. Maybe not the privacy invasion potential but ... As we got started building amzn in the fall of 94, it was a no-brainer decision to not use cookies even though they were just arriving. The controversy around the idea was intense and it was far from clear that they would be a success as a technology. It is likely true that there was more attention being paid…
How did you manage session information without using cookies?
http://yourdomain.com/path/to/something?SESSION=af2828c119ae1
and yes, all URLs in every page were rewritten during page generation to include the session ID.Re: Firefox rolls out Total Cookie Protection by default to all users
#249Why weren't separate cookie jars the default in the first place? I know that browsers other than Firefox have no real incentive to protect your privacy, but I'm wondering why cookies were designed to be shared among different pages in general
> Why weren’t separate cookie jars the default in the first place? Tracking today is an interaction between cookies and pages, not really because cookies were designed to be shared between domains. Because of that, ads on web pages are a reason that information gets shared across sites. Any ad or other iFramed content that’s served on a site can get the domain name of where it’s be served from and then access the iFr…
Cookies need restricted to the URL in the address bar. Anything else is like a side effect or unintended and woefully non-transparent consequence of sneaky fucks harvesting your information (clicks, keystrokes, and metadata) via JavaScript and cookies.
Re: Firefox rolls out Total Cookie Protection by default to all users
#250Why not abolish third-party cookies altogether? There are very few good uses for them.
Turns out, Getting rid of 3rd party cookies concentrates power in the ad world in the hands of those with the most 1st party data (and active session cookies). Google, Facebook, Amazon and Apple. [2]
The tracking debate is contentious and has a lot of folks on here who are privacy maximalists, and I'm not trying to debate the ethics of ads.
But in terms of utility, 3rd party cookies are the backbone of ad-tech auctions and targeting, and currently give the non-Goog/FB/Amazon ad providers a way to compete on performance advertising.
Digital ad markets are expected to be nearly $565b this year, and the Tri-opoly of Google/FB/Amazon have 68% of the market. 32% of the market depends on 3rd party cookies to have a chance at competing. [3]
1 - https://privacysandbox.com/intl/en_us/open-web/#how-works-on... 2 - https://www.siliconrepublic.com/business/googles-privacy-san... 3 - https://www.emarketer.com/content/google-facebook-amazon-acc...