Live data from Hacker News

Firefox rolls out Total Cookie Protection by default to all users

blog.mozilla.org

311–320 of 339 posts

Re: Firefox rolls out Total Cookie Protection by default to all users

#311

Why weren't separate cookie jars the default in the first place? I know that browsers other than Firefox have no real incentive to protect your privacy, but I'm wondering why cookies were designed to be shared among different pages in general

There are legit cross-domain use cases. A good example is how someone here mentioned (comment seems deleted though) account sessions being shared between Atlassian products like JIRA and BitBucket. The problem with that is domains are a poor way of representing ownership that can be trusted. If the web was rebuilt from scratch, a better approach might be to allow cookies to be shared between secure sites using the sa…

> allow cookies to be shared between secure sites using the same certificate

In some ways that will be less strict than Firefox's implementation. A CDN might have a certificate with hundreds of unrelated sites in it.

In some ways that will be more strict than Firefox's implementation. A site might want to serve large static files on static.foo.com but a secure login page on login.foo.com , and want to hand over the private key for static.foo.com to a CDN but not hand over the private key for login.foo.com .

Re: Firefox rolls out Total Cookie Protection by default to all users

#312
post #146

Earlier quoted context omitted.

There are legit cross-domain use cases. A good example is how someone here mentioned (comment seems deleted though) account sessions being shared between Atlassian products like JIRA and BitBucket. The problem with that is domains are a poor way of representing ownership that can be trusted. If the web was rebuilt from scratch, a better approach might be to allow cookies to be shared between secure sites using the sa…

> allow cookies to be shared between secure sites using the same certificate Or maybe encrypting cookies using the site certificate, which would still allow cookies to be shared with domains having a different certificate, but the server needs the correct key for decryption.

Sounds like it'll make key rotation tricky.

Also it'll likely break javascript access to the cookies.

Re: Firefox rolls out Total Cookie Protection by default to all users

#313

Earlier quoted context omitted.

I’ve got this enabled - the only one that’s been more than a mild pain in the ass is the UTC timezone change. Always takes a minute to remember why a site is telling me my appointment is at 2:30 in the morning.

Is there a way to reset the timezone but have all the other protections? Timezone provides pretty low information relative to the pain it causes me when I show up to my meeting 5 hours later.

Just move to London

Re: Firefox rolls out Total Cookie Protection by default to all users

#314
post #79

Earlier quoted context omitted.

Which incidentally Mozilla also has a product for: https://relay.firefox.com (Disclosure: I work on Firefox Relay :) And yes, I know some people also have their own domain with unlimited email addresses.)

> I know some people also have their own domain with unlimited email addresses A friend of mine does it the hardcore way, through DNS. He adds MX records for subdomains corresponding to the name of the site he's signing up for. Lets say his domain name is example.com: bob@hilton.example.com bob@ycombinator.example.com bob@firefox.example.com and so on He also does it for friends(!) meaning when he gives you "his" ema…

Woah, I did not know that, but that is indeed hardcore!

Re: Firefox rolls out Total Cookie Protection by default to all users

#315
post #79

Earlier quoted context omitted.

Which incidentally Mozilla also has a product for: https://relay.firefox.com (Disclosure: I work on Firefox Relay :) And yes, I know some people also have their own domain with unlimited email addresses.)

Is there any plans to support naming my different relay addresses? :) The service is awesome but it's quite confusing to know which one to use on which websites and which one to delete etc

There is already! However, depending on how long you've been a user, you might not see it yet; there's an option to allow us to store that data on our servers that we didn't turn on for people who were using Relay before that setting was introduced. You can enable it here ("Allow ⁨Relay⁩ to collect data showing the sites on which your masks are created and used"): https://relay.firefox.com/accounts/settings/

If you use the extension [1] [2], it can also store them locally if you want, and it will automatically track where you used the addresses, rather than you having to manually label them.

And finally, if you have Relay Premium, you can claim your own subdomain, and come up with an arbitrary address name (e.g. "hackernews@yourdomain.mozmail.com"), but since that's less anonymous than a random address, we recommend only using that if you need to come up with an address on the spot in the real world.

[1] https://addons.mozilla.org/firefox/addon/private-relay/

[2] https://chrome.google.com/webstore/detail/firefox-relay/lknp...

Re: Firefox rolls out Total Cookie Protection by default to all users

#316
post #79

Earlier quoted context omitted.

Which incidentally Mozilla also has a product for: https://relay.firefox.com (Disclosure: I work on Firefox Relay :) And yes, I know some people also have their own domain with unlimited email addresses.)

I'm sorry to bother you (and rest of HN) about your product in an off-topic thread, but I noticed ⁨Relay Premium⁩ is available in limited countries. Considering some countries in that list are part of EU, what are the limitations why I'm not able to subscribe to the premium service? Or is there a way to join Relay Premium while not in listed countries (for example, having credit card issued by a listed country)?

I'm not entirely sure, actually, but I think it mostly has to do with legal clearance (but might be wrong here). Your country is autodetected from your IP, so a different credit card won't work, I think.

I did recently build a waitlist, so you can sign up to be notified when it becomes available in your country. We're not linking to it from anywhere yet, but if you promise not to tell (just kidding), you can already find it at https://relay.firefox.com/premium/waitlist/.

Re: Firefox rolls out Total Cookie Protection by default to all users

#317
post #79

Earlier quoted context omitted.

Which incidentally Mozilla also has a product for: https://relay.firefox.com (Disclosure: I work on Firefox Relay :) And yes, I know some people also have their own domain with unlimited email addresses.)

I've been following Firefox Relay features for a bit now. Is there a difference between the service offered by Firefox Relay premium to the free DuckDuckGo Email Protection? Do you believe DDG will also eventually move to the subscription model for these features (unlimited aliases, reply to sender)?

I'm not super familiar with DDG's offering (and of course can't predict what they will do in the future), but some differences that I see on first glance:

- You need to use their app or browser extension to use it. (You can use Relay using just the website at https://relay.firefox.com.)

- Mozilla is a non-profit, whereas DDG is a for-profit company. (Though I should add that I'm a happy user of DDG search, and that I think they're pretty great.)

- There might still be a waitlist?

- Relay Premium has features like your own custom subdomain so you can come up with new addresses on the fly, the ability to reply to forwarded emails without revealing your address, unlimited addresses, of which I don't know whether DDG's service has them.

- On the other hand, Relay doesn't block trackers yet (but incidentally, that's the feature I'm working on right now).

- And of course, by subscribing to Relay Premium, you can support Mozilla and make it less reliant on Google :)

So yeah, not a particularly helpful comparison, since I'm not too familiar with their offering, sorry.

Re: Firefox rolls out Total Cookie Protection by default to all users

#318
post #313

Earlier quoted context omitted.

Is there a way to reset the timezone but have all the other protections? Timezone provides pretty low information relative to the pain it causes me when I show up to my meeting 5 hours later.

Just move to London

UK has daylight savings time. Better move to Iceland instead. They're always on UTC.

Re: Firefox rolls out Total Cookie Protection by default to all users

#319
post #245

Earlier quoted context omitted.

You can turn them off. However, most single-sign-on stuff will break without them :/ (at least MS accounts just don't work)

Single-sign-on stuff can be fixed by redirecting through the authenticator domain and passing the token or whatever back as a url parameter. > You can turn them off. Of course I did, long ago. The issue is that they're on by default. And defaults matter a lot because most people don't change them.

That would have to get fixed by the corporate maintaining that SSO. I even tried whitelisting domains, but it's also PITA since MS redirects you through 10 domains or so. Now I'm using cookie autoeater almost everywhere... so feel free to save your cookies, as soon as I close the tab they are all gone. I have to login every time, but saved passwords solve it reasonably well.

Re: Firefox rolls out Total Cookie Protection by default to all users

#320
post #92
post #52

I've never understood the thinking that went behind allowing one site to see the existence of another site's cookie in the first place. I don't think I'm even coming at this with the security hindsight of decades, it's just common sense, isn't it?

It's not that one site is seeing another site. It's that multiple sites will serve content (ads, Javascript libraries, like buttons) from a common site (eg an ad network) that uses its own domain. That domain is allowed to get the cookie for itself because it is referenced by multiple site, that's how this type of tracking works. If you go to bbc.com, it still won't be able to see cookies from cnn.com, but say if adv…

Thanks man! I misunderstood the whole thing!
Post reply on HN