Live data from Hacker News

Firefox rolls out Total Cookie Protection by default to all users

blog.mozilla.org

331–339 of 339 posts

Re: Firefox rolls out Total Cookie Protection by default to all users

#331

Earlier quoted context omitted.

> Everyone should use FF. Wouldn't simply installing an ad/tracking blocker like uBlock Origin be just as effective, if not moreso?

Not with Google hamstringing extensions w/ Manifest v3, no.

Thankfully we have Brave (and I think Vivaldi too). When the blocker isn't an extension, Manifest v3 doesn't matter much. Brave does CNAME uncloaking too, even though Chromium doesn't provide an extension API for it the way Firefox does.

Re: Firefox rolls out Total Cookie Protection by default to all users

#332

I know Firefox has a small market share, but this is the sort of feature other browsers may adopt. Maybe not the big boys like Chrome or Edge, but I could see all the niche privacy focused browsers implementing it and maybe even Safari given Apples claims to support user privacy. If a certain percentage of browsers started to use similar functionality I could tracking companies starting to develop countermeasures. In…

Safari and Brave have been doing it already. Notice Mozilla's wording: "MAJOR browser available on Windows, Mac and Linux" to exclude the competition that got storage partitioning shipped before Mozilla did.

Re: Firefox rolls out Total Cookie Protection by default to all users

#333
post #9

I really want to enable resist fingerprinting, unfortunately it disables dark theming on github, ddg and other websites. I wish I could add an exception rule to this...

You could always step out of the cave and join the rest of humanity in the light.

Re: Firefox rolls out Total Cookie Protection by default to all users

#334
post #284
post #210

Earlier quoted context omitted.

Right, the consent window should have been a browser thing so that it is always the same and so that it follows the laws and cant involve dark patterns. By reading this message you agree with it.

The answer is similar to the DNT (do not track) debacle. When you give users a clear, informed, singular choice that would be sticky across their entire web/app experience, the choice in itself essentially becomes obsolete. Since pretty much nobody opts-in. You saw the effect with Apple's new "do you want to be tracked" permission, which has a disastrous impact on Facebook. Consider that this is still a per-app permi…

Facebook neither needs or deserves my pity.

If person A wants to do something to B that we can assume B does not approve of then A can ask if its okay. If A would never approve it doesn't magically become okay to do it. The thing could only happen if A has authority over B. As FB is not ur mum, not the government and not your employer they should ask the question or shut up.

Re: Firefox rolls out Total Cookie Protection by default to all users

#335
post #118

Earlier quoted context omitted.

> Why weren’t separate cookie jars the default in the first place? Tracking today is an interaction between cookies and pages, not really because cookies were designed to be shared between domains. Because of that, ads on web pages are a reason that information gets shared across sites. Any ad or other iFramed content that’s served on a site can get the domain name of where it’s be served from and then access the iFr…

> Total Cookie Protection is going to put cookies that only Facebook can see in a different jar for each separate site you visit, making it so that Facebook can’t read it’s own cookies across different sites. Won't this break some basic features like being logged in to Facebook (or similar services, e.g. Disqus) for the purpose of embedded comment sections on other sites? They don't use cookies only for tracking butt…

They handle it gracefully. As per their write-up[1]:

> In addition, Total Cookie Protection makes a limited exception for cross-site cookies when they are needed for non-tracking purposes, such as those used by popular third-party login providers. Only when Total Cookie Protection detects that you intend to use a provider, will it give that provider permission to use a cross-site cookie specifically for the site you’re currently visiting. Such momentary exceptions allow for strong privacy protection without affecting your browsing experience.

[1] https://blog.mozilla.org/security/2021/02/23/total-cookie-pr...

Re: Firefox rolls out Total Cookie Protection by default to all users

#336

Earlier quoted context omitted.

If the contents of the cookie is a JSON array of recently viewed items, then the size is correlated to whether I've been actively viewing items recently. Adding random padding makes it harder to get a signal, but with a high enough sample size, it's still possible to get some information. If you always pad to a fixed size, then there's probably no useful information. At the moment, I think I have enough to do, but I'…

>If That's are really big word in that sentence. You have NO idea, like 0, what is stored in an encrypted cookie. To even think you do is just pure folly.

This is a very simplistic way of looking at things. A lot of the times in security, having an idea of what's not in there can be almost as valuable as having an idea of what's in there.

I will provide a very simple counterpoint to your argument: say I log in, log out and log in again, dumping my two encrypted session cookies in between. If they are perfectly identical, then knowing nothing else about the environment nor the encryption used, I already know that there's no timestamp value in the cookie acting as a time barrier, nor a challenge-response check, nor a nonce value.

Knowing that, I can focus my attention on stealing session cookies from users for trying replay attacks.

Re: Firefox rolls out Total Cookie Protection by default to all users

#337
post #282

Earlier quoted context omitted.

FIrefox used to ask, then it would ask if you set the right preference, and then it stopped asking entirely. I was very disappointed in them.

Why was it disappointing in them? Don't they need to compete with Chrome and Safari's UX, that just allow those cookies?

That's no reason to remove the preference that allowed people to re-enable the dialog box.

Re: Firefox rolls out Total Cookie Protection by default to all users

#338

I wonder if there's anyone from any advertising/ad-targeting companies on HN who can shed some light on if/how much this change may affect their "product". Asking this since I know friends working at companies that were DRASTICALLY affected by the Apple advertising changes in terms of user targetability (and hence revenue) and I'm wondering if this change will be similar.

Most ad agencies don't know anything about targeting. It's something in the platform they have, but they don't know how it works and if it works at all. Had worked on both sides, providing ads and using them in pages. Would be much easier if the default becomes context sensitive ads. Showing an ad next to some news - give the platform some keywords and pick an ad based on that. No tracking or user targeting needed at all.

Re: Firefox rolls out Total Cookie Protection by default to all users

#339

Earlier quoted context omitted.

Chrome has on the roadmap to do exactly this. [1] Turns out, Getting rid of 3rd party cookies concentrates power in the ad world in the hands of those with the most 1st party data (and active session cookies). Google, Facebook, Amazon and Apple. [2] The tracking debate is contentious and has a lot of folks on here who are privacy maximalists, and I'm not trying to debate the ethics of ads. But in terms of utility, 3r…

How does the tri-opoli keep traking users when there are no 3rd party cookies? Do they mean to implement an explicit exception/a different tracking protocolol?

Those big companies can simply rely on the amount of informations they get from their own services.

Google has a service for almost everything, Amazon knows exactly what you want to buy and like google is extending to all the aspects of your life with digital services and Facebook as well has apps people spend enough time in to obtain informations about their interests. So their ad networks could work without cookies. But they also rely on fingerprinting that’s done through the ads themselves and the analytics tools almost every website has.

Post reply on HN