Live data from Hacker News

Firefox getting smarter about third-party cookies

blog.mozilla.org

41–50 of 103 posts

Re: Firefox getting smarter about third-party cookies

#41
post #15
post #5

Earlier quoted context omitted.

But a request is still a request. It might not make sense to include referer data in the case you mentioned but that does not mean every cros request will fit that description.

Give me an example where sending a Referer is essential to providing me as a user with a better experience. There are no such cases, period. Also, with an exception of dumb content protection schemes (anti-hot-linking), Referrers are used exclusively for tracking purposes and carry zero positive benefits for the users. If Mozilla is in fact "passionate about putting its users first", these headers must go. It is as s…

I don't think the referer info is ever really essential but here are some possibilities:

1) If you came from a social media site, maybe I'd highlight that particular social sharing option in a share bar, or hide others.

2) In an e-commerce store, maybe Google sent you to some page on my site that isn't really the best for your search term (product discontinued, other better matching product), I can give you a link to that other page. Google isn't necessarily magical in its ability to pick the best page on a site for a specific term. Maybe if you come from a competitor I can highlight some content that compares my product to the competitor's.

3) I've never derived a ton of benefit from it, but some sites will highlight your search term for you on a page. It could possibly also automatically scroll you to a relevant section if it's a long page and what you searched for is an exact match for some subsection.

In general it can be a valuable data point sites can use to improve the end-user experience. That being said, I can't think of anything where the value really outweighs the potential for abuse, but I think saying that it has no value to the user is short-sighted.

Re: Firefox getting smarter about third-party cookies

#42
post #27

I'm really enjoying the self-destructing cookies addon: https://addons.mozilla.org/en-us/firefox/addon/self-destruct... . It's really great to go to Facebook and see it have absolutely no idea who I am every time I go there. Plugin works very well.

Never heard of this one, and it looks really good. I'll try it right now. But will it still be useful with the new Firefox updates?

Re: Firefox getting smarter about third-party cookies

#43
I have been thinking about cookie sandboxing for a while:

The idea is to have a separate cookie store for each 2nd level domain I am visiting.

So the Facebook cookie on some site I am visiting that has a Facebook "Like" button on it is different from the actual Facebook cookie I would get from visiting Facebook.

This would make cookie tracking across sites unusable, since each site would have it's own version of a cookie.

Re: Firefox getting smarter about third-party cookies

#44
post #24

Does this affect Google Analytics (or any analytics software for that matter)? if so: How would a webmaster deal with that?

Google Analytics javascript runs on your domain and the cookies it uses are on your domain. So it should count as "first party" here.

There is no creation of cookies in the snippet you have to copy/paste on your website. So if some cookies are created they are not first party.

Re: Firefox getting smarter about third-party cookies

#45
post #36
post #14

Earlier quoted context omitted.

>It would actually hurt all the other "smaller" players Exactly. But it's not neccesary a bad thing though. What all the "smaller players" in emerging retracking field - where 3rd party cookies are used in the first place - are doing now is nothing conceptually different from "ah, you've added iPhone to shopping cart at shopX! Now we'll show you iPhone ads for a week on every site you visit!". And user is beating her…

You're right that these retargeting shops have a stupid thesis and can only exist because marketers' metrics haven't evolved enough yet (and that's changing). Highest purchase % doesn't mean you changed intent or created business, you just won the bidding war to show an ad to someone who was already going to buy, or maybe already bought. But users will never manually enable 3rd party cookies, even if they agreed with…

> Content has to be monetized in some way -- if not ads, then how?

Charge for it perhaps?

Re: Firefox getting smarter about third-party cookies

#46
post #15
post #5

Earlier quoted context omitted.

But a request is still a request. It might not make sense to include referer data in the case you mentioned but that does not mean every cros request will fit that description.

Give me an example where sending a Referer is essential to providing me as a user with a better experience. There are no such cases, period. Also, with an exception of dumb content protection schemes (anti-hot-linking), Referrers are used exclusively for tracking purposes and carry zero positive benefits for the users. If Mozilla is in fact "passionate about putting its users first", these headers must go. It is as s…

Isn't the Referrer header what Google Analytics et. al. use to tell you how people are finding pages on your site? Seems like that could be quite useful for a webmaster to learn more about his audience, tailoring his content to better fit the traffic coming from those sources and identifying other sites that might be abusive (e.g. scraping his content).

Re: Firefox getting smarter about third-party cookies

#48
post #45
post #36

Earlier quoted context omitted.

You're right that these retargeting shops have a stupid thesis and can only exist because marketers' metrics haven't evolved enough yet (and that's changing). Highest purchase % doesn't mean you changed intent or created business, you just won the bidding war to show an ad to someone who was already going to buy, or maybe already bought. But users will never manually enable 3rd party cookies, even if they agreed with…

> Content has to be monetized in some way -- if not ads, then how? Charge for it perhaps?

I guess. The NYT/WSJ are trying that already because they don't get enough from ads to do original reporting; ads can barely fund recycled opinion pieces from bloggers as a full-time job. Results are decidedly mixed.

Re: Firefox getting smarter about third-party cookies

#49

Earlier quoted context omitted.

> Is this because some of the third party resources are only authorised for use by certain sites and rely on Referer to establish whether a given request qualifies? Given that there is no security or verification for Referer headers, that seems like a rather broken model to start with. It's just a first-order approximation to defend against hotlinking. Disabling referes wholesale has mostly worked out for me (via abo…

But if you're linking to an image on your own site from your own site, the proposal not to send Referer headers across domains to third parties wouldn't do any harm. In other words, if your interest is in blocking unauthorised hotlinking, can't you just assume anyone who doesn't include a Referer is equivalent to someone sending a Referer from a malicious site and decline the request?

Sure, that works in many cases. It's also fairly typical to host static-ish content on another domain though, in that case you would have to inspect the referer header, or otherwise conspire with your "main" domain.

Re: Firefox getting smarter about third-party cookies

#50
post #36
post #14

Earlier quoted context omitted.

>It would actually hurt all the other "smaller" players Exactly. But it's not neccesary a bad thing though. What all the "smaller players" in emerging retracking field - where 3rd party cookies are used in the first place - are doing now is nothing conceptually different from "ah, you've added iPhone to shopping cart at shopX! Now we'll show you iPhone ads for a week on every site you visit!". And user is beating her…

You're right that these retargeting shops have a stupid thesis and can only exist because marketers' metrics haven't evolved enough yet (and that's changing). Highest purchase % doesn't mean you changed intent or created business, you just won the bidding war to show an ad to someone who was already going to buy, or maybe already bought. But users will never manually enable 3rd party cookies, even if they agreed with…

>But users will never manually enable 3rd party cookies, even if they agreed with you that the ads were adding value

It depends. Maybe not the ads per se would be added value, will see anyway.

And by the way, ads may be the content on its own, don't you think? Ask anyone of 30+ mln people who had viewed last Pepsi&Jeff Gordon commercial on YouTube for example.

Post reply on HN