3 ms·
While I like the mechanism, I am not too certain about the policies. From the paper [1], they use "a subset of approximately 1500 domains from Disconnect’s priv
by hrjet 11y ago
While I like the mechanism, I am not too certain about the policies. From the paper [1], they use "a subset of approximately 1500 domains from Disconnect’s privacy-oriented blocklist to identify these unsafe origins". Further, they update the block list every 45 minutes. Which means, a service which wants to track the user can use domain names outside that block list of 1500, and change it every 45 minutes (in case it becomes popular and the block list catches up).
Am I understanding this right?
Aside, I realize that there are no easy solutions for this. As the paper also says, it is hard to identify which requests belong to third parties because of the prevalent practice of using third-party CDNs.
I believe one approach is to disable cookies, javascripts and other sensitive functionality from all third-parties, without any biases or curation, and to provide the tools to enable them selectively. The only drawback is that it won't fly with non-tech-savvy users. However, I think the tech-savvy segment is large enough and growing, to make it worthwhile.
This is the approach that the uMatrix addon, and gngr, the browser that we are developing, take. It would make me very happy if other browsers integrate such a facility within them.
[1]: https://kontaxis.github.io/trackingprotectionfirefox/resources/papers/trackingprotectionfirefox.w2sp15.pdf https://kontaxis.github.io/trackingprotectionfirefox/resourc...