6 ms·
That is mostly the case. However, other websites may ask your browser to make requests to Facebook domains (to load in social buttons or tracking scripts/pixels
by proaralyst 9y ago
That is mostly the case. However, other websites may ask your browser to make requests to Facebook domains (to load in social buttons or tracking scripts/pixels). Those requests will include any cookies your browser has for Facebook as they're direct to Facebook domains.
This extension gives Firefox selective amnesia: if you're in a Facebook container tab, it'll remember and send those cookies. If you're not, it won't!
An alternative solution is to never make those third party requests in the first place, but you might need some of them for content you're actually interested in viewing. Using both a blocking extension and this container extension should improve your privacy towards Facebook.
- throwawayReply 9y agoThere's a "Same-Site" cookie flag that helps prevent CSRF by preventing cookies being sent in that scenario. Can the browser be made to treat all cookies as "same-site" for a quick 'fix' to this issue? Obviously this would need a white-list (and a pair<from,to> whitelist, not just "this domain is OK list) to allow SSO scenarios.
- tscs37 9y agoSimply set the configuration value privacy.firstparty.isolate in your about:config. This will treat every first party domain as it's own container for cookies and other stuff.
- UncleMeat 9y agoYes, but as you say this breaks a large number of applications. The web browsers aren't super likely to break existing behavior since people simply blame the browser that whatever thing doesn't work.
- SOLAR_FIELDS 9y agoThere’s uMatrix for that of course but is uBlock Origin and PrivacyBadger combo enough with this extension? As the de-facto tech guy in my family I know how to take care of my own privacy but I’m always searching for the most hands off solution for the tech illiterate family members who come to me asking to “fix their laptops”.
- dao- 9y agoHave you considered Tracking Protection? https://support.mozilla.org/en-US/kb/tracking-protection https://support.mozilla.org/en-US/kb/tracking-protection I had to disable it for a few select sites but I guess there's currently no solution that won't ever break a site.
- alkonaut 9y agoThis begs the follow up question: Why can’t my browser always send zero cookies for all third party requests in all tabs? Presumably the like button wouldn’t work - but that’s what I want. So the Q is: what will break that I didn’t want to break?
- cachvico 9y agoSingle sign-on? (e.g. logging in to Trello with your Google account)
- romanovcode 9y agoIf you get tokens by callback urls you don't need any 3rd party cookies.
- cachvico 9y agoThat's not relevant to the question.
- bugmen0t 9y agoIt breaks federation, i.e., Single SignOn. But there's a thing for Firefox which does it for all sites. Called First Party Isolation.
- DesiLurker 9y agoknowing what fb is doing with your data, why would you still want SSO?