5 ms·
Disclosure: I'm the author of the add-on mentioned in the story. Basically, various privacy protections cause various kinds of website breakage. https://blog.
by groovecoder 9y ago
Disclosure: I'm the author of the add-on mentioned in the story.
Basically, various privacy protections cause various kinds of website breakage.
https://blog.mozilla.org/data/2018/01/26/improving-privacy-without-breaking-the-web/ https://blog.mozilla.org/data/2018/01/26/improving-privacy-w...
- cuckcuckspruce 9y agoThen those websites should be considered broken much like we consider Adobe Flash and sites with invalid TLS certificates.
- billysielu 9y agoAgreed. There are good kinds of broken.
- kuschku 9y agoThe problem is that basically all of Google’s products would be affected, which is something no browser can easily ship without angering users.
- ballenf 9y agoCan you elaborate? Is there some reason that running every Google property except google search (unless desired, but I prefer non-tailored results) in one container wouldn't work?
- JetSpiegel 9y agoIn that case each origin is not really getting an isolated cookie jar.
- groovecoder 9y agoI really like that perspective! A few more high-profile cases like this and we just might nudge the internet in this direction! :)
- scrollaway 9y agoYes please. Third party cookies and the like are the plague. They have so few legitimate use cases. Make it a long deprecation if you have to. Give even longer exemptions to the really big players / the big breakage / the legitimate use cases while we find better ways. But it is up to the browser vendors to remove the weapons here.
- chopin 9y agoUnfortunately, OAuth relies on them. Many SaaS offerings rely on OAuth.
- scrollaway 9y agoSAML and some oauth flavors do, but most of oauth does not.
- rb12345 9y agoI don't think OAuth requires third-party cookies, and SAML definitely does not. The authentication parts use HTTP POSTs or redirects from the IdP to SP. You probably do want cookies to track the sessions on each end, but those would be first-party. It's possible for your IdP to track the SPs you authenticate to regardless of protocol or cookie use, of course.
- billysielu 9y agoOh hey, love your work mate. Thank you!
- groovecoder 9y agoMy pleasure ... but it's not just my work. Firefox privacy & security and add-ons engineering teams have poured a ton of effort into Firefox Quantum to make features like this possible and easy.
- peteretep 9y agoHow easy is this to extend to other sites? LinkedIn and Google, specifically?