3 ms·
afaik, extensions will not provide you with 100% protection in this case. It could be for multiple reasons: 1. The 3rd party domain is not on the list: a. C
by kkm 8y ago
afaik, extensions will not provide you with 100% protection in this case.
It could be for multiple reasons:
1. The 3rd party domain is not on the list:
a. Could be because the presence is not huge.
b. The domain is too new, and not available on any lists
right now.
2. The user might have whitelisted a 3rd party domain
because it breaks some component on the web.
They always need to catch-up, so it's a whack-a-mole game.
Along the same lines, a user can also control the referrer. for example in Firefox based browser you can control(globally) what info should be sent in the browsers itself. - https://wiki.mozilla.org/Security/Referrer https://wiki.mozilla.org/Security/Referrer . But this will also come with some breakage.
Similarly, blocking third-party cookies also does not help, as the leaks the telltale URLs will still pass on.
The legit use cases of these third-parties actually do not require the first-party to share these sensitive details.
1. Google analytics actually states that in their privacy policy - https://support.google.com/analytics/answer/6366371?hl=en https://support.google.com/analytics/answer/6366371?hl=en
2. To load a font from CDN, I don't see why a company needs to send my booking ID and/or token to them. In some cases, domain might be needed but definitely not booking ID.
So, imo, the websites should take onus when implementing 3rd parties or atleast be transparent about what information is being shared and with whom.
- donaltroddyn 8y agoGiven that this analyses network traffic on the client side, Local Sheriff is probably playing the same catch-up game that a blocker targeting that same PII is.