6 ms·
I commend Firefox for trying to do this... but it worries me. 3 obvious holes: - Proliferation of dialogs. When you don't know whether a site will suddenly br
by undecisive 6y ago
I commend Firefox for trying to do this... but it worries me.
3 obvious holes:
- Proliferation of dialogs. When you don't know whether a site will suddenly break or not, standard users will be implicitly trained to say yes to all dialogs.
- Domain "homogenizing" (spoofing) services will win. Trackers that offer a widget you can install on your server will win. Facebook et all will still know where they sent you, and will be able to track you server side. If mozilla provide a centralized whitelist, then SSO providers who also provide trackers will win. Essentially, the big players will find a way, the little players (who users weren't worried about anyway) will still lose.
- The web will break. SSO will be broken for a good couple of months on over 50% of websites using it - possibly more. "This only works in Google Chrome" will become more and more popular. Potentially, Firefox doesn't have the market share to make this work.
Those of us who will stick with Firefox regardless are in for a world of pain, and not a lot of gain. I guess it's necessary to move the web on, but the pessimist in me doesn't see that happening any time soon.
- sdeframond 6y ago> Firefox doesn't have the market share to make this work. Potentially indeed. On the other hand it will give FF evangelists one more selling point. "Why should I switch to Firefox?" - "Because it lets you chose who is tracking you and who is not."
- laurent92 6y agoIt’s a difficult argument, depleted of its true meaning by its overuse in VPN ads (which make it... easier to track you at the VPN level). But Firefox has a good enough corporate image to tell that _they_ are the ones who really do it.
- kuu 6y ago> Facebook et all will still know where they sent you, and will be able to track you server side This is not a problem a browser can fix
- ThePhysicist 6y agoSSO really doesn't need cookies to function, you can e.g. pass short-lived authentication tokens via URL hash fragments, that is already supported by OAuth 2.0 via the implicit grant flow (and for API-based flows it's not a problem).
- twodave 6y agoIMO this and referrer URL are the only information that ought to be able to be shared between two different domains via the browser. Either put it in the query string so the user can be aware of it or leave it alone. Of course, there are downsides. Query string character limits constrain what can currently be passed (some would say a it's good thing in this context), and browsers are headed more and more towards showing only the domain in the address bar by default. The other remaining problem would be tracking via XHR. The only mechanism for limiting which servers an XHR request can talk to currently is CORS, and that config is controlled by the server, not the user.
- the8472 6y ago> SSO will be broken for a good couple of months OpenID Connect should continue to work just fine. It's redirect based so 3rd-party cookies don't apply. But I can see HTTP-based redirects being used for tracking on every page load (so much for SPAs, heh). Techcrunch already does that.
- ulucs 6y agoNothing that ultimate bypass/redirector can't solve, assuming the target url is somewhere in the GET data
- CuriousSkeptic 6y agoOIDC in an 3rd-party iframe breaks with SameSite
- ignoramous 6y ago> ...the little players (who users weren't worried about anyway) will still lose. The little players not having data is a win in my eyes, because those are more likely to get breached or sell data to the highest bidder. > This only works in Google Chrome Regardless of Firefox abiding by the standards (or doing what Chrome does) or not, this was always going to be the case, and so it isn't that big a deal. > Trackers that offer a widget you can install on your server will win. This is already a thing thanks to the popularity of content blockers like Pi-Hole and uBlockOrigin. Firefox's move here is another nail in the coffin for third-party tracking through third-party servers. At least, first-party tracking with third-party "widgets" means first-party would need to shell out the cost of running that infrastructure. > The web will break. The web always has been :) > Those of us who will stick with Firefox regardless are in for a world of pain, and not a lot of gain. For me, Firefox seems to be making decisions with user's security and privacy in mind, and I see that as a net positive. As a long time user, it is the only reason I use Firefox.
- undecisive 6y agoI agree with pretty much everything you've said :) I guess my gripe is more "Why does the world not work right" than "Firefox has done a stinker here". And I suppose my reaction really should be "How can we work to give Firefox a leg up, while still encouraging it to intentionally fail many of the metrics most people care about". It's a hard battle to fight. Don't suppose Google will implement these things that might hurt their user tracking businesses... yeah?... no?... no. > thanks to the popularity of content blockers like Pi-Hole and uBlockOrigin Unfortunately these are "block these please" which hurts all the big players for the tiny portion of web users that use them. Every time I've ever moved a feature in software I've written from "all except this" to "none except this", it has always failed spectacularly, at least for a few people. The fact that users will get an option to unblock the services they need is encouraging... the fact that they mention that users might see the dialog multiple times for the same service is not. But yes, I will try to be hopeful - and you are right, the fact that Firefox does this kind of thing is a big part of the reason I use them in the first place.
- hctaw 6y ago> Regardless of Firefox abiding by the standards (or doing what Chrome does) or not, this was always going to be the case, and so it isn't that big a deal. It's a huge deal to me as a Firefox user. This is a total anecdote, but the number of websites and apps that are broken in Firefox seem to be on the rise. I try to report bugs when I can but the task is Sisyphean. If Firefox is increasing the friction between web developers and the browser while chrome is lowering it, the problem will only get worse.
- baybal2 6y agoMozilla went chasing Chrome, and lost almost all of its market share. Chasing Chrome was a bad decision. When they realised it was, they should've corrected the mistake, but instead Baker doubled down on the wrong direction, breaking all fiduciary duties she has as a CEO of non-profit in the process.
- jamespo 6y agoIf you're referring to XUL extensions being given the elbow, the small proportion of users using those does not correspond to Firefox market share loss.
- Karunamon 6y agoThat's not Mozilla's only or most significant misstep. CEO drama, Hello, Pocket, UI indecisiveness, repeated feature removal over objections, breaking everyone's addons first with the XULening then with the addon cert fiasco, opt-out telemetry, force-pushing addons without affirmative consent, opt-out advertising, buying into scummy tracking outfits like cliqz (and trying to hide it), poor prioritization, lack of focus.. If there's ever a choice between giving the user more control and transparency or taking it away, Mozilla seems to take the latter option.
- IggleSniggle 6y agoWow, I had actually forgotten about a ton of this stuff, shines a different light on how hard it’s been working to gain trust and be the “privacy browser” in recent years.
- coldpie 6y agoOutside of HN, no one I've ever talked to has mentioned any of those as reasons for using Chrome. The two most common reasons I've heard are "dunno" followed distantly by "I use ten hundred thousand million tabs and Firefox crashed on me once fifteen years ago." I suspect the rise of mobile browsing, with Chrome as the default, plus users' Google account having strong integration with Chrome--not to mention Google pushing Chrome across all of their properties--have a lot more to do with Chrome's popularity than a button on Firefox's toolbar that you don't like.
- _pmf_ 6y agoLayering leaky abstractions over leaky abstractions and calling it security is what the web has turned into. All the while introducing new side channels and attack vectors like WebGL that allow completely covert access via unknown access paths in GPU driver binary blobs. It's unfixable.
- jannes 6y ago> The web will break. I have been using the First-Party Isolation feature for a few months now. FPI (privacy.firstparty.isolate) is a flag that was originally created for the Tor Browser project. It's a strict version of State Partitioning without any way to unpartition (no permission dialogs, no heuristics). So far I have only come across one broken website: Microsoft Teams login through Okta SSO. The rest of my logins worked flawlessly with FPI turned on. Nothing close to the 50% that you mention.
- undecisive 6y agoThat's encouraging news. Do you use a lot of sites with SSO? Are they mostly mainstream (where I would class MS Teams to fall in that bracket) or do they tend to be more niche services? (I totally accept that my "50% of SSO systems will be broken by this" to be a worst-case random number i-have-no-idea-but-for-all-I-know value. Probably shouldn't have been so blasé about it! But very much interested to hear what real-world values look like)
- not2b 6y agoOkta SSO is used heavily inside my company to access internal sites, but if there's a way to whitelist, or the user sees a popup the first time and allows Okta cookies after that, this problem is taken care of.
- egeozcan 6y agoI don't understand why the SSO would be broken. AFAICT, I'd just need to re-login to the SSO-provider (Okta in this case) in the context of the initiator (Microsoft Teams, in this case). They'd otherwise need to be doing something silly if it stops working.
- hirsin 6y agoTeams relies on iframe auth to fetch the Nth token from AAD (multiple resources to call, multiple tokens required). The iframe calls are partitioned and lose cookies, even under Firefox's helpful "redirect exemption" setup, it's not clear why.
- hinkley 6y agoI have only gotten a virus once on my computer, and it was because IE was harrassing me with dialog boxes on a regular basis, and one time when it was asking me a yes/no question about downloading code, my brain went into "SSL Warning mode" and didn't say "wait!" until my finger was descending on the OK button. I only had the virus for ten minutes, but it reconfirmed everything I knew about dark UI patterns.