5 ms·
The problem starts when the user has not been educated about the potential drawbacks of enabling such a feature. The privacy.resistFingerprinting option is the
by dessant 4y ago
The problem starts when the user has not been educated about the potential drawbacks of enabling such a feature. The privacy.resistFingerprinting option is the leading cause for angry Firefox users and unwarranted negative reviews on my part, despite being an obscure feature that can only be enabled from config.
Things will break in unexpected ways, while web developers are the ones expected to spend their time offering support for a browser that has been rendered broken.
They need to be very careful about how these features are presented, and evaluate how they affect the entire web ecosystem.
- gruez 4y ago>They need to be very careful about how these features are presented, and evaluate how they affect the entire web ecosystem. It's hidden behind an about:config option (rather than being in the settings page), and the linked article literally says "It is likely that it may degrade your Web experience so we recommend it only for those willing to test experimental features". What more do you want?
- 6510 4y agoGive the settings page a "blog" (like the extensions page) describing each setting that has been changed manually in a way users can understand it so that they might learn the drawbacks and can restore it.
- gruez 4y ago1. it doesn't change any of your settings. If you want to revert it, all you have to do is set the about:config value back to 0 2. The linked blog posts already lists the things it does (although it's non-exhaustive)
- 6510 4y agoPeople follow instructions from a web page that tell them how to change the about:config values. Then they forget what they've changed. I just noticed there is a "Show only modified preferences" which is wonderful. It shows me uhh.. a few hundred things I haven't changed myself. I really can't remember what I've changed. (5 minutes later) I remembered, last time I've looked the about:config right click context menu was replaced with the rather useless default webpage menu. Kinda funny as I was looking to disable dom.event.contextmenu.enabled Putting "enabled" and "disabled" behind the preferences feels kinda silly. It would make more sense if the gui replaced true/false with disabled/enabled.
- dessant 4y ago> What more do you want? Inform users when they silently pass garbage through web APIs such as HTMLCanvasElement.toDataURL(), when it happens. And the UX of that should also be very carefully considered. Otherwise you might end up with some critical document scans on a government website being uploaded as striped nonsense images without your knowledge, and the "may degrade your Web experience" that you glanced over a year before when you enabled the option may not cut it when your Visa application is delayed or rejected.
- gruez 4y ago>Inform users when they silently pass garbage through web APIs such as HTMLCanvasElement.toDataURL() >[...] when your Visa application is delayed or rejected. Isn't that what the prompt (pictured in the article[1]) is for? It doesn't always show up, but AFAIK it only does that when the page tries to grab canvas data before the user has interacted with the page. For a page where you're uploading documents, that seems unlikely. [1] https://user-media-prod-cdn.itsre-sumo.mozilla.net/uploads/gallery/images/2020-04-24-10-28-54-496d8e.png https://user-media-prod-cdn.itsre-sumo.mozilla.net/uploads/g...
- dessant 4y agoIt can auto decline the canvas request and return fake image data from the API by default when privacy.resistFingerprinting is enabled. privacy.resistFingerprinting.autoDeclineNoUserInputCanvasPrompts must be set to false to always show the popup, and even then they shouldn't serve fake data when the user declines the request, but throw an error for the API call.
- gruez 4y ago>It can auto decline the canvas request and return fake image data from the API by default when privacy.resistFingerprinting is enabled. privacy.resistFingerprinting.autoDeclineNoUserInputCanvasPrompts must be set to false to always show the popup Right, it can auto-decline it in certain circumstances. As the name suggests, it auto-declines it when there there isn't any user input. That seems fairly reasonable to me, and is unlikely to cause issues with you uploading documents for a visa application (you need to interact with the site to upload the document in the first place). That said, I was playing around with it using various codepen demos and discovered that even if you interacted with the page, if the page was in an iframe it would always not show the popup. That might cause issues in certain circumstances and I do hope it will get fixed. >and even then they shouldn't serve fake data when the user declines the request, but throw an error for the API call. Whether that's the best approach is debatable. For the use case of uploading a document, I agree that would be the best behavior, but for other cases (ie. it's trying to display something), an exception would likely crash the app. In many cases (eg. google maps), the garbage data doesn't interfere with my use of the app, and crashing the app would be far more disruptive.
- Dylan16807 4y ago> Things will break in unexpected ways Like the webgl max texture size dropping to 2048. I wish they'd give that one a bump.