21 ms·
Firefox rolls out Total Cookie Protection by default to all users
- legalcorrection 4y agoI wonder why Microsoft doesn't make Edge a privacy-oriented browser. I'm surprised they think they can make more from the data economy than they would gain by seriously hurting Google et al.
- itsbits 4y agoThey have a private experience setup available(not private mode).I don't remember name but as soon as you install edge, it asks what level privacy you want to manage. That I guess should be fine.
- Nextgrid 4y agoMicrosoft went all-in on "growth & engagement" since Windows 8. Why sell OSes for money when you can get "engagement" instead?
- ravenstine 4y agoBecause Microsoft has had a history of caring about privacy? I'd expect something like this from Apple with Safari, but not Microsoft. M$ can't even give its own developer base privacy by allowing all telemetry to be disabled.
- legalcorrection 4y agoCompanies don't care about jack shit. Tim Cook doesn't "believe in" privacy, he thinks it helps sell devices (and that lack of privacy could lead to scandal that would hurt sales).
- ravenstine 4y agoWhether one company is effectively more private than the other has nothing to do with what the company actually believes. It doesn't really matter what they believe. When you compare the two companies, Microsoft arguably has a greater history of embedding tracking in its products than Apple. This isn't to say that Apple doesn't track anything. As far as I'm aware, Apple didn't help the NSA bypass encryption or build backdoors into its OS.
- ntoskrnl 4y agoThere's too much money to be made foisting payday loans on the dwindling userbase. https://www.howtogeek.com/769427/microsoft-edge-wants-to-give-you-a-loan/ https://www.howtogeek.com/769427/microsoft-edge-wants-to-giv...
- legalcorrection 4y agoThose aren't payday loans, but interesting nonetheless.
- fritigern 4y agoSince when does Microsoft care about privacy?
- corentin88 4y agoReminds me of what Google Chrome (and others browsers) did for cache. That's clever, not 100% sure this will prevent tracking, but at least it makes tracker's life a bit harder.
- eps 4y ago
- suprfsat 4y agoGaining security and privacy by partitioning the cache (October 6, 2020) https://developer.chrome.com/blog/http-cache-partitioning/ https://developer.chrome.com/blog/http-cache-partitioning/
- thatguy0900 4y agoTo some extent chrome only cares about google being able to invade your privacy, if google can get information a different way anyway then its a good thing to block it for everyone else
- Taywee 4y agoTone policing is irrelevant and annoying. Technical relevance and accuracy trumps any of your personal feelings on Google, and I say that as a person who generally detests Google.
- ajvs 4y agoYes these are each subsets of State Partitioning[1], of which cache has also been partioned in Firefox for some time now. [1] https://developer.mozilla.org/en-US/docs/Web/Privacy/State_Partitioning https://developer.mozilla.org/en-US/docs/Web/Privacy/State_P...
- ape4 4y agoSo what about things besides cookies and cache? Is there anything else that might be shared between 3rd party sites?
- robin_reala 4y ago
- lucasyvas 4y agoHow does this relate to the existing tracking protection settings - should I turn off "block all third party cookies"? That setting breaks a few things, but mostly works OK. I'm confused which protection level this new capability corellates to.
- asicsp 4y agoThis might help: >Total Cookie Protection offers additional privacy protections beyond those provided by our existing anti-tracking features. Enhanced Tracking Protection (ETP), which we launched in 2018, works by blocking trackers based on a maintained list. If a party is on that list, they lose the ability to use third-party cookies. ETP was a huge privacy win for Firefox users, but we’ve known this approach has some shortcomings. If a tracker for some reason isn’t on that list, they can still track users and violate their privacy. And if an attacker wants to thwart ETP, they can set up a new tracking domain that isn’t on the list. Total Cookie Protection avoids these problems by restricting the functionality for all cookies, not just for those on a defined list.
- lmkg 4y agoThis is strictly in-between allowing third-party cookies and blocking them. They are allowed, but isolated to prevent data sharing. Previously: Site A has a facebook Like button, which iframes in facebook.com and sets a third-party cookie for facebook.com. Site B does the same. Site B can see that you previously visited Site A, and if you have a Facebook account, then Facebook can connect your browsing activity on both A and B to that account. New feature: Site A's Facebook Like button iframes in Facebook, and sets a cookie on facebook.com. This is a different cookie than the one Site B sets for facebook.com. The cookies cannot tell that you're the same person. If you have a Facebook account, your browsing activity on A and B is not connected to your Facebook account.
- ziddoap 4y agoThis seems to be a middle-ground. You can more confidently allow third-party cookies, which means that certain features that broke with the blocking of all third-party cookies will now be able to work, but you maintain most of the protections that you gained when you used to block them.
- xnorswap 4y agoDoes this affect single-sign-on implementations?
- jaywalk 4y agoIt shouldn't. SSO doesn't typically work by sharing cookies, which have always been limited to a single domain in the first place.
- jrochkind1 4y agoI'm not sure about that. It depends on where the boundaries of the "cookie jar" are (through redirects and such). And I suspect it will effect it, in order to accomplish it's purpose. After all, what is tracking but a sort of "SSO" you don't know about. (OK, technically tracking is less powerful than SSO, since only the third-party needs to know your "single" identity, the first-party website doesn't actually know it, where in SSO it does) I mean, to be clear -- I mean the new thing might make you enter your username and password to SSO login on each site, whereas ordinarily if you have an active SSO session you don't need to re-enter username and password to login with SSO on a new site. Will it break SSO even if you are fine re-entering username and password every time you SSO login? I am not sure, but I definitely wouldn't be confident 'no' without more details/testing.
- mmis1000 4y agoThose work by redirect you on top level domain (the url you see in url bar) shouldn't be affected. They don't even share cookie directly anyway. (Which is just.... standard oauth) Those work by enbedded into pages (iframe) or popups may. The biggest offender of this kind of usage is probably facebook comment / disqus comment.
- jrochkind1 4y agoMakes sense. The difference will be (I predict) that when you are redirected to the SSO, you will _always_ have to enter your username/password, or at least once per "first party" site you are logging into. Whereas right now, sometimes when you get redirected to the SSO/oath, it already knows who you are, and you don't need to log in again -- you just get invisibly redirected back, and/or just have to click a button saying "yeah, it's cool". But with the cookie sandboxes, you'll always have to actually enter username and password to your SSO. Because the cookies that would have told the SSO(/oauth provider) that you have an active auth session, from when you logged in earlier today or whatever -- won't make it. Or maybe not, depending on how it's implemented -- but if a redirect is enough to defeat it and make it think you're in a different sandbox, then I expect all the trackers will be able to defeat the sandboxing with careful use of redirects. So.
- jokoon 4y agoI really want to enable resist fingerprinting, unfortunately it disables dark theming on github, ddg and other websites. I wish I could add an exception rule to this...
- soundnote 4y agoYou could always step out of the cave and join the rest of humanity in the light.
- deleted 4y ago[deleted]
- Saint_Genet 4y agoI guess you could set up custom stylesheets, at least for sites you commonly browse.
- TAForObvReasons 4y agoThe time-based light/dark mode setting requires the current time. It is not currently accessible from CSS and is blocked by resistFingerprinting
- imbnwa 4y agoDoes that for extensions like Dark Reader Pro too?
- mlindner 4y agoI've had it on a for a while and I don't seem to have any issues getting dark theming to stick.
- 8organicbits 4y agoFor GH you can set your theme preference in your account settings.
- ajvs 4y agoDark Reader extension has made me never notice this was a thing.
- flipbrad 4y agoCool. Just a heads' up that I had to disable it on Zendesk and Asana so they could talk to each other - you might experience similar issues.
- shrikant 4y agoCan concur, this broke Zendesk integration with Jira so I had to disable it for our Jira setup.
- beej71 4y agoWhen I was blocking 3rd-party cookies on Chrome, I couldn't log into the IRS site. I figure that might happen here, too.
- lemoncookiechip 4y agoEDIT: Nvm, I found it. Thank you.
- toxicFork 4y agohttps://pbs.twimg.com/media/DzSc4mhX4AAi1Bz?format=png&name=medium https://pbs.twimg.com/media/DzSc4mhX4AAi1Bz?format=png&name=...
- zzyzxd 4y agoZendesk has been like this for me since forever. Every time I need to use it to talk to a vendor, I roll my eyes for 2 seconds and open my backup browser which does not have 3rd party cookie restriction.
- pbzm 4y agoThat's not ideal! Could you please file a bug and provide steps to reproduce the issue? I'm happy to take a look. You can file it here: https://bugzilla.mozilla.org/enter_bug.cgi?product=Core&component=Privacy%3A%20Anti-Tracking https://bugzilla.mozilla.org/enter_bug.cgi?product=Core&comp...
- pbzm 4y agoCould you please file a bug and provide steps to reproduce the issue? I'm happy to take a look. You can file it here: https://bugzilla.mozilla.org/enter_bug.cgi?product=Core&component=Privacy%3A%20Anti-Tracking https://bugzilla.mozilla.org/enter_bug.cgi?product=Core&comp...
- jaywalk 4y agoThis is a fantastic way to do this. I wish Safari worked the same way instead of just completely blocking third-party cookies.
- CharlesW 4y agoCan you explain why? Apple did this two years ago and I haven't personally seen any side effects, but Safari's also not my primary browser.
- jaywalk 4y agoIt makes my life harder as a developer. I've got some widgets (hosted by me) that are embedded on my customer's websites, and because of Safari I can't use cookies for things like a shopping cart. I have no need for the cookies to be accessible from another website, even if it's got the same widget embedded, so this implementation by Firefox fits my use case perfectly. Unfortunately that doesn't change what Safari does, so it doesn't help me.
- CharlesW 4y agoAh! I can see how that’d be a PITA, thanks for explaining.
- agluszak 4y agoWhy weren't separate cookie jars the default in the first place? I know that browsers other than Firefox have no real incentive to protect your privacy, but I'm wondering why cookies were designed to be shared among different pages in general
- Xylakant 4y agoCookies were invented at Netscape like 25 years ago, nobody considered the current situation.
- _jal 4y agoYes they did. It was foreseen, look at the sibling comment where the issue was discussed in the spec. They just punted, just like they did with https and CAs. (And Javascript, for that matter, although that's less directly security-related.) The concern was being first to market, not with solid engineering.
- ravenstine 4y agoThere are legit cross-domain use cases. A good example is how someone here mentioned (comment seems deleted though) account sessions being shared between Atlassian products like JIRA and BitBucket. The problem with that is domains are a poor way of representing ownership that can be trusted. If the web was rebuilt from scratch, a better approach might be to allow cookies to be shared between secure sites using the same certificate. But that adds more complexity that I'm not sure is worthwhile. The web can absolutely get away with not having shared cookies.
- deleted 4y ago[deleted]
- vman81 4y agoThere are also legit use cases for leaving all your doors unlocked. But they usually aren't really worth considering when you are installing your doors/locks.
- 4y ago
- fancl20 4y agoBefore anyone jumps to why Chrome doesn't block third-party cookies, some context: Regulators did warn Google NOT TO block third-party cookies before they provide a replacement, UK CMA accepted the latest proposal from Google: https://www.gov.uk/government/news/cma-to-keep-close-eye-on-google-as-it-secures-final-privacy-sandbox-commitments https://www.gov.uk/government/news/cma-to-keep-close-eye-on-... Apple's tracking rules also raised a lot of anti-trust concerns, giving advertisement in App Store unfair advantages among other ad platforms. Latest from German Government: https://www.bundeskartellamt.de/SharedDocs/Publikation/EN/Pressemitteilungen/2022/14_06_2022_Apple.pdf https://www.bundeskartellamt.de/SharedDocs/Publikation/EN/Pr... Banning third-party cookies will increase the gap between Google, Microsoft, Apple and other ad platforms, because they can still track you based on your account (e.g. Gmail, Hotmail, iCloud). It's a huge red flag for antitrust cases they are facing (especially Google).
- ComodoHacker 4y agoJust to clarify, Total Cookie Protection in Firefox is not the same as blocking third-party cookies. Firefox will accept third-party cookies and send them back, but only on this particular site. So third parties (read ad networks) will be able to track you on any site, but not across sites (without some other means of tracking).
- bpodgursky 4y agoYeah, which is why sites are all requiring logins nowdays, so they can use server-side ID syncs.
- Terry_Roll 4y agoI think OS Telemetry will see to it that its not private! However this will make it easier than it currently is, to work out who is data sharing illegally.
- 0daystock 4y ago
- hans_castorp 4y ago> What does "rolling out" mean? That Mozilla has the ability to modify my browser without my knowledge or explicit update installation? It seems obvious to me: it means "when you install the next scheduled update".
- ohthehugemanate 4y agoIt means in the next update this feature flag will be enabled by default for all users. If you don't update (or presumably, update and disable the flag), you won't get it.
- GNOMES 4y ago> Mozilla makes its complete cookie protection (Total Cookie Protection aka TCP) standard in its Firefox browser. For new users who get Firefox, the feature is enabled by default. In general, the aim is to achieve the changeover for all users, including existing customers, by August 23, 2022. https://www.realmicentral.com/2022/06/14/firefox-makes-total-cookie-protection-the-standard-starting-today/ https://www.realmicentral.com/2022/06/14/firefox-makes-total...
- ajvs 4y agoIf your browser is set to update automatically, then yes you'll get this feature. It's not a flag being switched on remotely, it comes with an update.
- ghusto 4y agoI've never understood the thinking that went behind allowing one site to see the existence of another site's cookie in the first place. I don't think I'm even coming at this with the security hindsight of decades, it's just common sense, isn't it?
- ComodoHacker 4y agoA site isn't allowed to see another site's cookies, common sense doesn't fail you.
- ghusto 4y agoNo, but I said see the _existence_ of. Or am I wrong there? Ha, I should really know this :P
- ComodoHacker 4y agoI'm not a front end guy, but AFAIK no, even the existence of. Apart from various hacks, of course.
- Renaud 4y agoIt's not that one site is seeing another site. It's that multiple sites will serve content (ads, Javascript libraries, like buttons) from a common site (eg an ad network) that uses its own domain. That domain is allowed to get the cookie for itself because it is referenced by multiple site, that's how this type of tracking works. If you go to bbc.com, it still won't be able to see cookies from cnn.com, but say if advert.com is included by both sites, then it will see that you visited them both. That's the power and great danger that things like facebook and google sense represent. The owner of the sites get some stats for free by using these services, but the biggest benefit is for google and facebook to be able to track what users are looking at accross the web. And you just need to be identifiable on one site that you visit (say, FB or gmail) for them to know exactly who you are. From what I understand, Firefox will only allow advert.com to get the cookie it created when being loaded as part of bbc.com, but it won't be able to read its own cookie from cnn.com, it will have to create a new, separate one, thus breaking the link tracking you between sites, or at least making it harder to connect the dots. Everyone should use FF.
- sampa 4y agoIt's nice, but is that so hard for Mozilla to tell in which version it will appear? Is it the current version or is it the next 102 version (which releases in 2 weeks, but then why they say it "rolls out"?)
- rebelwebmaster 4y agoMozilla occasionally rolls out features in the current release via remote mechanisms. So it's rolling out to existing v101 installs now. I would assume that v102 will also ship with it on by default.
- seanhunter 4y agoIf you want to enable it early, I believe you can go to about:config and set network.cookie.cookieBehavior to 5 Likewise you can keep enhanced tracking protection in general but disable partitioning (total cookie protection) by setting it to 4 https://support.mozilla.org/en-US/kb/total-cookie-protection-and-website-breakage-faq#w_how-do-i-access-the-enhanced-tracking-protection-settings https://support.mozilla.org/en-US/kb/total-cookie-protection...
- ridgered4 4y agoLooks like it's already in v101.0.1. It's under the Settings | Privacy and Security tab with a new checkbox to allow you to "Test Pilot our newest..." It is not automatically checked for me. I think the change might just be they will be setting that checkbox to on now? Although I don't remember seeing this option until now.
- Sytten 4y agoDoes someone have a link about the technical details for developers that it might affect (SSO, cookies for subdomains, etc). This is just a marketing post.
- GordonS 4y agoAlso keen to see something like this. Firefox surely (hopefully!!) isn't going to block cookies across subdomains, or a whole bunch of things are going to break. Would love to see confirmation though...
- wisniewskit 4y agoThere is some detail here: https://developer.mozilla.org/en-US/docs/Web/Privacy/Storage_Access_Policy#what_does_the_storage_access_policy_block https://developer.mozilla.org/en-US/docs/Web/Privacy/Storage...
- hericium 4y agoAbout 90% of Mozilla's income comes from Google. If this would prevent tracking, Google would not allow Mozilla to release it.
- deleted 4y ago[deleted]
- ajvs 4y agoGoogle would still have to fund Mozilla to prevent more anticompetition charges being levied their way regardless. uBlock Origin is a far greater threat since it blocks the more powerful JavaScript-based tracking, and you can see exactly how that's being managed with the move to Manifest v3.
- ars 4y agoGoogle's income will not change if they don't track. If they can't track, then each ad has less value. But then the advertiser has more budget available to spend on advertising. Net result is no change for advertisers, or Google. But they users will see more, less targeted ad. So that's my prediction as the result of this: We'll have more ads, but each will be less personalized.
- dev_tty01 4y agoIs this better or worse than Safari's "Prevent cross-site tracking" feature? https://support.apple.com/guide/safari/prevent-cross-site-tracking-sfri40732/15.1/mac/12.0 https://support.apple.com/guide/safari/prevent-cross-site-tr... It appears Safari is just blocking the cookies, while Firefox is isolating the cookies. I guess Safari has to keep track of who to block while Firefox just isolates everybody. Are there other benefits to the Firefox approach? Frankly, I have a hard time understanding why this Cookie Sandbox approach wasn't implemented a long time ago. I get that 25 years ago we weren't concerned about privacy, but there has been plenty of time to fix this. Advertiser influence?
- mmis1000 4y agoSites that use cross site resource will still work. Except the cross domain resource provider will always see the same domain coming to get resource. For example, if you are on Site A and use cross site resource from Site C. The site C will get a cookie C('A) And in another day, you visited a Site B that also use resource from Site C. The site C get a cookie C('B). And C('A) != C('B) Although these cookie are both issued by Site C. They are associated to different first party domain and can't be connected directly. It's just like you open a private browser session for every site you visit. I think it is a extension usage from Firefox's container technology.
- dev_tty01 4y agoThanks. In case anyone is interested, I looked around a bit more and found these descriptions of Safari's (Webkit) intelligent tracking prevention starting from 2017 (in reverse chronological order): Safari Tracking Prevention background: https://webkit.org/tracking-prevention/#intelligent-tracking-prevention-itp https://webkit.org/tracking-prevention/#intelligent-tracking... Blog posts about tracking prevention updates: https://webkit.org/blog/11545/updates-to-the-storage-access-api/ https://webkit.org/blog/11545/updates-to-the-storage-access-... https://webkit.org/blog/10218/full-third-party-cookie-blocking-and-more/ https://webkit.org/blog/10218/full-third-party-cookie-blocki... https://webkit.org/blog/9521/intelligent-tracking-prevention-2-3/ https://webkit.org/blog/9521/intelligent-tracking-prevention... https://webkit.org/blog/8613/intelligent-tracking-prevention-2-1/ https://webkit.org/blog/8613/intelligent-tracking-prevention... https://webkit.org/blog/8311/intelligent-tracking-prevention-2-0/ https://webkit.org/blog/8311/intelligent-tracking-prevention... https://webkit.org/blog/8142/intelligent-tracking-prevention-1-1/ https://webkit.org/blog/8142/intelligent-tracking-prevention... https://webkit.org/blog/7675/intelligent-tracking-prevention/ https://webkit.org/blog/7675/intelligent-tracking-prevention... Here is their tracking prevention policy definition: https://webkit.org/tracking-prevention-policy/ https://webkit.org/tracking-prevention-policy/
- mastermedo 4y agoI remember losing a bet a while back, because I was naive enough to think that was how cookies worked in the first place. Why did other sites ever have access to cookies they didn’t create was beyond me.
- dangrossman 4y agoYou don't need access to cookies you didn't create to do cross-site tracking. Think: Disqus or Facebook comments at the end of articles, which used to be pretty ubiquitous. You'd be logged in and able to comment on any website using a cookie set by Disqus or Facebook, so you wouldn't have to log in or register on each individual website. This Total Cookie Protection will break that. Your Disqus-set login cookie set on site A won't be visible when you're on site B, so you won't be logged in to Disqus there.
- Sohcahtoa82 4y ago> Why did other sites ever have access to cookies they didn’t create was beyond me. They don't. If you go to example.com, and it loads an ad on tracker.com, then tracker.com will create a cookie. example.com WILL NOT be able to see that cookie. Likewise, if you were to log into example.com, tracker.com WILL NOT see the example.com cookie. What happens (Without third party cookie blocking or FF's TCP) is if you then go to anothersite.com, and it also loads an ad from tracker.com, then the same cookie sent to it while visiting example.com will be sent, resulting in tracker.com knowing that you visited both sites. The admins of both example.com and anothersite.com will then be able to look at analytics and see that the visitors of their site also visit the other. At no point is one site ever able to see a cookie they didn't create. Otherwise, this would be a MASSIVE security hole as it would make session stealing trivial. However, a site is able to see a cookie they created while visiting another site. Maybe this is what you meant, but it wasn't entirely clear.
- michaelcampbell 4y agoThanks; this is a more clear explanation than I've seen elsewhere.
- madmax108 4y agoI wonder if there's anyone from any advertising/ad-targeting companies on HN who can shed some light on if/how much this change may affect their "product". Asking this since I know friends working at companies that were DRASTICALLY affected by the Apple advertising changes in terms of user targetability (and hence revenue) and I'm wondering if this change will be similar.
- unicornporn 4y agoFirefox has a sub 8% market share, so I doubt this will make a drastic change to how they operate.
- rkk3 4y agoSurprised it's even that high, I tried to switch to Firefox the other month for privacy but gave up because it crashed on me it-least once a day. Edit: thanks for the downvotes, I would have preferred if it worked but it didn't. I tried basic troubleshooting, disabling extensions etc. but didn't find it usable on macOs Monterey, think it doesn't play well with youtube.
- geekamongus 4y agoStrange...it's been rock solid for me for years, across multiple devices and OS's. I cannot remember the last time FF crashed.
- tristan957 4y agoI have used Firefox for 7 years and never had it crash once.
- raxxorraxor 4y agoI used it for a similar time if not longer and I think it crashed < 10 times. In the last years it was mostly just single tabs failing and probably was just another website with some endless js loop anyway. Extremely stable compared to almost any other software. Perhaps the parent means the mobile version. If not I would expect something is wrong with the system, even if visiting the worst pages of the internet.
- dmw_ng 4y agoDoes anyone know if this covers network-layer state like keep-alive or TLS session reuse?
- chasd00 4y agogiven that Electron is really just a featureless browser shouldn't it be straightforward to make your own browser now? An address bar, navigation, and bookmarks ought to be enough to get you there. Seems like you should be able to make a browser for your specific needs/wants pretty easily these days. I'm not suggesting some sort of money making venture where you're beholden to investors to try and turn revenue with it but more just like a utility. Like a script or something... maybe that's the way to think about it, something cobbled together quickly to read websites.
- pvg 4y agogiven that Electron is really just a featureless browser shouldn't it be straightforward to make your own browser now? That's not what Electron is but there are piles of fork-ish browser projects out there statistically nobody uses. This also answers the second question in the negative - it is not straightforward to make your own browser that's as useful as the browser you're likely using.
- Sohcahtoa82 4y ago> > given that Electron is really just a featureless browser [...] > That's not what Electron is I mean...isn't it? Forget the idea of what it's used for and just look at how it works. It's a framework for making apps that uses Chromium for rendering and a Node backend. Strip off the Node backend and you're left with Chromium. And Chromium on its own is a web browser. Electron just doesn't show the controls for it. As far as I'm concerned, Electron is a featureless web browser with a backend added to do things a browser normally can't do on its own, like reading local files without presenting a dialog.
- pvg 4y agoa backend added That's a huge change which allows for things like turning XSS into RCEs. It's a bit like 'why can't you make your own street legal sports car by removing the rear spoiler and replacing it with a jet engine'.
- gbN025tt2Z1E2E4 4y agoThis will only further entrench the big players (google, facebook, etc) while making it impossible for new & small players to compete. All of the services the big players offer effectively make working without universal cookies trivial. For the small players though, without massive ad-supported service offerings like Gmail, Facebook (as a platform), etc, this will screw them completely. Mind you, I'm a HUGE privacy advocate, so I like the new Firefox functionality... but the unintended side effects cannot be ignored.
- ddtaylor 4y agoDo we want anyone tracking us? I don't really care about the size of something that is tracking me - I care about the tracking itself.
- rcMgD2BwE72F 4y agoFirefox really needs to implement two features: 1. Cookie Auto-Delete (see https://github.com/Cookie-AutoDelete/Cookie-AutoDelete/wiki/Documentation https://github.com/Cookie-AutoDelete/Cookie-AutoDelete/wiki/...), where cookies and local data are automatically deleted some time after closing the tab. You can, of course, whitelist Websites to exclude them. 2. Firefox multi-container extension, to assign some websites (domains and subdomains) to a container by default so that you can visit some specific Google sites without being logged in (e.g Web search, News, Maps…) but still open Gmail and be connected to your account. You can make this more intuitive and combine that in a single button: "Do not forget. Optionally, open website in <container>". This would drastically level the playing field, as one can continue to use some Google/Apple services for work (e.g Play developers console, Google calendar…) but all visit to other properties would not be tracked. No need to switch between browsers, profiles or containers, this is automatic. I've been using this set up for years now, and it works perfectly – just add uBlock and I don't care about cookies, and you'll ever see an ad or a cookie prompt ever again. Perfect.
- pid-1 4y ago(1) totally exists, that's always how I configure all my FF installs. You also can add exceptions, although I don't use this feature.
- drexlspivey 4y agoIs that basically the PrivacyBadger plugin integrated into Firefox? Can I uninstall it now?
- ghostwords 4y agoHi, Privacy Badger dev here. Total Cookie Protection helps by keeping all third-party cookies isolated to the site they were set on. This means tracker domains will no longer get their cookie identifiers persisted across different sites. However, tracking isn't limited to cookies. If unblocked, trackers can still use techniques like browser fingerprinting and cookie syncing. They could also just track you via your IP address, or, most likely, via some combination of different techniques. Trackers can also collect sensitive information such as your email address, or even become vectors for delivering malware. Outside of privacy/security concerns, unblocked trackers can slow down websites and waste your bandwidth. To learn about how Privacy Badger works, visit https://privacybadger.org/#faq https://privacybadger.org/#faq
- sdze 4y agoFirefox + ublock origin is my trusted porn browser.
- Sohcahtoa82 4y agoI hope you add Incognito Mode to that.
- sharno 4y agoWish there was a feature or extension to auto accept cookie banners on websites
- bityard 4y ago> making Firefox the most private and secure major browser available across Windows and Mac. Which one do they think is the most private and secure browser for Linux?
- harry8 4y agoMaybe they figure most linux users can tweak the settings, install & configure plugins on whatever browser they're using to harden things up with the hassle overhead they can live with..? Shoutout for firefox's cross OS, cross device syncing. "I found that and I have that it open in a tab on my desktop" and now it's open on my phone. Send another tab from phone to laptop where it's easier to work on. Really good stuff.
- Groxx 4y agoLynx probably
- smolder 4y agoYou'll be happy to see they've edited the announcement to include Linux now, likely in response to this or the other comment like it. :)
- easytiger 4y agoIf anyone wonders how bad the situation RE cookies is there is a local newspaper owner in the UK called reach PLC who own 100+ newspaper websites. Their cookie allow dialog has over 700 data share partners, not including their own "legitimate interest" cookies. The dialog looks like this [1] and cannot be resized and is lazy loaded (i.e. you have to manually scroll to have the page load all of them with a few visible each scroll). And its slow so it takes a while and doesn't play well with the mouse in the iframe. There are even ones not in english or latin characters [2] [1] https://imgur.com/a/ciuRWSx https://imgur.com/a/ciuRWSx [2] https://i.imgur.com/4yc6Flo.png https://i.imgur.com/4yc6Flo.png Anyway i lazy loaded all of them and there are 753 (the html just to display it is > 1 megabyte $ xmllint --format reach2.html | grep qc-cmp2-list-item-header | tail && xmllint --format reach2.html | grep qc-cmp2-list-item-header | wc -l <button role="listitem" class="qc-cmp2-list-item-header" aria-label="Yieldmo, Inc." aria-live="polite"> <button role="listitem" class="qc-cmp2-list-item-header" aria-label="YOC AG" aria-live="polite"> <button role="listitem" class="qc-cmp2-list-item-header" aria-label="YouGov" aria-live="polite"> <button role="listitem" class="qc-cmp2-list-item-header" aria-label="ZAM Network LLC dba Fanbyte" aria-live="polite"> <button role="listitem" class="qc-cmp2-list-item-header" aria-label="Zemanta, Inc." aria-live="polite"> <button role="listitem" class="qc-cmp2-list-item-header" aria-label="zeotap GmbH" aria-live="polite"> <button role="listitem" class="qc-cmp2-list-item-header" aria-label="Zeta Global" aria-live="polite"> <button role="listitem" class="qc-cmp2-list-item-header" aria-label="Ziff Davis LLC" aria-live="polite"> <button role="listitem" class="qc-cmp2-list-item-header" aria-label="zillian sa" aria-live="polite"> <button role="listitem" class="qc-cmp2-list-item-header" aria-label="Zoomd Ltd." aria-live="polite"> 753 It's crazy
- rdsubhas 4y agoPrivacy wins aside, can anyone please help educate if third party single sign ons will still continue to work?
- kayodelycaon 4y agoThis feature protects domains, not sessions. SSO relies on passing tokens over redirects, not cookies. As long as your redirected, the SSO uses their own first party cookies. You would be logged in to the SSO provider no matter who redirected you there.
- ezfe 4y agoSingle sign on doesn't need cookies. The data is passed in the URL when redirecting back and forth between the website and the SSO provider.
- jalk 4y agoI don't think they rely on third party cookies. You are redirected to the SSO provider which then issues a token which it transports back to the requesting site through other means than cookies (i.e. post body / query string)
- Strom 4y agoDepends on the specific implementation, but in theory this doesn't limit any functionality for SSO. Data can be shared via mechanisms other than cookies.
- wisniewskit 4y agoIt depends on the specific third party login service. Some rely on third party storage-sharing, and there are web compatibility measures built into Total Cookie Protection to allow those to keep working. One is that the login service can request access from the user using a new web API (requestStorageAccess). Another is heuristics which apply when the user interacts with the page in a way which implies a login might be taking place. In these cases, specific third parties can be granted access to allow the login. There are some more details here: https://developer.mozilla.org/en-US/docs/Web/Privacy/Storage_Access_Policy https://developer.mozilla.org/en-US/docs/Web/Privacy/Storage...
- stvnbn 4y agoI see this and I ask why it hasn't been this way since the beginning? why it took so long to have it?
- letmeinhere 4y agoDoes this obviate the need for [Facebook Container](https://addons.mozilla.org/en-US/firefox/addon/facebook-container/ https://addons.mozilla.org/en-US/firefox/addon/facebook-cont...)?
- deleted 4y ago[deleted]
- wisniewskit 4y agoFacebook Container is a stricter form of protection for Facebook specifically, so no, you should continue using it if you're interested in isolating Facebook. Total Cookie Protection is about isolating third party cookies/web storage, without breaking as much of the web as simply blocking third party cookies does.
- craigmart 4y agoWhat kind of protection does Facebook Container have other than deleting cookies outside of the container? For my case Total Cookie Protection is enough, but if you want the same protection of Facebook Container for every website (i.e. session cookies which are deleted each time you restart the browser) you can install Cookie AutoDelete or use the built-in option to delete cookies at restart (whitelisting websites where you need permanent cookies).
- wisniewskit 4y agoIt also blocks network requests made by third-party sites to FB. So unless you're already running ETP with the content blocker on (strict mode, private browsing mode) or another ad blocker kind of addon that also blocks FB strictly, then that's an additional measure.
- nightpool 4y agoIn which way is Facebook Container "stricter"? Are you aware of any potential third-party tracking vectors that Firefox does not currently mitigate, but Facebook Container does? The only possible difference I can see is that Facebook Container keeps sites "shared" via Facebook inside of the Facebook Container, so if you navigate from e.g. Facebook -> CNN, facebook can only see the history of CNN pages you've visited inside of the Facebook container. Otherwise, clicking on a share link from Facebook (with, e.g., a unique query parameter) would allow Facebook to correlate their CNN.com facebook cookie with their Facebook.com cookie, getting (retroactive) access to all of your CNN history. So maybe that's one reason to continue to use Facebook Container
- GRBurst 4y agoVery cool to see more privacy by default in Firefox. It is still a lot of effort to have clear separations in every browsern... I am using Firefox containers with the temporary containers plugins (with history deletion enabled) as well as cookies auto delete plugin (which supports containers). Therefore, everything is usually isolated in a container inside a tab and only white listed cookies are kept in the named containers.
- bitwrangler 4y agoIt would be nice to allow users to create "trusted tuples" to list small groups of domains that are allowed to share their cookies. For instance: Zendesk, Asana, Jira, etc. But have each tuple listed still be isolated from the other, only domains listed together in a single list could share a cookie container.
- InCityDreams 4y ago...as opposed to 'nested tuplets'? /fz
- laerus 4y agoProbably that is the use-case for the official multi-account containers plugin.
- TheNewsIsHere 4y agoI tend to agree, but as someone who uses this plugin a LOT, I have some complaints. If I decide I want, say, an Azure Portal container then I cannot have login.microsoftonline.com assigned to a different container -and- configured to automatically open in that container. If I do that, I need to have a combined Azure + Office 365 + anything-I-need-to-authenticate-to-Azure-AD-for container. It’s a good solution but with its lack of flexibility I find it’s too far in the direction of security versus convenience.
- bitwrangler 4y agoI use multi-account containers too, and I like it. This is exactly my point, instead of mapping each domain into a single container, any domain could exist in one or more "trusted tuples" Maybe another way to think of it is like a one-to-many join. A domain would not "belong" to a single container, but have tags to associate with 1+ containers.
- zagrebian 4y ago> small groups of domains that are allowed to share their cookies Could you explain how this could be beneficial to the user?
- DoubleGlazing 4y agoI know Firefox has a small market share, but this is the sort of feature other browsers may adopt. Maybe not the big boys like Chrome or Edge, but I could see all the niche privacy focused browsers implementing it and maybe even Safari given Apples claims to support user privacy. If a certain percentage of browsers started to use similar functionality I could tracking companies starting to develop countermeasures. In fact I've already encountered one site that gave me a popup telling me to enable third party cookies. It was one of those dodgy sites that scrapes and copies Stack Overflow content and the JavaScript that enabled it was very clunky - but it worked. I'm surprised there aren't more websites already doing something similar.
- alasdair_ 4y ago> Maybe not the big boys like Chrome or Edge Firefox has essentially the same market share as Edge.
- soundnote 4y agoSafari and Brave have been doing it already. Notice Mozilla's wording: "MAJOR browser available on Windows, Mac and Linux" to exclude the competition that got storage partitioning shipped before Mozilla did.
- deleted 4y ago[deleted]
- dizhn 4y agoWhen Mozilla comes out with a feature like this it usually whitelists google, microsoft and similar big sites so people can still log in across their network. Anybody know the current list for this feature?
- wisniewskit 4y agoYes, you can follow the meta-bug here to see the current issues we're working on resolving in a better way: https://bugzilla.mozilla.org/show_bug.cgi?id=1537702 https://bugzilla.mozilla.org/show_bug.cgi?id=1537702 Perhaps unsurprisingly, Microsoft logins are the most glaring exceptions right now (Teams, Logins, Office, Live), and we're working with MS to see if we can find an acceptable fix (or work-around while it's fixed). There are also exceptions for github.dev and history.com right now. It's worth mentioning that these aren't simply exceptions which blanket enable tracking for those sites, it's just to work around specific breakage. We're also working around some other specific site logins or features breaking, which would not break if sites called the new requestStorageAccess API appropritately. We're using SmartBlock to shim those cases until the sites can fix it themselves.
- daveoc64 4y agoWhat is the "better way" here? There is a legitimate use case for having login/identity stuff on a different domain - many of the largest companies in the world are doing this. How can this issue be solved without either confusing users through the requestStorageAccess API, or forcing everyone to use a single domain for everything?
- wisniewskit 4y agoRight, Total Cookie Protection has been baking for a while to try to minimize that kind of breakage, and we're already in discussions with other browser vendors and companies to get everyone onboard on the Privacy CG. In a nutshell, adding new case-specific web APIs seems to be the likely way forward here. There are proposals floating around like an "is logged in" API, the Federated Credential Management API, and so on. I'm not sure there's ever going to be a perfect solution for everything, but I would certainly rather have users more informed and empowered about their privacy than they currently are (even if some folks prefer to just "allow all"). I guess we'll just have to wait and see which proposals win out, and in the meantime rely on heuristic-based solutions like Total Cookie Protection to iteratively get us to a better place.
- dahart 4y agoWhen will the browsers take care of handling the cookie options for all the sites, so I can declare my preferences once and everyone stops putting up a popup? Surely this is already in the works?
- 6510 4y agoRight, the consent window should have been a browser thing so that it is always the same and so that it follows the laws and cant involve dark patterns. By reading this message you agree with it.
- fleddr 4y agoThe answer is similar to the DNT (do not track) debacle. When you give users a clear, informed, singular choice that would be sticky across their entire web/app experience, the choice in itself essentially becomes obsolete. Since pretty much nobody opts-in. You saw the effect with Apple's new "do you want to be tracked" permission, which has a disastrous impact on Facebook. Consider that this is still a per-app permission, imagine the impact when its a single permission across all apps. As users we may say "good" and "this is what we want", but I don't think we can truly oversee what impact that would have.
- 6510 4y agoFacebook neither needs or deserves my pity. If person A wants to do something to B that we can assume B does not approve of then A can ask if its okay. If A would never approve it doesn't magically become okay to do it. The thing could only happen if A has authority over B. As FB is not ur mum, not the government and not your employer they should ask the question or shut up.
- hestefisk 4y agoWould love for Safari / iOS to follow suit.
- samstave 4y agoUIs there a dashboard of somesort where I can see all the tracking/cookies bullshit affecting me?
- eslaught 4y agoHow is this different from the old privacy.firstparty.isolate, and do I still need that/should I keep that enabled?
- kuon 4y agoI've been blocking cookies actively for a long time, and except some technical embeds (for example STEP file viewer on misumi) I had zero issue. This is great news. I really hope we will not lose firefox. I'm not saying it is better than chromium, but I think it is important that it exists.
- qxxx 4y agoplease someone fix the internet... I don't want to see any cookie popups on each site and accept / decline each cooke first only so I can see the content I want. I don't care about all these cookies and this should be managed by a browser. I hope what Firefox did is the beginning of such a fix.
- neop1x 4y agoYes. Browsers should be required to show a cookie settings dialog once and then send the selected answer to all websites in a header. And websites should be required to read the header and behave according to it. The problem would be solved quickly that way...
- grishka 4y agoWhy not abolish third-party cookies altogether? There are very few good uses for them.
- exyi 4y agoYou can turn them off. However, most single-sign-on stuff will break without them :/ (at least MS accounts just don't work)
- grishka 4y agoSingle-sign-on stuff can be fixed by redirecting through the authenticator domain and passing the token or whatever back as a url parameter. > You can turn them off. Of course I did, long ago. The issue is that they're on by default. And defaults matter a lot because most people don't change them.
- exyi 4y agoThat would have to get fixed by the corporate maintaining that SSO. I even tried whitelisting domains, but it's also PITA since MS redirects you through 10 domains or so. Now I'm using cookie autoeater almost everywhere... so feel free to save your cookies, as soon as I close the tab they are all gone. I have to login every time, but saved passwords solve it reasonably well.
- celestialcheese 4y agoChrome has on the roadmap to do exactly this. [1] Turns out, Getting rid of 3rd party cookies concentrates power in the ad world in the hands of those with the most 1st party data (and active session cookies). Google, Facebook, Amazon and Apple. [2] The tracking debate is contentious and has a lot of folks on here who are privacy maximalists, and I'm not trying to debate the ethics of ads. But in terms of utility, 3rd party cookies are the backbone of ad-tech auctions and targeting, and currently give the non-Goog/FB/Amazon ad providers a way to compete on performance advertising. Digital ad markets are expected to be nearly $565b this year, and the Tri-opoly of Google/FB/Amazon have 68% of the market. 32% of the market depends on 3rd party cookies to have a chance at competing. [3] 1 - https://privacysandbox.com/intl/en_us/open-web/#how-works-on-web-hero https://privacysandbox.com/intl/en_us/open-web/#how-works-on... 2 - https://www.siliconrepublic.com/business/googles-privacy-sandbox-third-party-cookies-removal-uk https://www.siliconrepublic.com/business/googles-privacy-san... 3 - https://www.emarketer.com/content/google-facebook-amazon-account-over-70-of-us-digital-ad-spending https://www.emarketer.com/content/google-facebook-amazon-acc...
- Animats 4y agoI've had third party cookies blocked for ten years. Some sites don't work. I don't use those sites.
- bombcar 4y agoWhat has become very annoying is so many sites are using "third party cookies" for whatever asinine "single sign on" product they've been sold. The number of redirects my browser undergoes when I log into my health insurance portal is mind boggling.
- apeace 4y agoMaybe I am getting this wrong, but I think the reason you're being redirected through so many sites is because they're not using third-party cookies. They have to redirect you through each domain so that they can all set their own first-party cookies.
- xtat 4y agoCool but this product naming sounds like some scummy antivirus from 2001
- olliej 4y agoOk, is this just a more complicated (and less private) version of the 3rd party cookie blocking that’s been in safari for more than 15 years? If it is better - which seems surprising given it still seems to result in 3rd party cookies continuing to exist - how does it compare to safari’s domain partitioning from what seems like 5 years back, or the newer aayyyy iiiii tracker detecting stuff?
- deleted 4y ago[deleted]
- steren 4y agoCan someone help me understand how this is different from blocking third party cookies?