7 ms·
Firefox also plans to have builtin support for auto-rejecting cookies when there is a consent banner. See https://bugzilla.mozilla.org/show_bug.cgi?id=1783015 h
by vbernat 4y ago
Firefox also plans to have builtin support for auto-rejecting cookies when there is a consent banner. See https://bugzilla.mozilla.org/show_bug.cgi?id=1783015 https://bugzilla.mozilla.org/show_bug.cgi?id=1783015. From my understanding, this should be similar to Consent-O-Matic. It will be available on both desktop and mobile versions. This is enabled recently by default in Nightly (but I don't use Nightly).
- Danieltchi 4y agoI want to use your comment to outline a broader criticism of what Brave is about nowadays. In this case, it should be obvious that even Firefox is more innovative than Brave - Firefox plans to auto-reject based on intelligent patterns. This should, if done right, take care of almost all cookie prompts, especially if they also add a filterlist. Brave has been in the business of blocking ads for a long time. Surprisingly it took them years to come up with cookie banner blocking, even though all they do is include a list maintained for free by easylist maintainers. This could have been implemented already 2 years ago without much effort. What's going on at Brave? Is everyone busy with crypto-stuff? Brave should work on detecting cookie-banners, even if they are not blocked by some list. The Brave Browser looks like they abandoned many important things because they are focusing on crypto - the UI is very basic, the customization is not better than Chrome, and due to the addition of many optional features, some users have reported the browser slowing down significantly. Maybe they should offer different installers for different audiences. People have asked about new-tab page customization for a long time. People have asked to have the uBO-functionality ported to the built-in Brave Shields, including cosmetic filtering, and granular control. People have asked for Brave to not activate the new-tab background sponsored images by default, which is in conflict with their user-first ideology. The VPN ad for guardianapp on iOS is too prominent and shows that they try to push it to increase revenue. If Brendan Eich is worried about ROI, he should start putting contextual ads on his search engine, instead of focusing on in-browser ads.
- rat9988 4y agoI'm not sure why you think firefox solution is better (it seems worse) nor why you think highly of firefox in this case, or at least higher than brave.
- smoldesu 4y agoFirefox at least develops their own browser engine.
- forgotpwd16 4y agoHow is this relevant to the topic at hand?
- smoldesu 4y agoThey're asking why people think highly of Firefox when compared to Brave, I'm giving them an answer.
- MichaelCollins 4y ago> "nor why you think highly of firefox in this case" Emphasis added. They're asking in the context of cookie banner blocking. You didn't answer the question rat asked.
- smoldesu 4y agoOh, I thought they were already aware that Firefox had cookie banner blocking too. My bad.
- deleted 4y ago[deleted]
- antonok 4y agoI can give some context here (I work on Brave's adblock engine). > Brave has been in the business of blocking ads for a long time. Surprisingly it took them years to come up with cookie banner blocking, even though all they do is include a list maintained for free by easylist maintainers. Brave has been sponsoring Fanboy's work as an Easylist maintainer since early 2019 via an employment contract. This "list maintained for free" you're talking about was originally "Fanboy's Cookie List" and was promoted into Easylist as of November 2019 [1]. > This could have been implemented already 2 years ago without much effort. Indeed, it was available through the brave://adblock settings menu 2 years ago. Building a new filter list is really difficult though - not only do you have to cover enough websites for it to be useful, but you have to make sure that important functionality doesn't break when it's applied. Multiply that by approximately every website on the internet and you'll have some idea of how difficult it is. The list is finally comprehensive enough to be rolled out to a much wider audience - which is exactly what we're doing. > People have asked to have the uBO-functionality ported to the built-in Brave Shields, including cosmetic filtering, and granular control. Not sure what you are referring to here, but we do have cosmetic filtering and the ability to add custom filters or subscribe to anyone else's list with auto-updates. Procedural filtering is the main missing feature, but I'm actively working on that. [1]: https://github.com/easylist/easylist/commit/f479000932294df083fd5bde832bd03b7fd7176a https://github.com/easylist/easylist/commit/f479000932294df0...
- morelisp 4y ago> you have to make sure that important functionality doesn't break when it's applied. This feels unnecessarily conservative for a browser trying to achieve literally any market share; nobody's got only Brave installed and those who have it at all are those most likely to understand if a site is broken because of its blocking measures. If Brave isn't going to be the one to push privacy features over compatibility, who is? I mean, you didn't name it "Caution".
- antonok 4y agoWe generally try to expose these kinds of things for the more technical users who are interested in finding them - again, the cookie list has been available in brave://adblock for years now, we have "aggressive" blocking mode, "strict" fingerprinting protection mode, etc. But ultimately we want to change the standards of privacy on the web for everyone, not just those who can tolerate frequent breakage (or those who will switch to a less private browser when something isn't working). Honestly, building any browser software that relies on filter lists takes some appetite for risk. By definition, the lists are reactive and so there's always going to be a gap in compatibility in sites which have updated recently enough.
- MichaelCollins 4y ago> In this case, it should be obvious that even Firefox is more innovative than Brave - Firefox plans to auto-reject based on intelligent patterns. Was Firefox's plan publicly documented before Brave's feature was publicly announced? I heard about them in the opposite order; Brave first. It seems to me that Firefox is reacting, not innovating. FWIW since these conversations are often tribal, I use Firefox.
- BrendanEich 4y agoI see haters in the surrounding replies and agree on tribal aspect, so to defuse that, I'll say Firefox is doing something interesting and different from what we're shipping. It is worth having browsers try different approaches, no matter who is "first" (Brave likely will be, for stable release channel distribution). It seems Firefox’s cookie consent blocker automates clicking Reject after letting consent-management-provider(CMP)-scripts load. https://searchfox.org/mozilla-central/source/toolkit/components/cookiebanners https://searchfox.org/mozilla-central/source/toolkit/compone... (shared above already) It looks like the code also injects opt-out cookies too, may sometimes do both click and cookie injection. Session cookie, so has to inject recurrently. The Brave approach blocks the CMP scripts that pose these bono-consent dialogs in the first place. One reason we favor this approach beyond simplicity: many consent frameworks, besides being found illegal already in EU courts (going to top court soon), do dark deeds: extort from publishers, lie to and track users no matter what the user clicks. See https://twitter.com/nataliabielova/status/1570385096259108866 https://twitter.com/nataliabielova/status/157038509625910886...
- forgotpwd16 4y ago>plans to auto-reject based on intelligent patterns Not sure what you mean with that. Checking code[1] it apparently uses a rules list (can be found in [1]) to function on site-by-site basis. This is the same approach utilized by popular "I don't care about cookies" add-on. [0]: https://searchfox.org/mozilla-central/source/toolkit/components/cookiebanners https://searchfox.org/mozilla-central/source/toolkit/compone... [1]: https://github.com/mozilla/cookie-banner-rules-list https://github.com/mozilla/cookie-banner-rules-list
- stoicjumbotron 4y agoHighly OT, but is there any glaring difference between FF Dev edition and the stable version? AFAIK, all the devtool features are same in both the versions and I did not find any glaring difference as such.
- Jap2-0 4y agoDev edition is the same as beta, except occasionally (not often, as far as I can tell) some features in development are enabled slightly earlier. In other words: it's beta but with different branding.
- paulryanrogers 4y agoDev edition also makes it easier to run both Firefox stable and a non-stable install since they default to separate profile folders.
- denton-scratch 4y agoI'm increasingly encountering banners that (a) get past my banner-blocker, and (b) pop up a sequence of different banners; i.e. I dismiss the first banner (accept, reject, doesn't matter because I use cookie controls); and another one pops up - sometimes waiting for me to scroll 10% or so of the way through the article before it appears. I think they believe that "human interaction" (like a click) somehow gets them around browser protections. I think they are wrong, at least as far as my browser (Firefox) is concerned.
- rollcat 4y agoIt's an arms race, it has always been. Companies will continue squeezing as hard as is legally allowed, browser extensions will be effective until they gain adoption and get actively countered. Legislation seems somewhat effective, but many websites purposefully won't adjust to comply, just to see if the law will actually be enforced. Cookies and JavaScript were a mistake.
- denton-scratch 4y agoSome of the worst offenders are mainstream news sites. They know that most of their website readers haven't paid; I'm sure there are managers who want to extract money from those web visitors. But monetizing web-visitors promises diminishing returns - the harder you try to force visitors to cough up, the more they'll stay away from your site. If I see an interesting-looking link from washpo, for example, I'll usually walk by, and find the story elsewhere, rather than paste it into archive.ph. I'm simply not going to subscribe to every site that asks me to; I visit about 30 sites a day. I'm a pensioner, and I'd go broke. I understand the "cookies and javascript were a mistake" posture; mostly they're useless to me. There is a handful of sites that are useful, but are completely dependent on Javascript. And anywhere that you have to login to, you need something equivalent to cookies (like, my bank). I block ads because - well, I don't consume food that I picked up off the footway. They run scripts in iFrames, they auto-run videos, they try to set cookies, I don't know what they do. I don't know where the site sourced its ads. Perhaps they want to use my computing equipment to mine bitcoin for them, or try to actually take over my network. Ad-blockers work fine (unless they have a pay-to-play whitelist). Cookie management is more problematic, because (a) the variety of different kinds of cookies, (b) the fact that most users don't really understand the different ways cookies are used, and (c) the lack of clarity and granularity in cookie controls. Users can't exercise informed consent unless they can understand the information.
- account42 4y agoWill Firefox also apply that same auto-rejecting logic to their own telemetry?