5 ms·
Firefox rolls out Total Cookie Protection by default to more users (2022)
- dustypotato 2y agoThis is so cool. Makes me wonder why it hadn't been done already. Side note: Could have used something else other than the TCP abbreviation probably, but who cares
- drpossum 2y agoThere are still sites out there that require third party cookies to function and it was only in the last few years you could consider getting away with this and not breaking a ton of sites.
- red_trumpet 2y agoNot sure I get your point. Total Cookie Protection doesn't get rid of third party cookies.
- drpossum 2y agoConsider a third-party cookie login flow where you go to one site to enter your password different from the site you are logging into. The password site sets a cookie which the site you are logging into will use to determine if your password was correct or not. If I follow TPC, this pattern would break because that cookie is now isolated from the site which wants it. This used to be somewhat common. It is not anymore recently.
- andrewaylett 2y agoIt was never great, but Safari's anti-tracking was probably what killed it, rather than anything Firefox does. Safari was certainly the driver of significant similar changes in projects I've worked with. My recollection is that Firefox has exclusions for requests to third parties where that third-party just redirected the user to the site, in order to allow the login flow you wrote about. Don't ask me for a cite, though. Safari, on the other hand, will (or at one point would) block requests to domains if it's seen more than one domain making third-party requests to that domain and it's not been visited as a first-party.
- rdimartino 2y agoThis is great. I’ve been using multi-account containers for years and have loved the isolation. But I wonder how Total Cookie Protection works with different auth flows, like logging in to Trello using an Atlassian domain. Maybe it’s unaffected; I haven’t really looked at how/if cookies are involved in that process, but I can imagine TCP causing some frustration for users. Definitely will give it a shot, though.
- codedokode 2y agoI think third-party cookies should be disabled out of the box but there should be an option to manually allow them for legacy applications (if there are popular legacy applications then Firefox could include some of them by default).
- dylan604 2y agoUsing what, the legacy app flag?
- KennyBlanken 2y agoWhich of course wouldn't be abused. Either set willy-nilly, or companies purposefully implementing broken methods to get an exemption so their tracking cookies work /s
- beej71 2y agoLocal domain whitelist? Would that work?
- dylan604 2y agoCreated by the user? Like, who's going to go out of their way to create a whitelist of associated websites so it's okay to share across those sites? So, I'm totally on board for this! The only other thing would be to just not let cross domain sharing. at. all.
- dylan604 2y ago
- hk1337 2y agoIt would be nice if this were more obvious to a user without having to read a blog post saying it's doing this. Example: In Safari private mode, I can open up Facebook and login, then if I open up a new tab or window and try to go to Facebook it's going to prompt me to login.
- Vinnl 2y agoAFAIK in Firefox you should stay logged in in that case. It's just that if you then visit someothersite.com and that has a Facebook widget embedded, that you'll appear logged out of Facebook there.
- hk1337 2y agoThat's good. I didn't mean to hint that it wasn't working just that I wish it were more obvious to the user. Logged in vs Not Logged in on a Facebook widget is not that obvious.
- simonw 2y agoThis is from 2022. I learned recently from a Mozilla engineer that Firefox never made samesite=lax the default for cookies set without the samesite= attribute - they went with this Total Cookie Protection strategy instead: https://lobste.rs/s/98rp8f/cors_is_stupid#c_9dtjao https://lobste.rs/s/98rp8f/cors_is_stupid#c_9dtjao Here’s my exploration of samesite from a few years ago: https://simonwillison.net/2021/Aug/3/samesite/ https://simonwillison.net/2021/Aug/3/samesite/ As before, my frustration with this kind of browser feature is the lack of detailed technical documentation. As a web developer, what does Total Cookie Protection mean for how I build web applications at the nuts and bolts level? Show me some set-cookie examples that previously would have behaved differently and explain those differences.
- ryu2k2 2y agoHonestly, I barely understand how Firefox's cookie protection works anymore. It used to have the simple option to block third party cookies that I had running all day and felt good with. That was until they started becoming necessary in certain scenarios (I can't even remember the details of what that was). And then these days I have no idea if I can just accept a website's advertising cookies and expect Firefox to block them anyways, or if clicking on such a button would disable the browser's tracking protection.
- andrewmcwatters 2y agoThe most common scenario I can think of is needing to login through a third-party gateway on a first-party site. This is now broken with mainstream browsers, and you need to find another way to do the same thing. I'm not sure what people are doing now, because you can't retain state. I had my clients just enable it on the browser.
- immibis 2y agoOAuth. You open the login page in a new window with a callback URL. The third party service adds a token to the callback URL, which authorizes you to retrieve the real auth token from that service.
- deleted 2y ago[deleted]
- andrewmcwatters 2y agoI've never seen OAuth replace the scenario of a first-party site allowing user generated content that can embed a third-party site authentication flow. Are people using OAuth for that? I've only ever seen it for explicitly supported authentication flows by the first-party site.
- moi2388 2y agoThe flow is supported by the first party, but the login goes through a third party gateway which sends a token to the callback uri. I think the previous poster was responding to this: “I'm not sure what people are doing now, because you can't retain state.” They do OAuth.
- Vinnl 2y agoFor clarity, I think this was posted because it was just updated. I think just the following was added: > And starting in 2024, all our users can look forward to Firefox blocking even more third party cookies. That’s right; we are taking big swings to adopt new cookie partitioning and clearing mechanisms so that users can browse with fewer cookies that won’t stick around as long and will result in an even better browsing experience. Just another step on our road towards creating a better internet where your privacy is not optional.
- ThinkingGuy 2y agoDoesn't everyone set Firefox to delete cookies at shutdown? (with exceptions for a small number of frequently-used trusted sites)
- bonestamp2 2y agoThis would be useful if I closed my browser regularly, but I haven't closed my browser in months.
- SoftTalker 2y agoI shut my computer down to a cold power-off every night, or whenever it goes into my shoulder bag (laptop).
- deleted 2y ago[deleted]
- ChrisArchitect 2y agoIt says Updated Aug. 28, 2024 - what is the update? That they're expanding the deprecation of third-party cookies that they blogged about in December? Edit: yes, looks like that last paragraph is the addition
- k8sToGo 2y agoI switched from long time chrome using to Firefox 2 weeks ago. I also installed the android app. It seems rather slow and the android app is horribly buggy. I gave up and switched to Brave. Now Brave on Android isn't great either but it works. I don't quite understand the appeal of Firefox other than it maybe having the same appeal as Linux Desktop or LibreOffice(being free and an open alternative).
- tedivm 2y agoI'm curious what extensions you installed and what your hardware looks like. I've found firefox to be faster than chrome, but I know others have run into issues like you describe.
- k8sToGo 2y agoI should probably say that performance was certainly not the number one reason, as benchmark numbers are irrelevant for human users, but I was running it on M3 Pro MacBook Pro and on Galaxy S24+ each with ublock origin and dark reader.
- Loughla 2y agoWhat do you use for hardware and extensions? I'm currently using Firefox on Android, and have for years and years, and have never found a bug.
- k8sToGo 2y agoFirefox on Android to this day does not switch to dark mode automatically https://github.com/mozilla-mobile/fenix/issues/27568 https://github.com/mozilla-mobile/fenix/issues/27568 https://bugzilla.mozilla.org/show_bug.cgi?id=1813529 https://bugzilla.mozilla.org/show_bug.cgi?id=1813529
- mrguyorama 2y agoI have used Firefox on android since 2018. I have never encountered a bug. Not a UI hiccup, not something doing something unexpected, not slowdowns, not crashing, not anything. I routinely open links in the default android browser (chrome now), and it literally crumbles under the weight of ads in your average article, and then open it in firefox and uBlock means it runs great and any issue I was having disappears. >I don't quite understand the appeal of Firefox It's not chromium based, so Google can't force it to grow in the direction that only benefits their infrastructure like they do so much with chrome, and uBlock is a strictly better ad blocking system than anything I have ever used. I don't think Brave is independent, as they are beholden to the Chrome team's architectural decisions and design goals. It attempts to send less tracking information to people tracking me (with a caveat that Mozilla themselves do a little first party tracking and advertising, which I consider morally less wrong than Google's entire business), and is not incentivized to make the web a worse place for the sole purpose of increasing Google's share price.