4 ms·
Standard, Strict or Custom? Strict should block that one for sure, will check once at home.
by Topfi 2mo ago
Standard, Strict or Custom? Strict should block that one for sure, will check once at home.
- traceroute66 2mo agoI just double checked `about:preferences#privacy` is "Enhanced Tracking Protection: Strict" and clicking "Advanced Settings" confirms the radio button is indeed under "Strict". Firefox 153.0.4
- Topfi 2mo agoJust saw the edit, all clicked now. As described this is expected behavior. The entitieslist (can't link right now because Github is down but got a local copy for some experiments) contains exceptions for owners of tracking URLs, in this case as a resource for Cloudflare.com and others owned by them only. Basically, because they are the same entity, they are considered one. Whether that could be communicated better by upstream, that's worth a discussion. Anyone besides Cloudflare.com has cloudflareinsights blocked. Here the specific entry for context from my local copy of ESR 153: { "entities": { "Cloudflare": { "properties": [ "cloudflare-quic.com", "cloudflare.com", "cloudflare.tv", "cloudflarestatus.com", "cloudflareworkers.com" ], "resources": [ "cloudflare.com", "cloudflareinsights.com", "cloudflarestream.com" ] } } } On a side note, spent a while learning how upstream Firefox works in-depth over the last few months, if ETP didn't block cloudflareinsights on pages outside Cloudflare.com I'd have lost any confidence build up and my project would likely linger even longer. Might just add a setting that totally excludes such exceptions if I can properly test it before release, seems there might be demand. Admittedly more for UX and honest communication clarity reasons (top setting truly prevents everything) then privacy, not the main goal of Hominis as a project.
- traceroute66 2mo agoYeah, I was trying to get hold of the list from Github myself before posting the edit. It is unfortunate strict isn't truly strict, but at least now I know. Thanks for that. Pending Github fixing itself, could you confirm if `browser.events.data.microsoft.com` is on your local copy ?
- Topfi 2mo agoYeah, agree, purely from a user expectation perspective, strict sounds like it'd suppress everything, not just third-party, especially with lower compatibility turned on. Yeah "browser.events.data.microsoft.com" is in, but mainly because it just ends up under microsoft.com anyways, subdomains are accepted inside the entitieslist. Here the full copy (initially wanted to share via Pastebin but some links triggered a spam filter): https://cdn.jsdelivr.net/gh/mozilla-services/shavar-prod-lists@e3dc3016f654286992ad51275585580e748bd379/disconnect-entitylist.json https://cdn.jsdelivr.net/gh/mozilla-services/shavar-prod-lis... If you or anyone else reading is interested, Mozilla has written some pleasant docs, lots to learn, easy to understand, comprehensive. Could not even consider what I am attempting without the resources they've provided: https://firefox-source-docs.mozilla.org/toolkit/components/antitracking/anti-tracking/tracking-lists/index.html https://firefox-source-docs.mozilla.org/toolkit/components/a...