8 ms·
Mozilla anti-cookie tool plans crumbling
- IBM 13y agoVery disappointing.
- tareqak 13y agoI tried searching for the patch in question, and here is what I came up with: Searching for Jonathan Mayer in Bugzilla https://encrypted.google.com/search?sitesearch=bugzilla.mozilla.org&q=jonathan+mayer https://encrypted.google.com/search?sitesearch=bugzilla.mozi... Here is the meta bug: https://bugzilla.mozilla.org/show_bug.cgi?id=818337 https://bugzilla.mozilla.org/show_bug.cgi?id=818337 I think this is the patch: https://bugzilla.mozilla.org/show_bug.cgi?id=818340 https://bugzilla.mozilla.org/show_bug.cgi?id=818340
- kibwen 13y agoI think that Mozilla's recent re-launch of Lightbeam (nee Collusion) shows that they're not trying to back away from the issue of third-party cookies. The complication is that you need to find a solution that doesn't break enough sites that users give up and switch to less-privacy-conscious browsers, which would completely defeat the purpose.
- interpol_p 13y agoHow does it break sites? I use Safari, where this setting is the default, and everything seems Ok.
- gcb0 13y agosafari use case means nothing. it is disabled only if the 1st class site does not set a cookie or something futile like this. you probably have 3rd party cookie working as usual.
- deleted 13y ago[deleted]
- nly 13y agoGoogle will never deprecate 3rd party cookies, and without cross-vendor support Mozilla will be attacked when sites start breaking. It's a real shame, I've been blocking all 3rd party cookies and referrers for years and really want to see the web to a more privacy concious model. With all the web features tracking tricks out there now though, I feel it's nigh impossible. Take for instance, common Javascript libraries hosted on CDNs. Every time you visit a jQuery based page where the js file is on a CDN you reveal to the host of that CDN (e.g. Google) what website you're on. You also put complete faith in that 3rd party CDN provider for your security. 3rd party cookies are just the tip of the iceberg in terms of how broken the web is for the privacy concious.
- yeukhon 13y agoThe real deal is to find a way that user and business can both gain something. And this is hard.
- nly 13y agoThat's easy. Just ask me (the user) for permission and explain why you would like to do so. If your users don't like it then maybe you shouldn't be doing it. On the server side, companies are bound by data protection laws. Using the browser as a loop-hole for profit is not acceptable. Instead we get these absurd EU 'this site uses cookies' banners that do less than nothing for user privacy.
- Silhouette 13y agoJust ask me (the user) for permission and explain why you would like to do so. Unfortunately, it's not that simple. From a user's point of view, asking questions that interrupt their browsing experience on every other site is usually unwelcome. The "We use cookies (like everyone else in the known universe)" messages in Europe that you mentioned are a great example, where good intentions ran headlong into practical limitations and the result was something that no-one actually likes. From a business point of view, that same poor experience is a negative because it makes your site less attractive to visitors and ultimately hurts conversion. This remains true even if you're doing something reasonable with innocent intentions that almost all of your visitors would actually be happy for you to do. I am very much in favour of protecting privacy on the Web and letting users make informed choices about when they are willing to give it up in return for something they value, but I don't see this working in practice until we have some sort of mandatory (with force of law) standards for disclosure by site operators that allow browsers to offer standardised preferences to their users that can be set once and then safely forgotten about. I think we need some sort of standardised, automation-friendly privacy policies, like the credit agreements where providers are required to provide key information up front in a standard format with the same assumptions for everyone, or the way a few open source licence agreements have become established and much of the time both the licensor and the licensee can just say "GPLv2" or "BSD" and everyone knows the deal. Unfortunately, the wheels of standards turn slowly, the wheels of law more so, and the wheels of laws respected across borders even more so. Meanwhile, the wheels of businesses funded by invading privacy or otherwise exploiting users via modern technologies tend to turn very fast. I'm not sure how we fix this problem as long as the politicians are as technically illiterate and generally open to manipulation by special interest groups as they obviously are in many first world countries today.
- bolder88 13y agoGood. This recent war against cookies is futile and silly. If you visit a website (Assuming you don't go via some anonymizer proxy), they can track you, and they can pass your details to any 3rd party who wishes to also track you. Cookies are the easiest way for them to do that, but its absurdly naive to think that if you block cookies then people won't track your browser activity online. If you don't want to be 'tracked', stop generating HTTP requests, or do them through an anonymizer service. And good luck getting any website to work properly.
- icebraining 13y agoA single website can only track you inside their own pages. The problem with third-party cookies is that they enable cross-site tracking, which is much more privacy invading. First-party cookies don't help with that, since a cookie dropped by siteA won't be sent to siteB. Now, sure there are other ways of doing cross-site tracking, like Etags, fingerprinting and such, but why shouldn't we try to plug those leaks too instead of giving up?
- bolder88 13y agoNo, we shouldn't bother trying to plug those leaks. Current situation: * You request website A, which includes 3rd party code from C. C drops a cookie * You request website B, which includes 3rd party code from C. C knows you previously visited A. New situation: * You request website A, which includes 3rd party code from C. Website A sends details of your visit via a backchannel to C. * You request website B, which includes 3rd party code from C. Websites B sends details of your visit via backchannels, and C knows you previously visited A. Wouldn't you rather such tracking to be out in the open and easily blocked - stop accepting cookies, rather than them creating backchannels to track you instead? Yes - You should give up if you think you will able to continue sending websites HTTP requests directly, whilst not being tracked.
- jrochkind1 13y agoI'm not sure. Those backchannels would be enormously more expensive and technically challenging for the commercial entities to do right. So, yeah, I see your point, but maybe I _would_ rather make it much more expensive to do that, and much harder for them to do it succesfully rather than messing up a technical detail. On the other hand, I guess eventually they'd get it right in commodity software that everyone can use. Eventually. Really, I don't know why anyone that wants to do the kind of tracking we're talking about is using cookies anyway, instead of user-agent fingerprints that have been shown to be pretty much unique anyway. So the cookies is perhaps all a distraction. The browser makers don't need to invent a new cookie-less browser fingerprint tracking system, they've already got it with the over-specialized user-agents.
- r0h1n 13y agoPrivacy on the Internet today is so riddled with conflicts of interests and doublespeak that it's hard to know where anyone stands on anything. Microsoft implemented a Do-Not-Track by default in IE 10 [0], only to later reveal it was planning an even more intrusive ad tracking system of its own [1] Google added a Do-Not-Track feature belatedly to Chrome, buried within levels of settings and warnings [2]. And yeah, they're working on their own cookie replacement too [3]. Facebook meanwhile is tracking you across the web through its own re-targeting tech [4] and even your cursor movements on its site [5] In fact, when companies like Google, Facebook and Microsoft want to dump cookies [6], I'd argue that we're already past the point where a Firefox can make a difference. IMHO Internet tracking has become like fast food. A meaningful difference will only come when average users start caring about their privacy and are willing to make conscious choices for it. [0] - http://arstechnica.com/information-technology/2012/08/microsoft-sticks-to-its-guns-keeps-do-not-track-on-by-default-in-ie10/ http://arstechnica.com/information-technology/2012/08/micros... [1] - http://adage.com/article/digital/microsoft-cookie-replacement-span-desktop-mobile-xbox/244638/ http://adage.com/article/digital/microsoft-cookie-replacemen... [2] http://www.pcmag.com/article2/0,2817,2411916,00.asp http://www.pcmag.com/article2/0,2817,2411916,00.asp [3] http://www.usatoday.com/story/tech/2013/09/17/google-cookies-advertising/2823183/ http://www.usatoday.com/story/tech/2013/09/17/google-cookies... [4] - http://adage.com/article/digital/facebook-launches-retargeting-alternative-fbx/244746/ http://adage.com/article/digital/facebook-launches-retargeti... [5] - http://www.pcmag.com/article2/0,2817,2426602,00.asp http://www.pcmag.com/article2/0,2817,2426602,00.asp [6] - http://online.wsj.com/news/articles/SB10001424052702304682504579157780178992984 http://online.wsj.com/news/articles/SB1000142405270230468250...
- mildtrepidation 13y agoIMHO Internet tracking has become like fast food. A meaningful difference will only come when average users start caring about their privacy and are willing to make conscious choices for it. Definitely agreed. Unfortunately, I think it's much harder for your average web user to make that choice than for your average person to avoid fast food: Everyone knows what and where a grocery store is and that fast food is not usually nutritious, but I don't believe most web users understand how many browser options there are or, in many cases, what that actually means or what other means could help preserve their privacy, if they understand this particular privacy issue in the first place.
- wnevets 13y agoDoesn't Apple already do this?
- ploxiln 13y agoYes, unless you manage to do a form post in an iframe or something like that... which every web developer does to "make it work" in safari http://www.electronista.com/articles/12/02/16/google.alleged.in.safari.privacy.circumvention/ http://www.electronista.com/articles/12/02/16/google.alleged...
- fletchowns 13y agoYea I think by default Safari blocks third party cookies. I don't use Safari but I remember having to work on a bug somebody was having and that ended up being the cause. Same behavior on Mobile Safari too I believe.
- ihsw 13y ago> "This default setting would be a nuclear first strike against (the) ad industry," tweeted Mike Zaneis, general counsel for the Interactive Advertising Bureau. Such dramatic silliness. An actual first stirke would be NoScript and AdBlock installed by default (which I already do to begin with). Removing third-party cookie functionality is just a shot across the bow.
- flagnog 13y agoIf ONLY there were an open source browser that we could modify to disallow the tracking technologies...
- snorkel 13y agoI feel most users got over the creep factor of cookies back in 1998, and nothing that happened since has demonstrated that cookies need to be severely restricted. In fact, I expect more physical businesses will be installing face recognition to essentially cookie and track casual shoppers in a real stores offline, consumers are already used to this online, and don't feel threatened by it.
- gcb0 13y agoPretty sure if that happens a few malls would advertise privacy, charge a premium, and only the poor would use the others.
- stolio 13y agoMozilla isn't positioned to stand up to Google while they're getting $300 million a year [0] from them. (For reference Mozilla's 2011 revenue was $163M [1]) I trust (to a point) their motivations but I would imagine that much dough comes with more strings attached than just making Google the default search in Firefox. I think we're very lucky to have Mozilla in the FOSS world but the will for better privacy will have to come from the community. [0] - http://www.forbes.com/sites/timworstall/2013/01/22/so-why-is-google-funding-its-own-competition-in-the-firefox-os/ http://www.forbes.com/sites/timworstall/2013/01/22/so-why-is... [1] - http://www.mozilla.org/en-US/foundation/annualreport/2011/faq/ http://www.mozilla.org/en-US/foundation/annualreport/2011/fa... edit: I didn't state it explicitly but my argument is based on the idea that Google is primarily interested in a low-privacy and ad-based web.
- gcb0 13y agoYou are right. Google silently removed 3 (that i counted) times the ability to remove referrer from chrom[e|ium] And apple probably disabled some 3rd party cookies more to harm google than thinking on user privacy (now this is speculation, but add that the fact that jobs had said he'd gone nuclear on google at the time)
- tracker1 13y agoWhy don't browsers just generate a UUID on first run per user.. then anyone tracking can do so server-side.. with a browser/user option to re-generate a new one. It would effectively be the same.. then have a white/blacklist for sending this id. Or they could make a system where a site can set their own unique id, that they can use.. oh, maybe have a custom key for this value.. and maybe they could call it a token system.. ooh or maybe cookies. /sarcasm
- Udo 13y agoThere is no need for a "tool" (which will only add to code bloat and be circumvented anyway). Just don't accept 3rd-party cookies and be done with it. All browsers already have this setting, it just needs to be enabled by default. I invite all who haven't done so yet to change their browser's settings right now to refuse 3rd party cookies. They have almost no legitimate use anyway. The only breakage of a useful site I'm aware of pertains to active Disqus logins, a price well worth paying in my opinion. The 3rd party cookie tracking problem is worse than most people think. For instance, every time your browser pulls a file from a CDN, you're tracked.
- jfasi 13y agoPhilosophically, this effort seems fallacious to me. Many of the Internet's services are only free because of advertising, and while Mozilla's intentions seem admirable, they're at best short sighted and at worst naive. As for the immediate reason Mozilla is backing off, have you ever wondered how you make money as a browser? One of the key revenue streams for a company like Mozilla or Opera is referral fees from search engines. Ever wonder why Microsoft is so desperate to make it difficult to use non-IE browsers? it's because they have their own search engine. My own personal speculation is that some of Mozilla's search engine customers, whose business model often includes using cookies, came forward and indicated their displeasure with this initiative and pointed out that this would basically amount to biting the hand that feeds it on Mozilla's part.