Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
groovecoder
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
36 ms
·
61.
▲
by
groovecoder
9y ago
Check out this book: https://mitpress.mit.edu/books/obfuscation Full of obfuscation tactics like that.
62.
▲
by
groovecoder
9y ago
It still works that way. We close the previous tab and cancel the webRequest before it's sent to the site so none of the default cookies are sent. "Converting" a tab from one container to another is actually a bit complicated
63.
▲
by
groovecoder
9y ago
Check out https://addons.mozilla.org/firefox/addon/multi-account-conta...
64.
▲
by
groovecoder
9y ago
This is essentially a light-weight version of that.
65.
▲
by
groovecoder
9y ago
The aim is the same, but ITP only strips cookies after a 24-hour period when you HAVE NOT visited the site. So ITP does nothing to protect a user who visits facebook.com every day. Which is most of Facebook's user-base.
66.
▲
by
groovecoder
9y ago
I really like that perspective! A few more high-profile cases like this and we just might nudge the internet in this direction! :)
67.
▲
by
groovecoder
9y ago
My pleasure ... but it's not just my work. Firefox privacy & security and add-ons engineering teams have poured a ton of effort into Firefox Quantum to make features like this possible and easy.
68.
▲
by
groovecoder
9y ago
It works similarly to Private Browsing Mode - it actually uses the same architecture. But the Facebook container retains your Facebook cookies (and therefore your login) after restarts.
69.
▲
by
groovecoder
9y ago
Disclosure: I'm the author of the add-on mentioned in the story. I'm also interested in this claim. If you're referring to Intelligent Tracking Prevention, I don't think it does this.
70.
▲
by
groovecoder
9y ago
Disclosure: I'm the author of the add-on mentioned in the story. We tried a few different UXs and none of them felt ideal. We have an open issue to add Messenger to the list of FB domains that are contained. https://github.c
71.
▲
by
groovecoder
9y ago
Disclosure: I'm the author of the add-on mentioned in the story. Basically, various privacy protections cause various kinds of website breakage. https://blog.mozilla.org/data/2018/01/26/improving-pri
72.
▲
by
groovecoder
9y ago
do not skip the section on "Cloudflare, Privacy and k-Anonymity" ... it is a great summary of an elegant privacy solution. And check out Cloudflare's detail post too: https://blog.cloudflare.com/validating-l
73.
▲
Intercept Bitcoin by hijacking gravatar.com sessions (2017)
(groovecoder.com)
2 points
by
groovecoder
9y ago
|
0 comments
74.
▲
by
groovecoder
9y ago
https://lists.w3.org/Archives/Public/public-webappsec/2014De... is a good run-down of referrer uses from the AdSense perspective.
75.
▲
by
groovecoder
9y ago
Disclaimer: I'm the Firefox engineer who wrote the patch and the blog post. I'm very interested in this thread. Other replies here are correct - there are many ways that sites try to detect private browsing, and many ways they can
76.
▲
by
groovecoder
9y ago
Disclaimer: I'm the Firefox engineer who wrote the patch and the post. We did a user research study measuring website breakage under various privacy protections: https://blog.mozilla.org/data/2018/01/26&#
77.
▲
by
groovecoder
9y ago
The default user agent policy is no-referrer-when-downgrade, which strips the referrer header going from HTTPS pages to HTTP resources. Firefox 59 PBM now implements strict-origin-when-cross-origin by default, which trims the path off the r
78.
▲
Preventing data leaks by stripping path information in HTTP Referrers
(blog.mozilla.org)
4 points
by
groovecoder
9y ago
|
0 comments
79.
▲
Improving privacy without breaking the web
(blog.mozilla.org)
5 points
by
groovecoder
9y ago
|
0 comments
80.
▲
by
groovecoder
9y ago
Privacy Engineer @ Firefox here ... Extensions operate on requests before the platform-level channel classifier. In theory, the platform-level classifier should be faster than the webRequest API, but we've not measured it specifically.
81.
▲
by
groovecoder
9y ago
It's a Web Extension add-on, so it's written in HTML, CSS, and JavaScript. There should be a post on hacks.mozila.org soon.
82.
▲
by
groovecoder
9y ago
As the user-base grows, we'll likely adopt more settings. We had some original mock-ups with more settings, but they cluttered the introductory UI and seemed to only confuse people new to the concept.
83.
▲
by
groovecoder
9y ago
No, you don't need a Firefox account to use this feature or add-on. The "Multi-Account" describes multiple accounts on websites - not Firefox itself.
84.
▲
by
groovecoder
9y ago
Good idea ... file an issue for it? :)
85.
▲
by
groovecoder
9y ago
That's what Containers on the Go does: https://addons.mozilla.org/en-us/firefox/addon/containers-on... It wasn't our core use-case, but there's a Web Extension API for others to build on!
86.
▲
by
groovecoder
9y ago
https://addons.mozilla.org/nn-no/firefox/addon/context-plus/ does the first part.
87.
▲
by
groovecoder
9y ago
You can also assign the site to the Container in the browserAction pop-up UI.
88.
▲
by
groovecoder
9y ago
No. Canvas-fingerprinting is mitigated in other protections; they are not per-Container. :/
89.
▲
by
groovecoder
9y ago
If you install the Test Pilot experiment (add-on), you'll be automatically migrated to AMO. We plan to "graduate" the Test Pilot listing soon.
90.
▲
by
groovecoder
9y ago
The keyboard shortcut for the browserAction pop-up is ctrl + . and then you should be able to tab down to whichever container you want.
More ›