Container Tabs
wiki.mozilla.org
wiki.mozilla.org
Say site www.a.org includes an image from www.evilcorp.org, and www.evilcorp.org sets a cookie. When I then go to www.b.org and it includes an image from www.evilcorp.org, I don't expect the cookie to be sent back.
In other words, the cookie should be tied to www.a.org, even though it actually came from www.evilcorp.org. It should only be sent if my URL bar says www.a.org AND the image is coming from www.evilcorp.org.
I feel that this is how browsers should have been designed in the first place. I welcome this Container Tabs feature, but I don't think it quite goes far enough to restore my privacy.
You can test first-party isolation now by flipping the about:config pref "privacy.firstparty.isolate" to true. Beware that there are still bugs that break some sites, which is why the feature is not enabled by default yet. If you find bugs, please report them in Bugzilla! Here is the Firefox bug tracking the integration and known bugs:
> Blocking third-party cookies can break some site that rely on third-party resources
Can anyone name sites that require them?
As someone who defaults to deny all cookies and manually enables every one my browser accepts, I don't think I've found a site that requires 3rd-party cookies. Few sites require cookies unless you login or have shopping cart.
Of course, that's anecdotal. Maybe I just don't visit certain categories of sites and don't encounter them.
The other way is to have all StackExchange sites be subdomains of stackexchange.com - which is how the designers of the web intended it to be, I think.
The entire notification center, cross-site hangouts chat, etc all requires third-party cookies.
For anyone else interested: now that I know what to search for, I also found some status at https://wiki.mozilla.org/Security/FirstPartyIsolation
I'm not sure this description is as clear as you intended.
... so evilcorp.org cookies for evilcorp.org images on A.org will not be set for evilcorp.org images on B.org.
note how every single privacy feature came after google-money. during google-money what did we got? third party cookies accepted as default.
good riddance, google.
I remember, as a volunteer, debating some privacy issue with a Google dev in Bugzilla. They made some crack about looking a gift horse in the mouth, but the discussion was out in the open. I don't recall evidence that Google was influencing Firefox improperly, but OTOH absence of evidence is not evidence of absence ...
You're the one who accuses Mozilla and Google, of different things, sure, but fairly important things anyway.
The burden of proof lies with you. Not us. It is not up to us to "find the pattern."
Not that I disagree with you on the fact that Mozilla seems much better off, post-Google.
* Note that "withdrew" might also mean "offered less money than before because Firefox had less users than before, and Yahoo! offering more.
[1] https://addons.mozilla.org/en-US/firefox/addon/self-destruct...
* History (Personally, can't live without it). * Whitelist (HN's cookies, for example, I keep). * Saving submitted form data (for auto-complete). * 10-seconds remorse time to reopen that tab and have it stay as it is!
I disabled 3rd party cookies ever since the option appeared in Firefox, and never had any issues.
Sadly, that is currently not possible, not even with addons, because the containers can only be assigned when creating tabs, not when navigating them. There is a related feature (1st party isolation) but that is always-on, so it fails the unless I say otherwise aspect.
I have filed a bug explaining my use-cases [0], but it does not seem to be a priority at the moment. (other addon devs signalling interest might help)
Also if you start a new context every time you navigate you can't for instance log into Google.
That's the point of having an addon API instead of fixed behavior, to implement logic around such complications.
Having special cases for every exception doesn't scale. What about Outlook Web Access using Microsoft accounts or domain accounts? Are you going to build an add on for every webmail installation?
Example: my main general browsing profile has flash, PDFs and all plugins disabled, absolutely all handlers switched off, all hardware access off, WebGL switched off, no account logins and uBlock Origin set to aggressively block most third-party requests.
My second most used context is for personal sites I login for - with access to third-party cookies (for those sites) and running most third-party requests with standard uBlock rules.
I have yet other contexts (Chrome profiles) where Flash is enabled if I need that, then a separate browser for Java etc.
I'd like to see these security levels built into browsers where the contexts are built around permissions and site trust rather than access to the user store (which is also important)
I don't think it's realistic for most users to do this right now with profiles, as it requires a lot of discipline - it needs to be in the UI.
Browsers have become as sophisticated as operating systems and we're accessing more and more of our personal data using them, yet the model of 'every site has access to everything' be it a site you trust, like Gmail, or a random URL you're clicking on - has somehow survived.
It's the equivalent of the old days where everyone would run their local systems with an admin account for everything. I really think browsers need a rethink along these lines where websites are treated like apps and you can apply a trust group to each.
This feature is not meant to solve that use-case since if your case is security, you need separate browsers/contexts/proceses anyways.
Separate profiles in firefox implement separate profiles (which may all be independently open side-by-side in different windows).
This exchanges less secure/strong separation with better UX by intermingling.
Firefox is just choosing to support either set of tradeoffs there.
While if you had a "Create a new profile" button that does it in one step and that they would advertise on install much more people would be using it, even if it's just for family members separation.
The majority of people already separate family members with different user accounts on the machine or mostly just don't seem to care.
This seems to be the interesting UX compromise that the new "Container Tabs" is trying to meet "where they live": the users that could use some of the advantages of profiles without the full overhead of using multiple profiles. It will be interesting to see if the compromise is picked up by average users.
(Fwiw, I've used multiple profiles in Firefox off and on for decades but have yet to find a relative I'd recommend that to.)
In the old days, seperate profiles were used to seperate Moms browsing from Dad's browsing. Now, we need different profiles to browse: one for shopping, one for banking, one for work...
Seems to me that coders forget that people evolve. Same with Moxie saying that it is fine for WhatsApp not ticking the 'tell me when the key changed'-box by default because that confuses people. Perhaps it /did/ confuse people, when security was not a known issue. People tend to learn, in my experience. You can't say: "Well, we did an A/B test in 2002 and now we're done for the next millenium."
Which is where we arrive today with Mozilla's work on "container tabs". The code and UX evolve, too.
I'm not sure what your complaint here is, mverwijs? That Mozilla should test Firefox starting up with the ProfileManager again? Like I said, I think "container tabs" might be a good way to do this in a way that mainstream users might pick up and this will be interesting to watch.
(I guess one trick that might be interesting if there was a way to easily "graduate" from I know/love "container tabs" to "oh, the next thing I can try is profiles to do more complicated things", but I think the answer is that profiles will adapt more to work with "container tabs" UX than "container tabs" UX will adapt to the old profiles UX. Given "incognito" tabs in other browsers can be seen as a specialization of a "container tab"/"profile tab", I suspect mixing profile tabs in a single browser window is a UX that is here to stay.)
Even though people don't use multiple-user-accounts too much anymore, it's still usually present in schools and in older family computers.
Conceptually they're very similar.
I'm worried about that because I used to browse with no Noscript/similar, and then I got a infected by a rootkit, which I traced back to a new site I'd visited.
Since I didn't enjoy having to nuke my entire computer environment from orbit, I now have a rather locked-down browser.
I want to take it all the way to eleven and 'jail' a gui process (in this case, the web browser - any web browser). It gets its own filesystem root and its own IP BUT I don't have to pay the penalties of firing up a full blown virtual machine.
This isn't easy to do in the way that, for instance, jailing a daemon is easy to do ...
Further, even if I did have a workable recipe to jail a chrome process (and all of it's children) it would certainly only be for X. Maybe there's some recipe for that in OSX but it would be profoundly different. OSX doesn't even have the 'jail' command (although it does have chroot ...)
Well, yippee, now the application can read all keyboard input from that X11 socket, there goes your "sandbox"...
You really need Wayland to get a practical security benefit for GUI applications from containers.
install NoScript in firefox and allow flash/etc per domain temporarily or permanently.
profiles/context tab is all about tracking. You just happen to successfully abuse one tool to your ends in one case.
For example, when visiting example.com you could allow scripts from example.com but not from gstatic.com, analyticshost.com, or shadylookingdomain.com. Yet at domain.com you could allow gstatic.com scripts and images because it embeds Google Maps.
It's all done in an amazing, quick GUI that provides a visualization of the rules. I wish all firewalls would adopt the UI.
2. visit a site, click the noscript icon
3. allow the domains you trust.
no step 4.
how is this hard?
you only have to click the icon again if some site is not working.
And then you start realizing that blocking all scripts is a pain. You want just this script to work, but not this one. So you start filtering and it takes so much time.
Then often, a site is not working exactly right, and you don't know no-script screw you. Sometime you realize it after 10 minutes looking for something no-script removed. Waste of time. Then you for some time you want it one for a site, then off for the same site. And on. And off. And you have 30 tabs, then you have to jungle with the state of it.
do you have a link to an official chrome help page?
also what chromium do you use? and where did you get it?
sorry for my ignorance.
Chrome has had it for a years, and it's a killer feature for many developers. It's very very useful to have multiple browser windows open, each logged into the same site as a different user. A lot of people do this by opening multiple browsers (FF, Chrome, Edge, Safari, etc) but that has its limits and it just adds another variable my poor brain would prefer not to handle.
Also very useful for home/work separation. One browser account for work and one for home. And also maybe one for porn. So that when you're screensharing in a meeting and you type a URL into the browser, you don't get autocomplete suggestions for your favorite porn sites popping up. Happened to an old (married) boss of mine once while displaying his screen on the projector... typed "a" into the URL field and the browser helpfully suggested he navigate to AdultFriendFinder. Right in front of some clients. :)
Firefox's "container tabs" implementation may be slightly confusing. Chrome's implementation is dead simple. One identity per window, and the identity name is always displayed in the upper right.
With FF's container tabs, I'll have one identity per tab, and I can see they're color coded, but that means I'll have to mentally map colors to identities. It's more flexible than Chrome's implementation but there's more cognitive overhead involved.
Also, what's up with the name "container tabs?" That tells me nothing about what they do. All tabs... contain things. I think they need to rename it to "identity tabs" or something. How on Earth would anybody ever guess that "container tabs" is related to identities and data sharing?
We'll see how it plays out though. I'm excited to try it and I am continually grateful for Mozilla's efforts. In fact this reminds me I haven't donated to them in a while....
Firefox has had this since, well, forever; they're called "profiles". I run two windows with different profiles (for "personal" and "work"), each with different install addons, Sync accounts, etc. Unfortunately the UI is clunky (requires adding a couple of flags to the shortcut/command).
ff-home contains:
firefox -P home
etc...
Each of them has a different theme so the windows are clearly visually different.
No, not really, not at all. Chromium has an equivalent (but more accessible and more user friendly) feature than Firefox profile, but it's nowhere close to this.
The profile feature in Firefox and Chromium allows you to have a different set of add-ons or browser configuration, but this feature is really different: it allows you, with the same features and add-ons, to have different sessions, with independent cookies to limit tracking and mitigate CSRF attacks.
/Applications/Firefox.app/Contents/MacOS/firefox-bin --profilemanagerpersonal: For personal banking, gmail, facebook, etc. very high security except on my trusted sites.
Work: Work stuff. high security.
Browsing: normal security, so everything works.
wild west: No history, high security. Like private mode. gmail, facobook, banks etc blacklisted so you cant log in even by accident.
:)
Original comment:
I'm kind of surprised that Mozilla went with a per-tab approach here, since they went with per-window for private browsing (while Chrome did the opposite: per-tab private browsing and per-window profiles).
[1] https://bugs.chromium.org/p/chromium/issues/detail?id=24690
So Firefox seems to be just jumping ahead of that initial limitation from the start here.
I recall Opera 12 had per-tab incognito - I'm not sure, do any current browsers have it?
Honestly, this whole thing is a bit of a pain - my ideal solution would be one where I can set up "domain groups" matching on the URL in the URL bar, each fully isolated from one another (different extensions, settings, caches, histories, forms, cookie stores, etc), and clicking links that go from one profile to another, all referer information is stripped out. Anything not matching one of the domain groups would go to the "default session" (which I would configure to be completely locked down and ephemeral).
Additionally, I'd want a context-menu item "Open link in group <x>", which would open something matching another domain group in the domain group of my choice, so that I could do things like visit gmail in two different groups.
FWIW, this is also doable in Firefox: try 'firefox --new-instance -ProfileManager'; you can also directly open up a new profile from the command line (and hence do the same from scripts, desktop entries, or whatever else your platform supports).
I have one profile for my finances, one with NoScript in blacklist mode, and then my normal profile.
i found that i can have on session space in regular chrome and one more in incognito, but all tabs in incognito seem to share that same session. i.e. opening a new tab automatically shares the same session as the other tabs in x domain. Maybe there is a way to control this behavior?
At work I test lots of user accounts on the same site and make heavy use of Chrome profiles for that. This would fill a similar role.
But while I'm glad to have them, no average user would ever understand any of these concepts as presented in these screenshots.
I have been using Self-Destructing Cookies[1] for few years and while I think the extension is great, I always feel there's not enough isolation between tabs. For example, if I have Twitter logged in in one tab, and other tab contain Twitter button, then the other tab can still have access to my Twitter cookie. (Because Twitter tab is still active, so SDC would not destroy the cookie.) I know this is solvable using tracker blocker, but something like SDC but worked on tab container level would be very welcomed.
(Other side effect of using SDC is I seems to get the harder ReCAPTCHA that make you click an object until all of it disappear, with new ones popping up after clicking. Usually took about 5-10 clicks. Very annoying.)
[1]: https://addons.mozilla.org/en-US/firefox/addon/self-destruct...
[1]: https://addons.mozilla.org/en-US/firefox/addon/umatrix/
SDC + uMatrix do make a really great combination, and I'm really glad I use these extensions when I see some sites loading 10+ trackers that are not relevant to site's function at all.
Just run "firefox --no-remote -ProfileManager" and here you go.
So the serious question is: how is this any different from using multiple profile?
Multiple profile also have the pro/con that they are actual different processes, so there's no information leak between profiles whatsoever (well, unless some serious hacking happens).
Edit: being different processes with different profiles, they also have different configuration folders, different cookie sets, different password storage locations etc...
I'm sure Grandma and Joe SixPack will do that... Not everybody is tech savvy. I'd say the majority of FF users don't even know there's a profile manager.
> The containers feature is enabled in Firefox Nightly 50 by default with the about:config pref `privacy.userContext.enabled` set to true.
Grandma and Joe SixPack aren't running Firefox Nightly with about:config tweaks either.
Of course, most people are probably not running Firefox nightlies either.
I'd been using the command line way for a long time, until I found this. Now the first thing I do is install it in every new office computer, and then I have a Work and Personal firefox profile, completely separate from each other. At home we have mine and my wife's profiles on the laptop.
https://addons.mozilla.org/en/firefox/addon/change-window-ic...
To answer your question, it's probably quicker and takes up less HD space :) And now we can have profiles and container tabs in those profiles, or just use profiles or just use container tabs, how cool is that.
Yo Dawg!
We heard you like profiles, so we put profiles in your profiles so you can use profiles while you use profiles!
I do think container tabs makes it easier for the everyday user to enjoy some of the benefits of seperation, though. Most people aren't goint to want to deal with settup up multiple profiles, choosing profiles, and all that jazz. This is certainly a cool feature for FF to add in.
At least in OSX I haven't figured out how to make an icon I can click that will open a specific profile and running the command from terminal leaves a termnial window open.
I know it is not hard, but it makes the multiple profile thing cumbersome enough for me to never have adopted it.
To answer your question directly: It is easy to use and integrated into the UI. It also works across tabs instead of just across windows.
It has a lower bar of entry.
I use separate Firefox profiles in order to have different add-on configurations, e.g. in my daily driver NoScript is set to whitelist mode, while in my special JavaScript-permitted profile it's in blacklist mode.
Every time I try using Firefox I pretty quickly hit the limitation on selecting tabs. Chrome lets you select tabs like files in a file manager: Shift click for ranges, ctrl+click for adding/removing single tabs. You can then drag & drop the group in or out of various windows, close all at once, etc.
Container tabs imho won't be usable unless something like this is in place. When dealing with as few as 5+ tabs, I certainly wouldn't want to manually tweak them one at a time. Can't imagine for 20+, 50+.
But the idea is nice for feature separation, I like that a lot.
`privacy.userContext.enabled` `privacy.userContext.ui.enabled`
The pref might be avaiable in other version too.
I'd like a container per Google account since trying to switch users in their apps is a disaster that forces me to run multiple browsers.
I'd also like to tie sites to specific containers. So supposing Banking stays its own category, that should mean that any sites that open in the Banking container will never open in another container. Similarly it should be possible to whitelist a set of sites for a container so e.g. only specific banking sites will launch in the Banking container.
Each container should have its own set of security permissions.
I'd like to have disposable containers. I want a safe space where I can open a sketchy link and not have to worry about that page doing anything to the rest of my environment.
There have been autofill/form-data attacks in the past[0] and there was a story recently on HN's front page showing the same[1].
I'd like to point out that mozilla already has a configuration option to disable form data saving on https sites, 'browser.formfill.saveHttpsForms'. Why?[2]
> Right; the idea is to eliminate "opportunism". If my laptop is stolen, Firefox's current behavior makes it easy for a thief to find a https: site in my history, go to it, check out, and then just let autocomplete hand them my complete credit card details.
[0] https://news.ycombinator.com/item?id=12171547 [1] https://news.ycombinator.com/item?id=13329525 [2] https://bugzilla.mozilla.org/show_bug.cgi?id=252486
(Googling does not seem to have produced any relevant hits.)
I use Firefox for testing my dev work but reading about the privacy use-case, I might seriously consider switching from Chrome as my main browser.
This is a Firefox addon that uses part of the security model of Firefox OS to create sandboxed tabs. Each sandbox is a completely separated world: it doesn't share cookies, storage, and a lots of other stuff with the rest of Firefox, but just with other tabs from the same sandbox.
I became a huge fan of Opera Neon's interface, though. And it would be a perfect fit for "containers". Drop icons into folders, and done. Folders represent containers.
Edit: I love the color coding feature that distinguishes the distinct containers you have open.
Something like container windows, isolating different browser windows instead of tabs, might be a clear way to visibly show the separation to the user. In one window, they can log into their work Gmail. In another window they can log into their personal Gmail without any Google cookie confusion.
Private Work A Work B Work C
Ideally it would seem like a different user. (Filesystem, cmd-tab). But easily accessible like the three finger swipe. Fast user switching doesn't cut it.
I even tried logging in on my local machine using VNC or remove desktop.. Is having 4 VMs the only way?
KDE Plasma has what they call "Activities". In its basic idea, it's kind of like fancy desktop workspaces. So, it does separate your windows into workspace-like groups, but you can also set what files and widgets are displayed on the desktop on a per-Activity basis.
So, you don't have a different filesystem, but you can have a folder or multiple folders displayed on each Activity's desktop. Also, shortcuts to different applications, including for example Firefox profiles, as well as different sets of widgets, for example I like to use the little post-it note widgets to write things down on.
And yeah, with that you can then just switch between Activities via a simple keyboard shortcut or by clicking an Activity-selector on your panel (if you've put one there).
Long time ago (win2000, before XP)I tried to do it on windows with the "runas" command, but things like IE would keep popping up with the wrong user (they managed to communicate with the desktop and have that open the new window) so it wasn't a good solution. Perhaps it is better now.
My school's security is a joke. You cannot log out except by closing your browser. The session also never expires.
Not only that, but now they moved to a "single-sign on." If I sign in on one app, it signs me in for all apps.
What's planned instead, is to use a set number of processes across all tabs. So, if this would be two processes, then every other tab will share a process with one another. And they'll probably have around 5 processes for tabs at a maximum once this is fully rolled out, at least for the foreseeable future.
You can manually change this maximum number of processes in about:config, though. And if you do set it to something like 500, i.e. just a very big number that you're not likely to hit in number of tabs, then it will separate each tab into its own process, with whatever performance problems come with that.
However, very nice feature.
I would love if I could use this to organize my 100 tabs I always have open.
Now site2.com (aka facebook like button) knows that you have visited both site1, 2, 3, 4 and 5.
You can work around this in some ways by disabling "third party cookies" but this breaks certain features, such as using your facebook identity to post comments on other sites, so sadly all browsers enable this by default.
Valid use for 3rd party cookies is something like single sign on. (Eg. sign into all Google services at the same time, even though they use separate domains)
I don't think this would work if you use the container tabs.
If it's the latter, there's two preferences that you can flip in about:config to enable it (even in Firefox Stable): privacy.userContext.enabled and privacy.userContext.ui.enabled
Mind though that since this feature is currently still under active development, that it might actually be less error-prone in the normally less stable versions of Firefox.
https://blog.jessfraz.com/post/docker-containers-on-the-desk...
When Chrome came out, I and many others switched to it just because it was lacking so many features. It was great!
I like this new feature in Firefox. OS-level profiles being the slowest method, Chrome profiles being faster but with this annoyances (for me)... Firefox new container tabs look like a more lightweight/faster method for context separation.
Chromium-based Ghost Browser [1] can do it per tab or tab group.
It would be nice if Google implemented the same feature into Chrome since multiple profiles can be a hassle.
[0]: https://support.mozilla.org/en-US/kb/profile-manager-create-...