Containers Come to Firefox Test Pilot
hacks.mozilla.org
hacks.mozilla.org
I am reading this name also on other places, surprised Mozilla sticked with "containers":
* https://blog.mozilla.org/tanvi/2016/06/16/contextual-identit...
* https://wiki.mozilla.org/Security/Contextual_Identity_Projec...
* https://wiki.mozilla.org/Security/Contextual_Identity_Projec...
I kid, but it makes sense. Containers describes the implementation, not the user experience or benefit.
(Reusing the name "Persona" for any new project is a running joke at Mozilla. :)
This. Sure, "contextual identities" sounds too academic, but who knows, maybe Containers (as a word) will become as ubiquious as Tabs are today (very common word in German today): Hey, dude, open a container ;)
https://developer.mozilla.org/en-US/Add-ons/WebExtensions/AP...
If a FF PM is reading this: being able to register a domain for a container type would be a killer feature.
With this pref enabled, advertiser X will serve you different cookies on site A and B. They won't be able to track your browsing history from site to site. However, this breaks a lot of sites that depend on third-party services for login authentication or comment systems.
Here is the Firefox bug where you can report broken sites:
Essentially building a new container per origin.
privacy.firstparty.isolate
I think per-window contextual identities, instead of per-tab, might be a good mental model. It's easy to explain to users that tabs in different windows can't see the same cookies. This is a generalization of Private Browsing window's throwaway context identities today. It's harder to explain that some tabs in the window are in the "Shopping" container and others in the "Personal" container.
I personally use Tab Groups add-on and associate each of my tab groups with a container, but I also mix my containers in a certain group. E.g., sometimes I'm on hacker news for fun, and sometimes I'm here for work. ;)
It is a really good browser.
In any case, if you wanted to add a third item to your list, I'd recommend Quantum:
Yes. e10s is short for E-lectrolysi-s. :)
The main issue here is one of UI. If you click a link in a PDF, what profile should the link be opened in? My take is that if you have multiple firefox instances it should ask you, otherwise it should just open on the only one open.
For example, one of the major use cases for this sort of separation is being able to use multiple accounts on a site like Twitter or Facebook (which don't support multi-account) or Gmail (which does, but it's a bit rough). There's no reason I should have to have separate windows or separate addons for each of those accounts.
The choice of container is no more or no less complicated than the choice of profile for links in external programs (or within Firefox)
I.e., Containers do NOT protect against some lower-level privacy vulnerabilities like plugin enumeration or history-sniffing that are mitigated more by using entirely separate profiles.
Anyways; it's not safe by default which should preferably be.
The test pilot experiment is really to help us to figure out how people are using containers.
Are container tabs are being moved out of the browser core to the Test Pilot walled-garden extension store? Or Test Pilot extension is just enabler and all the stuff is still in the core? Or core is becoming chromeless/API-only and extension does the UI? Or both systems are going to be developed in parallel (or maybe Test Pilot is fast-ring and built-in stuff is a snapshot of whatever looks stable at relase time)? Or is it something else?
Test Pilot isn't a "walled garden extension store." It's just a bunch of normal Firefox add-ons that are authored by Mozilla and happen to be explicitly experimental / ephemeral.
Containers are indeed internal to the browser using origin attributes which are a platform feature. We have opened this up to extension authors also in WebExtensions so they can play with ideas also.
Telemetry isn't an issue. If anything, it can be fully disabled. And yours is done right - all the data sent is properly described and observable. (Although it would be cool if there'd be a helper "let me decide later" mode when I can let browser collect data for a short while, get notified to review it, and then decide whenever it contains anything I consider sensitive or not...)
Maybe this is silly and irrational, but... While it's all your work (and thank you for this!) and decision, it just somehow doesn't feel right that an locally-installed software - no matter how experimental - is ephemeral, almost like it's not a software but a service. With normal AMO addons - even the experimental ones - I can browse the version history and roll back if something's not right. Test Pilot feels like end-user is completely out of control of whatever happens (unless they don't participate and just install from Git repos).
A problem with using our full release channel Telemetry is that so many users have so many variables it's hard to compare apples to apples. E.g., was their performance issue caused by a setting, an add-on, the site they were on, or Firefox itself?
Test Pilot experiments give us some controls and parameters on the experience so we have a clearer idea of what's causing what.
There's a setting, privacy.userContext.ui.enabled than enables management UI in the "privacy" section of "options" system (about:preferences#containers)
The biggest issue with using Activities has always been that browsers know nothing about them, so when clicking a link in any application, it was opened in the most recently active browser window - no matter which activity it was on.
So ideally there'd be a way to have Firefox simply inherit KDE Plasma's Activities as Containers, so one wouldn't have to maintain and somehow map Activities/Containers for both at the same time.
It lets you open private tabs in the same window as regular tabs.
> How will users know what context they are operating in?
I find that themes are great for knowing what context I'm in, like the Totem mechanism in Inception. I'm not sure if we can have a different theme for each container though.