Firefox Multi-Account Containers
blog.mozilla.org
blog.mozilla.org
This was also discussed in the issue tracker, in a now closed issue, in which the intuitive behaviour (staying in the same container) was proposed, but got sidetracked and in the end implemented something totally different.
So if anyone from Firefox is listening here: please PLEASE consider implementing Ctrl+T in the same container :)
And you still have no way to have bookmarks that open in a specific container. (you can however flag a URL to always open in a container since recently).
But it's just because the feature is very new. They do listen to the community, and will fix it on the long run.
At the very beginning containers where unusable, because even links you clicked would not open in the same container :) The community reported it and it was fixed.
So don't worry, it takes time, but Mozilla will do the right thing. They most often do, that's the beauty of it and why I kept using Firefox to support them, even when it was clearly less practical than chrome.
That's almost exactly the opposite usecase I have for using accounts in Chrome.
GitHub issue: https://github.com/mozilla/testpilot-containers/issues/462
Of course, this is no replacement for a keyboard shortcut.
It's a popular request; about as popular as everyone who wants Ctrl+T to open in the default container. :)
So, for our core experience we picked the default behavior that helps maximize the privacy and security protections of Containers.
The good news is that, with the contextualIdentities extension API (exclusive to Firefox!), add-on authors can make their own add-ons to change this behavior. Like Taborama is doing:
https://github.com/kesselborn/taborama
Check out https://developer.mozilla.org/Add-ons/WebExtensions/API/cont... for more info on making Container-aware extensions.
https://github.com/mozilla/testpilot-containers/issues/245
"Opening a new tab from a container window opens a normal tab and not a
container tab"
I should note that the last comment on that issue was made in July, so I went ahead and commented asking about adding a setting to change the new-tab container inheritance behavior.* CTRL-T opens in DefCon
* Right-clicking a link and selecting "Open in New Tab" opens in SameCon
That's what I would expect the default behavior to be.
But, if you're someone who browses primarily using keyboard shortcuts, this just doesn't cut it.
I don't think this is the ideal solution, because I'd imagine there are a population of users who just wouldn't consider the possibility that SameCon could Be an add-on. Especially if the community is split roughly down the middle.
I think yours is the ideal solution, making SameCon a configurable option, but having the default option be DefCon. That way, the privacy and security protections are the Default behavior, but a user has the option to change it Built In
Personally I would want tabs to be in the bozo container by default, unless I explicitly grant the website access to a trusted container, or something.
Extension makers will experiment and Firefox can choose from what gets learned.
Unfortunately my suggestion of Ctrl+Shift+T is already taken.
It's a bit awkward although it works, until they get the CTRL+T solved.
Mixing different containers in the same window feels a bit awkward to me.
Why isn't this under Test Pilot?
And maybe some hints during the second time you open a tab.
We had some original mock-ups with more settings, but they cluttered the introductory UI and seemed to only confuse people new to the concept.
Do you have any proof like a larger survey? I highly doubt that's a 50:50 request.
Why should one want to open a new tab in the default container with Ctrl-t? Ctrl-t is used and learned as a shortcut to open something (like a tab) in the current context. The current context would be not just your current browser window but also your current container. Ctrl-n would go more in your direction.
Would be great if we had sensible defaults without the need to get exensions.
Besides, do I need to get a Firefox account for this feature?
Example: I contain google.com to a container called "Google", then I perform a Google search. I click a search link, and it opens in the Google container.
Ideally this would still use default. There is the option to right click every link, select "Open in Container" and then pick the default but it's not really optimal for two reasons: 1. Manual effort by the user 2. The link is to a redirector on Google's site, before it forwards to the third party site (though I guess I can live with this, its kind of outside scope of the feature).
So, really, I just want to pin a domain to a container. If I leave that domain, I want it to change containers.
I haven't been able to find a good way to do this automatically, with any of the configurable settings.
EG, if you open it within the Google container, your privacy is most exposed. Whether you have to right click and select 'Open in a different container' when following search or email links, or whether you can have the browser do this automatically, the end result is the same. You're following a Google link, so if they create a special one that tells them which result you clicked on, they still see it and know about it because it's on their domain.
But once you get to that third party domain, you're in a separate container instead of one filled with your own special Adsense cookies.
There are extensions you can use to remove Google's redirect link in their result page.
But this is kind of tangent to what I was trying to get across.
If one has goal is to contain a web property, giving them their own container but then keeping that container open when you leave their site is not really containment.
CTRL+clicking the "+" sign will open a new tab on the same container.
[0]: https://github.com/mozilla/testpilot-containers/issues/245#i...
I'd say it's highly subjective and it may vary case per case. Also this would completely defeat the security purpose of this feature. Imagine someone has opened a "Banking" tab, and want to convert an account number to IBAN, or just convert amount between two currencies. You'll need a new tab for that. But you definitely don't want to do that in the "Banking" session, right?
This, along with the speed improvements (both the UI and content processes) in Firefox 55 have made it my default browser for the first time since Chrome was released.
Open your google/twitter/whatever accounts in separate profiles, et you get the benefits of being "always logged in" with no tracking on your main session.
Having multiple github accounts next to each others is a bliss and prevent so many stupid mistakes I used to make, like commenting with the wrong identity on a PR.
Combined with the tab group extension, it makes currently Firefox the most productive browser experience I had in years.
_well_ what about web sites that use information about your browser that isn't stored in cookies? Check out https://panopticlick.eff.org/
Unless Firefox has a story to prevent this kind of tracking, don't rely on multiple profiles for any important separation you're trying to keep.
Despite their claims for it: "Maybe you want to keep your bank’s website farther away from your Pinterest board"
Just be mindful of what add-ons you install.
I have separate LastPass accounts on each chrome profile (one for work and for personal use) and there's no way to keep them separate like this
It sooo much easier when reading articles to be able to zoom in to the 'article text only' in Safari/Chromium.
Alternatively type "about:profiles" into the URL-bar, which you can also bookmark.
firefox -no-remote -p
If you're not on Windows, you can also instead use `firefox -new-instance -P`, which is better, because -no-remote cuts off communication from other applications to that Firefox instance, meaning that you can't open links from those other applications inside a Firefox instance that's been started with -no-remote.
The aforementioned "about:profiles" also has a button "Launch profile in new browser", which is much easier than the above methods, but those are useful, if you for example want desktop shortcut for your individual profiles.
As an aside, I've been migrating away from Chrome for a while - and I posted here a while back being dismayed by how terrible Firefox was, how slow/etc it was, etc. Many people suggested I switch to nightly.
Nightly is .. a night and day experience. I've been fully switched from Chrome now, thanks to Firefox. Note that on OSX I've had no complaints with Safari as my Chrome replacement, so I've stuck with them - but on windows it's all Firefox.
Keep up the great work guys, the new stuff is amazing. Hope you can push it to stable branch soon for people. :)
One conspicuous absence is that there's no way to save a web app to desktop, I use that a lot with Chromium on Linux.
Stylish has a Chrome version so I'd guess they'll port that to Firefox for 57+. In the meantime there's Stylus, which is a fork of the Chrome version of Stylish:
The change of hands happened after the last Firefox version update, so it should be safe for the time being.
If you follow why the Stylus extension was made (port from Chrome's Stylish), you can find more explanations.
It is indeed a night and day experience! More approachable UI, and much faster performance... Big well-done to everyone working hard to keep Firefox competitive :-)
On HN we seem to get reasoned arguments for or against Mozilla and Firefox, but not seemingly mindless hate.
Now I know that HN is a higher class forum these days--Slasdot is not still in its heyday--but I have to say it is refreshing.
I even posted my Cookiepie extension for the first Firefox extension contest [1] and there was no prize or mention for it.
[1] https://blog.mozilla.org/press/2006/03/mozilla-announces-win...
I'm not sure if Cookiepie directly inspired the engineers who built originAttributes and Containers features here, but after working with this Firefox team I can definitely say that the core Containers tech is not hackish at all - great engineers here.
Anyway, thanks for contributing!
For the original FirefoxOS security model, sicking and jlebar rototilled all the security checks in the codebase to switch from comparing origins to comparing (origin, appId, isInMozBrowser) tuples.
Later on, for the eventually-abandoned FirefoxOS New Security Model (NSec), we needed to pass around a signed package id instead. So the options on the table were to rototill the codebase again, or to do something out of band with the cookie service (sicking's proposal).
When I found out about this I wasn't particularly happy with either option, and used my sec module ownership to insert myself into the discussion, and push for a more general approach (i.e. OriginAttributes). Sicking was initially kind of peeved about this, because they were on a deadline, but eventually came around. So we did one more pass of the rototiller to switch everything from appId+mozBrowser to the general and extensible mechanism.
Years later, FirefoxOS is no more, but OriginAttributes are still used to implement Private Browsing, Containers, and First-Party Isolation. Here's to general/reusable solutions!
I never thought Cookiepie was an original idea since many people wanted to have cookie separation per tab once they started to use multiple accounts from the same service.
The interesting part of Cookiepie was solving a problem that, supposedly, was not possible to solve with the API, and required some exploratory techniques like automating the search of relationship between objects.
As Multifox was one of the old XUL/XPCOM extensions, I am glad that this functionality was integrated natively before Firefox 57 will disable all extensions that are not WebExtensions.
It is a great way to login to multiple accounts on various sites such as Twitter, without going through the hassle of a full logout/login cycle. You can use the accounts side-by-side in different tabs, which will be color coded to indicate which container they belong to.
More details can be found on the Mozilla wiki: https://wiki.mozilla.org/Security/Contextual_Identity_Projec...
1. Implements the browserAction pop-up UI for managing containers & tabs 2. Adds the ability to assign sites to always open in a certain container
EDIT: I guess I just had to ask then my brain figured it out. :) Open the page in the container you want, right click the extension icon and choose "Always open in this container"
I hate not knowing what consequences my actions are going to have.
I'm sure in many cases the recommendations give more traffic than less, but I can't help but feel for me personally, it's giving Youtube less traffic. I actively avoid clicking some videos on Youtube, because I don't want that crap to repeatedly show up for me. It's a cancerous feature.
This new extension should help with this experience, BTW.
It's so easy to open a tab in the default container, or the wrong container, and being able to move that tab, along with all the data it has spawned (like cookies) would make this a killer feature for me.
The only other thing, which admittedly makes my one singular gripe less singular, is that I didn't see any separation in the history, as far as what was in a given container. In an ideal world, each container would have its own "Show all history" data.
One limitation I currently see to that workflow (that works better for me in Chrome) is that this appears to all reside under a single Firefox Account which essentially creates master set of data to Sync. I would like to be able to setup Containers to be pegged to different Firefox Accounts (or not at all).
Or maybe a new bug in the [META] Contextual Identity / Containers Bugs ? (https://bugzilla.mozilla.org/showdependencytree.cgi?id=11914...)
You can, it's just not easy to discover :( Edit your Firefox shortcut and add "-P --no-remote" after the command.
I even have a "Testing" container when I'm testing a webapp and need to log in with 2 different users in the same window. Very convenient.
If you do want bookmarks and browsing history separated, then yeah, as the other guy said you'll want to use classic profiles. Easiest way is to type "about:profiles" into the URL-bar and then the rest should be self-explanatory. Another (scriptable) way is explained here: https://support.mozilla.org/en-US/kb/profile-manager-create-...
And then you'd create a second Firefox Account and give each profile a different Firefox Account to sync to.
However, I wonder. What is the technical reason for not making it default to 1 container by site? Sure that would mean hundreds of containers...but does that pose performance problems?
It would break some webpages. Also, yes, the vast majority of broken things will be tracking, but as a browser vendor you sort of need to not piss off webpage owners (which often benefit from tracking, directly or indirectly), as otherwise they'll stop testing their webpage against your browser.
Also, as far as I understand things, Tor Browser actually has what essentially is a separate Container Tab per domain. It's described somewhat more precisely here: https://wiki.mozilla.org/Security/Contextual_Identity_Projec...
I did provide feedback to the developers on the following:
1. Opening new tabs should have better intelligence about which container a user wants to go with.
2. Improving the look of the tab bar for better tab visibility and clarity on which tab was the current one.
3. Detailed and clear documentation on how containers work across normal windows and private windows, because I certainly wouldn't want to use something believing that it's providing me isolation while it does not in certain scenarios. In my limited knowledge, the behavior of different browsers, in keeping cookies/storage isolated, in private/inprivate/incognito mode varies when it comes to multiple windows, multiple tabs and closing windows/tabs. That is already not clear enough (to me) that I don't open more than one private/inprivate/incognito window at the same time.
I would love for this to get into Firefox main instead of being an extension!
Oh and for the commenter wanting Ctrl+T in the same container, a Ctrl+Shift+T in Doogie does open a child page in the same bubble.
I use Private mode a lot and it doesn't really make sense to group everything together just because it is "Private".
I've had the problem that many restaurant rewards program have gone from "10 punches on this card and your next sandwich is free" to "type in your phone number / scan this card" on each visit and have now become "install our app" to get that free sandwich. That's more than I'm willing to give up for a cheap meal once every few months.
Similarly, things like Focus let you access a throwaway experience even more easily. Still no password saving though.
[EDIT: comments show this does exist! great] Missing: easy way to open a new tab in a specific profile. ctrl-T always opens in Default profile, not the one you're on. So have to go File menu -> New tab -> select profile. And that menu changes items around slightly, so no muscle memory. I end up going to a tab already open, middle clicking a random link, ctrl-L, and using that as a fresh tab. I see on their little drawings they show some cool drop down under the + button at the right of the tab row, but I can't find any such functionality.
[EDIT: Comments show exists. Good enough!] Missing: a way to fix certain hosts to certain profiles. E.g. {XXX.myclient.com -> always open in "Client X" tab}. E.g. with links from GitHub (which is client independent) into custom CIs (jenkins etc). You forget, "why isn't this logged in? oh, profiles", go back, right click the link, open in new container -> select container. Ugh.
Missing: a way to disallow any non-whitelisted hosts from a tab. E.g. having a gmail tab is useless, because every link you click will open in that profile (and you won't notice because hey, it works) and now your gmail credentials and cookies are available there. Again defeats the purpose. Especially for a "Banking" tab, for example.
Missing: clear warning that this doesn't do anything meaningful against tracking. It's a complete waste of time to separate your Facebook into a separate profile if you don't want to be tracked across other domains. Fingerprinting goes well beyond cookies. They don't need your account cookie to link your visits.
Missing: segmentation of plugins!! Different NoScript or µblock settings per profile? yes please! Or even just native Firefox settings (3rd party cookies, clearing policy, etc) per website per profile would be lovely.
All in all: I'm stubborn so I'll keep using it, but I'll be honest: there's quite a low ROI on them, as they are. Good start, hope they improve.
EDIT: Another missing: clear cookies only from a certain profile. E.g. discover I've accidentally been browsing youtube in work profile (or whatever), I want to delete all youtube cookies _but only from that profile_. Can't do it. I encounter this problem often with GMail, where I want to clear a friend's login but not log out all my sessions from different containers.
(PS: Sorry for using "profile" and "container" interchangeably---it was a bit stream of consciousness. I mean "container" for both words).
Long click the new tab button then select the profile. Or just click the button on the toolbar and select the profile.
> Missing: a way to fix certain hosts to certain profiles.
When you click the toolbar button, you get the option to always open in the current container.
Further to this, I've been using (and meaning to embellish on) a little trick to make this even simpler, without having to use the mouse, using the "always open this host in container X" feature.
I have 2 gmail accounts so don't want to tie gmail.com to a specific container. I only have 1 pagerduty account so I have that open in my Work container automatically. So, to get to my work gmail I open a new tab (Ctrl+T), go to pagerduty (you don't have to wait for it to load), then go to gmail. Voila, work gmail without the mouse.
The embellishment is to set up work.mydomain.com, play.mydomain.com, whatever.mydomain.com. Tie each of them to a container and go from there.
Click and hold the new tab button. You should see the menu.
You can mitigate some of this with Cookie AutoDelete which has support for contextual identities. After you close a tab it'll nuke cookies for any non-whitelisted domain for that context.
https://www.reddit.com/r/firefox/comments/6y7lpw/what_is_fir... (sorry, don't know any mozilla.org link for FPI that has any good description what it does and how it works)
Privacy extensions could do this on their own. They can integrate with containers where it makes sense. Enforcing it from the firefox side would probably be more confusing than useful.
> EDIT: Another missing: clear cookies only from a certain profile.
Extensions could implement this.
> Missing: a way to disallow any non-whitelisted hosts from a tab.
Extensions could implement this.
https://addons.mozilla.org/en-US/firefox/addon/context-plus/
https://github.com/mozilla/testpilot-containers
And we're asking folks to upvote their favorite issues, so we can point more add-on developers at these lists. Since we can't solve for every workflow and use-case, we really want to enable an ecosystem of container-aware addons. (Some of the other comments here link to the already-growing number of container-aware addons)
And check out https://developer.mozilla.org/Add-ons/WebExtensions/API/cont... if you're interested in making your own.
Now, I only just learned recently that in theory you can use Chrome extensions in Firefox, does this actually work well? Or just so-so.
Because of that Mozilla has wanted to move to a different extension API for a long time, they just couldn't really afford to, because it would require breaking all extensions for good.
Now they are at the point where they do feel like breaking all extensions weighs up with the benefits. Another big factor here is the new multiprocess-architecture, which is the foundation for most of those performance improvements that you've seen, and also requires breaking all extensions. (Currently those old extensions can still be used, but Firefox will then drop back to singleprocess - another quality problem that you likely encountered.)
So, now they needed that new extension API. And instead of writing and testing a completely new API, Mozilla decided to base it off of Chrome's extension API.
Some smaller Chrome-specific APIs were left out / adjusted, but short of that and potential bugs in the implementation, Firefox is going to be compatible with Chrome extensions. (They are also adding new APIs that Chrome does not support, because they want to offer more extensibility, so it's essentially a superset of Chrome's extension API.)
For most extension developers, the only porting work is going to be to test it, work around bugs if they run into some and then upload it to addons.mozilla.org.
The more or less 1.0 release of that implementation is going to be with Firefox 57 on November 14th, which is also when the old extension API is going to be disabled. But most of this new extension API (called "WebExtensions") is already in Firefox as of today, there's just still some bugs left to be squished.
So, that's why and how you can run Chrome extensions in Firefox. It's up to the individual extension developers to port their extension.
Well, that's the normal path, which is not going to be so-so.
As I said, the porting work is often minimal. So minimal that it can almost be automated. That's why this extension can exist: https://addons.mozilla.org/en-US/firefox/addon/chrome-store-...
Assuming there's no bugs, then the only part which can't be automated is signing the extension. Haven't done it myself yet, but from what I hear, it's a matter of creating/having a Firefox Account, uploading the extension-file and then waiting for a few days or so.
So, to summarize: Firefox now supports Chrome extensions with minimal porting work necessary, meaning that lots of those will get ported over. You can try to port things on your own and if there's no bugs then it shouldn't be hard (and it's not hard to find out if there are bugs). And lots of old, unmaintained and problematic extensions will get thrown out with Firefox 57, making it much easier to find the qualitatively better ones.
Chrome's approach at least helps to keep multiple profiles visually separate.
The main use-case is when you have home/work split with multiple accounts.
Also, you can (obviously) use them in tabs, not just in separate windows like profiles.
https://addons.mozilla.org/en-us/firefox/addon/containers-on...
It wasn't our core use-case, but there's a Web Extension API for others to build on!
Now if only Pentadactyl/Vimperator could be reproduced on top of Web Extensions without loss of functionality... ;-)
Tor Browser has essentially what you described, so it's not the case that resource usage would be problematic.
Update: Nevermind, the right answer is that users probably expect that different tabs pointing to the same website share the same context.
I figure it comes down to some combination of lack of consideration and performance concerns, but that is just speculation.
I suppose restricted cookie sharing is also a lot more complicated for the user.
If I want to test my web app with say 4 different identities then figuring out which container is "free" becomes cumbersome.
https://developer.mozilla.org/en-US/Add-ons/WebExtensions/AP...
https://addons.mozilla.org/en-us/firefox/addon/containers-on...
You can also set certain domains to open on certain containers by default.
It's available here for now, but I really hope this ends up making it into firefox itself:
https://addons.mozilla.org/en-GB/firefox/addon/multi-account...
Time to test the thing.
People might get a false sense of security if all of these methods of saving data in the browser are not also separated along with cookies.
"Users can log into multiple accounts on the same site, even when the site does not natively support concurrent sessions. ... Current solutions: Users open multiple browsers (this takes users away from Firefox). A user opens one account in Private Browsing mode (this has a limit of 2 accounts, and forces one to be ephemeral)."
There is no mention here of the -no-remote flag which has been available for many years.
And the technology behind this was developed by the Tor Browser devs and then uplifted into Firefox and reused for this, so this is a proper security/privacy feature, not something that only works on the surface.
Is multi-process here already?
Yes.
Switching between profiles in Chrome involves clicking on an easy to find button, and lets you easily run multiple profiles in parallel. No terminal involved, accessible to anyone.
To be fair, running multiple chrome profiles in parallel kills my (somewhat old) machine (mostly by virtue of having too many tabs in each profile), so Firefox does win there.
The one thing I miss over the old plugins is the ability to set home pages per profile, which I know doesnt really fit in with the new tab ethos of default Firefox, but I would love a plugin to be able to add the functionality back.
(Ex: if I want a container for my streaming apps, there's no way to segregate Amazon Video from the rest of the "shopping" app)
Then again I may be getting too fine grained with my personas but segregating Reddit, HN et al away from my Google account and away from my streaming accounts seems to kick tracking in the ass.
If you want security rather than security veneer, use a real VPN instead, with browsers set to either use or ignore the system proxy, depending on what you want out of each browser.
I like that extensions are separate for each profile.
For example, I have two separate LastPass accounts. One for work and a personal one. There is no way for me to keep them separate like this.
"Containers" makes me immediately think of Docker-like containerized applications, which I suspect is not actually the case here.
There should be a post on hacks.mozila.org soon.
It's not really overloaded here. 'Container' means a contained environment that can see itself, and cannot see other contained environments on the same machine/network. It has the same basic meaning for both Docker and Firefox.
Docker was released in 2013, so if you search for "software container" or "software virtual container", or "chroot container" on Google filtered to before 01-01-2012, you will find plenty of examples of it from the past.
LXC - Linux Containers – was released in 2008... Virtuozzo Containers since at least 2000.
Here's something called Aurora for containerizing CORBA services in 1998: https://link.springer.com/chapter/10.1007/BFb0054506?no-acce...
maybe the best feature since HTML5 has gone mainstream!
i'm so tired of using Icognito Window for that!
For what definition of "easily" ?
If they make it opt-in like you suggest, then a good number of casual users will not understand, because they can't try it without opting in, and therefore ultimately not opt-in, even though they would probably like this feature. (They've had it in the Test Pilot project like the above and got a very good response to it.)
But yes, this continues to work after Firefox 57.
It is just a number.