An Update on Firefox Containers
blog.mozilla.org
blog.mozilla.org
After time the container gets polluted with cookies from links clicked on website Ax.
Hopefully this gets fixed soon.
Edit: replaces 1 website with multiple websites
Edit 2 : Another useful feature, would be cookie policy per container. So when I quit FF, I can delete all cookies except those in Container X
Is there now an option to whitelist specific origins, and block all other cookies by default?
Nor there's any protection against HSTS and HPKP pinning, ETags or other "supercookie"-grade stuff. I'm not sure even Contextual Identities are enough, given that e.g. HSTS leaks into incognito mode if the flag was already seen in non-incognito session. That's only a suspicion, though - I haven't checked it, and it's well possible containers are isolated.
And alternatively, "merging" with the empty container, which would retroactively implement incognito mode on that tab, and incidentally coincides with the desktop metaphor for dragging things into the recycling bin... this metaphor can be extended by password protecting the recycling bin of "lost" incognito tabs.
That sounds a lot close to self-destructing-cookies, or now, this:
https://addons.mozilla.org/en-US/firefox/addon/cookie-autode...
The thing about "new container by default", is that sessions are always lost, and people generally want to keep session alive.
https://addons.mozilla.org/en-US/firefox/addon/containers-on...
Someone also made a theme which will color the temporary container windows a different color so you can easily differentiate them from the normal tabs/windows.
https://addons.mozilla.org/en-US/firefox/addon/containers-th...
Do you keep that your personal container, and opt-in to other containers like work, shopping, etc.
Or do you use the default container as your most used type - perhaps work - and opt-in to personal/shopping containers as needed?
Keep the default container blank and try to always open up a specific container?
Eg: AWS I have a work and personal account, and their login flow sucks, but the work and personal containers handle this situation easily.
I want youtube & google music to only use my personal account, so I never need to switch accounts, so google music and youtube open in their own container where only my personal account is logged in.
I want gmail and calendar to use my work account, so they open in the default container and automatically use my work google user.
I know that you can set your default google account by logging into it first, but I specifically don't want one default, I want different defaults for different google services, and that use case is handled beautifully by containers.
Firefox used to have something like this in the past, but it's either buried deep inside some obscure setting or has been ripped out. It's a damn shame.
If needed you can drag windows/tabs between profiles or even other browsers. I disabled all the referral options too.
EDIT: It seems I was unclear in what I was trying to say. I wasn't criticizing multiple profiles in general; I was criticizing using multiple profiles as a replacement for containers. The way I see it, they don't substitute for each other, and they both have their own great use cases.
That's a feature!
I have observed dozens of time coworkers using their BYOD work laptpos that autocompleted porn URL. Dozens.
I use FF for work and a special Chrome profile (not the default one) for anything that shouldn't pop up in my autocomplete in front of coworkers/clients.
That way it's pretty hard to screw up...
But on Firefox it seems totally unusable because of near misses in UI. I haven't found a nice menu for switching between profiles, or a way of getting a list of available profiles short of rooting about in my settings. The default profile is can change itself in strange, and will only sometime coincide with the profile called "default".
Great work, Firefox team!
I've separate containers for: work, home, facebook, shopping. It's particularly useful for google accounts, as I have gmail for work, home, etc.
And the ergonomics - e.g. being able to sort tabs by container, or hide work tabs in the evening - is great.
* Containers need to be per window. Keeping track of containers at Tab level is lot of mental work.
* Set a different default container per device. For example I want to set different default for an office laptop, home computer, shared device, etc.
Firefox is getting there i feel it is just moving too slow for me to make a complete switch.
Containers already are not shared between devices.
[0] https://webkit.org/blog/7675/intelligent-tracking-prevention... [1] https://www.theverge.com/2017/9/14/16308138/apple-safari-11-...
https://developer.mozilla.org/en-US/Firefox/Privacy/Tracking...
If this is the case then containers might be an okayish first step but may convey a false sense of security to the user.
The security and ease-of-use is simply a separate storage for sessions / cookies / etc for each container. Nothing more, nothing less.
If you're concerned about privacy and leaking information there are a TON of tweaks you can do to about:config or via a user.js file such as: https://www.ghacks.net/2015/08/18/a-comprehensive-list-of-fi...
Might still want something that deletes all cookies when the entire container is closed, though.
Edit: They've totally got the default right. Pressing control-T from a banking container should not open a new tab in the banking container. It's just that's not my use case.
Selecting a new "persona" opens a new window, and pressing C+T opens a new tab.
Being able to right-click on a link in your personal container and open it in your work container is pretty slick.
Edit: Above is when opening from a default tab. Maybe this is expected, but the clicked links show as visited in the default tab even when they're opened in a container tab. Perhaps this is to be expected, but it seems like a type of information leakage across containers? Actually, seems like links clicked in the default container show as visited in other containers. Odd as well is that I'm not seeing the duplicate tab issue when clicking YT links from a non-default container.
Edit 2: Is there any way to opt-out of "always" opening a specific site in a given container? Say I configure youtube to always open in a personal container, but for some reason I now have to test something in a work container on youtube. Is that possible? Or do I need to go edit out the config and then replace it when I'm done?
What I would like is the option to assign a site to two different containers, so mail.google.com would not offer me to switch when in in Personal or in Work, but would give me the choice to open it in either when I'm in a default container.
So I just told you to always open a site in a specific container, and then you're going to ask me when I next load that site starting from another container whether to open in the container I've asked the site to always be opened in. Why would my choice be anything except 'Open in <Preference> Container' and 'Remember my decision for this site'. Isn't that what I already asked you to do?
Why am I setting the same preference twice? It seems like the opt-out is there by default when I don't want it, and not there when I do.
* Cleared all cookies for Facebook and Google
* Created a new container called "No tracking"
* Set facebook, gmail, analytics, youtube and all google services other than Search to always open in "No tracking"
Now in theory Facebook and Google can't track me across the web (at least not in a way that it's linked to my real identity), and I don't have to do anything to maintain this.
Anybody see any faults in my logic?
even if you're splitting your browsing between sessions manually, they still only need to match them once.
- Storing visits across the web on different sites that use 3rd-party Google/Facebook-hosted services against a shadow session. Google Analytics, Google Maps, Google Web Fonts, Google CDN / JSON APIs, share buttons.
- I presume you don't login with Facebook / Google on any websites? If you do, that would conclusively link the aforementioned shadow session with your actual account.
- Also, there are integrated browser services calling home to Google. Check about:config?filter=google
---
Edit: For an extra step to mitigate some of the above:
Install either uBlock Origin or uMatrix and painstakingly block all of the above-mentioned 3rd-party origins: analytics, web fonts, share URLs, login APIs, CDNs and JSON APIs. Blocking the last two will break some websites - e.g. Stackoverflow - but you can further mitigate this breakage by installing the Decentraleyes extension.
- Does this represent a deprioritisation of the feature by Mozilla (it would seem not, since there's an explicit WebExtensions API just for this, but I'm curious to see how the level of maintenance of the extension UI keeps up with browser changes going forward)
- This seems like the first major WebExtensions API that Firefox has added post 57 (though it was available with a flag before) that no other browser supports[0]. Does the represent Mozilla's future policy w.r.t. WebExtensions in general - i.e. building out the API with Firefox-specific features? This could be good for differentiating Firefox again, but probably more work for devs creating cross-browser extensions.
[0] https://developer.mozilla.org/en-US/Add-ons/WebExtensions/AP...
If WebExtensions doesn't allow for this, then yes, Firefox should extend it. That way, other extensions can make use of it. You might not be able to port it to Chrome because it is using specific Firefox APIs but the alternative is not to have this feature. I expect to see other extensions in the future like the ability to hide the tab bar.
It is absolutely possible to have your cake and eat it here, and the main reason for this is that extensibility - from an engineering perspective - is complex. Providing extension APIs necessitates generalised code, that fits a range of use-cases and is parameterised in a generic manner. Providing specific browser features on the other hand requires specific code, which can be written in a targetted fashion for the single feature, and therefore can be made much leaner and optimised.
This is absolutely not always the case - you can of course have the worst of both worlds (inflexible non-extensible apps with inefficient badly written code), but I would not underestimate the heaviness of extensibility, nor the potential "lightness" of built-in features.
---
That said - I'm impressed with the performance of 57 and the ease of writing WebExtensions, so I'm pro this move personally.
Oh, and about the API: they already had quite a few API's that weren't available in Chrome (e.g. the sidebar API). It will be interesting to see whether/how much they will be able to get standardised, and if they are willing to make breaking changes to the API if the W3C desires those to be made.
For anyone wondering about the extension and what’s built into Firefox, here’s a comment on the blog post:
> Graham Perrin wrote on October 3rd, 2017 at 6:22 pm:
>> Containers is now available as a Firefox Extension, …
> Also worth noting: the essentials do not require an extension.
> about:config privacy.userContext.enabled change to true
> privacy.userContext.longPressBehavior change from 0 to 2
> privacy.userContext.ui.enabled change to true
edit: From some experimenting, it looks like "Firefox Multi-Account Containers" extension extends the "Container Tabs" feature in Firefox. (This is an assumption based on the fact that the Options/Preferences now tell me I can't disable "Container Tabs" since "Ff MA Containers" is using it.
https://developer.mozilla.org/Add-ons/WebExtensions/API/cont...
they landed on using ctrl-. (control-period) to open the containers dropdown and then you have to tab to the container you want. not only does this require two hands, but even tanvi in the blog post admits this is not discoverable at all.
ideally, you could have a single hand command (like cmd-shft-1, cmd-shft-2, etc) that would open blank containers of the corresponding type, with the (awesome?) address bar auto-focused. then for discoverabilty, you could put the corresponding number next to each menu item with a mouseover tooltip providing the full keyboard shortcut.
even without the single-hand shortcut, the numbering could be useful for selecting a container: ctrl-. then "2" for a personal container or what have you.
but at the very least, let us also use the up and down arrows to select conainers. tabbing is one of the least obvious options here.
(yes, i've spent entirely too much time thinking about this! =)
I do like that you can hide containers or manipulate them as a group. This has great organizational benefits.
Operating-system-level virtualization never had a monopoly on the word container, and as long as there's no potential for confusion I don't see why it should.
1: https://en.wikipedia.org/wiki/Container_(abstract_data_type) 2: https://en.wikipedia.org/wiki/Container_(type_theory) 3: https://en.wikipedia.org/wiki/Web_container 4: https://en.wikipedia.org/wiki/Object_Linking_and_Embedding 5: https://en.wikipedia.org/wiki/Audio_Video_Interleave
Anybody with context can trivially differentiate between the two...