How do FF users do this?
How do FF users do this?
I also wrote this up for the owners to send to their staff, feel free to reuse if appropriate for you:
We’ve seen at least one situation recently where a user “signed in” to Chrome when prompted, which brought that user’s personal bookmarks and website logins onto their work computer. While Chrome offers this as an option, there are no situations where your personal account should be linked to a browser at work – if you need to be using personal email, etc. please do so from your own phone or other device on your own time. This is for your own privacy and security as well as for the practice – we want to not have your personal data on our systems, and you don’t want your private email, bookmarks, etc. accessible to anyone else who happens to be at your desk while you’ve stepped away.
If you have linked your browser to a personal account, please remove that connection using the instructions below.
You can check whether Chrome is linked to an online account by clicking on the small person icon at the top right corner of the window – just to the left of the “X” to close the window. • If you click on that and it asks you to sign in, you’re not linked to an account. • If you click on that and it lists a personal account, click on “Manage People” to open a new window listing connected accounts. On each account there are 3 dots in the top right corner – click those and “Remove this person” • If you see a name rather than a generic person icon, click on that and use “Manage People” to remove that connected account.
Firefox offers a similar but less-used version of this that would have required creating a Firefox account to use Firefox Sync. If you have done this with Firefox please disconnect it; if you’re not sure then you almost certainly haven’t done this in Firefox and don’t need to worry about it.
LOL
So the offence was merely having porn bookmarks in their browser - not visiting porn sites at work? Wow.
It wouldn't surprise me a bit if the person whose account it was didn't even know that bookmarks exist in Chrome - it's not like Google makes it obvious these days. I suspect there were some awkward discussions at home that evening, or possibly on the phone with college-age children.
Of course, if someone is signing into their personal account using work hardware, they're basically saying they trust the company not to do any intrusive monitoring, where "intrusive" is something I'm deliberately leaving a bit vague. The company probably has some idea what sites they visit but employees expect that the company is not stealing their credentials or having someone virtually read over their shoulder without a very good reason. If outside intruders get into work device management servers and such, employees' personal stuff is at risk also, but they're willing to accept this for the sake of convenience.
I have, on my work-owned laptop, both work and personal Chrome profiles. (The analogous Firefox feature is multi-account containers.) I might only bring a work laptop when traveling for work. Most of the time, and certainly if I'm presenting during a meeting, I'm using the work profile. I'll use the other only when I'm alone. I lock my screen when I'm not there; I have sensitive access, so this is expected for reasons other than protecting my personal data.
Conversely, work allows me to access my work email and some other internal sites from my personal phone if I agree to certain device management restrictions. I do this rather than carry two phones. Some people choose otherwise.
Once upon a time that was the case - "Cyber Monday" as a prime case in point. Some limited amount of non-work browsing is generally still fine at most offices I deal with, most notably checking news, weather, sports scores, etc.
However as a person responsible for making sure there are no breaches (particularly reportable ones) at offices, I'm moving more and more to the "No personal use. Period. No debate." position. I can control the kind of filtering, AV checks and attachments that come into the office via the business email as an example, but if people are checking their personal email on company systems I may not be able to catch the "Huh, I don't remember ordering from them, I wonder what this invoice email is all about?" person. Antivirus is all well and good but it's not 100%, and while I can look at the mail filters and see that there were 400 PDFs with variations of "Delivery Notification" or "Invoice 1234567" blocked in the last half hour to a ton of different addresses, Jane Smith in Billing or Accounts Payable may only see one or two - and on a really bad day, opening just one may be all it takes.
Also, these days a huge percentage of people not only have smartphones but use those smartphones as their primary devices for Internet access. 5 years ago that wasn't the case, but now? George with the iPhone 7 Plus can quite easily check his email or do plenty of other things that would have been much less pleasant on an iPhone 4.
Wouldn't Jane Smith from Accounts Payable anyway open a PDF invoice email, regardless of the address?
https://addons.mozilla.org/en-US/firefox/addon/multi-account...
But not at the same time, which is a showstopper to me (still using Firefox Nightly as main browser).
I've been using Firefox this way for over a year, 2 instances open right now.
Compared to ProfileManager, Container Tabs are absolutely awesome. Completely different experience, smooth and nice.
The solution for me was to use one Firefox installation per profile: primary = stable, secondary = nightly.
Container tabs are way nicer than this, but since I open lots of tabs, I still like the distinction between stable and nightly (stable = regular browsing, nightly = FB).
Containers splits them out beautifully, with minimal tracking.
With Chrome / Chromium, Google wants you to log-in using a Google account, so you fall into the trap again.
Google of course has all the information server-side to do this; I'm unsure if they actually use it. There's usually a line on tracking that (you think) a company won't cross; e.g. I wouldn't expect Google to use browser fingerprinting to track you when logged out in a different browser, but I'm not sure about web activity in Chrome. Sounds plausible either way.
My question is independent of container tabs, it's a question of whether we know the level of tracking Google does on a signed-in chrome where your google account is not signed in in the session (is this even possible?)
But personally I certainly don't need to be logged in using any of Googles services except for GMail so I'd rather just not build up the history rather than having to go about deleting it (or not because there's so many other things to get distracted by)
Entire or not, does Google analytics apply here?
I'm happily using DDG as a replacemet for most Google searches. But I guess I need to stop using GMail.
If your use case is not covered, you surely can write a WebExtension to provide the functionality. Containers as well as sync are exposed in the API.
Also, changing a container's color does not change the color shown on existing tabs.
Container settings (names, colors, icons, assignments) should be synced (if not, please file a bug). Open tabs will be synced, not sure how they will open on another machine (considering URL-to-Container assignments should be synced, they should open in the respective containers – maybe there's a possible improvement here).
I expect the different Cookie stores to be synced as well, if not, that's a bug.
It was locking out journalists drafting stories!
How can you trust Google anymore? There's something rotten festering in Mountain View.
Why shouldn't we hold corporations to the same standards as governments? If we don't want the government arbitrarily censoring people, why are we OK with corporations doing it?
Because the "opt-out" process is orders of magnitude easier. You don't have to use Google. Microsoft has online document creation applications, as does Apple, assuming iWork still exists. Or you can just write documents offline using any of several thousand tools.
Corporate censorship is entirely under your control. You can always stop the censorship by simply not saying it using that corporation's tools. Corporations can control how you say something, but not what you say. Governments can control the act of saying it. One is far worse than the other.
Easier or more difficult to get by without shouldn't distract us from the core point GP made, that corporate (arbitrary) censorship, with no redress, should be taken as seriously as govt censorship. These days they are just two arms on the same chimera.
The answer is: groups of people (and corporations are groups of people) are free to limit speech according to whatever rules the group decides upon. What you're proposing is that certain large corporations be treated as quasi-governmental entities. Which is a _free-speech restriction_.
Not saying it's a bad idea, necessarily. But I'd rather my freedom to say that certain types of speech are unacceptable was guaranteed.
My point is censorship is a huge responsibility and power, especially when it is done at the scale govts and multi-national corps do, and therefore it needs serious transparency and checks and balances, in both cases.
I don't see this happening to satisfaction. Instances of regrettable censorship stay regrettable, and keep recurring.
I just can't quite go as far as to say that Google or Facebook should be treated as governmental entities. The bill of rights restricts what government can do. It has never been interpreted as restricting what an individual person can do, even if that person heads a giant corporation.
Solve these problems another way, not by literally nationalizing social media.
Again, by all means, protest Google/Amazon/Facebook. I'd love to see the state of affairs change too. Just don't pretend like missing your church bulletin is equivalent to actual imprisonment.
Everybody understood implicitly that you only put in your own information. Giving away other people's personal information to a some company for which it is clearly valuable is not considered nice. It's simply not yours to give away. For the few who didn't understand this most companies had this in their terms of service anyway, as there could be legal risks involved.
All those companies are gone now. They are out-competed by a select few very large companies who did everything possible to make it very easy for people to input everyone else's contact information in their database, including making that behaviour default in the software that ships with your phone. In the beginning you could ask people nicely not to input all your personal info in third party phone book services. That's not really possible anymore.
The days when you could practically opt out of these companies are long gone.
Because one of these organizations can throw you into a cage to be raped and tortured for the rest of your life, and the other can deny you access to some fairly useful web apps.
There is already a case where private companies can't shut down their service to you as they wish, it's utilities (water, electricity, gas). I hope we can recognize at some point that Internet access should count as a utility too, and some core services like email service too.
Any power that you take away from (comparatively weak, subject to competition) Google by giving it to (already terrifyingly powerful and monopolistic) USG is not a move in the right direction.
There are other email services which offer what people want. Want people are proposing is imposing their will on Google and the people that run it, even though there is competition out there that people could use instead and get what they want. Gmail and Google Apps are far from the only options people have, and far from the only free options people have. But if it is so important that people have an email address, then the USG could actually offer that (I've long thought the USPS should offer verified email addresses with strict spam protection by aggressively pursuing violators). Otherwise, let people pay what they want for the level of assurance they want.
The other side of this argument is that there are some things we do want to enforce companies do, such as offer a base level of health care in a package. I support this as well, because that solves an endemic problem where people have restricted choice and it also hurts society as a whole. That is, I think Hobby Lobby should have to provide birth control in their health plans because of the reasons outlined above, but I don't think any non governmental service provider that isn't a monopoly (and Google isn't a monopoly in cloud apps, even if there is an argument that can be made about them being one in search) should have to adhere to dictates about what what content they must allow on their service. That's a pretty slippery slope in my view.
Because you have choice of what to use. You don't always (or even often) have choice of what country to live in, and there's not a lot of unclaimed land that's hospitable. Some people may want a service they know the operators of will be proactive about keeping certain content off. Others will want a service that makes it their goal to not do that and protect everything on it. Choice is key here, and the government stipulating what needs to be done is actually restrictive, not freeing (you're just imposing your own views on others systematically). When there isn't a choice of what service/product to use, that's when other laws may come into effect. Anti-trust laws.
https://www.engadget.com/2017/10/31/google-docs-users-locked...
This sounds like one of those "damned if you do, damned if you don't" no-win solutions for Google. Users (and Google) don't want Google to allow people to use Google Docs to distribute malware and harvest passwords, they don't want someone at Google to look at their documents to see if they are "safe" (which Google couldn't realistically do even if they wanted to), so then people got upset when the automated software Google uses to look for these problems did a bad job for some people.
While it'd be nice if every system and process worked well 100% of the time and had no bugs, that's just not a realistic expectation.
firefox -ProfileManager -no-remote &
(I alias it to `ff`.)Create different profiles[2] for each separate browser you need, and then make shortcuts to launch them.[3] Each Firefox profile will work like a completely separate browser.
[1] https://addons.mozilla.org/en-US/firefox/addon/multi-account...
[2] https://support.mozilla.org/en-US/kb/profile-manager-create-...
[3] https://developer.mozilla.org/en-US/docs/Mozilla/Command_Lin...
Chrome supports multiple profiles, which may optionally be associated with a Google account. Firefox has the same thing, minus the Google account.
The new panel containers are also handy. They allow you to have shared history and bookmarks but separate cookies and sessions. You can be logged into the same site on different accounts in two tabs in the same window.
But containers don't have separate extensions, bookmarks and history so they can't completely replace profiles.
So at least until then, about:profiles is no replacement for using the -P command-line switch to start the profile manager.
Using multiple profiles seamlessly is one area Firefox can and should seriously improve, or Chrome's "User" feature will always have the edge.
http://kb.mozillazine.org/Shortcut_to_a_specific_profile
Also don't forget to add -no-remote option to each of the links to enable starting such browsers in parallel. Sadly it's not mentioned behind the URL above.
Firefox needs to improve on Chrome here. The erstwhile "Profile Switcher" addon provided a nice UI but is sadly gone after the WebExtensions transition and I cannot find an equivalent so far.
- New tabs do not inherit current container
- No way to make Ctrl-T do this by customization (I investigated extensions (can't remap Ctrl-T) and even system-wide Ctrl-T remapping with Karibiner; neither gives you what you want)
- History is shared across containers. So e.g. work URLs mixed up with personal. That's contra to one of the main purposes of Profiles.
- External applications do not open a tab in the current container. So e.g. clicking in a link in work slack will fail because it will not open in a tab which has work cookies / google account etc.
Evidently Containers are not designed as a Profile replacement. I'm not sure what they are for but I don't think it's a need that I have.
As I understand it using the long-standing Firefox profiles feature is the way to go, but personally I switched back to Chrome after a month of the new Firefox Beta because of the convenience of Chrome profiles. I should try Firefox profiles, but I exhausted my experimentation energy on Containers.
Middle-clicking or Ctrl+clicking the New Tab button does inherit the current container. It also opens the new tab to the right of the current tab instead of at the far right of the tab strip. These actions are one in the same, so any extension that opens a tab to the right of the current tab (like Always Right or All Tabs Helper) also make the tab inherit the current container.
It's strange that such a useful feature is barely advertised at all in the UI, but it's there.
But your other criticisms of using containers as profiles are spot-on.
Anyone know how to make the windows visually distinct?
Syncing extensions and browsing history is not something I feel I need.
You could always try tweeting him. He's also on HN.
DISCLOSURE: I work for Mozilla, and Pocket in particular.
It's good even for creating fake accounts, test accounts, testing apps from the perspective of different user sessions etc.
- Profiles
- Containers
- Persona tabs
?
Really? I can configure two personas to go through two different proxies? I can disable javascript in one and leave it enabled in the other?
Those are features I need in Containers, but as far as I've been able to read, they aren't present and there are no plans to allow for them.
Don't do that. On one hand you mix work and personal related issues (not recommended) on the other hand it makes it easier to track you (as your accounts can be correlated). As a dev I have my own (personal, work, ...) users/accounts even at home (if I do remote) to separate the stuff - maybe that's paranoid, but for me it was great to improve work-life balance.
about:profiles gives you the same functionality as Chrome's profiles; it's just a bit harder to discover.
Ok, I spend my life filling in captchas, but to me that’s a signal that it is working and Google aren’t overly sure who I am.