Basically, various privacy protections cause various kinds of website breakage.
https://blog.mozilla.org/data/2018/01/26/improving-privacy-w...
Make it a long deprecation if you have to. Give even longer exemptions to the really big players / the big breakage / the legitimate use cases while we find better ways. But it is up to the browser vendors to remove the weapons here.
It's possible for your IdP to track the SPs you authenticate to regardless of protocol or cookie use, of course.
This extension gives Firefox selective amnesia: if you're in a Facebook container tab, it'll remember and send those cookies. If you're not, it won't!
An alternative solution is to never make those third party requests in the first place, but you might need some of them for content you're actually interested in viewing. Using both a blocking extension and this container extension should improve your privacy towards Facebook.
Obviously this would need a white-list (and a pair<from,to> whitelist, not just "this domain is OK list) to allow SSO scenarios.
This will treat every first party domain as it's own container for cookies and other stuff.
Presumably the like button wouldn’t work - but that’s what I want. So the Q is: what will break that I didn’t want to break?
But there's a thing for Firefox which does it for all sites. Called First Party Isolation.
Sites that put a checkout flow hosted on a different hostname in a subframe break.
Some forms of "sign in with X" break.
It can. Blocking third-party cookies is available in the browser settings of at least Firefox, Chrome, and Safari. I think it’s even on by default in the latter.
I’ve been using it for years and never seen a broken page as a result.
Default privacy settings are tough to manage.
Some people want privacy, and will accept broken websites if it keeps their data and online movement private.
Other people just want their usual websites to work, don't understand or care to think about privacy, and if some random content farm looks busted in Firefox, will just switch to another browser.
Aside from picking a sensible default, Firefox also offers to educate users where it makes sense. For example, when you open a new private browsing window in Firefox, the tracking protection section includes a "See how it works" button that takes you to a tour-style walkthrough of how tracking protection works.
There's an add-on that does something close to that:
https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
This add-on's options include opening each (sub)domain in its own container. These containers are temporary: they're deleted a short time after you close their last tab, so you have to log back into each site on each visit. (This may be something you do anyway.)
I don't (yet?) know of an add-on that automatically assigns each domain you visit to its own permanent container, and automatically creates new containers for each new domain.
You can set Firefox to behave that way, though. Look for First Party Isolation.
What is really nice, is you can tell it to ALWAYS open your banks website in a particular container, and it will. If you go to that URL from a tab in your work profile, it will switch to the banking profile for you.