I never disconnect from anything, i just open a non container tab. I never connect to anything on my laptop, i open the site in the desired account container.
This website is in a state I don't want ? New container, and it's sees me as a new customer.
I have a "personal" container that I use for my Google/PayPal login, and sites that I use Google oauth with, same for a "work" container.
If each site used it's own container, I couldn't sign in with Google without signing in multiple times (let alone the mess of signing out old sessions, which I do once in a while).
I use this feature with container tabs and it's fine. There are so far one or two sites I've come across that this breaks, neither of them anything I care about.
Related: https://wiki.mozilla.org/Security/FirstPartyIsolation
https://wiki.mozilla.org/Security/FirstPartyIsolation#First_...
Container tabs works for me very well, so I don't see much point in switching over and dealing with little bugs like this.
I'm logged into four, including a Gapps account.
I still don't fully trust it, but that's a different matter.
Right?
It'd hard to ban Google from your life even if you want ti. I think governments should help citizens achieve that when they choose so.
Your home device may not live in such a family, but it's hard for Google to determine that.
But again, the issue is not your specific configuration (or GP's specific configuration), the point is that Google cannot assume same IP or browser fingerprint is a definitive association of identity, whereas signing in additional users in Google's app definitely does.
For a very odd definition of the term 'good' I suppose that's may be the case. It's certainly not been in any place I've worked in the past 20 yrs.
But suffice to say, it's very common for Chrome extensions to be able to both modify any content on websites you view and read data you enter into them. Both adware and spyware is prolific on the Chrome Web Store, and it's the number one infection vector I see.
Controlling extensions is downright basic competency for network security. With regards to Chrome, I currently operate an outright block, though obviously we can whitelist extensions as necessary. (One thing Chrome does particularly well is their ADMX templates: It's easy to blacklist and whitelist extensions, and install them compulsorily for users as well.)
But with its own IP, possibly a non-routable, private IP ?
I think not ... and that's too bad because that is what we really need. We need the ability to chroot jail a GUI program just like we jail named or (whatever).
A different root, a different IP, and no access (or knowledge) of the rest of the system. If I used facebook, that's the browser I would run it in.
Strict site isolation > Enable.
The minor difference is that with OAuth they cannot log-in to the site pretending to be you, but if they don't hash the passwords, or use weak method to do it, then it's possible.
Regarding other user data stored in the DB (which is usually more valuable than just the passwords) there is no difference between the login method.
CAD or any similar cookie deleting add-on will essentially kill any cookie that isn't required for your active tabs. This way nothing is left behind to track or trail you.
So instead of standing out of the crowd why not disguise so well that the tracker doesn't know the real you.
The idea is to use something that gives a fake readout of your fingerprint thus making you look normal but keep changing it occasionally so it leads no where for long time. Try Canvas blocker[1] and/or Canvas Defender for fake readout.
What is "normal" in this case? One correct way to counter fingerprinting is to standardize the fake readouts to a specific value and not change it every so often. So if everyone's browser is reporting the same value for this feature that feature will become meaningless in the context of fingerprinting since its entropy is very low.
That's what Tor Browser has been doing with font enumeration, reported windows size, screen resolution etc. - they all report the same value. On the other hand, you can correlate these values and identify Tor Browser users.
I use uBO with dynamic filtering[1] + I've replaced 'CAD' with 'Forget Me Not'[2] works like a charm.
[1]https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-qu... [2]https://github.com/Lusito/forget-me-not
That might be more usable than blocking third party cookies for sites that break because of SSO.
Personally I use Containers and block third party cookies and I don't have any troubles.
9/10 times I navigate off a link from one container and boom I've pulled in everything in that new container by ctrl+l reflex.