All sites should run in containers and no advertiser should be able to track you across sessions. When I want 3rd party interaction, I should need to opt in and connect the current site with Facebook or some other 3rd party.
All sites should run in containers and no advertiser should be able to track you across sessions. When I want 3rd party interaction, I should need to opt in and connect the current site with Facebook or some other 3rd party.
As much as I hate third party cookies, turning them on drastically simplifies the captcha solving process. So much so, I now use a separate browser profile with third party cookies allowed, just for the sake of captcha heavy sites.
Given that Google benefits by tracking my activities and free labor from my captcha solving, they will always punish privacy conscious users via such dark patterns.
The pessimist in me thinks that if a browser were to disallow third party cookies, users might simply switch to a different browser that does allow them.
— Essentially off: Challenges only the most grievous offenders
— Low: Challenges only the most threatening visitors
— Medium: Challenges both moderate threat visitors and the most threatening visitors
— High: Challenges all visitors that have exhibited threatening behavior within the last 14 days
— I’m Under Attack!: Should only be used if your website is under a DDoS attack (Visitors will receive an interstitial page while we analyze their traffic and behavior to make sure they are a legitimate human visitor trying to access your website)
I think a lot of companies set it to "High" and forget about it, not realizing that it's ruining the experience for a lot of users.
[1]: https://www.cloudflare.com/a/firewall/ebelinski.com#security...
It's very good at blocking malicious traffic though and it's totally worth losing a pair of users for that.
That needs to bring everybody to the same table, Firefox will not do that alone and Google Chrome is not there for nothing.
Basically, Google must accept the proposal of disabling third-party cookies by default which will effect their income negatively, so they may just refuse to implement that feature for Chrome and even may prevent that feature from become a standard.
Sad.
Kinda hard to find though.
I make no claim that the above is a good idea. It is possible, but it strikes me there are unintended consequences that I won't think of.
I've been accused of being a bot before also.
It feels like Google is using me as a mechanical turk to solve their autonomous car rubbish, which will make them millions, and I have no choice but to do it, or I'm barred from the sites I need to access. It's profoundly despicable, as if I didn't hate Google enough already.
That explains why the majority of ReCaptchas I get are along the lines of "Click the squares that contain a street sign" or "Click the squares that contain a bicycle."
The web is a lost cause as far I'm concerned, it was under-engineered at the start and as a result people kept pilling mounds of crap on top to make up for it. What started as a way to display basic markup and images has been arm wrestled into handling complex web applications and videogames. The thing is so complex that it would probably take me less time to write a basic operating system and run Firefox on it than implementing my own browser from scratch on Linux. And despite all of this you end up having to use a billion of 3rd party javascript libraries to do anything remotely complex in the browser, things that have been standard in Qt or GTK since forever with a fraction of the code base and memory footprint.
And now people seem to enjoy reimplementing all the internet protocols on top of HTTP. The world has gone mad. I'm going to get a "gopher should've won" tatoo and live in as an hermit on some nearby mountain.
I'm glad that there appears to be a lot of discussion surrounding internet privacy lately, including in the mainstream. However I think that focusing all the discussion of Facebook is becoming counter-productive. Facebook exploited the weaknesses of the web very successfully but it only exploited tools that existed long before it was created. I have absolutely no illusion that Google & friends are doing pretty much the same thing, and if you have an Android phone the amount of info Google can harvest is nothing short of terrifying when you think about it from an Orwellian perspective. Don't miss the forest for the Facetree.
Assuming that internet giants will adhere to some "code of conduct" is naive at best. "Do no evil", yeah right. We let them have to tools to do these things, we need to pry some of them away from their hands through technology and regulation (probably in that order).
I wonder why you say that. I concede that web has evolved from no-security in the 90s, when random applets and ActiveX controls were 1-click away from rooting your machine, through faulty security in 2000s, where stack smashing IE was a hobby of mine, and up to the current era of sandboxes. Which do work, sandbox evasion zero days have become very rare and remote execution has largely ceased to be an infection vector against the masses.
The problem with 3rd party tracking is not technological, the web was deliberately engineered to work in this manner. The browsers work exactly as specified, and that specification is the problem. It's compounded then as a political problem, where major browser investment are controlled by advertising companies that have a massive conflict of interest regarding the users privacy, and are likely to promote bandaids like "Do not track" instead of the fundamental privacy re-engineering the web urgently requires.
> The world has gone mad. I'm going to get a "gopher should've won" tatoo and live in as an hermit on some nearby mountain.
When I'm thinking like this is usually a sign of age. Hang in there buddy, we'll be fine. There is a promised land just around the corner with rich, secure web applications and strong privacy. If only everybody agreed we want it.
I consider that the widespread fingerprinting and user tracking is a form of sandbox evasion but I agree that it goes way beyond JS. The only identifying info that ought to be sent to some website by default is your IP address since it's necessary to actually send you back the data. Having the size of my view port, the version of my browser and OS, the type of video codecs I support and other shenanigans shouldn't leave my browser without my consent. The problem is that I can easily spoof most of my browser's info but JS makes it almost impossible to sanitize everything.
>The problem with 3rd party tracking is not technological, the web was deliberately engineered to work in this manner. The browsers work exactly as specified, and that specification is the problem
How is that not a complete contradiction? I'm not saying it's a bug, I know very well it's just a huge dump of features that keeps pouring in year after year. I'm just saying that web standards are the embodiment of "we were so preoccupied with whether or not we could that we didn't stop to think if we should".
IMO there are broadly two different use cases for the web currently: Web applications like Google Docs on one hand and glorified PDF reader for mostly static content like HN, internet forums, news websites, Wikipedia etc... on the other. Web Apps are the part that require this ridiculous complexity to expose rich content. That's the stuff you'd use Java applets, XUL, Flash or ActiveX for in the past. Those apps could be whitelisted on a site-by-site basis in the same way that you install an app on your smartphone for instance. You know that you expose yourself to bugs and privacy leakages but you know what you're in for.
99% of the websites I browse everyday don't expose any functionality that ought to require any form of interactive scripting or advanced features beyond displaying text and images (and maybe video). Yet my browser will gladly let them access all these advanced APIs by default, load custom fonts, let them run code on my GPU, make 3rd party requests, mine cryptocurrencies... That's just ridiculous.
The safest code is code that doesn't run.
>When I'm thinking like this is usually a sign of age
Come on, we're not old, we're wise! At least I hope so...
https://news.ycombinator.com/item?id=2300836 (2011) https://news.ycombinator.com/item?id=10734966 (2015)
Also: Some user would ask the site's support about the prompts, not the browser's, which would be an incentive to get rid of JavaScript for the site.
We're so deep in this that a first party isolation would break almost every single website. In a cooperation with Tor, Mozilla actually ported the first-party isolation feature in mainstream Firefox (available in Nightly, don't know about stable), but since it would break almost every single website, there are no plans to turn it on by default. You can, of course, enable it yourself by turning on "privacy.firstparty.isolate" in about:config.
Disclaimer: I'm a Mozilla Foundation affiliate that has nothing to do with Mozilla Corporation nor Firefox.
What I proposed above is that we introduce an opt-in feature: before the browser is allowed to connect to 3rd parties (in the tracking and cookie sense), the user needs to opt-in, for example by clicking in a notice window displayed at the corner of the browser window. Instead of nagging every user of every site that "This site is using cookies", developers should nag only when connecting to other applications, using a standardized browser API. After sometime from standardization, you can roll out this functionality to all users and nothing legitimate would break.
There should be no presumed used consent - because there really is none, the outcry against Facebook and advertiser tracking shows people don't expect the web to work the way it does.
First-Party Isolation (FPI) did have the highest breakage scores: ~18-19% of users reported problems with it, and 9-10% of FPI users disabled the study.
Those are low relative numbers, but at entire-market scale, they are big absolute numbers. :/
https://blog.mozilla.org/data/2018/01/26/improving-privacy-w...
I think the stats are iffy because a lot of the breakages are things I would want broken.
Using the extention: https://addons.mozilla.org/en-US/firefox/addon/first-party-i...
Is there any plan to create an exceptions mechanism? "Allow Facebook access to your activities on this webpage?" or something like that?
While we are at it, I keep wondering (in a strictly SSL world) if it would be a good idea to restrict CORS calls only to sites using the same certificate as the webpage. Would make life easier for folks like facebook.com making CORS to fb-blablabla.fbcdn.com.
Basically, you couldn’t do it without breaking a large part of the internet.
[1]: https://addons.mozilla.org/en-US/firefox/addon/multi-account...
[2]: https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
Firefox just blocks them. Safari blocks them unless you visited that site in a first-party context. Shipping the thing Firefox implements breaks a lot more than what Safari ships.
So for example, if you visited facebook normally, third-party Facebook cookies won't get blocked in Safari.
Firefox _could_ ship the same thing as Safari. The upshot is entrenching existing monopolies, because only big enough players are then able to track you via third-party cookies.... This is the main reason Firefox hasn't done this, as far as I know.
Disclaimer: I work on Firefox, but not on the cookie bits.
Apple can do this, because they have a limited yet consistent market share that mostly consists of their own customers.
But Firefox? If they block third-party cookies and Chrome does not, they might just end up losing even more users.
Websites can be changed to work without third party cookies. I'm blocking cookies since years and I have come across less than 10 sites that require it. When that happens, most of the time I just go elsewhere or I'll send them an email.
There are also lots of one-off cases where developers split functionality across multiple domains in ways that were fine at the time but now get blocked. These are all fixable, unlike the iframing case, but it's still a lot of sites.
Breaks because it was abusing lack of FPI.
Breaks innocently.
<snark>So, nothing you'd want to use.</snark>
Fortunately, many US companies are starting to consider a GUID and your IP address to be PII, and no longer allow that information to be stored.
It seems to me, if users act differently, there "should" be a way to fingerprint them.
https://github.com/mozfreddyb/webext-firstpartyisolation https://www.eff.org/privacybadger https://github.com/Cookie-AutoDelete/Cookie-AutoDelete