We're so deep in this that a first party isolation would break almost every single website. In a cooperation with Tor, Mozilla actually ported the first-party isolation feature in mainstream Firefox (available in Nightly, don't know about stable), but since it would break almost every single website, there are no plans to turn it on by default. You can, of course, enable it yourself by turning on "privacy.firstparty.isolate" in about:config.
Disclaimer: I'm a Mozilla Foundation affiliate that has nothing to do with Mozilla Corporation nor Firefox.
What I proposed above is that we introduce an opt-in feature: before the browser is allowed to connect to 3rd parties (in the tracking and cookie sense), the user needs to opt-in, for example by clicking in a notice window displayed at the corner of the browser window. Instead of nagging every user of every site that "This site is using cookies", developers should nag only when connecting to other applications, using a standardized browser API. After sometime from standardization, you can roll out this functionality to all users and nothing legitimate would break.
There should be no presumed used consent - because there really is none, the outcry against Facebook and advertiser tracking shows people don't expect the web to work the way it does.
Using the extention: https://addons.mozilla.org/en-US/firefox/addon/first-party-i...
First-Party Isolation (FPI) did have the highest breakage scores: ~18-19% of users reported problems with it, and 9-10% of FPI users disabled the study.
Those are low relative numbers, but at entire-market scale, they are big absolute numbers. :/
https://blog.mozilla.org/data/2018/01/26/improving-privacy-w...
I think the stats are iffy because a lot of the breakages are things I would want broken.
Is there any plan to create an exceptions mechanism? "Allow Facebook access to your activities on this webpage?" or something like that?
While we are at it, I keep wondering (in a strictly SSL world) if it would be a good idea to restrict CORS calls only to sites using the same certificate as the webpage. Would make life easier for folks like facebook.com making CORS to fb-blablabla.fbcdn.com.
Basically, you couldn’t do it without breaking a large part of the internet.
[1]: https://addons.mozilla.org/en-US/firefox/addon/multi-account...
[2]: https://addons.mozilla.org/en-US/firefox/addon/temporary-con...