I reread my initial message and I'm sorry if the tone felt a bit rude, It's not an attack against Firefox but against all those "industry best practises" that are so unfair to everyone. Firefox is pretty much the only hope when it comes to enforce better practises across our entire industry that are more privacy friendly. Be sure, I have a lot of respect for what you are doing. I'm just a random dude that feel very sad everytime I try to dig what all those website are actually made of, pushing for behaviors that are against everything I stands for:
- even the W3C get trap (https://pbs.twimg.com/media/DWtqPzFUQAExO2h.jpg) probably without their knowledge but still that's the W3C ...
- twitter tracking youporn's user considering their track record when it comes to database leak. The damage that can be done here from a political perspective would be absolutly terrible.
- ..... many other examples as you probably know a lot more
> That's not true with web workers. And "How many workers should I spin up?" is a common question people actually using them want to answer...
It would be common when it comes to create real world complex apps which isn't what most of the web is about (I know 1 person isn't very representative). Those questions are legit but feel to me as an edge case, not the general rule considering the market share of wordpress and co.
I would love to have a popup when it comes to reveal information that should be considered as edge case. If a newspaper need access to this information, there's small chance it benefits my experience but more the complex network of advertising and even sometimes some real time bidding system that have performance imperative for which web workers are a great fit
> Asking users for permission isn't really a solution either, unfortunately: all the bad actors will just spam permission prompts continuously.
As I see, It doesn't mean the solution itself is wrong but rather a correct compromise hasn't been fount yet. There's a world between a website creating a cookie for legit purposes and a dependencies of this website that rely on another one that rely on another one.
> How does one go about determining that? This is an honest question; I'm not aware of any database of sites that classifies them along this dimension.
Considering some actors like Cloudflare that track a big part of internet, a database approach is broken by design. As I see it, the only approach that can work is behavior based: if a third party website is forcing a cookie despite having a do not track header, it's shady and thus shouldn't be acceptable (eg: twitter, facebook and a lot more as the "industry standard" is to ignore the DNT). What about you'd do like Chrome did by forcing HTTPS enverywhere, by bringing a message "this site has unfair trackers" instead of "this site isn't secure"
> reducing fingerprinting attack area, by the way; we should just be clear that providing sites less information does mean they can't do various performance optimizations,
Not all the time, I can think of a few things that shouldn't have such an impact if implemented well:
- I've read a bit around fingerprinting using canvas and webgl. Why not adding some sort of randomness that are pretty much invisible to the eyes of a human but put those type of algorithm innefective?
- don't make the navigator object global across all pages and make a few tinny changes everytime. For example Firefox provides the buildID as part of the navigator object. Mine is on this machine: "20180327223059". Will it really break the world if some existing website receives "20180327223434" while another receive "20180327224387"? If somebody is making such optimisation as to know the exact time the build was created, it sounds shady and creepy at best.
I understand some optimisations aren't possible without braking a lot of website for which your users will mostly wonder why they can't navigate it properly but why not creating a different mode, let's say a safe mode that expressly say some website might appear weird but that's only because you're taking active measure to block any sort of trackers? As of today, the private navigation isn't really effective at protecting against fingerprinting