Changing Our Approach to Anti-Tracking
blog.mozilla.org
blog.mozilla.org
Wow, I had completely forgotten about what a scourge pop-ups used to be, and what a relief it was to finally be free of them. The fact that what used to be such a prevalent scummy tactic could be completely abandoned due to pushback from browser manufacturers gives me a tiny bit of hope that maybe pervasive tracking isn't an irreparably permanent feature of the web after all.
It's honestly an improvement that sites have to obscure their own content (and thus spite their nose to save their face) and nothing else in order to give you intrusive ads. You'll always know what websites don't put value on their own content that way.
[Reverse Engineering new PopUnder for Chrome 63 on Windows] https://www.youtube.com/watch?v=VcFQeimLH1c
https://www.reddit.com/r/LiveOverflow/comments/84ertx/new_po...
Back then it was just supported behaviour and the dominant browser went several years without a major update. Like night and day.
https://en.m.wikipedia.org/wiki/Interstitial_webpage
Now we have interstials behave like SPAs, so siblings are calling this modal, but that’s more about a dialog box you can’t click outside of until dismissed.
Interstitial is the entire content until you get past it, like Forbes when you have a content blocker on.
Case in point: https://www.reddit.com/r/web_design/comments/99ljrr/research...
https://addons.mozilla.org/en-US/firefox/addon/in-page-pop-u...
The biggest difference between the two, in my experience, is UX. uMatrix is the best UX for a content blocker I've ever seen - very intuitive and simple.
uBlock Origin, check I'm advanced, block whatever you want per site, click save button
https://addons.mozilla.org/en-US/firefox/addon/disable-javas...
the problem has gotten so bad that i no longer use the plugin "store". i only install plugins that are open source, and only by building the source myself... meaning i miss out on automatic updates (but at least i know my plugin isn't spyware!).
it sucks.
New api functions are coming all the time as well. Its not yet as powerful as the old system but is there any reason to believe it will never be?
However I genuinely do want stuff that isn't yet implemented. For example I want add-ons to get access to Firefox's copy of the Public Suffix List, which is what you usually wanted when your add-on actually just treats TLDs as special. I just this evening sent a PR to PassFF, a popular password manager to do something crude as a stop gap while we wait to access the PSL via Web Extensions.
Safari user here. Which key and which click is that?
(That’s command comma. Which I described as one key, cheating slightly, but hey they are so close to each other.)
Preferences panel comes up.
If you leave it on the security tab, the checkbox comes up. Uncheck it and now the site is usable without JS.
Another click on background or Esc to dismiss the dialog if you want to, but for some things that’s not even needed (therefore I claimed that low click count... ymmv).
In all seriousness, it's partly that I have dumb habits. I highlight text as I read it (and that causes all sorts of idiot pop ups to share the quote on social media etc) and micro scroll up and down even when not actually trying to actively change the field of view.
I can't even justify why I do it. But I do. It's just how I read longform text on computers. On the plus side "reader view" can be a lifesaver
I use the top of the browser's viewport as a transient "bookmark." That is, I read for awhile and then scroll until what I have read scrolls out of view. Now the line of text at the top of the viewport is the first line of what I have left to read.
Scrolling in most browsers is quantized to a value much greater than the line height of the text I'm reading. This means I must occasionally scroll past the part I've read and then retreat to reveal half a line or so of what I already read.
Unfortunately, all the algos that trigger new shit on a change of scroll direction disrupt my own manual adjustment algorithm. Even on a news site, a directional change in scrolling triggers some douchebag horizontal menubar that animates itself into view and obscures the next line of text I want to read. I have to scroll back down to make the douchebag menu disappear. When it disappears it reveals... a line of text which I already read!
So now my bookmarking technique is ruined because the disappearing douchebag menu is guaranteed to reveal at least a line and a half of text I already read.
I don't like this behavior because it disrupts my completely rational and reasonable behavior as a user of the browser. I am the one in charge, and if a web page tries to challenge me on that I swear to god I will copy the damn text and paste it into a contentEditable about:blank.
Then they can only sit there and dream about all the places I'm scrolling.
You're helping your eyes stay on point when reading, just like some people reading a physical book/printout will use their finger or a pen for that purpose. It's perfectly normal. Your habits are not dumb. What those sites are doing with floating headers and bullshit on-select popups that's dumb.
I wondered why for a while, because as soon as I see those shenanigans, I'm gone. But then I realised: I'm not the target market for the websites we have at work (a full service travel tour company). Most of our clients are booking travel for a group of 30 people from their company 6 months or a year in advance. They are coming to our website because they want the damn newsletter. Took me a long time to understand that.
As well, when they do occur, going into Dev-Tools and deleting the <div> (or whichever element it happens to be) that is the actual popup is often sufficient to remove the popup and make the content view-able again.
Popups/Overlays = cover your current website.
Pop-unders = open new tab with your current site, while redirecting the old tab to an ad, thereby surprising you when you close your current site.
Bounce/Exit intent = the above formats but triggered when you leave the site or close the tab.
Interstitials = the above formats but triggered when you navigate between pages, common in image galleries.
I put this in my global Stylus rules:
/* Remove CSS animation on all websites */
*, *:before, *:after {
transition-property: none !important;
transform: none !important;
animation: none !important;
}
[1] https://addons.mozilla.org/en-US/firefox/addon/styl-us/[2] https://chrome.google.com/webstore/detail/stylus/clngdbkpkpe...
[3] https://addons.mozilla.org/en-US/firefox/addon/umatrix/
[4] https://chrome.google.com/webstore/detail/umatrix/ogfcmafjal...
Arguably, that creates a more user-hostile internet browsing experience compared to just allowing for those in-page modal pop ups. At least with those they're few and far between and you can just close the tab and forget about the site.
I've heard that these are called pop-ins.
1. https://www.webfx.com/blog/marketing/non-intrusive-pop-ups/
2. https://www.laptopmag.com/articles/stop-pop-ups-chrome#comme...
4) Pop-up Blocking: Imagine a web experience without pop-up blocker. What we take for granted today was first introduced by Opera 5 in 2000.
I don't think you can protect yourself from tracking unless you stop using the internet and mobile phones. Wherever you have an account, a cookie, or simply make a TCP connection will be a place that can track you. Especially if they cross correlate with other tracking services.
https://www.theguardian.com/cities/2016/mar/03/revealed-faci...
And it's not just high end retailers https://twitter.com/GambleLee/status/862307447276544000/phot...
Used to be? IME they still are, just not as bad as they used to be. If you go browse a few adult video sites (for science) you'll see pop-up/unders are still a thing. Even on chrome you'll see a variation of them, making the current tab the ad after the user has opened the link in a new one. Instead of webgl, webasm, etc I'd love to see a browser vendor focus on making a good browser again.
It's also hard to take their privacy promises seriously when they've got google analytics embedded in their blog.
While they are not immune from poor decisions I really believe they try to do the right thing in the end. That’s more than I can say for many other companies.
Without it, billions of people in developing world are going to have every every second of their lives snooped by Google.
It failed, but it was still a good idea.
There's a few alternatives to the Android/iOS ecosystem, notably Librem 5, KDE Mobile, Ubuntu Touch, microG (e.g. with LineageOS), and last but not least Sailfish.
MeeGo was a combination of Intel's Moblin and Nokia's Maemo. I'm not sure what became of Intel's efforts after MeeGo. Sailfish is the successor of Maemo/MeeGo whereas Mer is an open source mobile Linux OS which Sailfish uses as base. Both utilise libhybris [1] for Android compatibility layer. Backwards compatibility = important; no apps / ecosystem = no users, and that curve is very steep.
Another interesting effort I saw the other day is actually from Google. An effort to easily build an app which is easily ported to Android and iOS. That might directly benefit Android and Google most, but indirectly it could benefit libhybris users. I'm unsure how good Sailfish 3's Android compatibility is these days. It used to be Android 4.4 compatibility for a long time.
A while back Samsung released a Tizen phone to Indian (and Russian?) markets, but it wasn't much of a success.
Google is everywhere. What if you don't want it on your KaiOS-powered Nokia phone and prefer open source alternatives? If I want Google, I'll get Android with OpenGapps. It has terrific support for Google's products.
Buy a different phone?
I believe the development kit for apps is now available.
Regardless, the hardware is what I really want. I have a feeling it will even end up with a removable battery and a headphone jack!
You can already run Purism on other machines(laptops, desktops, etc). The mobile version will essentially be Purism with gnome-mobile UI. I’m sorry to read that you don’t think an open device that will have its drivers available and probably work with Android, isnt worth the cost.
They might have even been able to work with Amazon, who has a vested interest in Android a la FireOS, and possibly forced Google to make AOSP a truly open project.
You might as well start clean with an OS designed for the modern era, Android's over a decade old now, and it shows. You're stuck with the app gap either way.
I think it was a huge mistake to abandon FFOS but not enough people felt that way.
Compare how FFOS did to how Ubuntu Phone did which was essentially vaporware IIRC.
> I think it was a huge mistake to abandon FFOS but not enough people felt that way.
Sometimes you need to pick your fights and when even MS decides they don't stand a chance I guess it is time to stop bleeding money and try another approach.
Also, which other approach are you talking about?
Other approaches to furthering their mission: if getting their own phone to market is to expensive, regroup behind the main product(s) and use them to launch new approaches like we are seeing in the linked article.
I haven't looked at their books but surely there was enough money to fund FFOS if they just stopped their rapid expansion into every single emerging market they could find. Make 1 high quality, expensive headset, that nerds will buy (OnePlus did this), and keep working on the software.
IMO There are more than enough nerds out there (myself included) who will fork out $400/500 for a FFOS phone with how much of a difference it was from other OSes.
Very good point.
But you really need to nail the marketing on such a thing:
- you really want people to buy it to support mozilla and FFOS
- but you don't want to look desperate
- you want people to talk about it
- but there are a number of reviews and articles you don't want to be written. ('FFOS phone arrives and is already outdated', 'Too late, too little from Mozilla')
- etc
It is still early on the morning and I'm in a hurry so I cannot name any but I have a strong hunch that this has happened to comparable initiatives in the past few years.
I know it's naive to think so, but fuck marketing posturing, just make a good thing, in a strategic market, and stick to it. They literally did the hard work, making the platform, getting big apps to add compatability (LINE, a huge messaging app here in Japan had a FirefoxOS app) -- which was also easy for them... Then you just throw up your hands because of rough waters in literally the hardest arena you could have gone into (the low margin arena)... Also, people in other developing countries were starting to use the phone and it is way easier to develop for.
They really let go of something that could have changed the game. I see how their other products have benefitted but it really doesn't seem like they didn't have the money to do it, it seems like they didn't have the money to do it the stupid way they were trying to do it.
There's the firefox team, and the thunderbird team. I know mozilla does a lot of other shit, but maybe stop doing that other shit if you want to be an alternative to google/microsoft/amazon level players a mobile OS is strategic. Maybe stop trying to get clicks with IoT shit (gateway is cool though, so props) and just hunker down? They don't have a board in the traditional for-profit company sense so I dunno wtf.
I can't remember where I read (assuming I did) that mozilla's C-level team suffers a lot of turnover because people just come in, do whatever they want with mozilla's direction and then leave to some for-profit company.
Sorry this is more of a rant but I dunno, I just really feel like mozilla screwed the pooch. I literally flew to another country to try and buy the highest spec FFOS phone I could find (LG's FF zero phone I believe), and bought multiple because I didn't want one to die eventually. I can't be the only one who felt that way.
Firefox the browser was falling behind. While it was always my favourite it was totally eclipsed by Chrome for a while.
After they started focusing on Firefox again a number of great things have happened:
- Firefox is getting faster
- Firefox is getting safer
- Firefox is gaining mindshare
- Techies are starting to use and recommend Firefox again
- etc
All this puts Mozilla in position where they can do things like they now announce: they will make big improvements again, this time by squelching 3rd party tracking.
Still sounds like a better deal for them than no smartphones at all. Do they even care about Google's data collection? I find it to be a perfectly fair tradeoff for cheaper smartphones and free services.
A lot of other apps pops up a dialog saying they need Google services but then work perfectly without it. I'm not a android Dev but it's almost like that behavior is default even if the developer doesn't use any of Google services?
Could the Hooktube Redirector work on mobile too? https://hooktube.com/
On the PC I use that FF extension which sends any Youtube request to Hooktube and works like a charm.
It worked much better for me than the native player and I could download any videos at any time. Definitely a great application.
Mozilla has done incredibly well to have Firefox survive at all against competition from Microsoft and Google, and has undoubtedly had to make some tradeoffs (such as DRM), but it's at its best when it sticks to its principles.
This is something Mozilla should think about. There's a market for something like Chrome OS (digital signage, library PCs, the elderly, schools, etc).
I'm not really sure why you're viewing this as the end of the world, especially since all the money that Google pays to Mozilla enables the development of Firefox in the first place.
What else are you gonna use? lynx?
the bills don't pay themselves you know
The real explanation doesn't have anything to do with trust: Google pays Mozilla a lot of money to be the default search engine on Firefox. Deals like that are Mozilla's main source of revenue.
https://www.zdnet.com/article/googles-back-its-firefoxs-defa...
I'm not a conspiracy theorist, but seeing this so often...
As a personal story, a few years ago I was having trouble accessing youtube videos, buffering, timeouts, etc. I couldn't figure out why, tried upgrading my hardware, software, router, everything. But eventually I started suspecting my ISP[1].
I eventually tried using a proxy service to access the youtube videos. I think I routed my traffic through Iceland or something. Low-and-behold, perfect video streams _through_ a proxy routing traffic from another country. I had plenty of bandwidth. My ISP was just throttling my traffic.
Try a VPN, see if your ISP is messing with your traffic.
I don't trust Google either, and they already own me. But I fear my ISP more and don't believe that Google would be intentionally slowing you down. It's probably more of a function that Google optimizes for Chrome, less that they are trying to force you to change browsers.
[1] I will refrain from naming directly, but whose name starts with a 'C' and ends with an 'omcast'
I know that it could be any number of issues not related to youtube or centurylink, but that's been my experience 100% of the time so far.
They are not interested in user privacy for gods sake.
It seems very conspiracy theory'ish, but the speed and responsiveness difference is undeniable.
A YouTube developer once said on HN that YouTube uses Polymer for non-technical reasons. One could imagine serving as a testbed for Polymer could be that reason, with slower performance on Firefox as an accepted downside.
I have similar problems in Chrome on the rare occasion I use it, so my theory is just a lack of quality control.
[0] https://addons.mozilla.org/en-US/firefox/addon/multi-account...
[0] about:profiles (paste into URL bar in Firefox)
[1] https://support.mozilla.org/en-US/kb/profile-manager-create-...
Basically every site you visit will be completely isolated - and fully cleaned up afterwards.
1. I want my history saved locally (private browsing deletes history on close). 2. Private browsing requires a new window; I want to have a private tab. 3. All tabs in a private browsing window share the same cookies, so I can still be tracked* within a session; I want a new container with each new tab.
*trivially. I'm well aware that I can still be tracked by fingerprinting, etc, and I have other add-ons to help protect against that.
Not in Safari, to my experience
Can you selectively enable an add-on / extension for only one container but not others in Firefox with this extension?
This was a common feature request. Has it been implemented, yet?
Thank you very much Firefox/Mozilla team!
edit: One of the "compatibility" issues I always have with Firefox are sites complaining about the adblocker I'm using. The thing is, I'm not. lol
Is there a way to get rid of that? It seems to be not blocked by a default umatrix for example.
I think we really need a browser by a more trustworthy party. Maybe Debian could make a Firefox fork that is more user friendly in terms of privacy? Is there a way for vote for this or sponsor such a development?
/snark
The link also seems to say you can block it in uMatrix, but it isn't by default
They injected a non-removable external tracking system right into the browser that they market as privacy focussed.
In addition, they negotiated with google special terms for their analytics. This is the description [1] and this is the resulting options they got [2].
[0] https://github.com/mozilla/addons-frontend/issues/2785#issue...
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=697436#c14
[2] https://bug697436.bmoattachments.org/attachment.cgi?id=73207...
And no, I do not set the 'do not track' thing. Because that is one more bit of data sent out. To every website. Not just to Mozilla.
Actually more then a computer 'bit' by the way. What percentage of users use the 'do not track' setting? Let's say 1%. Voila. Setting it is worth about 7 bits of data to identify you.
In terms of a Debian firefox etc, I would worry about two things:
1. You'd be fragmenting the non-corporate* browser market, weakening the good that can come of that. Mozilla are invited to the table at browser discussions, Debzilla probably won't be.
2. You're reliant on the upstream from Mozilla, so you're still needing them to be big enough to continue to generate the base software the fork is coming off.
I don't consider Mozilla to be a bad actor and in fact like them a lot (although you may feel differently) however they have done multiple anti-user actions I don't agree with (this would be one of the lesser ones).
How are firefox design choices steered? Is it just at the whim of the corporation? If not, what would be the best way to become politically active in steering design choices like these in a pro-privacy pro-user direction? It seems like there are enough people with a similar sentiment on Hacker News to provide political weight to these issues.
*yes, strictly speaking Mozilla are corporate but I would say there are appreciable differences between them and Google, Microsoft, etc
You mean the tables where they then give in to making copyright a standard and giving legitimacy to that standard by staying on that table?
Fragmentation is not a pure evil.
That block is also going to keep uMatrix from being able to block anything specifically on addons.mozilla.org
Edit: OK, so I've played some with Wireshark. And it seems that Firefox is talking to many Google servers. So blocking google-analytics.com in hosts seems to do nothing. But then, this is a Firefox install with several extensions, so it's impossible to say who's doing what. So hey, I guess I need to check this out in a LiveCD VM.
I'd really want to know which websites do break, and if they do, in which fashion.
1 - https://addons.mozilla.org/en-US/firefox/addon/cookie-autode...
2 - https://chrome.google.com/webstore/detail/cookie-autodelete/...
However, don't use Disqus because they inject vulnerable JavaScript onto the page from unvetted ad networks and inject their affiliate links into every external link on your page[1].
[1]: https://en.wikipedia.org/wiki/Disqus#Affiliate_links_and_thi...
https://www.kajmagnus.blog/new-embedded-comments
(what happens if you try to post a comment. I think there'll be an error. I'm developing this b.t.w.)
I prefer a whitelisting solution. umatrix is a very elegant tool for this. You can say
On domain thisandthat.com allow scripts from domain
soandso.com'
Or On domain funkycars.com allow images from
domain carimageserver.com
That is exactly the level of whitelisting that feels logical to me.https://addons.mozilla.org/en-US/firefox/addon/umatrix/
I wonder how closely Mozilla analyzes the addons they offer for download? Are they as trustworthy as Firefox itself?
While that's a great approach for privacy, the usability loss would probably drive the average person away from Firefox. I think the listed approach is likely best for the average user, but I think it would be nice to have an option for a power user to turn on a whitelist-only mode. (One could argue that "install an extension" is an appropriate "option" for the power user, but as you mention, it's nicer to not need to rely on third party extensions)
I've used NoScript for a long time, and the hardest thing is knowing what the domain is doing so I can decide what to allow. It's hard to tell the difference between opaquely named ad-networks and opaquely named media player providers.
It would be nice if someone could start compiling a database that
1. groups together the domains used by different sites and services (e.g. website.com and website-images.com) and
2. includes a brief description of their purpose or business.
So, doubleclick.com and doubleclick.net could be grouped and easily identified as an ad network, google tag manager is a tracker, etc.
I doubt such a list would take any more effort to maintain than the current ad-blocker lists.
This has been a contentious discussion of late. Mozilla does manual (human) code review add-ons after they're submitted to AMO and made available for install, but they don't tell you which add-ons have been reviewed by a person and which haven't. It's apparently too costly and slow a process to review every submission, so much of this is automated, for better or worse.
Sophisticated users can download them and look at the code, as .xpi files are really just zip archives, but everyone else is on their own.
Is there some value I'm missing? Why blacklist this? I'd rather whitelist it.
Some discussion which mentions that here: https://github.com/mozilla/addons-frontend/issues/2785
Now they probably don't NEED it, but with every user they lose to chrome, they get less and less money until the only market for them would potentially be the privacy focused ones (although I here chromes got really good privacy features nowadays) which are such a small population that they wouldn't even have enough customers to justify the revenue to even match competing browser features. Thus, you would end up with a lackluster browser that cannot match competing browsers and its only niche are privacy people.
That is terrifying.
a) I can block it from websites easily. Not so from Firefox about:... pages.
b) Firefox has a marketing angle that they are privacy protecting. But injecting external tracking code into the browser itself is the opposite.
Homebrew also has it included with a pretty good description why I think: https://github.com/Homebrew/brew/blob/master/docs/Analytics....
Actually it is. It suggests the organization behind the browser actively takes steps to embed tracking right in the browser.
Only in the "Get Add-ons" section, mind you. Everything else is local.
That should be a whole lot more terrifying.
That is not the issue. The issue is when they send Firefox user's data to google of all places.
Apparently there's some people who are not fans of Piwik, that's a shame.
I really hope this kind of non-sense starts changing in Mozilla soon. This post is promising, but—as the gp points out—still not without glaring irony/hypocrisy.
Plenty of huge sites out there could quite easily demand the same thing without affecting ABC's bottom line while making the lives of others better in incremental steps.
"Mozilla went through a year long legal discussion with GA before we would ever implement it on our websites. GA had to provide how and what they stored and we would only sign a contract with them if they allowed Mozilla to opt-out of Google using the data for mining and 3rd parties.
We now have two check boxes in our GA premium account that allows us to opt-out of additional usage of our data. Because Mozilla pushed Google so hard, those two check boxes are available to every other GA user in the world regardless if they have a premium account like we do. GA also doesn't track IPs or store PII within the tool."
--
Seriously, those bastards.
Only having internal controls and debate, sustained legal engagement, and ultimately DNT-obedience.
I expected more. /sarcasm
"GA had to provide how and what they stored and we would only sign a contract with them if they allowed Mozilla to opt-out of Google using the data for mining and 3rd parties."
(emphasis mine) am I the only one who finds the usage of the word provide odd? Literally it means GA had to list what and how (insinuating they blindly trust GA to do only what it says it does). Not-literally but the flow of the phrase makes it seem like they want to convey "GA had to prove how and what ..." but without actually making that claim. In the case Mozilla does have proof why don't they share the anonymization framework with proofs? In case they don't we are supposed to be OK with their feigned naivety?
Google is a company that have a track-record of breaking the law to contravene user-privacy. They are also Mozilla's primary competitor (albeit also a large revenue source). Please tell me how, as a company selling oneself on user-privacy, approaching such a company to negotiate a contract that ensures you can continue sending them your users' data is not naïve? Calling it naïve is kind, as the alternative is malice.
No matter what way you cut it, Mozilla is sending your data to Google's servers, and they're deciding what to do with that data. An opt-out contract doesn't change any of that.
> I really hope this kind of sensible demand becomes wider spread, with more people going to Google saying "we only want to use your tools if...
To turn that around, you're going to Google saying "your market dominance makes your tools are so indispensable to our business, that we would rather go through an expensive year long legal discussion with you to negotiate better terms that consider alternative competing solutions"
Like when, and did they get punished for that and change their ways?
> did they get punished for that
Not really, unless a fine 0.002% of their revenue counts.
> and change their ways?
On that specific issue, after being investigated for it, it seems so. On any other handling of personal data, one can only make assumptions based on their ethical record.
And incredibly, Mozilla talked Google down from their normally "and we get everything your users do" conditions to only "and you make us a trivially changed default search engine, and we are under contractual obligation to anonymise the data we get through our GA channel. And offer everyone in the world the option to have that same anonymisation turned on. For free". That alone is worth one-time changing a search engine after installation. After all, you get this product for free, and you're even given every possible way for you to customize it should you not like any of the default settings, from default search engine to default skin to default webgl hardware binding settings.
So if you still think none of that was worth doing, and just seeing google.com find you search results, but clicking three times to change that is too much work, then... I don't know man. I don't think browsers are for you.
If Google is not hostile to all ads, then they are not "becoming hostile to ads".
https://news.ycombinator.com/item?id=16866086
(perhaps their new approach comes close to these ideas)
Screenshot: https://blog.nightly.mozilla.org/files/2018/08/f712ffde-1c33...
I'm curious how this will work with things like Google Hosted Libraries[1] (for just one of countless examples)?
The site will stop working if you block the request, but the tracking will keep working if you don't block the request.
This sounds ambiguous to me. Does it mean they won’t block third party cookies for NON tracking content?
We rely on third party cookies for Single Sign On auth. The question is, how will this continue to work?
Ideally, these browsers should finally allow access to client side certificates functionality so you can authenticate with websites without being tracked by the certificate’s issuer!
XAuth was a step in this direction. We need a place to store these certs or private keys. But are all major browsers even close to supporting it?
Update: Firefox supports them but it’s so clunky. Focus on letting any site install a certificate with the user’s permission, firefox!! Apple already allows web based download of configuration profiles, which is far more insecure:
https://developer.apple.com/enterprise/documentation/Configu...
https://medium.com/@sevcsik/authentication-using-https-clien...
https://support.mozilla.org/en-US/kb/tracking-protection#w_b...
Its original name was HTTP Switchboard, which I thought was a great descriptor for what it does (and for its interface).
Still Privacy Badger and apparently iPhone believes the cookies are tracking cookies. Privacy Badger doesn't see the difference between unique cannot-track cookies on `per-blog-sub-domain.example.com` and tracking cookies on `example.com`.
If you have time: How will the new Firefox browser deal with such cookies? (unique per blog cookies, different on each subdomain)
Maybe I'll have to make the commenting system work completely without cookies in any case, because of iPhone and Privacy Badger.
Apple's Intelligent Tracking Prevention (version 2 of which will ship in Safari/iOS 12 in September[0]) uses some sort of ML-based solution to decide what is and what is not a tracker, blocks cookies from being sent to domains that haven't been visited in a first party context, and has an explicit way for the user to opt-in to cookies being sent upon interaction in an iframe (e.g. the FB "like" button). Unclear how this Mozilla version stacks up.
0: https://webkit.org/blog/8311/intelligent-tracking-prevention...
Hopefully Firefox's implementation will avoid this pitfall!
I'm sorry but this isn't going to help motivated companies who have businesses and teams of engineers. It's just going to be some JIRA ticket that says "fix tracking for firefox users".
https://github.com/QuadrupleA/private-secure-sharing-buttons
What exactly is it they are blocking? Do they have a black list of sorts, or a heuristic?
Writing code to handle the failure to load of third party scripts like this should really be a best practice anyway. Even if you use subresource integrity checks on all the external scripts you load, what if some analytics provider's site is down for a while? Do you want your site to still work? I do. (Obviously this does not apply to scripts that are actually necessary for the core functionality of your site, but that doesn't really apply to analytics/tracking tools for the most part.)
Making this the default behavior of FF will make this sort of breakage more visible to more people, it's true. If anything maybe this will encourage sites to write their code to handle failure more elegantly and I'll spend less time annoyed. One can dream.
https://webkit.org/blog/8311/intelligent-tracking-prevention...
Why a website needs to know what fonts I have installed?
Why a website needs to know my plugins?
Why a website need to know the gazzilion of data points tools like evercookie are uaing to fingerprint users.
I asked for a website. Just give it to me. I will render it if I can. If I can not - too bad for the website.
So it can render the website in an appropriate font, while avoiding unnecessary network downloads.
>Why a website needs to know my plugins?
Plugins used to be used for rendering applets. It made sense to see if you had Flash/Java installed before trying to insert one.
Thankfully, plugins are now going away.
if (!isFontAvailable(font)) {
downloadFont(font);
}
It's not like a tracking script is going to try to iterate over every single existing font out in the wild for finger printing purposes. Doing so would be too easy to detect and block at the browser level. In the meanwhile, a script can get the list of fonts directly.That's not feasible without turning off JavaScript completely.
I know which option I want
This is a fatalist attitude that ignores things like ethics still remaining in developers, the fact that the cat-and-mouse means the defenses ARE working, and the fact that the engineers you are so awed by aren't really magicians.
Yes, there are data breaches and tracking, and it will continue. But the fight has moral and practical value, and I appreciate Mozilla for continuing it.
This works especially well if the person you're convincing to give up is, at that moment, winning, or beginning to win.
Which means they might always find loopholes like these to track you:
https://github.com/mozilla/addons-frontend/issues/2785
Search 'telemetry' and 'tracking' under about:config .
Set all true to false where appropriate.
search for google and mozilla, remove all url entries.
or just wildcard-block them via dnsmask.
"Historically, search engine royalties have been the main revenue driver for Mozilla. Back in 2014, the last year of the Google deal, that agreement brought in $323 million of the foundation’s $330 million in total revenue."
The default search contract went to Yahoo between 2014 and 2017 then back to Google after that. Looks like they do get most of their money from Google.
Is that an impact on LocalStorage?
By the way it's spelled "Tor" ;)
In the near future, Firefox will — by default — protect users
by blocking tracking while also offering a clear set of
controls to give our users more choice over what information
they share with sites.
Sounds promising. However, having Google as the default search engine is a good enough reason to discourage one from using Firefox. Wonder if it would ever change.Within a few seconds I can easily adjust my search engine preferences in the options menu, and DuckDuckGo is listed as one of the default options.
Hm? The only browser that doesn't ship Google as the default search engine is Edge (with apologies to Lynx users). Is the alternative to suggest that people not on Windows simply shouldn't browse the web? Changing the default takes only four clicks: search box -> change search settings -> default search engine -> select from dropdown menu.
As far as I recall, the Google search is part of the funding agreement (because Mozilla is still a non-profit, the money has to come from _somewhere_ and we, the users of the browser, sure aren't paying them?) with the explicit agreement that it is trivial to change the default search engine for people who don't want to search with Google.
Click on the drop-down on the left of the search field in the browser, you click "change search settings", you pick your preferred search (options for which include "duck duck go" these days) and you're done forever. That... feels like a perfectly fine way to go about offering people what they want: make what the majority wants the default, and make it trivial to change for people with different wants or needs.
HN users will switch to something they prefer, normal users wouldn't know there exists anything other than google. By making what you think majority wants as default, you are forcing something on people who doesn't know any better.
If somebody cares about their online privacy, they can change the default search engine very easily - I think what we should be doing is teaching the average web browser what kind of tracking goes on so that more people are willing to switch to things like Firefox/DDG.
https://duckduckgo.com/ -- The search engine that doesn't track you.
> make what the majority wants the default
No. That amounts to choosing the default for the majority and diverting majority to a particular search engine.