Latest Firefox rolls out Enhanced Tracking Protection 2.0
blog.mozilla.org
blog.mozilla.org
"Protip: Use Firefox instead of Chrome. We get very little data from Firefox users"
Without an adblocker the internet is such a slow heap of trash that I'd never go back to not using one. This is also one of the main reasons I use my iPhone so little, since it doesn't really have any way to adblock.
https://apps.apple.com/us/app/wipr/id1030595027 Or like, any similar app. There's hundreds of them.
Is adblocking not common? Every tech literate person I know uses an ad blocker. I'd say about 30-40% of millennials I know use them, most using ADB or uBlock Origin.
Every time I see someone using a browser with ads I forget what a nightmare the internet is.
At my company people are either don't know about them, or actually fundamentally disagree with their purpose. (No, it's not an AdTech company, before anyone asks)
I don't think most people minds ads, such as on TV, but everyone hates the ad that is 10x the volume of the show and that's how the internet feels to me currently.
Is that true? I despise ads and the entire advertising industry. I would wear special glasses that would block billboards from my vision if they existed. I pay extra for the ad-free version of Hulu. When I'm at someone's house and they have cable and the TV is on, I find ad breaks incredibly jarring.
Am I just an extreme outlier? It would make me sad for humanity if that was the case. Not minding blatant emotional manipulation in your face all day seems... not great.
if you spend a significant time travelling through rather diverse countries, one of the first thing that hits you is different laws and norms around what can be advertised and where. moving through dictatorships and seeing elections is eye opening in its "weirdness". as a non American, visiting America and seeing laws, flags, billboards and medicine advertising is weird.
anyway, my point is, if you haven't been brought up with it, you see it for what it is, and normal becomes what you experience every day. one you spend a few years ad free, it's incredibly hard to go back, it's really jarring, and you see advertising the same way you see plastered images of the dictator in absolutely random locations when you visit other countries (and there's a good reason for that, because they're fundamentally the same thing).
No. You are not alone. MOST people don't realize that there is an alternative.
And I do like to pay for services to bypass ads even though I use ad blockers that mitigate them anyways.
So number of (uBO + ABP users)/ Firefox users is probably 33%. So that might be where it is coming from
"Has addon" metric. uBO + ABP is far less than 33%.
More than a handful choose that browser for privacy, including keeping stuff private from Mozilla.
Also those that disable telemetry after starting Firefox still sent telemetry. Mozilla only promises to delete it after 30 days not that they don't generate a number that says what % new installs in the last month disabled telemetry (though they don't publicly report this to my knowledge).
So that leaves those with whitelist only firewalling or similar measures that I (hope?) we can all agree isn't going to swing these numbers at any interesting digit position.
But I just can't bring myself to indiscriminately block all ads, knowing how important they are as a funding source for the websites I use.
There's only one thing that destroys privacy even more thoroughly than ad targeting: payment.
News, community, educational, etc? Is it a small group of sites, or a wide variety?
It's also got me really close to paying for YouTube red, which is the other option,and o e I wouldn't consider without the annoyance of ads.
Essentially, it's the great variety of what's available on the open Web that I don't want to lose. I don't want everything to become one big app store with all its suffocating narrow-mindedness and oppressive control freakery.
Would be way too hard to solve something like that with subscriptions.
Maybe one day, concepts like Brave Rewards or Google Contributor[0] will actually work... No idea what it'd take for those to reach critical mass, maybe government intervention.
There must be a better way!
I disagree with this. Maybe you can elaborate?
If I am paying for a service then there is no incentive to mine my personal data for revenue. It's a mutually beneficial transaction. And there are plenty of ways to hide your personal information (even your name) when paying for something (e.g. using a service like privacy.com).
I doubt that there will ever be a widespread, convenient way to make anonymous electronic payments. The authorities would never allow that to happen (for understandable reasons I have to say).
Incentives are not working at all. Lots of services I pay for go to great lengths to squeeze even more out of that customer relationship. And how could I possibly trust a large number of small companies I know very little about?
I try to minimize ad problems by using containers and profiles. I have a Facebook-only container and Google-only container and never login to either in any other container. So far this approach seems to work for me.
Also important: start asking websites that need to take payment to provide a cryptocurrency alternative. Something based on Ethereum blockchain preferably, given that is possible to easily get stable-tokens (meaning, no volatity risk) and that is on its way to get rid of Proof-of-Work.
The ad-based economy needs to die and we already have the tools to kill it. All we need now is to stop with the excuses and take action.
I don't believe cryptocurrencies will work. As soon as they become widespread they will be banned or regulated just like other forms of electronic payment, including know your customer rules.
For the moment, I don't see that we really have the tools to replace ads, much as I would like that.
No. The biggest claim of Brave is that all of the information for ad matching is in the browser. So they can not control it. The only thing that Brave can control at the moment is the on-boarding ramps - i.e, if you want to take your BAT out of their wallet and to your own, you need to go through KYC via Uphold.com. But you can pay and contribute BAT to other people even if you haven't done KYC.
Even in this case, the KYC that needs to be done is only with Uphold. After you take out your tokens you are free to spend them however you want and no one will ask you anything.
> I don't believe cryptocurrencies will work
They already do.
> regulated just like other forms of electronic payment, including know your customer rules.
Even in this libertarian nightmare that you are imagining, crypto would more likely help you to keep your data away from businesses and third-parties. If every transaction needs to be authorized and monitored by the government or central authority, then there is no need for the business to collect any information from you - all they would need is to ensure that you are sending your payment from a government-validated address.
Governments don't do that today due to the sheer costs of trying to run such an operation. But tracking things on the blockchain is reasonably easy, so there would be no need for banks and third-parties to do the dirty work for them.
In any case, it seems like you are just looking for a way to rationalize your current behavior. I only mentioned Brave because it is the first strong offering for an alternative to the ad-based economy. If for whatever reason Brave stops being a valid alternative, there is nothing holding you to it. Why not try it for yourself?
Not in the least. I find ads annoying and I don‘t have any skin in the game when it comes to advertising. But it‘s not a matter of simply trying Brave. I want to understand how it works for users and also for publishers. And I want to understand how it is not a proprietary system with a gatekeeper role as a structural feature.
Hell, a competitor could even decide to have an advertisement network that also operates with the BAT supply that has been taken out of the exchanges. If for some reason the company starts doing anything user-hostile, they will lose the business to someone else.
The only important thing is that anything is better than the status quo. If you are weary of Brave, you can go for something like flattr, or you can start looking into crypto as a way to pay directly for those you want to support (and still keep your privacy). Whatever you decide, just please realize that "I don't like ads, but I don't see any good alternative" is not a valid statement anymore.
Does Brave support a way for other ad networks to integrate into their BAT system? If not, any competitor would first have to popularise their own web browser.
BAT is just a token like any other on the Ethereum chain. The "easiest" way to acquire at the moment is by using the Browser and setting up the wallet, but if you don't want to that you can just go any exchange and trade it. Or you can have a website and accept it as payment.
I am sorry if I made you on focus on the specifics of Brave when the point of my original post was to say that there are alternatives nowadays for ads. Alternatives that may not be perfect, but that do work and are better than the status quo.
In any case, I think that the best way for you to understand how things work and make sense of what I am saying is if you try it yourself. You can start by using Brave on your phone to replace Chrome or Safari and get a feel of things, see how the rewards system work, etc.
What I mean is Brave‘s specific Browser integration that creates a compensation scheme for publishers. I would only support such a system if it doesn‘t put Brave a privileged gatekeeper position.
I’m not sure which other alternatives you‘re talking about specifically, but I have explained many times elsewhere in this debate why I see subscription based services as an additional loss of privacy and why I don‘t believe that there can ever be a widely used general purpose system of anonymous electronic payments.
But I do believe that a Brave style system could work if it can be structured in away that does not allow one company to impose content restrictions.
There is nothing stopping other browsers to adopt it. There is nothing stopping other companies to create a similar alternative. There is nothing stopping a publisher to get an advertisement deal and place an ad on their website; as long as it does not use third-party cookies or tracks you in any way, it won't be blocked.
> subscription based services (...) loss of privacy (...) there can ever be a widely used general purpose system of anonymous electronic payments.
Look, I am not trying to sell you anything ok? I don't work at Brave and I am not interested in doing shilling for any specific cryptotoken. It's okay if you want to say "I don't want to pay for content that I am now getting for free. It's also okay to say "I don't mind having my data exploited in exchange of a few dollars that can go to content producers and publishers".
The only things that you are saying that are total BS is that (1) ad-tech is less of threat to privacy than a digital economy based on crypto and (2) that no alternative currently exist.
Your argument against usage of cryptocurrency for payments is just concern trolling. You are presenting a very, very unlikely hypothetical (companies might be required to collect user data to accept payments) in order to justify the status quo. Likewise, you are making these near-impossible demands from a company that has a fraction of the market share on a trillion dollar industry while having no qualms with all of the ethical violations from the dominant oligarchy. Again, concern trolling.
I'm not accusing you of anything either. I wasn't thinking for a moment that you were trying to sell me something or that you were shilling.
It's a simple disagreement. I'm unconvinced by the case you're making for specific alternatives. That doesn't mean I'm happy with the status quo.
You have said absolutely nothing to show that Brave would not be in a position to impose content restrictions if their system turned out to be successful.
My concerns about cryptocurrencies are anything but hypothetical. The authorities are extremely jumpy about cryptocurrencies. Regulation is already well under way. There have been crackdowns on crypto exchanges all over the world. Banks are suspending accounts left and right. I was personally invited by the local tax authorities to take part in a consultation on the subject.
And have you not noticed what happened when Facebook threatened to introduce a payment system that only so much as mentioned the word cryptocurrency? It was absolutely crushed before it even got off the ground. Granted, a lot of the concerns were related to Facebook's oligopolist status. But there were also huge concerns about the possibility of widespread money laundering, tax evasion and funding of terrorism.
What we need is a system that inherently limits the size of any financial transactions that a single party can initiate. That is very difficult to do while guaranteeing anonymity.
Let's not accuse each other of bad faith when what we're talking about is simply a difficult problem that many have tried to solve with very limited success.
> The authorities are extremely jumpy about cryptocurrencies. Regulation is already well under way.
Regulation already exists. It is due to the regulation, for instance, that Brave requires you to do KYC if you want to get the money out of their wallet and into your own. It is due to regulation that exchanges that do not comply with the law are getting crackdowns.
This is not an argument. This is FUD.
> Let's not accuse each other of bad faith when what we're talking about is simply a difficult problem that many have tried to solve with very limited success.
If the status quo was not harmful for society as it is, I wouldn't be nagging you about it. But this whole thread started with you claiming that accepting ad-tech's destruction of privacy is less of a problem than any alternative proposed so far. This is not a "simple disagreement"; it's plain wrong.
In my view, the status quo of ad funding is very annoying and somewhat harmful, but it is far less harmful than the app store model, which is pure oppression.
That's why I tend to be sceptical of any new scheme that once again puts someone in a gatekeeper role.
With regard to any widespread rollout of cryptocurrencies for anonymous payments you're going to have to accept that I'm pessimistic. You can call it FUD all day long. That's just aggressive rhetoric that adds nothing to the debate.
It's not that hard to make the argument that the moment that it became normal for websites to rely solely on ads for its revenue was the moment that we subverted a lot of our cultural institutions.
It's not that hard to make the argument that the rise of populism and extremist politics is rooted in this "eyeballs is all that matter" mentality for publishers.
It's not that hard to make the argument that ad-tech is making so many people addicted to our tech gadgets that its damage to the general public health is going to make Tobacco companies look innocent by comparison.
If that is not enough for you, take the amount of fraud and the amount of money that goes from advertisers to the pockets of the big ad companies and I hope you realize how ineffective it is.
> That's why I tend to be skeptical of any new scheme that once again puts someone in a gatekeeper role.
We are going in circles now. Again, there is nothing about Brave and its ad network that can not be replicated by any one that decides to compete with them. It's not like an "app store". The ads are optional, you joining the rewards program is optional. If for some reason someone else decides to create a competing ad network, it could run either as a fork or an extension. I fail to see what is so potentially evil that they can do that is worse than the evil that is currently done by the status quo.
Populism and fascism have been a problem for far longer than we have had ad-targeting. That said, I'm not opposed to putting restrictions on what ad networks are allowed to do.
>Again, there is nothing about Brave and its ad network that can not be replicated by any one that decides to compete with them.
Of course not. Others can build search engines and social networks and app stores as well. All of it can be replicated - theoretically. That doesn't change the fact that Google and Facebook and Apple are in an all powerful position to dictate content restrictions and access.
So in order for me to support a any new system, there would have to be an element of deliberate design to prevent that sort of power imbalance. I don't see that Brave has that, but I'm going to look into it more closely as I could easily be wrong.
I didn't say that it is the sole reason, but it certainly is one of the reasons and it is something that I have a way to control my input into the system.
> I'm not opposed to putting restrictions on what ad networks are allowed to do.
The problem is not "ad networks". The problem is in ad-funded business models and in PPC/PPP. When the business have the consumers just as a vehicle for delivering eye-balls, business only important metric is "how many eye-balls can we get?" and this is where everything went to shit.
> So in order for me to support a any new system, there would have an element of deliberate design to prevent that sort of power imbalance.
On one side you have an incumbent that is light-years away from having any kind of dominant hand and that you can hedge against an eventual abuse from their side. On the other you have giants that "are in an all powerful position to dictate content restrictions and access" but your only response is "it is annoying and somewhat harmful" and shrug it away? "Oh, I am pessimistic about every alternative that came so far, so let's just keep the existing abusers?"
I don't get this logic at all. It is either a display of apathy or dishonesty.
If a site wants to use adds that will work despite, I have no issues seeing them. The extensions block pretty much any I would find unethical.
Can you expand? Because I disagree. I would rather a company have my name, payment info, and email address than all those things plus other personally identifying information. I feel like a payment model decentralizes the issue and that I would not be tracked around the web. I don't need the WaPo to know the other sites I've been on, what my political affiliations are, my age, gender, etc. This is because I don't see the issue as companies know who I am, but rather that I don't like that companies have intimate details of who I am, or maybe more simply put "who I am vs what I am." To me the latter (tracking) is invasive, the former (payment) is consensual. As one might say "just shut up and take my money."
But I am open and interested to differing opinions.
I don't know many subscription based content publishers that promise not to monetise what they know about me in all sorts of other ways. I do have a newspaper subscription. That doesn't stop them from showing me ads or using ad networks and trackers. Payment networks and banks monetise my payment data as well.
Even if a particular publisher is willing make such promises, I wouldn't have much confidence in their ability to keep my data safe.
So the upshot is that I simply don't want my real name irrefutably and permanently linked to everything I read, write or watch.
What ad neworks know about me is extremly patchy. Every time I see what they think about me I wonder who on earth would ever consider paying them for that rubbish. But that's not what it's about. All they need to be able to do is make predictions that are slightly better than random guesses.
https://www.businessinsider.com/30-of-all-internet-users-wil...
Also depends on the financial model, if it's primarily ad based then the group of users you don't have good ad data for isn't something you should care about either.
Also to note the above % for FF share isn't just from 3rd party analytics anyways, places like Wikimedia report similar numbers. Different services different amounts but again, target demographic usually and not by much unless it's extremely tech niche or something.
10M Brazil
13M China
12M France
20M Germany
12M India
9M Indonesia
6M Italy
7M Poland
7M Russia
30M United States
It's honestly a bit frustrating how even on HN everyone thinks they know who around the world uses something more than the actual public data on it. On one hand you have people insisting the data is missing huge swaths of people and on the other you have people insisting a region has over half the users when that would be less than half the users according to the very data the other person is trying to say is missing lots of people!
It seems amazing how clueless people on hn are yet they post their middle class thoughts.
25% is indeed greater density than 10% and bicycles have two wheels but neither has anything to do with making "50% of global FF users are based in DACH " anywhere near an accurate statement.
DACH is not just Germany neither is it just Germany, Austria and Switzerland it's the German speaking world (and that isn't just DE, CH, AT, LU and LI either) Those reach nearly 30-40% of worldwide users go look it up yourself.
>25% is indeed greater density than 10% and bicycles have two wheels
Someone seems mad his useless comment got debunked. You tried to "well actually" while not understanding the irony of your own post.
>HN isn't the kind of place for your closing comment. Also you replied to yourself by accident.
That should be a reply of mine to you seeing you are literally just posting for the sake of posting after realizing your argument is beyond useless. Your post could literally have been "I LIKE SPAGHETTI" and it would have contained the same amount of valuable information as it does now.
You can block ads in Safari iOS with a Content Blocker. 1Blocker is pretty robust: https://1blocker.com/
Firefox for iOS also has Tracking Protection built in, which blocks most ads.
Focus is designed to be a short use browser that deliberately minimises tracking, akin to fast access private browsing.
That said you only need to get the app to turn on their tracking protection which blocks ads on Safari.
https://www.bleepingcomputer.com/news/software/mozilla-is-ad...
- ios does not let you see the traffic
- ios diverts all traffic anyway, and allows apps on the phone to have visibility into web traffic (deep linking)
It'll definitely help with the web if your goal is just to speed things up and make things look better, but if you're worried about privacy, iOS's browser is going to be less thorough than other platforms. It doesn't even support page-source rewrites, let alone protecting against more advanced anti-adblock techniques like CNAME cloaking.
Funnily enough, this has come up a few times in the context of Chrome's manifest V3 changes, where people have asked why it matters since Safari already works pretty similarly to what Google is proposing. Ironically, the answer is that the similarity is exactly why we know it's a bad idea for Chrome to go in the same direction. Safari has less effective adblocking compared to where the rest of the industry is at.
It's always going to be easier to bypass what is effectively a declarative DNS blocklist than it is to bypass a system that can run blocking logic per-request.
You can use wireguard to tunnel to it when you are outside of your home network
Not much setup or configuration needed.
Reading this, I was actually surprised to find that for some reason or other this has gotten a lot better for me during the 2+ years I've been using uMatrix.
At first it's rather annoying to enable CDNs and stuff for the sites you frequent, but mostly I've started noticing that the sites that break for basically no good reason are the ones that a sane person probably shouldn't visit anyway. So maybe it is just that I've started steering clear of those sites.
Also as a side note, uMatrix is awesome. Many times even on HN I'm surprised to find comments complaining about pop ups or something, and realize that uMatrix silently made my browsing actually tolerable.
It is high maintainance, only if you visit many new sites every day. For a single site/domain, set it once and go.
There are built in 'recipes' allowing YT embeds, twitter embeds, google capthas if a site wants it.
Once you globally whitelist CDN's (cloudflare and others), it's enough. For popular sites (reddit, YT, twitter use the Recipes)
I should try globally allowing the CDNs as you suggest and see how it feels. At that point, though, I wonder how much I'll be blocking that won't already be blocked via the blocking lists.
1: apps on my Windows, Android, iOS devices along with specifying it as the default nameserver in my routers.
My concern with ad blocker proliferation is that it invariably leads to paywalled content. Which I’m sure most HN users are ok with, thanks to their 6 figures jobs, but I think it’s a bad thing overall.
Yes.
1. Content blockers for safari are sold in the App Store. Not bad.
2. A private Pinole instance on a vps. Just set your phone to connect to it. There are turnkey docker installs of this now.
Neither are perfect / have quirks. I def recommend pinhole. I thought it would be a pain to set up, it wasn’t and it’s great.
Games for my young kids have terrible ads and finding quality, ad free ads (even paid) is very hard to do. I really wish Apple Arcade would release some early-ed games.
Presuming you have a decent set of rules it can block ads and shield the IPs of your kids devices.
It's just that Firefox is noticeably slower than Chrome (or at least was about a year ago). Even simply switching between open tabs around what feels like 0.5 seconds, whereas on Chrome, tab switching is instantaneous. I've run Firefox in multi-process mode (since that was an option), but even with it, in general it seems like Firefox gets noticeably slower than Chrome when you have a lot of open tabs. I've always preferred and wanted to use Firefox over Chrome, but the performance degradation was too much to bear.
Could you guys please add a feature where any link opened from within a container opens in the same container category? (Like if i'm in Personal, I stay in Personal unless I explictly opt-out)? It's such a pain to constantly right-click and open tabs. Thanks :)
Open the extension, click on 'Personal' and deselect 'Limit to designated sites'
PS: You can ctrl+click on the 'plus' button on the tab bar to open a new tab in the current container.
N.B. I'm currently a happy user of Brave as it has integrated AdBlock-style blocking, fingerprinting protection, and HTTPS Everywhere. I'm always evaluating my options as a user, though!
So there might be a factor there. But perhaps it could be an add-on. I discovered that Lastpass injection feature to autofilled had a performance impact.
Switched to Bitwarden and it was noticibly faster.
Google Docs performance is a long-standing issue, but it sounds like you're seeing an unusual problem. (I usually have 10-20 Google Docs tabs open all day in Firefox Nightly.) Perhaps try reproducing with any Firefox extensions disabled. Some, particularly ad blockers, can cause performance problems as they repeatedly scan the page's DOM.
Sorry ... hijack ...
Could you please implement a special:
settings://tabs
... URL that just gives a plaintext list of tab URLs currently open ?
As it stands, the only way to get this list is to poke around in /Library/ files and then use JSON command line tools to export ... etc., etc.
I just want a built-in page that gives me all the URLs of current tabs. I could then cut and paste them, or save the page, as I see fit.
1. Shift+Ctrl+D to bookmark all open tabs (in the current browser window) in a new bookmark folder.
2. Right-click on the new bookmark folder and select "Copy".
3. Then paste into your favorite text editor.
This isn't so much a feature request as it is a request for some simple debug info which can be accessed with a special://url (whatever those are called ...)
FWIW this sounds super easy to do within an extension: https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/Web...
It probably is but I feel like debug/info URLs are simple and lightweight and belong in the core feature set - especially this one which you can find hundreds of examples over decades of people asking how to get this information.
I actually never filed a bug report. I didn't think of the slowness as a bug per se. I thought it was just that Firefox was slower.
One thing I should note is that I've been using an ancient Firefox profile. I copy the profile onto new installs, and I've got bookmarks going all the way back to 2008 or 2009 (my bookmarks are organized into 50 or 100 folders). I also have a bunch of extensions.
I typically have well over a hundred tabs. I used to use the extension Tree Style Tabs, and sometime get close to a thousand tabs (with like 5 to 10 windows, with between 100 to 200 tabs per window).
Also, Firefox was slow on every laptop I used, but not on my desktop. I have a desktop that's fast by 2015 standards. It's got a i7-5280K, 32 GB RAM quad-channel, etc. The few laptops I've had have had far slower CPUs (the fastest one being an 8th Gen Intel i7 "U" processor). While on my desktop, I might average 700 tabs, on my laptop I try to have under 200 tabs.
I've always been on the newest versions of Firefox. For my laptops, I was on Aurora / the Developer Edition. On my desktop (which has an Ubuntu-based Linux distro), I'm on Firefox nightly.
Not sure if all of that info helps. I haven't investigated too much into what's happening. The most probably culprit might be my ancient Firefox profile. Perhaps, if I go back into Firefox with a fresh profile, it'll be a lot faster.
I am replying only because I think your comment can be misleading to other readers of HN.
Try one of the many browser extensions that spoof Chrome useragent. For me it makes a big difference on Google search results and Youtube
Your browser fingerprint appears to be unique among the 303,579 tested in the past 45 days.
Currently, we estimate that your browser has a fingerprint that conveys at least 18.21 bits of identifying information.1. Blocking redirect tracking is about more than just fingerprinting users. I'm a huge fan of Panopticlick's work here, but it's not a be-all end-all measure of whether a browser is getting more or less private. There are a lot of different, complicated things we're talking about when we bring up browser privacy.
2. Disable Javascript with something like uMatrix by default, and that number will drop dramatically. By default with JS disabled, I think my Firefox leaks about 8 bits of information, which Panopticlick lists as sufficient protection.
Major caveat in that non-JS users are likely disproportionately represented at Panopticlick, and people shouldn't use Panopticlick as more than an indicator of what's possible. In the real world, disabling Javascript will leak more bits since fewer other users will be doing it.
However, it's still likely worth doing if you can tolerate the inconvenience. And of course, the more people that block JS by default, the better protection it provides.
The point of these by-default protections is that they are supposed to work for most people. Suggesting that someone techie can do extra stuff that most people won't do is not really germane to the conversation.
Of course this depends on what sites you frequent, but you'd probably be surprised. I disable Javascript by default, I'd say 70-80% of the sites I visit load. An even larger percentage load with only 1st-party Javascript enabled.
I do think excessive required Javascript on the web is a problem, but I also think Hackernews overstates this problem sometimes, to the point where people think it's literally impossible to browse the web without Javascript.
I don't think that characterization is helpful, a lot of us browse the web every day without Javascript running by default. Most news sites are fine, high-end publications like the NYT actually tend to be pretty good at progressive enhancement. Lower-quality engineered sites like Kotaku won't load images, but the articles are still completely readable.
And to be clear, permanently enabling Javascript for a specific site in UMatrix only takes 2 mouse clicks.
> Suggesting that someone techie can do extra stuff that most people won't do is not really germane to the conversation.
I suspect at least 50% of Hackernews readers are smart enough to disable Javascript and selectively enable it when a site breaks. It's germane to the conversation in that those people might want an effective way to mitigate tracking.
I don't have to restrict myself to the lowest common denominator of features when I'm choosing a browser, and I don't think other users should need to either.
Of course raising the lowest common denominator is important, but if you really care about your own security and privacy, at some point you have to make technical decisions that go beyond that. I think it's relevant to the conversation to point out in a technical forum that those options exist for people who need them and can use them.
Out of curiousity, what is the "threat model" when using Panopticlick? Is it suited for users that just want to avoid tracking for commercial purposes? If the user does not enable Javascript, what good is that user to such trackers? How much commercial tracking is conducted without any use of Javascript (and without cookies)?
So something like disabling Javascript might mean that that you blend in on Panopticlick because a lot of users disable Javascript. But on a small news site or ring of nontechnical blogs, it might help narrow you down because very few people disable Javascript.
The other thing I want to get at is that privacy isn't just about fingerprinting, it's also about the effects of being tracked, and what specific information that you're leaking. So what you bring up -- that not having Javascript makes a user less useful to an ad network -- is true. Not having Javascript makes it harder to show you flashy ads or to guarantee that you're looking at them. It makes it harder (but not impossible) to set up persistent tracking that works over longer periods of time and across multiple devices. It also makes it harder to detect and circumvent adblockers.
Disabling Javascript doesn't address threat models like using your location to change the content that you get served, or sticking information into cookies, or doing some screwy things with image caches.
But that's... sorry, it's just a kind of complicated question. I'm not sure I can give a short, concise answer about how good you should feel about a low Panopticlick score, I think that's dependent on what sites you visit and what kinds of tracking you're trying to prevent, and what other measures you're taking. It's just a very broad topic.
> why not just disable (HTTP) redirects?
Unfortunately that would break a lot of sites, so it's not feasible as a default setting in the base browser. That being said, I believe that what you're looking for is `network.http.prompt-temp-redirect` inside `about:config` if you want to disable it for yourself.
I'm not sure I'd advise it, and I suspect that it's a kind of superfluous setting if you're already invested heavily into other privacy settings, but maybe there's some benefit. I haven't played with that setting to know for certain whether or not there would be non-obvious downsides or caveats.
There is some relief for the location issue. It is not too difficult to discover alternate geolocated IP addresses for websites that choose to employ such strategies. Further, proxies, even just Tor with a proper config file, can give the user a specific geolocation of the user's choosing.
Do users choose different user-agents for different web usage? On smartphones we routinely see users choosing a variety different applications for different purposes, e.g., an online shopping app versus a news reading app. For example, if the user is engaged in online shopping, then she almost certainly will need to enable Javascript and cookies. However, if the user is reading^1 news on small news websites or nontechnical blogs (to use your examples) then IME neither Javascript nor cookies are required. Using the same application (the same "modern" browser) for both purposes, and with Javascript and cookies enabled, is, IME, from a technical standpoint, unnecessary. The text of the articles can be retrieved and read with much simpler software; none of this software needs Javascript nor cookies to perform its respective task.
1. The situation changes if the user is "viewing" news (photojournalism) or "watching" news (autoplaying videos). IME, neither Javascript nor cookies are required, however short of the user writing custom Javascript to process page contents, employing some software, e.g., standard UNIX utilities, other than a modern browser, to extract the image or video URLs, is sometimes necessary.
Well, to push this a step farther, the great thing about extensions like uMatrix are that you can turn off Javascript+Cookies on a site-specific basis. So I know people who would feel like it was too cumbersome to juggle two browsers at the same time, but who don't have the same aversions to saying, "oh sure, I could turn Javascript and cookies off by default, but turn them on for this one specific video/shopping site."
> There is some relief for the location issue.
Definitely. I didn't want to go too in depth here, but this one of the things I'm getting at when I say Panopticlick shouldn't be the only thing people look at. Panopticlick doesn't even consider geolocation around IP addresses at all, so there's an entire vector there where Panopticlick won't tell you whether or not you're vulnerable.
There's a world of considerations here that are just hard to fit into a single comment.
> employing some software, e.g., standard UNIX utilities, other than a modern browser, to extract the image or video URLs, is sometimes necessary.
cough youtube-dl cough
If you're a user who's comfortable with the terminal, this can be a game changer even ignoring the privacy aspect. I see people all the time on HN complain about bookmarking a video and having it disappear later. Not a problem if you download them.
If you want to go even farther and you're comfortable with Bash scripting, youtube-dl even has options around managing playlists, so you can kind of "subscribe" to ongoing playlists/channels and treat them like podcast RSS feeds.
But with that I'm straying off topic.
https://addons.mozilla.org/en-US/firefox/addon/canvas-finger...
https://addons.mozilla.org/en-US/firefox/addon/webgl-fingerp...
https://addons.mozilla.org/en-US/firefox/addon/font-fingerpr...
https://addons.mozilla.org/en-US/firefox/addon/audioctx-fing...
I would really love to have more addins like this, doing one thing and doing it good. They will kill fingerprinting and as a proof, I was downvoted the next moment i posted the links in another post but I want you to know there is a way out.
Make sure you turn them on though!
Firefox by default doesn't block canvas fingerprinting, that's a setting you need to enable in `about:config` under the `privacy.resistFingerprinting` section.
The issue I had more often is random captcha's for sites I actually need to use not letting me through. (Thanks school).
My solution for this is to keep de-googled Chromium installed, and just use it when I run across these sites.
There are a few ways of looking at the captchas; the optimistic lens is to look at it as a response to people who say that it's impossible to meaningfully reduce fingerprinting. If that was true, Google wouldn't be so mad at me for flipping this setting on.
But it does make some browsing more annoying, especially if you're not technically savy enough to realize what's going on when something unexpected happens. I think it's the right decision for them to have it off by default (at least for right now).
If you have the "restore previous session" option enabled and have grown accustomed to Firefox remembering all the windows you had open before, you may find it annoying that it no longer remembers the size of your windows; it just puts them to the default size. Although now that I think of it, this might possibly be specific to the X11/Linux version, as other window systems might handle window size in such a way that it's not affected by this.
Also, if you like having websites automatically detect if your system uses a dark color scheme and adjust their CSS accordingly, that no longer works. Again, speaking from an X11/Linux perspective here.
How do they decide which captcha is harder ?
I think that only two things can defeat this madness
1. Legislation
2. Breaking captcha to the point it's not effective anymore
Ideally I’d like to see fewer captchas. But there’s no good alternative to it really. I mean, requiring phone verification instead is an alternative. But I don’t necessarily want to hand out my phone number to each and every site on the net that I interact with either.
For example, a fingerprinting script might try to measure the viewport height and width, calling on window.height can give it that info, but if Firefox were to fake that info when a friendly script calls for it, the page might try to reflow to the new size, etc. All kinds of desired behavior can use these same values, the challenge is determining whose a bad actor.
That said, it wouldn't hurt to split it out into a different about:config preference. I'd probably disable it since I don't use a vpn so my time zone can be deduced from my IP anyway.
(Or, if you’re just interested in helping advance the anti-tracking ecosystem! In which case you can test resistFingerprinting and file Webcompat issues when you encounter them — but be sure to mention that resistFingerprinting is enabled or your issues will probably be closed “unable to reproduce”.)
The first is, like you said, that resistFingerprinting can be kind of a gateway to Tor in general, since Tor will do everything resistFingerprinting does, and better.
The second is that uplifting Tor features to "normal" browsers and allowing "normal" users to enable them makes it harder for website operators to say, "well, I don't need to worry about this because it's just Tor users and they're all criminals." Right now, enabling these features in Firefox will result in some website breakage, but as more people say, "well, this is a mainstream browser thing", maybe more website operators will start to accommodate the protections.
I think there's value in continuing to blur the line between Tor and other browsers, if only to push the idea that the kind of privacy protections Tor offers should be available to everyone across multiple browsers. Not to mention that it's nice to be able to take advantage of a few Tor features while still getting stuff like fast video streaming.
But agreed, there's definitely a continuum here, and it might be valuable for some people to explore farther down it.
E.g. I usually use Firefox with NoScript. I frequently exit Firefox; when I do I clear everything using "Clear history when Firefox closes".
When I want to visit a site that requires JavaScript I switch to Safari. I'm just as aggressive in Safari in clearing my history.
Consequently, about the only ads I do see (in Safari) are clothing ads for teenage girls. I have two teenage girls, they have their own computers, so it must be the shared IP address.
So far it hasn't been worth the hassle for me to switch to a new IP address from Comcast more than about once a year. By default my firewall asks for the same IP address and even if it didn't, Comcast will use my firewall's MAC address to give me the same IP address.
It’s very difficult to have a non-unique fingerprint. Your browser would have to be the exactly the same as a bunch of other people. At the moment (AFAIK), this is only possible with Tor (all Tor users have the same browser fingerprint.)
You don’t have to worry about this too much, though. Firefox and uBlock Origin blacklist many fingerprinting scripts.
Some other useful ones for seeing what you're leaking: https://www.bromite.org/detect https://www.doileak.com/ https://www.deviceinfo.me http://fp.virpo.sk/
If you're showing up as unique it's either because:
1. your blockers are randomising each time
2. your blockers aren't blocking everything and what's left is still enough to uniquely fingerprint you against the database of fingerprints they have.
If it's 1 above, that's fine. If it's 2, you may need more (or better) blockers.
Also, it obviously helps from the get go if you're on a bog standard platform like Windows and using FF.
For things that should always be unique (like a canvas fingerprint), just make sure to randomise it each time.
Basically, you want to appear as mundane as possible (user agent, screen resolution, fonts, platform etc.) and be able to change on demand as much of the remaining entropy (as is feasible) that would normally be expected to be unique.
I fail to see how Tor affects your browser fingerprint. Are you talking about a "tor browser" or something?
https://chrome.google.com/webstore/detail/dont-fingerprint-m...
extension is able to block most of the fingerprinting attempts. If you guys know about better "plug-in" solution, please let me know.
I don't want to sacrifice basic comfort of browsing though, like disabling .js, wiping everything on browser restart or diddling with uMatrix on every website.
"Dont FingerPrint Me (DFPM) is a browser devtools extension for detecting browser fingerprinting."
I use uMatrix with strict defaults for privacy. I agree diddling is annoying. I find diddling with sites more annoying.
Here are some of mine in my privacy browser:
BP Privacy Block all Font and Glyph Detection
Canvas Blocker
Clear URLS
Cockiebro
Decentraleyes
I don't care about cockies
NoScrupt
Privacy Settings
Privacy Oriented Origin Policy
Startpage
ublock origin
WebTRC Control
HTTPS Everywhere
And as a bonus, not really related: Bypass Paywalls Clean
Also use a host file manager. I use host flash
Most important thing: use many many browser. I have chrome for Facebook, Banking sites and Booking travel tickets (Trust me, you don't wat to do this with you privacy broswer).
I have chromium for gmail
I use firefox with all the plug-ins for webbrowsing
opera with build in VPN for some other stuff (carefull, owned by Chinese)
Vivaldi
There is also blue moon. There are many browser out there. Another option would be to use virtual machines with seperate VPNs.
Why are you reinventing the Tor browser?
I'd be even happier if the tricks to get video to play were somehow canceled.
I have adblocker and video blockers, but somehow, news sites have a video that plays. If I scroll off the page, the video pops out into the lower right hand of the page and resumes playing, even if the big version of the video at the top of the page was stopped /paused (which it is by default), and it needs to be stopped again. On mobile (Android) this is a double nightmare, even in Firefox, because the little video has a tiny little X, and somehow my finger doesn't ever hit X the first time. I can plug in a USB-A connector in the right way faster than I can press that little X.
Is there an explanation for this, and am I the only one?
So you could allow the video to play in view while you scroll through the remainder of the page.
(You can right-click the value you modified in about:config to Reset it back to the default, so that animated GIFs work again, after you're done testing that.)
This is so annoying, engaging in such obviously obnoxious UX patterns should be regulated and punished with fines when user-intent tries to be circumvented.
The "just dont visit that website lol"-trope really doesn't cut it anymore; operating a news paper organization nowadays is such a cutthroat business that you simply can't not do it if your competition does it, there really needs to be regulation to level the playing field to stop this kind of bullshit
- There's no real mechanism in the free market for long-term goal setting, apart from massive capital or collective action. Collective action is pretty hard to organize without capital.
- People have vices and virtues. Long-term thinking tends to lead to better outcomes. Long-term thinking tends toward virtues. Short-term instinct tends toward vices. See e.g. the marshmallow experiment.
- A/B tests and the concept of "revealed preference" optimize for vice without regard to long-term good. If you ask a smoker if they want to quit, they'll often say yes. But their "revealed preference" shows that they want to keep smoking. So "revealed preference" optimizes for vice.
- There's a feedback cycle between the most effective micro-optimizers and the accumulation of capital. So those who have the most money, can afford the most micro-optimizations. And those micro-optimizations favor the holders of the capital at the expense of society at large. Thus we are gradually optimizing ourselves into the will and control of the wealthy, AKA feudalism.
We can see this playing out in operating systems, too. Windows, despite MS's antitrust sins, and much as the Slashdot crowd loved to hate it, used to be very focused on compatibility and widespread use. There used to be a saying, "80% of your users only use 20% of your features, but they all use a different 20%". Now everything's gone from focus groups to telemetry. In other words, from planning and virtue, to reactionism and "revealed preference". Anything not used by 100% of users, or anything that doesn't favor the holders of the keys, is at risk of being destroyed in the next automatic update.
The problem with these "free market" explanations is that comparisons aren't being made equally and there's a lot of tech illiteracy when quantifying metrics.
To the unfair comparison, who is going to stop the videos? A small news publishing site? You're going to argue that everything else besides the autoloading video is the same? Including the knowledge of the existence and quality to the public? I thought it was pretty well known in the tech community that a superior product isn't guaranteed to win, even if it is able to be manufactured at the same rate. These arguments barely work on paper and have a long history of not working in reality. (BTW, this isn't an anti-capitalism comment as you are already thinking.)
As to the quantifying metrics, well sites see that "engagement" goes up. So why would they stop? Don't believe me? Well see this comment[0]. Metrics are only good metrics if you know what they mean and how to interpret them. Goodhart's Law is especially prevalent when people are illiterate.
Sites are loading videos in frames (looking at you Reddit) and in GIFs (news sites)
I wrote about it at https://danshumway.com/blog/chrome-autoplay/. The spec evolved a little bit since then, so not everything in that post is up to date, but most of the core problems still remain (or did the last time I checked).
Firefox was forced to follow suit, and to their credit their spec was a lot more sensible, but it was really only papering over the problems in the Chrome spec. It wasn't at a fundamental level thinking about video/audio differently than Chrome was, it was just trying to do the same thing minus the egregiously bad decisions.
I feel like a lot of the problems with hijacked interactions on the web can be traced back to spec histories like this.
A good implementation of video/audio blocking:
- wouldn't reveal to the page that audio was blocked, it would either silently mute the audio or refuse to render the video without reporting an error.
- wouldn't have exceptions based around trying to interpret user intent or (in Chrome's case) exceptions based on how you navigated to the page.
- wouldn't try to distinguish between things like GIFs, animated backgrounds, and videos (they're all moving pictures that use data and distract motion-sensitive users, you don't need to treat them differently)
My (subjective) opinion is that video autoplaying never really got better because we never really tackled the problem correctly from the start, and since then we've just been continuing to apply band-aides on top of a fundamentally broken strategy.
> am I the only one?
Depending on how much you hate this and how much effort you're willing to put into getting rid of it, disabling 3rd-party Javascript will fix the problem on most news sites.
Nearly all of them that I run into load the Javascript to run the player from a separate script being served from a separate subdomain or CDN. It's usually possible (even for news sites that require Javascript) to block that script in specific, or load just enough Javascript to get the page rendering and nothing else.
This would cause 95% of users to correctly say that your browser is "broken", regardless of the opinions of motion-sensitive users on tiny data connections. Having a nuclear option for just these people is fine, but you do need to distinguish between the two types of video for everyone else.
I think that would be fine, I'm certainly not against sensible defaults. But I don't think any browser currently has a good implementation of that nuclear option The distinction between video types shouldn't be something that's baked into the core design of the feature itself.
As it stands, I have no idea how I'd even start to implement a good nuclear option on top of the current design of autoplay blocking. There are so many weird rules about what is and isn't allowed to work, and the end result is that the system is trivial to bypass.
One of the criticisms I had when the system launched was that it's really not hard to make an autoplaying video even with these restrictions[0] -- clicking, highlighting, or pressing any keyboard key counts as a user action. Or if you're navigating within a domain, then your video is special and allowed to autoplay. The distinction between "this is probably an animated background image" and "this is probably a video banner" is fundamentally baked into the feature itself in a way that users can't customize or disable, and where its difficult for even the browser-makers themselves to expand on the feature of change it as the ecosystem evolves.
Even the distinction between autoplay on page load and autoplay in general is a bad one to have so hard-coded into the design. Youtube is an SPA, so even though Firefox properly blocks autoplays while you're moving within a domain, that doesn't work on Youtube, because no actual navigation happens when you click a link in Youtube, so Firefox thinks you've already given the page permission to auto-start the video. That's a really inconsistent, bad user experience for nontechnical users who have no idea what an SPA is.
[0]: See https://danshumway.com/blog/chrome-autoplay/demo/ for a really simple implementation. If I'm building a news site and I want autoplaying ads, I'm pretty certain at some point while reading you're going to highlight some of the text on the page.
I feel like adblockers are becoming less and less useful overall, even as they become more widespread and more advanced, because I have to turn them off to see anything on the internet.
Am I the only one with that issue?
Related: I don't know if this applies to other platforms, but the newest version of FireFox on FreeBSD (79.0,1) generates errors on every website you visit stating insufficient security. (including google & mozilla.org) This is somehow related to not having a virus scanner installed or something.
This is the about:config setting to disable that:
network.http.spdy.enabled.http2=false
I inclined to believe that it's just my luck. You need somebody to find edge-case bugs? I'm your stooge.
I feel like you've just described my life. I don't know if everyone feels like they fall just off the happy path for everything or if I really am this cursed. It's exhausting sometimes.
I do really enjoy some of the apps, but I'm fully in the i3 camp for several years now.
Isnt that what is used with Google Search? For example if you go here:
https://www.google.com/search?q=sunday
the first result appears to be:
https://en.wikipedia.org/wiki/Sunday
but its really:
https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&c...
There's also a "Google search link fix" recommended extension that fixes those URLs (replaces https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&c... to https://en.wikipedia.org/wiki/Sunday in your example). Also available for Chrome and Opera.
[0] https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Pri...
The best fix is using duck.com and getting off Google search.
google.*##+js(set, rwt, noopFunc)What is breaking/supposed to break? I might have to remove the filters from all my machines.
https://addons.mozilla.org/en-US/firefox/addon/skip-redirect...
I'm now concerned that companies would attempt to circumvent this by profiling users via fingerprinting through canvas, screen resolution, user agent and other means.
I wonder how such profiling can be minimized / eliminated ?
[1] https://blog.mozilla.org/firefox/how-to-block-fingerprinting...
As I understand it, this is different from the various "resistFingerprinting" ("RFP") settings in about:config, which will work on every site (and are notorious for breaking things). Ditto CanvasBlocker, which AFAIK runs on every site.
I got this info from one of the links in the informative post you cited: https://blog.mozilla.org/security/2020/01/07/firefox-72-fing...
The only place I've whitelisted is Youtube, because of course Google is spying on you, and won't let you watch Youtube unless you allow them.
Or circumvent their restrictions with eg. Invidious or youtube-dl
The official name for this spec is “hyperlinking auditing”...
Anyway, does anyone know a way in Firefox to stop sites from changing a URL's target when it gets clicked? This seems like it should be an about:config option.
Using chrome once it loads with everything else shutdown seems fast.
Firefox is overall faster because of those issues. But firefox will use too much memory and kill itself in time. But has gotten better at killing itself without killing everything else.
Google maps has never worked well for me on FF. The "old"/basic interface for Gmail works fine, but the new one was noticeably slower.
It doesn't seem exclusive to Google, however. Many PWA sites (including bank websites!) have, from time to time, inexplicably failed to load certain elements on FF, while loading them without fail on GC.
I don't really fault FF for this, but it is what it is.
The good news is it seems to be getting better. Every month or so, I try these trouble sites in FF, and every month I have fewer "trouble sites".
https://megous.com/dl/tmp/33d9622c7e53e3bc.png
https://megous.com/dl/tmp/8b3e50856a913236.png
I still use it as a primary browser even for development, but with issues like this being unresolved for almost a year, it's really hard.
Ever since the rewrite in React, it's really bad. First a massive performance regression (which improved over time, thankfully), but it still has major issues like the above.
It’s the only thing that keeps pulling me back to Chrome, as well as many others I’ve seen discuss it in forums over the years.
There’s no Firefox extension to add it and as Firefox users don’t have it they don’t miss it.
Really, sort this, you’ll quietly unlock a bunch more switches.
You can add things like YouTube etc as well so long as they have "OpenSearch" metadata. (Presumably what Chrome is using for "tab to search"?) [1]
[1] https://support.mozilla.org/en-US/kb/add-or-remove-search-en...
What you're describing is a bookmark substitution search feature that's independent of OpenSearch, and Mozilla calls the feature keyword searches[2].
For reasons I cannot understand, firefox on my 8GB RAM windows surface eats up huge amounts of memory. But it uses very little RAM with the same profile on my much more powerful desktop.
The developer console is also slower than Chrome's.
Some sites routinely load hundreds of items from dozens of third-party servers, so this shouldn't be surprising.
On the other hand, everyone keeps saying that it speeds up their browsing experience, but anecdotally, I'm not sure I experience the same thing.
I do have a couple of other addons that are likely clouding this judgment. Not to mention my specific machine, network connection, sites I typically browse, etc, etc.
But is it possible that processing the requests for things to strip, and then updating uMatrix's UI elements is causing more overhead than just letting the assets load (which may even be cached)?
Not to mention that if I do encounter a broken site and I decide to try to make it work, I end up refreshing it 5 or so times before getting it minimally functional. The time spent doing that surely outweighs the time of just letting it load.
But I'm not saying to abandon uMatrix. Just that I use it for privacy, not performance or convenience.
To access many things like history and bookmarks, you need to use the dropdown menu on the right, which has like 30 different options in it, some of which seem similar but are actually different. Those options are sometimes also available from different locations, so it can be confusing how to access what you’re looking for.
Other browsers are a lot more polished in this area, like Brave, Chrome, and even the new MS Edge. None are perfect, but I find their UX and UK slightly easier to use and generally less clunky. If FF fixed that, I’d be completely sold on it. But as is, I keep going back to the drawing board.
It was nearly invisible for quite a long period.
But then I installed the Firefox iOS app, which must surely have an UI written from scratch, and it's just as weird. I'm starting to think that they just don't put enough effort into UX, or perhaps don't hire the right people.
The last time I noticed a UI change, it was for the worse. The made the url/navigation/search bar get bigger when it had focus. To me that is pretty dumb, and I wish you could turn it off. Knowing Firefox you probably can, but a few Google searches couldn't tell me how. If this was done on a product that already had a good UI, it wouldn't seem like a big deal. But given how much low hanging fruit there is in Firefox's UI, it makes you question their priorities.
This is all really weird, since what made Firefox take off in the first place was its better UI. A lot of websites had compatibility issues, and people wanted to use Firefox in spite of them. A lot of webdevs got to work fixing these issues because they wanted to be able to switch to Firefox themselves. It seems that Mozilla never really understood how much its UI advantage helped Firefox get popular. Instead they seem to attribute that period of success to things that I think most people consider nice to haves: extensions, privacy, about:config, etc.
Given those early reasons for favoring it, from my perspective it's mostly gotten worse since 2.0 came out.
Font rendering looks non-native on most platforms.
Scrolling behavior seems non-native on most platforms.
The combined location/search bar seems slower, and gives less useful results, than the same feature in other browsers.
Inferior developer tools.
Mozilla's marketing portraying itself as the white knight of the open web is tiresome and contradicted by past behavior. Pocket is still installed by default, and remember the Mr. Robot scandal?
Tracking is easily defeated in other browsers. Besides, if you use Gmail and Google search, and watch videos on Youtube, you've already decided to give your data to Google and you might as well use Chrome too.
Very much an opinion, I prefer the Firefox dev tools, especially with the recent changes.
And while I can’t speak for other OS, scrolling and font rendering looks native on Windows and has for years.
Here, the perfect is the enemy of the good.
Firefox is the only Web browser that is not owned by a giant for-profit company with a vested interest in controlling your computing platform.
3 big problems (and many minor little things that i hit every day but haven't bothered to record)
- composing email in gmail is horrible. unexplained bursts of lag where it hangs for several seconds and may or may not lose anything I typed in that interval. This one is recent as of the past couple of months.
- outlook email just not updating or refreshing until I restart the browser.
- lagginess in most if not all input boxes (could be related to the first problem above).
- every few updates it will lose all my containers and I have to make them from scratch.
It may be something these sites are doing wrong, but I don't have the patience any more. Chrome works, Edgemium works, so I switched.
still use firefox for facebook container, but that's about it.
Not to mention Firefox is usually brought to its knees when trying to delete large segments of History/Cookies at once.
Is that still the case? I remember that one of the developers was seriously working on improving that.
Nine year old bug related to this: https://bugzilla.mozilla.org/show_bug.cgi?id=734643
The 'Library' window in general is clearly neglected trash. For instance it still doesn't get themed like the rest of Firefox.
You might like the CookieAutoDelete plugin[1]. It's a recommended plugin which allows you to set a list of domains and domain patterns which retain their cookies while others are deleted. I've been using it for a couple of months now, and I love it.
[1] https://addons.mozilla.org/en-GB/firefox/addon/cookie-autode...
It can delete all cookies on closing browser (except the ones you have 'protected' in the addon settings like reddit and YT)
You cab also edit cookie values and change properties, etc
Yes to CookieAutoDelete. Medium was what pushed me over the edge to start using it. Has been working very well so far.
[1] https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
https://addons.mozilla.org/en-US/firefox/addon/temporary-con...
Cookie AutoDelete works in private mode.
I just installed it, and it does a great job.
>inconvenience
It's seriously doubtful you or any other user will notice any negative ramifications from third party cookies being deleted, because there basically are none.
I think if you can keep the mouse off the page and on the scrollbar at the side (I'm on mac) it scrolls more predicably.
What platform do you use?
I don't know what changed, but I haven't looked back.
are you sure it's not because you have smooth-scroll enabled?
If you spend a bit of time exploring the extension's options you should be able to find a combination that hits your personal 'sweet spot'. I've also found that really dialing in consistent smooth scrolling performance can require optimizing other factors including: OS settings, mouse software driver settings (I use Logitech Options), video card options (VSync especially) and even monitor options (often disabling motion 'enhancement' modes) because the end result is only as good as the whole stack.
It can help to ensure your hardware has sufficient performance to maintain your desired scrolling performance even when multi-tasking and the browser loading website with a bunch of JS and assets, especially on laptops and wireless connections. UMatrix helps block a lot of these loads.
If you have intermittent variable results, another thing to check is other FF extensions. I run quite a few extensions to customize my experience and have run across a couple (unrelated to scrolling, screen or visual appearance) that make scrolling performance on some sites inconsistent during background page load, perhaps some rare interaction of threads. Fortunately, none of them were any of the popular ones or ones I find essential.
I don't think it's possible to achieve truly 'perfect' scrolling behavior 100% of the time on all sites yet, at least I haven't been able to on any desktop browser or hardware combo I've tried. Currently, I'm quite happy with my FF configuration as all the sites I visit regularly perform very well and >95% of one-off sites do also.
general.smoothScroll.msdPhysics.enabled
to true (by double-clicking).EDIT: Formatting.
Wheel scrolling is awful in all browsers. The way to scroll is to use middle mouse button and move the pointer.
Only doing this you can accurately judge scrolling performance. I don't want 'snappy'. I want smooth.
mousewheel.acceleration.start mousewheel.acceleration.factor
I have them set to 1 and 15.
Works with Thunderbird as well!
Tried everything, even resetting the OS.
Have a new MPB since Monday, tried Firefox again, no issues at all.
Guess I need to submit a bug report.
Edit: apparently Bugzilla requires passwords longer than 10 characters - wow! At least the that's the error I got (password too short) when I tried to sign up. Seems excessive.
For example, sites that use Twitter or Instagram [1] embeds won't show the embeds. And there's no way, as far as I can tell, to whitelist those.
The only solution is to whitelist the sites that have embeds, but that ends up enabling all the tracking and stuff you don't want.
Embeds aren't broken, they just appear text only.
When you block twitter embeds , you can't like the tweet without opening the tweet in a separate tab.
You can't do both. Either have the like functionality, or block it.
- I use an ebook reader (Kobo) with Pocket to read saved articles and it can't load the embeds
- I listen to articles with the screen reading feature on iOS and when it goes over embedded tweets it's a nightmare
Many articles are nonsensical when you cut out the twitter embed that added key context or information to the article. Consider copy/pasting the text into the article & then linking to the tweet.
Does this mean if I visit a site twice the cookie stays but otherwise it’s gone in 24 hours?
So if you get a 3rd party cookie from www.marketingsite.com, but never visited that site, it will be deleted in 24 hours. But if you get a 3rd party cookie from facebook, and you're a semi-active facebook user, the cookie will be kept.
The article mentions you get redirected to a website before going to your destination, so the third-party cookie is no longer 'third' but 'first' since you (unbeknownst to you) visited the site.
In the security blog post, they explicitly say "An origin will be cleared if it [...] is classified as a tracker in our Tracking Protection list" and "[has] No origin with the same base domain (eTLD+1) has a user-interaction permission".
So it's not a catch-all for any and all redirect trackers, just those Mozilla knows about, and whitelists trackers that are first-party in spirit. I do wish they didn't frame it as "we're blocking redirect trackers" but instead as "we extended our tracking blacklist to include known redirect trackers, unless we have a good reason to think you allow them".
Clean URL cleans many links. No utm_source, no amazon trackers, no google/yandex changing links just right before you click it. It has adblock built in, so turn it off if you already have an adblocker.
You can also do it with https://addons.mozilla.org/en-US/firefox/addon/netflix-party...
Can you link a site here or report to https://gitlab.com/KevinRoebert/ClearUrls ?
One example is hey.com's webmail. With ClearURL messages are never marked as read.
Check whether you can be tracked here - https://hinternesch.com/page1
Visit the site. Then clear cookies and history (don't touch cache) . Then return and you will get the same ID, provided you are not using any extension that removes the E-Tags.
I learnt about the possibilities of Etags from here - https://privacy-formula.com/reader/no-cookies-no-problem-usi...
> What data is collected and sent to the Leanplum backend?
> Leanplum tracks events such as when a user loads bookmarks, opens a new tab, opens a Pocket trending story, clears data, saves a password and login, takes a screenshot, downloads media, interacts with a search URL or signs in to a Firefox Account.
Witness this example of the most terrible UI ever; how frustratingly convoluted it is to delete specific cookies:
1: Open Preferences
2: Search "cookies"
3: See a bunch of cluttered stuff
4: Scroll all the way down to "Cookies and Site Data"
5: Click "Clear Data"
6: Oops, that's not it. Cancel and try "Manage Data"
7: Search "google" for example (to avoid their crappy tactic of signing you into Search when you sign into YouTube or Gmail, but that's another story)
8: Click "Remove All Shown"
9: Click "Save Changes"
10: Get hit with a modal alert in your face showing you the list of changes to confirm.
11: Click "Remove"
1. Open settings
2. Privacy and security
3. Scroll down to find the tiny "See all cookies and site data"
4. Use the search box for the site you want
5. Then you only have the option of removing everything from that site?? There's a little X icon to the right of each cookie but clicking it does nothing
Unless there's a better way I haven't seen (I use chrome infrequently)
> Brave’s policy of disallowing any third party state by default makes it already more privacy-preserving than ITP 2.0 in regards to third party redirection-based tracking. Brave users however may benefit from an ITP-like protection from first-party trackers, although their number is small.
Apparently Safari had ITP, a similar type of redirect tracking mitigation, for some time.
https://addons.mozilla.org/en-US/firefox/addon/canvas-finger...
https://addons.mozilla.org/en-US/firefox/addon/webgl-fingerp...
https://addons.mozilla.org/en-US/firefox/addon/font-fingerpr...
https://addons.mozilla.org/en-US/firefox/addon/audioctx-fing...
I would really love to have more addins like this, doing one thing and doing it good. They will kill fingerprinting and as a proof, I was downvoted the next moment i posted the links.
Perhaps (I am trying to guess) it would have been more helpful to explain why these four add-ons, individually, are so necessary. Or perhaps a more expanded comment on why you picked these, and what effect they provide.
Also, Mozilla should really think about what is wrong with the statement "Since we enabled ETP by default, we’ve blocked 3.4 trillion tracking cookies." I imagine most people who care about tracking would like to not be tracked by anyone, not just anyone other than Mozilla.
What I'd be interested to know is if all of this anti-tracking technology matters if you just isolate domains by using containers. My guess is that Google and company have so many tracking domains that containers have no impact on that, at least 3rd party. But it seems like part of a real solution.
- more or less forced to use windows for development / to access marketplace content - have to modify engine source code to disable analytics - have to use Chrome to access their sites and dashboards
I really miss my old Linux setup
You can also see the full list of tabs (with titles) in the tab overflow dropdown menu. It's the down arrow button to the right of the tab strip. The dropdown menu only appears after you open at least ~20 tabs. I set the browser.tabs.tabmanager.enabled about:config pref = true to always show it (because I like see the full tab titles).
Those tracking numbers will reduce, the more that Firefox cracks down on it.
User agents hitting server logs are probably more accurate now.
Presumably if you want to run ahead of that, there's ways to get it early via Beta or Nightly channels, but I don't know what those are.
GCNAT, roaming (WiFi <-> mobile), shared networks (NAT/IPv6 Privacy Addresses). All of these things mean you can't be sure you're tracking the _same_ person, unlike with cookies.
I absolutely agree that browser vendors have huge conflicts of interest, and we need to address those by forcibly separating browsers from companies inherently in conflict with privacy.
But it makes you wonder, if other browser vendors' interests do conflict with ad blocking, why would they ship with uBlock Origin? They would want to control what most people do by controlling the defaults. The vast majority of users never change the default settings.
There's not a mission-level conflict-of-interest, but there's a practical one. Until they can somehow be funded directly by users, Firefox will have this tension of "don't piss off Google or other referral partners, even if that means going against the users' interests". They won't serve the users well by losing all their funding and then dying.
This situation is why Firefox and Mozilla aren't just everything they could be in terms of completely aligned with users.
If Firefox was solely aligned with protecting their users, the default search would be DuckDuckGo, not Google, and it would fully block Google Analytics, Fonts, and AdSense right out of the box.
Which is why they have things like telemetry, backdoors like normandy, tracking via safebrowsing, unblockable tracking via google analytics in about:addons and any mozilla pages, a great track record with pocket and the mr robot addon, tracking-related bugs which have gone ignored for years, and richly paid executives, right?
The general population has no idea such an addon is necessary. I applaud Mozilla including at least basic privacy blocking by default now.
I can't help but wonder why you don't just go to the front page of your settings, and select "Blank page" on the "New tab" field though. Unless I am misunderstanding where you are talking about.
I like that Firefox Home is the default option because you as the user are offered something. If you don't like it, you say no, go to the settings page, and are never offered it again. If you do like it or don't mind it, you keep it. Win-win.
If Firefox Home wasn't on by default, those that might have preferred it wouldn't know what they're missing. It seems difficult to think someone would actually prefer ads but if there's some engagement, then that speaks for itself.
There are 6 levels to your process above. Imagine being tech-illiterate and asked to navigate that - or, maybe easier, imagine trying to dictate that process to someone you know who is tech-illiterate over the phone. Even if you know exactly what to do, it might go something like this:
> "You saw an ad you don't like on a new tab of The Internet? OK, what you need to do to fix that is set the New Tab preference to Blank. Click the Firefox menu - no, it doesn't have the familiar File/Edit/Help menu bar, it uses a hamburger menu - the stack of three horizontal lines - in the top right. Something about a library? No, that's supposed to be a bookshelf icon, it has vertical lines, you want the horizontal lines to its right. The menu went away? Make sure to single-click the menu, not double-click. Look in that menu for something named Settings ... not Customize, no, that's kind of like settings but different, oh yeah, it was called Preferences. In Preferences, look for the Home section ... shouldn't have to scroll, it's in the menu to the left ... yeah, that's a menu, it's just separated by whitespace instead of a line. On the Home preferences screen, there's a drop-down box for New Tabs, click that dropdown and set it to Blank. Great, you're all set. Talk to you later. Bye!" Ring - "Hey again - it didn't work? You closed and reopened Firefox and the ads were still there? Oh, right, that gives you a new window, not a new tab. Let's go back through the menus one more time, it was just above the New Tabs dropdown, yeah, we were just there. Click the three horizontal lines for the Firefox menu...."
It's disingenuous to say that those who prefer the ads might not know what they're missing, even more disingenuous to say "you're offered something". No, with ad tech, the user is the product being offered to the advertisers, and I expect that more people don't know how to turn it off or that turning it off is a thing you can do than that like being advertised to.
Hit options -> Click dropdown of "new tab" field and select "Blank page". 2 steps.
If the parent post is being disingenuous with their point, yours is as equally disingenuous by being an incredibly over-complicated deconstruction of hitting options and reading 2 fields down.
If they have to be walked through finding the options menu (half your paragraph is about opening the options menu, really?), they are going to have difficulties with every browser and every option -- including understanding what a "custom URL or set of URLs" is.
>"Oh a URL? That's the address thing you see at the top. Oh but it's not shown completely in some browsers. And, if you want multiple URLs you have to use the pipe operator symbol. Oh, the pipe operator? Look above your enter key. No, not the one on the number pad, the other one near the backspace." Etc..
I fully understand why you think that should be the case, but please understand that most people are not like you. Putting barriers between first start of an app before the user can actually do something with the app is the way to annoy your users.
Sane defaults are nearly always the right choice. You personally may not believe their default is sane, but you're in the minority, clearly.
(It's telling that you call it "Mozilla Ads"; such hyperbole only serves to weaken your point.)