Multi-Account Containers Add-on on Mozilla VPN
blog.mozilla.org
blog.mozilla.org
That said, what is so hard about Multi-account containers that Chromium doesn't have it?
For testing, you can just type the SOCKS5 address from your VPN provider, but that's not very secure.
In my case, I have a Pi running a few Dockers (with network pairs of OpenVPN/WireGuard + Socks5 proxies); it works decently enough, I can even use streaming services like Netflix / etc. if that's something you care about.
https://mullvad.net/en/help/different-entryexit-node-using-w...
These SOCKS5 proxies are only accessible when Mullvad VPN is on, so the security is no worse than not using the proxy.
Mozilla VPN is a rebranded Mullvad, and both VPNs use the same SOCKS5 proxy mechanism to switch your location. The Multi-Account Containers add-on is better integrated with Mozilla VPN, but the feature works well with Mullvad, too.
If you have a spare Raspberry Pi (perhaps running PiHole / AdGuard as well which takes care of DNS security and ad-blocking on top), or another server running you can spin up a Docker (or VM/or baremetal) with an OpenVPN / WireGuard client and a SOCKS5 proxy.
For example, in my setup I use the "dperson/openvpn-client" and "serjs/go-socks5-proxy" docker images (set the socks5 container to use the network of the vpn client, and expose the socks5 port out of the vpn container). You should explore whatever option works best for your home and VPN setups.
Of course, the data is just TCP and UDP packets, so you could be running a HTTPS connection over it (or DOH for DNS) but from the ISP's point of view SOCKS5 or no SOCKS5 they can see just as much of your traffic.
SOCKS5 to an external server is not solving encryption, you need a VPN for that; at most, it can solve anonymity (by hiding your IP address, presuming you trust the SOCKS5 server operator).
In my case, I'm using SOCKS5 to another machine in my LAN which in turn connects to an external VPN provider over an encrypted channel (OpenVPN or WireGuard).
And that is far more common than having a VPN, and again, might not even need to install anything on the client. So you could quickly configure a friends laptop to ssh+socks inside your own network to stream from a local jellyfin server, or whatever. Or bypass language restrictions on regional services when you are abroad on vacation etc. (all are trivial to do with a VPN of course, but this is quite handy when you normally don't have a need for a VPN and/or just want something quick with tools and accounts you know at the back of your mind).
Chrome can create multiple browser windows that are isolated from each other, making a very clear distinction of scope.
Firefox has containers, chromium has profiles. They accomplish the same goals is sightly different ways.
Did you or your friend not even try and Google for "firefox profiles"? Because if you did you would have found the following link as the top result
https://support.mozilla.org/en-US/kb/profile-manager-create-...
Profiles have been in Firefox for longer than I can remember. I am pretty sure longer than Chrome has existed.
I've always felt Chrome was missing proper containers and Firefox was missing proper profiles.
These are obviously answered problems for anyone on HN but not obvious problems for the majority of users that have never even installed an extension (even an adblocker). Chrome avoids all of these by automatically managing the shortcuts (clearly named), providing clear in-browser always visible UI about multiple profiles (also clearly marked), and explaining to the user how to make/manage them in app.
This is before getting into problems Chrome shares with Firefox like not syncing local profiles or issues with the way things work on Android.
For firefox, you would type it in the run box under windows from the start menu.
Whatever plugins or bookmarks or changes to the toolbar will help me tell this isn't my profile. If I haven't customized why would I care this isn't my profile.
If I am an average user am I using this feature?
It can be a Google account or it can be a local account, both are treated the same.
> For firefox, you would type it in the run box under windows from the start menu.
In Chrome you don't have to know to leave the browser and run a magic command, you just click the profile icon built right in the browser. When you do it has stuff for managing the current profile as well as adding new profiles. If you add a new profile you can switch right from the browser window. It also creates the separate shortcuts to launch straight to the profile on the desktop and names them based on the profile. Part of creating a profile is it gets a unique theme automatically (or you can pick one of course), it's not something the user has to think ahead about or implement manually. This is all pointed out on the initial out of the box experience walkthrough as well as by in browser tooltips and descriptions. It'll also default to the profile selection window on a generic launch (e.g. another app triggers a page load) rather than require you follow any of these special shortcuts manually.
For some visuals I created a quick local profile: https://imgur.com/a/5nQhh3K
> Whatever plugins or bookmarks or changes to the toolbar will help me tell this isn't my profile. If I haven't customized why would I care this isn't my profile.
Remember most people don't use plugins, on top of the whole "you don't need to do anything for the profile to differentiate itself" difference. The bookmarks bar is also off by default. And even if there are minor differences it's a backwards way of telling which profile a window is in - the window should tell me the profile obviously, not just my memory of the settings for a profile and matching them to a Window. Worth noting profiles are also differentiated with the user profile picture in the taskbar button overlays and any shortcut icons automatically so this integration extends even outside of the browser window without effort of the user.
> If I am an average user am I using this feature?
I'd say most by percentage aren't. The most common use cases are kids with personal and school Google accounts or adults with personal and work Google accounts but even then it won't be every user. The number of multi-profile users on Chrome as a percentage of user population is significantly higher than on Firefox because of all of the above though.
I love Firefox to death but the profile UI is absolute garbage which is just crazy considering they are the ones that made all of the excellent UI around containers.
Longer than even Firefox has existed. Multi-profile support has been there since the Netscape days.
However, the UX for Firefox's profiles feature is godawful.
Lately though, I find I prefer not to trust the application to manage this and just launch separate profiles in their own separate app namespaces using things like firecracker, firejail, or similar (depending on need).
Similarly, -ProfileManager has existed for ages and that experience is also bad.
If I have to go to the lengths of about:profiles or using the -ProfileManager or -P command-line switches, why not just sandbox the entire thing?
It definitely needs a useability upgrade.
I've never had any issues typing "about:profiles" into the URL bar. It even autocompletes.
I keep my NSFW Firefox profile in a veracrypt drive. Using about:profiles I can launch the profile that I want to use, and start from previous session.
[1] https://addons.mozilla.org/en-US/firefox/addon/profile-switc...
With both profiles and containers in Firefox, you get different containers per profile, which can be a useful way to organize them.
You can have as many as you want.
Just something to look into since it could get you spanked by your net or sec team if your company has those.
https://github.com/mozilla/multi-account-containers/issues/3...
Which leads me to the idea that maybe the feature should be better motivated! Perhaps we can show the user a meaningful and well-defined number, comparing for example the sheer size of a normal request vs one made in a container. If necessary, you can dig deeper into the payload, and ask questions of the system like, "What are they saying about me and my activity, using my own browser as a communication channel?" This latter one could be quite fun and take community contributions, small code snippets that know how to parse a request and interpret and display the meaning to the user.
This is where the imagination of a developer can be helpful, to basically characterize as completely as possible the patterns we expect to see. Because so far, that's a very low-level mechanism, and clearly there's more room for protocols - and given the nature of this problem, multiple, overlapping, dynamic protocols that are proprietary in nature. We can imagine origins that just suck everything in, doing unknown processing on that data, but giving us tools to measure aggregate engagement. The need to define an audience on something more than source IP becomes immediately apparent, and permissive 3rd party cookies have enabled a huge ecosystem to arise, and each persistent part of that is specialized in some way. But the money is in showing users ads, and showing them really useful ads. This means measuring the users and trying to anticipate their needs. We can base this on "identity" facts that don't vary much over time, or on "behavior" facts that vary a lot over time, albeit with lots of consistency for most of it. Both are used to predict what a user wants enough to spend money on. In particular, behavior, what are they asking about, learning about? What sorts of tools and supplies - things you can buy - are associated with the subject?
TBH if this happened on the client side, I wouldn't find it creepy at all; I'd find it quite useful. There are really two problems with server side processing of identity and behavior: first, it quickly gets bigoted when people are asked to associate an identity with a consumer demand. Who gets to make this association? Are we okay with this being a self-reenforcing mechanism since we are pushing identities toward the behaviors we associate with their stereo-type? Second, it lets servers split the internet without our knowledge. The incentive to garner as much attention as possible leads inevitably to breaking our shared perception of the world. At least, back in the day, you could argue with someone over a book, and know you have read the same book. But now, the book is a screen, basically a browser, and it is very different for each individual, and no-one is fully aware of this truth.
I'm being utterly serious when I say that these are the kinds of issues, technical and philosophical, that users need to be aware of before they can get excited about a feature like tab containers. Given the level of civic discourse in the wider world, my hope that people would be open to learning about it is slim to none. Heck, even most devs prefer not to think about it, and just make the changes the money wants to make, without regard to the users benefit. Then of course there is the secondary market for this data, law enforcement. You could probably get 80% of a panopticon by just hoovering Google analytics data for "alternative" processing. You get the rest by piggy-backing Cloudflare and the like. The interesting thing about CF and other CDNs is that they can provide an alternate, and unavoidable, surveillance function, since they can use access logs, and you cannot use the software without getting the bytes. This ends up being a strong argument in favor of content-addressable resources, rather than named resources: they would let a client rotate physical access, and these segmented logs would make it hard to recreate a coherent timeline. But not impossible: if enough sources cooperated, the could aggregate their logs and you'd lose your anonymity.
No, what the world needs is not just a defensive thing like tab containers, but a more aggressive thing. Rather than isolate an account's data, why not provide all the connectivity it wants, but poison the well. Manipulate the messages sent out by your computer to mislead these trackers: shift identities, access different resources, do different things in those resources. It should look identical to ordinary host lookup traffic, but the messages will be different, noisy, worse than useless. Maybe call them "active defense containers".
Every time I've demonstrated containers to someone they "got it" right away. Some were unimpressed and didn't see how it would benefit them while others were blown away and ran off to install it on their machine, but seeing how I could log into the same website in different containers with different credentials -- without having to spawn new profile windows -- is not that hard of a concept to grasp. Explaining the "why would I want to?" is a different question entirely.
Also, can I ask more about the context in which you have demonstrated containers? Like, why would you do that? Was this to friends or family or...?
while firefox's concept is more powerful its also harder to use appropriately.
they're good for sandboxing one site from others but the way many people want to use profiles is to entirely separate their windows by profiles.
lets say for example I have two gmail accounts one for corporate and one for personal use. switching between them isn't fluid in firefox because containers are site based. and profiles are completely hidden.
firefox doesn't make this easy. I can't whole switch a window from one profile to another when I want to switch from personal -> work contexts.
You can wait for google to copy features. You might be waiting for a longtime.
https://addons.mozilla.org/en-US/firefox/addon/container-pro...
I also wish the UI was better. Adding domains and containers is awkward.
Not to mention that with some sites like Google, it's difficult to make containers work, for example of you want to use Gmail and google search without being logged in to Google search. Same with YouTube. It will switch to a new container because of a different login domain.
I use the "no container" default for work stuff, which means everything just works normally. Anything that isn't a tool for work, that gets a container.
Not exactly.
You can achieve pretty much the same result for the use cases described in the blog post today with the SPN (https://safing.io/spn/) - using any browser:
The SPN automatically routes every connection individually over multiple hops through the onion-encrypting network, resulting in many exit servers being used simultaneously.
Disclaimer: I’m Co-Founder/CTO of Safing, the company behind the SPN. You can ask me questions here - I have notifications enabled.
You may not feel that you owe deprivers of Android extensions better, but you owe this community better if you're participating in it.
Subscribe here for updates: https://github.com/mozilla-mobile/firefox-ios/issues/9155
Because Apple doesn't allow Firefox on iOS, it's just a Safari skin: https://news.ycombinator.com/item?id=21587191.
- Mull: https://f-droid.org/en/packages/us.spotco.fennec_dos/
- Fennec F-Droid: https://f-droid.org/en/packages/org.mozilla.fennec_fdroid/
- Iceraven: https://github.com/fork-maintainers/iceraven-browser
There's a way to use the other extensions, but it requires FF nightly and our own list of extensions:
https://blog.mozilla.org/addons/2020/09/29/expanded-extensio...
This is so incredibly misleading I struggle to take it seriously. They had _thousands_ of add-ons on firefox and any remotely popular add-on had a firefox-for-android release. If I open Nightly right now and disable custom add-ons I see a woping _18_ add-ons available and this is _3_ years after the first release with GeckoView.
They made the design decision to change to GeckoView engine in firefox 79.
They made this decision with the awareness that it would break all of these add-ons. They have made a very low design effort in the last 3 years to resolve this.
Users went went from hundreds of add-ons and stabilished workflows to 18 add-ons after 3 years of rolling updates.
Power users won't be stopped by this, as Celso mentioned you can add your custom collection on AMO, but it speaks volumes about how much lack of focus there is in FF and the lack of user voice in the current design decisions.
I agree that it's an issue, but the situation really wasn't great beforethen either.
Snark aside, this change (for once!) does have some benefits. Tracking using IP address & user-agent alone is pretty strong regardless of cookies/etc and can't be completely blocked client-side when you do need to load the requested resource (such as browsing the malicious website, or third-party websites using Google Fonts/ReCaptcha/etc), so containing these within their own VPN, separate from other browsing activity is an effective countermeasure.
Should Firefox prioritize compatibility with it? Yes. Should the uBlock Origin developers have the personal cell phone of Mozilla's CTO? Also yes. But there's nothing to be gained from absorbing it, and all we'll get is more bureaucracy.
If anything, I'd like Firefox to focus more on their core product, not less.
It largely does.
https://support.mozilla.org/en-US/kb/enhanced-tracking-prote...
It doesn't take much for a website to determine that the Firefox user agent (or detectable fingerprint) results in zero advertising ROI. They'll block it outright and ask you to use Chrome.
Then Chrome wins.
* https://github.com/gorhill/uBlock/wiki/Cloud-storage#firefox...
> Firefox for Android can't sync extensions settings. This is tracked in Bugzilla #1316442.
VPN by Google One comes to iOS