Firefox and Fastly take another step toward a privacy upgrade for the internet
fastly.com
fastly.com
My initial thoughts are: I don't have any reason to trust fastly or their motivations. I certainly don't have any desire to use them as a proxy server for all of my HTTP traffic.
I'll review the OHTTP spec carefully, which seems to have been put forward by mozilla (who I have limited faith in) and Cloudflare (whose motivations are suspect), and evaluate this in depth, but for now I just don't want to worry that a browser update is going to cause firefox to start sending my data to a third party.
If the concern is that websites know what our IP is due to HTTP requests, we already have some solutions for that, a VPN being a good one. Mozilla already offers a VPN.
It's not my place to say specifically what this is for (although I imagine Mozilla may announce it themselves), but as of now it's a single use case.
Now, this has very little to do with what you might trust Firefox or Mozilla to do. OHTTP only provides a degree of anonymity. If you don't want to share the data that is carried in the message, then you might want to disable the request, not the privacy protections that OHTTP provides. Firefox will use OHTTP for different purposes, so you need to look at each in turn.
Yes it can be hidden with userchrome mods, but it shouldn’t be necessary to resort to that, plus we don’t know how long userchrome mods will continue to work…
#TabsToolbar {visibility: collapse;} #sidebar-header {visibility:collapse;}
You're arguing against a strawman.
OHTTP is ideally suited for privacy enablement of APIs, whereas MASQUE is more for general purpose traffic.
OHTTP has similarities to MASQUE in that it uses a two hop proxy design where each proxy only knows part of the total requestor / request information. And in both cases these proxies must be operated by separate entities that do not collude.
However, the key difference is that in OHTTP the end destination is known, because there is a 1-1-1 mapping between OHTTP Relay -> OHTTP Gateway -> Target. This could become more generalized in future revisions to OHTTP, but right now it's all hardcoded behavior.
For more about OHTTP at Fastly, I wrote a blog post a while back at [1]. There is also the IETF draft spec at [2].
[1] https://www.fastly.com/blog/enabling-privacy-on-the-internet...
[2] https://datatracker.ietf.org/doc/html/draft-ietf-ohai-ohttp
So the Relay knows the requested URL? That’s not masked by the client?
Private Browsing: The goal is to prevent embarrassment. I'm looking at porn or shopping for gifts for my spouse, and I don't want it showing up in the autocomplete/history/remarketing ads as much as possible.
Tor: The goal is to prevent imprisonment. I'm accessing stuff that's politically sensitive and either inaccessible or likely to trigger consequences if it's detected by local ISP infrastructure.
Obviously, Tor offers a higher overall security profile, but tends to break things (services using IP blacklists, services that don't do well with its performance characteristics, etc.) that people expect to work with today's Private Browsing.
ISTR when one implementation of it came out (not sure if it was Firefox's or the original Chrome Incongito mode) the launch page said point blank "this will not hide your movements from your ISP, governments, site hosts, etc."