Firefox rolls out Total Cookie Protection by default to more users (2022)
blog.mozilla.org
blog.mozilla.org
That they're expanding the deprecation of third-party cookies that they blogged about in December?
Edit: yes, looks like that last paragraph is the addition
And then these days I have no idea if I can just accept a website's advertising cookies and expect Firefox to block them anyways, or if clicking on such a button would disable the browser's tracking protection.
So if you visit games.example which loads tracker.example it can set cookies. However these cookies are only used while you are on games.example. If you start browsing comics.example which also loads tracker.example it will start with no cookies, but can set cookies that only affect comics.example.
This way cross-site cookies can still be used for auth, experiments, spam protection or whatever else. But you can't do cross-site tracking as each top-level site had a separate cookie jar.
You could dodge around that with 'open in new window' but it was a pain in the ass. I think they've fixed it recently.
I had my clients just enable it on the browser.
I've only ever seen it for explicitly supported authentication flows by the first-party site.
I think the previous poster was responding to this:
“I'm not sure what people are doing now, because you can't retain state.”
They do OAuth.
There is no replacement. It's just not possible anymore. OAuth doesn't address this.
You can’t do an iframe, but you can still get the data if it’s supported by their api and yours.
Which is the way it should be, imo.
This used to be somewhat common. It is not anymore recently.
My recollection is that Firefox has exclusions for requests to third parties where that third-party just redirected the user to the site, in order to allow the login flow you wrote about. Don't ask me for a cite, though. Safari, on the other hand, will (or at one point would) block requests to domains if it's seen more than one domain making third-party requests to that domain and it's not been visited as a first-party.
I learned recently from a Mozilla engineer that Firefox never made samesite=lax the default for cookies set without the samesite= attribute - they went with this Total Cookie Protection strategy instead: https://lobste.rs/s/98rp8f/cors_is_stupid#c_9dtjao
Here’s my exploration of samesite from a few years ago: https://simonwillison.net/2021/Aug/3/samesite/
As before, my frustration with this kind of browser feature is the lack of detailed technical documentation.
As a web developer, what does Total Cookie Protection mean for how I build web applications at the nuts and bolts level?
Show me some set-cookie examples that previously would have behaved differently and explain those differences.
> And starting in 2024, all our users can look forward to Firefox blocking even more third party cookies. That’s right; we are taking big swings to adopt new cookie partitioning and clearing mechanisms so that users can browse with fewer cookies that won’t stick around as long and will result in an even better browsing experience. Just another step on our road towards creating a better internet where your privacy is not optional.
So, I'm totally on board for this! The only other thing would be to just not let cross domain sharing. at. all.
Example: In Safari private mode, I can open up Facebook and login, then if I open up a new tab or window and try to go to Facebook it's going to prompt me to login.
I don't quite understand the appeal of Firefox other than it maybe having the same appeal as Linux Desktop or LibreOffice(being free and an open alternative).
I routinely open links in the default android browser (chrome now), and it literally crumbles under the weight of ads in your average article, and then open it in firefox and uBlock means it runs great and any issue I was having disappears.
>I don't quite understand the appeal of Firefox
It's not chromium based, so Google can't force it to grow in the direction that only benefits their infrastructure like they do so much with chrome, and uBlock is a strictly better ad blocking system than anything I have ever used. I don't think Brave is independent, as they are beholden to the Chrome team's architectural decisions and design goals. It attempts to send less tracking information to people tracking me (with a caveat that Mozilla themselves do a little first party tracking and advertising, which I consider morally less wrong than Google's entire business), and is not incentivized to make the web a worse place for the sole purpose of increasing Google's share price.
I'm currently using Firefox on Android, and have for years and years, and have never found a bug.