Firefox getting smarter about third-party cookies
blog.mozilla.org
blog.mozilla.org
Combining this with a "forgiveness is better than permission" principle (which seems to be sorely lacking in web browsers, other than a few just-plain-strange places like alert() dialogs), the best UX might just be a warning bar stating "Example.com has reserved 1KB/5MB of your disk so it can remember its place. [Disallow]"
Disallowing would make the site think it still has a permanent store, but internally replace it with an ephemeral one (FS::TEMPORARY, session cookie, etc.) This also might make browser makers get off their lazy butts and make ephemeral versions of the rest of these mechanisms, to make this work ;)
"Example.com has requested 1KB/5MB of your disk so it can remember its place. [Allow]"
Not only that, website owners are incentivized to actively subvert whitelist-based policies: shady sites would paint arrows up to the "Allow" button saying "click this to continue!", doing iframe AJAX ping-pong to verify you've given them the persistence they want before they let you through, and so forth.
And even if they didn't, the request would still become one of those things naive users think you just "have to click OK to if you want the computer to keep doing the thing"--like Windows UAC elevation.
On the other hand, giving users an equivalent option to a "hellban" on a website--the ability to make the website think it's persisting, but then it turns out not to be--has far fewer incentives. It only ends up being something you click for a reason, rather than a "mother may I" you have to just click all the time, and since getting off the blacklist wouldn't be exposed directly through the browser chrome, there'd be nowhere for a malicious site to "point an arrow."
I would really dispute this. Compare the number of sites visited to the number of ad-tracking cookies stored in the average browser, I think you'll find a very different answer.
I'm not really sure what you mean by this. You said "almost all cookies are friendly" and I'm pretty sure you're wrong. Even if the numbers 'balance out' (which I doubt very much) that's still not close to 'almost all cookies are friendly'.
The pro-cookie side of the privacy debate really needs to just admit there's a problem here, then we can work together to try and ensure privacy and functionality, without making reckless assumptions that somehow tracking is sanctioned or providing value to the user without even the courtesy of asking.
For any given mechanism, if it has different behavior between an ephemeral session and a regular, persistent one, it should trigger the warning bar. Browser caching with distant Expires is definitely one of those. In this case, disallowing the persistence would make all the retrieved resources instead have session-length cache expiry.
Think of the full effect of the warning bar + "Disallow" button as going back and pretending you had opened the page in an Incognito/Private Browsing mode tab from the start--and then making that also happen automatically for any further pages from that domain. It session-isolates caching, cookies, and basically any other form of persistence except explicit bookmarking.
If on the other hand the site wants to store something in localstorage, the site has to run JS on your machine. That's a much higher bar.
The bar is essentially the same and the changes that privacy-invading 3rd party scripts have to do to bypass the Firefox's implementation are minimal, so Mozilla may as well not make any triumphant claims until this glaring issue is fixed.
Not mine :-)
(But point taken)
Any ETA for allowing to block Referer header from being included in cross-origin requests? If I'm on the page that pulls down something from Google Fonts, I see no reason why I should be sharing with Google the URL of the page I'm visiting.
There are no such cases, period. Also, with an exception of dumb content protection schemes (anti-hot-linking), Referrers are used exclusively for tracking purposes and carry zero positive benefits for the users. If Mozilla is in fact "passionate about putting its users first", these headers must go. It is as simple as this.
Referrers are used exclusively for tracking purposes
and carry zero positive benefits for the users.
This is short sighted. Sites can respond to referrers by improving themselves and better adapting to what users are looking for.I run a small site, and we would occasionally get hotlinked by random people searching for images on Google, which would kill our bandwidth caps. If it weren't for referer filters, we'd have to hide any image for unregistered users.
That said, keep just first-party referers would be fine - we'd just block any image request without referer.
1) If you came from a social media site, maybe I'd highlight that particular social sharing option in a share bar, or hide others.
2) In an e-commerce store, maybe Google sent you to some page on my site that isn't really the best for your search term (product discontinued, other better matching product), I can give you a link to that other page. Google isn't necessarily magical in its ability to pick the best page on a site for a specific term. Maybe if you come from a competitor I can highlight some content that compares my product to the competitor's.
3) I've never derived a ton of benefit from it, but some sites will highlight your search term for you on a page. It could possibly also automatically scroll you to a relevant section if it's a long page and what you searched for is an exact match for some subsection.
In general it can be a valuable data point sites can use to improve the end-user experience. That being said, I can't think of anything where the value really outweighs the potential for abuse, but I think saying that it has no value to the user is short-sighted.
You may disagree that is a better experience for you, but you may not make blanket statements that "there are no such cases, period".
Considering it requires whitelisting to avoid weird and hard to diagnose issues, it seems unlikely to be added to Firefox.
1. https://addons.mozilla.org/en-US/firefox/addon/smart-referer...
I also brought up the issue on Mozilla's dev.privacy mailing list [1] recently. See:
https://groups.google.com/d/msg/mozilla.dev.privacy/wmPzPCdz...
In general, we cannot block the Referer header by default on cross-origin requests because we know that would break too many websites. My proposal is to strip the Referer header down to just the origin + '/', e.g. http://example.org/ instead of http://example.org/foo?search=whatever+you+searched+for.
I think it will be difficult for us to go further than that in the default configuration any time soon (and, as you can see in that thread, there's even some pushback to my extremely reasonable proposal).
Also, I know there is active work happening to bring extra control over the Referer header to Firefox's built-in prefs. This seems to be a little bit in conflict with our "Checkboxes that kill" project so I'm not sure how it will turn out.
Also FWIW, I agree that this is indeed becoming a significant privacy issue. I too don't see why Google or Typekit or some widely used CDN should be gifted a convenient history of my web browsing just because they host popular JavaScript libraries or web fonts.
I'm intrigued by this comment:
In general, we cannot block the Referer header by default on cross-origin requests because we know that would break too many websites.
Is this because some of the third party resources are only authorised for use by certain sites and rely on Referer to establish whether a given request qualifies? Given that there is no security or verification for Referer headers, that seems like a rather broken model to start with.
I can't help thinking that if one of the big browsers forced the issue then those services would have to reconsider and do things a smarter way. That seems likely to inherently reduce the amount of unnecessary information being passed across to those third party services in the first place.
https://addons.mozilla.org/en-US/firefox/addon/smart-referer...
Here for anyone who didn't know: http://en.wikipedia.org/wiki/HTTP_referer#Origin_of_the_term...
It's just a first-order approximation to defend against hotlinking. Disabling referes wholesale has mostly worked out for me (via about:config, not an extension), but very rarely I have to turn them back on or switch to a backup browser profile or whatever.
In other words, if your interest is in blocking unauthorised hotlinking, can't you just assume anyone who doesn't include a Referer is equivalent to someone sending a Referer from a malicious site and decline the request?
This feature has been supported in Firefox for a long time, but you have to set it in about:config via the "network.http.sendRefererHeader" integer.
2 = always send
1 = send only to same FQDN (what you seem to want)
0 = never send
IMO this is one of the best bang-for-your-buck privacy configurations. I would love it if Mozilla changed the default from 2 to 1, and at the least, it SHOULD be an option under the Preferences -> Privacy tab.Right now it is done piecemeal by websites, but is confusing to end users. Having a direct, first-class API and UI in the browser that can show the user exactly what third party sites they are "logged into" and have a "Logout/Deauthorize" button next to them would be worthwhile, and have less of a chance of "breaking the web", or imposing workarounds that might hurt user experience.
BTW, how does Firefox treat a CORS XHR response? Does it allow a cookie to be set? Seems to be ad trackers could then just run a server that permits CORS, have a bit of JS that makes the request to opt it back in.
I don't like third party cookies either, but this is false. Your information is worth something to the right people. The websites you visit, mostly free, can make money off that information. The value to the user are free websites that provide you entertainment/content/etc... and are able to stay free because they are utilizing this as a revenue stream. We all know there are other ways, perhaps more moral ways, but to say it provides nothing to the user is false. It funds the websites you're visiting.
The European "cookie law" has caused many websites to give better notice that they're planting cookies, but it's rarely clear how those cookies are being used.
There is a better way. What if I purposefully signaled my intent to potential sellers, rather than having them guess what I want (based on their data about me)? Amazon wish lists are an example (although they'd be better if I stored the list in a place of my choice, where I control who sees what, and I'm told who looks). For more on this idea, see:
There is a simple answer to all this. Its called opt-in. If you need to harass and track users who do not want ads, then either the targeted ads are not targeted enough, or its a failed business model. Time to show which one it is.
I've browsed with 3'd party cookies disabled for years and very very rarely had any problem. I wouldn't say never, certain widgets do break, but those are less than one in a thousand. Only one i can recall from the top of my head is Discus.
For Discus, authenticating through the parent site will be an issue since one of the reasons for using Discus is to avoid many different logins.
The idea is to have a separate cookie store for each 2nd level domain I am visiting.
So the Facebook cookie on some site I am visiting that has a Facebook "Like" button on it is different from the actual Facebook cookie I would get from visiting Facebook.
This would make cookie tracking across sites unusable, since each site would have it's own version of a cookie.
Have you run into any problem websites with self-destructing cookies?
There are not many users that don't interact with google. While I don't expect the chrome team to add this to their feature list (even as optional), if they did, it would not really hurt google. It would actually hurt all the other "smaller" players.
Settings > Show Advanced > Privacy > Content settings... > Block third-party cookies and site data.
It's not exactly obvious, of course. :-)
Firefox is going to accept third-party cookies only from sites that you already browsed before, kinda like Safari does it now.
Exactly. But it's not neccesary a bad thing though.
What all the "smaller players" in emerging retracking field - where 3rd party cookies are used in the first place - are doing now is nothing conceptually different from "ah, you've added iPhone to shopping cart at shopX! Now we'll show you iPhone ads for a week on every site you visit!". And user is beating her head against the wall because she bought the iPhone offile a week ago.
If 3rd party cookies will be disabled by default in significant part of browsers, all that players will need to find a ways to add some value visible to users and show it to them and convince them to enable 3rd party cookies manually because that will be just the only way to track them.
We don't know yet what that added value(s) could be, but I'm sure they will be invented. And that would be good thing.
But users will never manually enable 3rd party cookies, even if they agreed with you that the ads were adding value (which odds are they never will either).
Content has to be monetized in some way -- if not ads, then how?
All that blocking 3rd party cookies will accomplish is put most of the less technically-mature shops out of business while the smart ones figure out a way to route around using the exact same data science for targeting.
Charge for it perhaps?
It depends. Maybe not the ads per se would be added value, will see anyway.
And by the way, ads may be the content on its own, don't you think? Ask anyone of 30+ mln people who had viewed last Pepsi&Jeff Gordon commercial on YouTube for example.
I work at a "retargeting shop" and our customers test the crap out of our tools to make sure we're actually driving results. Others may use more smoke and mirrors, but when done right, retargeting does in fact change user behavior and generate ROI.
But most e-commerce retargeting, IMHO, is trading on the fact that a naive marketing manager will put too much stock in a high conversion percentage. All of those people were, by definition, aware of the product and actively shopping. Did you create a customer? Probably not, maybe by virtue of them clicking the ad instead of going somewhere else, but that's still pretty zero-sum.
Prospecting for people who haven't previously clicked the item on your site, but would be interested, is a lot harder and potentially more valuable.
All IMHO of course.
granted not every viewthrough and clickhtrough conversion is driven by the advertising, but some definitely are and it is often profitable if a campaign is optimized and run well.
<script src="http://www.google-analytics.com/ga.js">
Inside the script there are calls to cookie-dropping javascript functions. The browser makes no distinction between javascript loaded via a script tag from your domain, another domain, or simply inline, so any cookies it leaves or reads are "first party".If they set cookies via HTTP on the request for www.google-analytics.com/ga.js, those would be "third party", and because google-analytics.com isn't a site anyone visits, the new firefox policy would reject them.
Thanks for the clarification. Using 1st party cookies definitely weights Mixpanel over Kissmetrics in our eyes.
Targeted ads are not a win-win, they're creepy.
Individual sites can still track you with third-party analytics tools by creating a CNAME (DNS alias) to a third-party tracking domain.
Outside of Local Storage, is there still a loop-hole (though it defies user expectation) for ad retargeters (they must rely on third party cookies)? I feel, if not, that this will totally kill those businesses. I am neutral and just wondering if I am missing something.
Google was sued for using iframes to get around this so defying user expectation no matter the loop hole is quite dangerous.
http://en.wikipedia.org/wiki/HTTP_ETag#Tracking_using_ETags
Not sure whether the Firefox folks have figured out a way to patch this workaround up or not.
I do think that retargeting businesses are in for a bit of pain given the headwinds re: third-party tracking across the US and world.
The only site that has ever had a problem was my local power company (aps.com). However, it was easy to get around because even though their site warned that 3rd party cookies were required, you could just click around it to pay your electrical bill.
I've never had a problem on any other sites that I use in at least five years, though I suspect it's been more than that.
On balance it seems a net gain all the same.