Self-Destructing Cookies – add-on for Firefox
addons.mozilla.org
addons.mozilla.org
Upon the first run, without warning, I see this: "If you read this, all of your cookies that are not currently in use just self-destructed. Don't panic. You can undo this if you prefer to keep them for now." . . . "Undeletes happen in batches. If you had a lot of cookies, you might need to restore more batches. Click SDC's icon again. Select Undelete (more) cookies from the menu. Repeat this until you get a notification stating that No more undeletes are possible."
Couldn't the extension have simply asked me once before proceeding with the delete in the first run? Basic usability.
Blindly following some person's recommendations doesn't even close to having good UI (or UX). eg. Opting for no confirmation and providing an undo option is an absolutely terrible idea for a 'format disk' button in an OS installer.
- The privacy model of browsers relies on the same-origin policy. The same origin policy is in practice routinely circumvented by active identifier sharing. The difference between 1st party identifiers and 3rd party identifiers has become meaningless.
- Self-Destructing Cookies is a proof of concept for a model that actively derives the minimum set of identifiers that you need to browse the web at any given moment. This is a possible workaround for a world without the same-origin policy.
- Cache abuse is rampant. The cache must be considered a store of identifying tokens. If you use SDC, you should definitely enable the automatic cache cleaning. Set the timeout to 3 minutes or so. Remember that identifiers are frequently shared. It only takes a single party to identify you from something they put in your cache.
I simply turned off disk and memory caching in Firefox (details in link above) and have been running this way for nearly two years. Browsing the web with cache is not as efficient, but with my ~8Mbit Internet connection, practically, I don't really notice any difference.
To get around the tracking issues, ideally, browsers would cache content, but it would be keyed on the domain in the address bar as well as the url of the content being cached. Also, content should be wiped from the cache when you leave the site it is linked to, ie there are no more tabs with the site open.
RequestPolicy would help against this sort of attack when performed cross-site. However, there is still a leak if a site can identify that you're the same user they previously saw. RequestPolicy wouldn't help against this as it's not cross-site.
1. Install the add-on.
2. Panic that it has deleted all "not open now" websites' cookies.
3. Choose the option to "Suspend Operation" via the add-on icon.
4. Repeatedly "Undelete" all cookies until it's all done.
5. Keep the add-on suspended.
6. Now, for the next few days, I will browse like normal, but will remember to "whitelist" the websites I like to stay logged-in (Hacker News, Webmail, etc.) by clicking on the add-on icon. Remember, it is still "Suspended".
7. After a few days of usage (and when I've re-visited enough number of my regular websites), I will "Resume Operation" on the add-on, where it can start destroying the rest of the cookies like anything.
I think the "Training Period" above in point 6 should have been by default. Somehow.
https://addons.mozilla.org/en-US/firefox/addon/cookie-monste...
It allows you to maintain a white-list of sites that are allowed to set cookies and allows you to pick whether the cookies the site sets are persistent or discarded at the end of the current browser session.
This feature makes many sites work which otherwise break with third party cookies disabled, while still discarding the majority of third party cookies.
What about sites that you never visit (= type in address bar / follow links to) directly, but which are on some subdomain of the visited site nonetheless? Cookiemonster will accept the cookie. Firefox, with your config, will not.
What about sites that you do visit (eg facebook.com) but don't want to accept/send third party cookies for? Firefox, with your config, will. Cookiemonster won't.
The most important feature is that it's easy and quick.
This way users of this plugin can rely on the wisdom of the crowds to quickly see which cooks people who know better commonly block.
Should every user look over the entire list of cookies on a site? Yes, in an ideal world. But since that isn't realistic, the best we can do is present them with those they will mostly likely want to block right at the top.
On a related note, Chrome has a setting that simply kills all the cookies when the browser is shut down. The price is having to log into everything all over again, but it's not that much of a hassle in exchange for a clean plate every morning.
Would be interested in something comparable for Safari. Anyone?
Cookies, flash cookies, evercookies, local storage, favicons, browser fingerprinting... I'm sure there are several others.
It's stunning to me because the amount of redundant ammunition available for trackers seems way out of proportion to how many people actually know anything about this.
Note that I am not trying to justify these techniques.
I'm signed into Google almost all the time and YouTube still shows "Sign in." Re-checked right now.
Third party cookie protection seems to be working fine. It's Firefox 22 with accept third-party cookies set to never.
But still, thanks for reminding that I can disable 3rd-party cookies -- I just did that for my firefox.
With Pingdom it asked me to reenter my timezone and site to monitor. It is like it totally lost my account without the cookie.
My buddy Cookie Whitelist has let me decide when I need them on temporarily for years. They're not auto-deleted until session-end, but since I've turned off access, doesn't matter.
I do like the cache-emptying feature. Decided to try what another writer suggested, turn disk and memory caching off.
Wouldn't that allow all the Adwords tracking cookies as well, across sites?
I thought there was a big fuss about FF doing this by default or something.
Wouldn't this mean that only doubleclick.net is used for advertisement tracking?
[1] http://www.google.com/intl/en-US/policies/technologies/types...