HNHacker News
TopNewBestAskShowJobs

ove

25 karma · joined November 23, 2008

submissionscomments
ove··on Self-Destructing Cookies – add-on for Firefox
that was my favourite test case when i developed the add on. I'm on the road now, so I can't verify if they still do it. it might depend on you having a YouTube account linked to your Google account. The technique I'm referring to involves redirecting you across other domains, allowing them to set 1st party cookies, and then back. this happens in an instant and "feels" like a 3rd party cookie to the user, because he does not even realize this happened. the browser will treat it as a 1st party cookie however.
ove··on Self-Destructing Cookies – add-on for Firefox
I'm the author of that add-on. Maybe I can add to the discussion by outlining my motivation for writing SDC. I'm currently in the process of compiling the results of an automated crawl of thousands of popular sites that I did last month. I think that every www user should be aware of this:

- The privacy model of browsers relies on the same-origin policy. The same origin policy is in practice routinely circumvented by active identifier sharing. The difference between 1st party identifiers and 3rd party identifiers has become meaningless.

- Self-Destructing Cookies is a proof of concept for a model that actively derives the minimum set of identifiers that you need to browse the web at any given moment. This is a possible workaround for a world without the same-origin policy.

- Cache abuse is rampant. The cache must be considered a store of identifying tokens. If you use SDC, you should definitely enable the automatic cache cleaning. Set the timeout to 3 minutes or so. Remember that identifiers are frequently shared. It only takes a single party to identify you from something they put in your cache.

ove··on Self-Destructing Cookies – add-on for Firefox
Thank you for your feedback. I agree that the first-run experience makes for quite the adventure. Until a few months ago, I also considered the idea of starting the add-on in a paused state a no-brainer. After supporting my add-on for some time, however,I'm not so sure about that any more. There's a huge portion of users (probably not HN readers) that would not realize that the add-on is paused. Pop-ups, etc. only go so far. It's really about managing expectations and expectation mismatches. I hope that the portion of users who care about their pre-existing cookies overlaps with the portion of users who read the "What just happened to my cookies" blurb that pops up. I haven't had too many angry complaints since I added the undelete feature, so it might be working.
ove··on Firefox getting smarter about third-party cookies
Disabling 3rd party cookies has never broken a single site for me. I've heard that some banks require them, though. As for Self-Destructing Cookies: it's a pretty drastic measure. Considering this, it's surprisingly compatible. Among the sites that I frequent, not a single one stopped working. Inter-domain transaction - e.g. a shop forwarding you to Paypal and back - used to be a problem, but the latest version has a heuristic for that. Still, I'm pretty sure that some people will experience fallout. You can work around that; SDC has numerous functions that can help in such cases (pause, undelete, whitelist for session).
ove··on Firefox getting smarter about third-party cookies
Hi, I'm the author of this add-on. You might want to read the FAQ entry "Q: How is this different from disabling 3rd party cookies and installing Adblock?". Firefox's new 3rd party cookie policy is actually weaker than disabling them outright, so this will not change anything.