Slashdot Mirror


Firefox Will Soon Block Third-Party Cookies

An anonymous reader writes "Stanford researcher Jonathan Mayer has contributed a Firefox patch that will block third-party cookies by default. It's now on track to land in version 22. Kudos to Mozilla for protecting their users and being so open to community submissions. The initial response from the online advertising industry is unsurprisingly hostile and blustering, calling the move 'a nuclear first strike.'"

27 of 369 comments (clear)

  1. Online Advertising Response by FSWKU · · Score: 5, Insightful

    The initial response from the online advertising industry is unsurprisingly hostile and blustering, calling the move 'a nuclear first strike.'

    Translation: Boo-fucking-hoo. Online marketing scum have been abusing users for years, making this a retaliatory measure. Let them cry all they want, because nobody gives a shit.

    --
    "So after all this, you make my case for me. To end this stalemate, you must die..."
    1. Re:Online Advertising Response by CheshireDragon · · Score: 5, Interesting

      I have always turned of the third party cookies, but good move for making it a default.
      And to hell with marketers, they can cry all they want. They have already stripped most television show of a title sequence and forced shows to start rolling credits while still running. Ihave always wondered why I pay for a ton of cable channels when all I am really doing it watching commercials. Good thought to the creator of the DVR.

      --
      "That's right...I said it."
    2. Re:Online Advertising Response by JaredOfEuropa · · Score: 5, Insightful

      Killing 3rd party cookies doesn't mean the end of advertising, not even the end of targetted ads like Google adwords. Neither rely on 3rd party cookies. It will mean the end of tracking users across sites, collecting browsing history that they have no business collecting (and which most users are not even aware of).

      --
      If construction was anything like programming, an incorrectly fitted lock would bring down the entire building...
    3. Re:Online Advertising Response by fluffy99 · · Score: 5, Interesting

      It's interesting that no-one has ever tried to retaliate against them using the COPPA law, which makes it illegal to track and retain information on underage kids.

    4. Re:Online Advertising Response by Cryacin · · Score: 5, Funny

      Wait a second. "Think of the children" used to PROMOTE privacy? That's not how it's supposed to work! My head hurts, I have to go and lie down for a while...

      --
      Science advances one funeral at a time- Max Planck
    5. Re:Online Advertising Response by Anonymous Coward · · Score: 5, Interesting

      IMHO, the next step is to block referrer information to third party sites. E.g. if example.com loads a script from gstatic.com, then the HTTP_REFERER header is not sent to gstatic.com. There's almost zero collateral damage (one captcha service doesn't work), and companies like Facebook and Google no longer get to know every site that most internet users visit.

    6. Re:Online Advertising Response by PopeRatzo · · Score: 5, Insightful

      Sorry Charlie, but advertising and monetization drives the "free content" you see on the web.

      And blocking third party cookies does nothing to stop advertising and monetization.

      It just puts it on a more honest footing.

      By the way, there was free content on the web before there was advertising. Maybe you're not old enough to remember.

      --
      You are welcome on my lawn.
    7. Re:Online Advertising Response by Anonymous Coward · · Score: 5, Interesting

      I canceled Sky a long, long time ago, when they started broadcasting general advertisement on History Channel, National Geographic etc. Went from reading 1-2 books per year to more than 30. There's not much to see anyway: films are quite boring and lame, TV series are the same or really bad production (Sword of Truth comes to mind) and most documentaries are simply ridiculous with one third of the content being useless reviews after advertisements (just imagine to see them with half of the number of interruptions, it's completely insane). I would gladly pay for BBC documentaries however.

    8. Re:Online Advertising Response by me+at+werk · · Score: 5, Interesting

      Ah, well, it seems they're doing that in the mobile market, anyway.

      They're actually doing something about this because some smartphone games for children do location tracking, and nobody knows why.

      According to the FTC, among its more troubling findings is that many children's apps "shared certain information with third parties -- such as device ID, geolocation, or phone number -- without disclosing that fact to parents. Further, a number of apps contained interactive features -- such as advertising, the ability to make in-app purchases, and links to social media -- without disclosing these features to parents prior to download."

      --
      For context, click Parent.
    9. Re:Online Advertising Response by TheGratefulNet · · Score: 5, Insightful

      I have not watched network/premium tv for quite a while, now (3 yrs, maybe longer).

      recently, I was staying in some hotels and wanted to see what 'was on'. realize, I have not seen the state of 'current tv' for years.

      the moving ads at the bottom and all the rest that you and parent posters have said really turned me off. enough that I will still not consider paying for satellite, cable or anything else 'pay tv'.

      really gross and hard for me to accept. I'm over 50 and I do remember when tv was watchable. (yes, goml, etc). but if you have not been desensitized by it gradually, the jump in annoyance factor is too great. I think they have lost me, forever now, as a customer.

      tv was always an ad medium, but now its just too absurd!

      I can fully, fully understand why the youth culture is all about capturing shows, editing the BS out of them and reuploading them. I fully understand that and I can't blame anyone for wanting to get around the crap.

      sorry, industry; you pissed off your customers and many have rebelled and won't ever come back.

      --

      --
      "It is now safe to switch off your computer."
    10. Re:Online Advertising Response by nedlohs · · Score: 5, Informative

      For firefox: network.http.sendRefererHeader, set it to 0 in about:config

  2. Why wait for v22? by Jimbookis · · Score: 5, Insightful

    Stick it in v19.0.1. Bring it on!

  3. Need more nukes by femtobyte · · Score: 5, Funny

    If the advertising industry is still capable of responding, we obviously haven't nuked them enough yet.

  4. A nuclear first strike... by John+Hasler · · Score: 5, Insightful

    ...would be incorporating AdBlockPlus and NoScript and enabling both by default.

    Do it.

    --
    Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
    1. Re:A nuclear first strike... by Mitreya · · Score: 5, Informative

      incorporating AdBlockPlus and NoScript and enabling both by default.

      Quite a few websites (whether intentionally or not) make it difficult to figure out which domain needs to run javascript for them to function. It is often _not_ the current domain. So users will end up choosing "Enable all scripts (dangerous)" option with NoScript sooner or later.

      Also, when the webpage redirects you to a processor for finalizing a payment, a lot of work can be lost. Cannot go back without losing entered data and cannot complete the payment because reload will screw things up. NoScript should really ask you "Click redirects to a different domain -- enable scripts there?"

  5. just block all cookies by manicpop · · Score: 5, Informative

    The great thing about Firefox is you can block all cookies by default, and whitelist only specific domains. Just block everything except ones you know you need (like maybe your banking site). Use "allow for session" for sites that need cookies for some reason but you don't need to save permanent data. There's also a great extension called "Cookie Monster" that will let you set all those options on a per-domain basis from the status bar.

  6. No the complaining will start... by Anonymous Coward · · Score: 5, Interesting

    When they just get websites using their advertising services to add subdomains covering their cookies.

    At that point you WON'T be able to solve this without a huge mess of per-domain whitelists, eventually coalescing into the cookies for the advertisers being handled THROUGH the corporate websites.

    I was arguing this a decade or decade and a half ago to anyone who would listen, but it was brushed off (And rightfully so given that it's taken this long for a browser to actually this by default.)

  7. Re:Feature Request: remove all cookies EXCEPT by rihkama · · Score: 5, Informative

    I regularly clean out my cookies with "delete all", but I'd prefer to keep the ones for sites that require a login. But it's too hard to delete cookies individually.

    You can achieve that in Firefox without any extra extensions: Under Privacy: 1. Use Custom settings for history - Accept cookies from sites - Keep until: I close Firefox 2. Under Exceptions: - Add sites you want to allow permanent cookies sites using "Allow" button Done. Sites you allow can store cookies until they expire while other cookies are cleared every time you close the browser.

  8. Not that simple (Re:Online Advertising Response) by Giorgio+Maone · · Score: 5, Informative

    The patch is not exactly a one-liner, because the implemented behavior is not as straight-forward as just "block 3rd party cookies".

    It's "block cross-site cookies from origins which I've not visited yet as a 1st party websites and have already 1st party cookies from".

    This means, for instance, that Facebook, Google and Twitter gets likely a free-pass to track almost anybody.

    And that once you (accidentally or not) click any ad box, you give a free-pass to its advertising agency too.

    --
    There's a browser safer than Firefox, it is Firefox, with NoScript
  9. Insanity laden cookies by WaffleMonster · · Score: 5, Informative

    If you have some spare time restart your browser, fire up wireshark and filter for DNS queries then go to just the home page of any of a bazillion web sites... It is insane... one single page load of something like cnn,fox,nbc,forbes translates into 20-30 of dns queries for all manner of advertising and market intelligence companies.. Everyone knows this stuff exists but I was genuinly shocked by the volume and number of sites involved.

    If it isn't cookies it will be fingerprinting, flash cookies, DNS cache probing + IP but we can work to mitigate these things as well.

  10. Re:Nuclear Response by Blue+Stone · · Score: 5, Insightful

    The ad industry launched several nuclear 'first-strike' slavos against browsers: pop-ups, pop-unders, interstitials, flashing seizure-inducing Gif ads, javascript pop-overs, flash audio adverts, scroll-overs, surreptitious super cookies, etc, etc, etc.

    Fuck them. In the ass.

    No lube.

    --
    Corporation, n. An ingenious device for obtaining individual profit without individual responsibility. - Ambrose Bierce
  11. Re:Not that simple (Re:Online Advertising Response by Anonymous Coward · · Score: 5, Insightful

    Above post should be moderated to +10.

    Sounds like the big guys are looking to squeeze out any smaller competition. Not a surprise, since Mozilla is pretty much Google's bitch.

    Although I'd prefer that tracking would simply be made illegal, I tell you what: I'm less concerned about letting the big guys doing it because they are more likely to have some basic security in place and controls to at least respect the TOS. I'm more concerned about small guys...

  12. Re:Consequences by Mashiki · · Score: 5, Interesting

    Sites will start blocking Firefox browsers...

    Considering anyone with 3 firing neurons already blocks advertising to begin with, this is pretty much moot. The reality is advertisers have been abusing cookies for decades, the worst of advertisers have been abusing advertising itself, and allowing malware into their networks and taking a 'cut' of the scam.

    Personally? Until advertisers man up, and stop acting like the guy standing on the corner of a shady neighborhood going "hey, wanna buy some shit..." they can simply suck it.

    --
    Om, nomnomnom...
  13. Re:Not that simple (Re:Online Advertising Response by eric_herm · · Score: 5, Insightful

    I also think this could block lots of cookies used for SSO. Some people do actually like to be able to log using their twitter or github credentials.

  14. Re:Not that simple (Re:Online Advertising Response by allo · · Score: 5, Interesting

    then the question is, why not doing it the other way round: allow 3rd-partys to access their own cookies, but do not allow them to set a cookie, if they are not the 1st party at the moment.

  15. - is tired of hyperbole by SampleFish · · Score: 5, Insightful

    Fuck these assholes until they bleed.

    "Nuclear first strike"? It's a counter-measure. I'm so sick of people using war rhetoric inappropriately. There is no "nuclear cookie blocker" and there is no "war on Christmas". There are no bombs going off and nobody is dying in the streets. This statement makes me want to bomb the corporate office of an ad agency so they have something to complain about*. Might stop the spam for a week too.

    *This user does not support the actual use of explosives to make a point. Bombs are not educational tools and should be used responsibly. We now return to your regularly scheduled flame war.

  16. Easy to bypass 3rd-party-cookie-blocking via CNAME by knorthern+knight · · Score: 5, Interesting

    I hate to rain on your parade, but...

    Let's say someone has a website http //www.good.example.com, and want http //ads.doubleclick.net to get past this filter. Assuming they control their own DNS, they simply need to set up a CNAME www.bad.example.com that points to ads.doubleclick.net. Voila, the ads.doubleclick.net server shows up on the same domain as www.good.example.com.

    --

    I'm not repeating myself
    I'm an X window user; I'm an ex-Windows user