News: 1614150132

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Mozilla Firefox keeps cookies kosher with quarantine scheme, 86s third-party cookies in new browser build

(2021/02/24)


Mozilla has revised the way the latest build of the Firefox browser handles HTTP cookies to prevent third-parties from using them to track people online, as part of improvements in build 86 of the code.

HTTP cookies are files stored by web browsers to save state – e.g. is the user logged in? – that get set by code running on the visited website. Some such code, known as tracking scripts or trackers, may point to third-party servers, like those run by ad tech companies.

[1]

The third-party cookies placed by these scripts can be read on other websites that also load tracking code and are often used to follow people from website to website in order to build interest profiles for behavioral ad targeting. At least that's the case for those who haven't already limited the reach of third-party cookies through privacy-focused browsers like Brave, Firefox, and Safari.

Though third-party cookies are on their way out – Google plans to stop supporting them in 2022, the ad giant has said – they're still used in ways that impinge upon the privacy of web users.

[2]

In a [3]blog post on Tuesday, Mozillans Tim Huang, Johann Hofmann and Arthur Edelstein said that Firefox, as part of its Enhanced Tracking Protection (ETP) Strict Mode, now includes a feature called Total Cookie Protection that creates a separate partitioned space for cookies so they can only be accessed by the website that created them.

Huang, Hofmann, and Edelstein describe this as a separate cookie jar for each website.

Firefox 85 crumbles cache-abusing supercookies with potent partitioning powers [4]READ MORE

"Any time a website, or third-party content embedded in a website, deposits a cookie in your browser, that cookie is confined to the cookie jar assigned to that website, such that it is not allowed to be shared with any other website," they said.

That sort of isolation will prevent third-parties from being able to read cookies set by code on first-party websites.

Total Cookie Protection represents a more accessible take on First Party Isolation, a privacy technology added to Firefox 55 in August, 2017 that was inspired by Tor's [5]Cross-Origin Identifier Unlinkability . First Party Isolation wasn't mentioned in Firefox's release notes at the time, presumably because it was experimental and broke services like third-party login systems (Single Sign-On services like Google Sign-In, Facebook Login). To enable it, you had to alter parameters in Firefox's about:config settings page.

What makes Total Cookie Protection more accessible is that it isn't really Total Cookie Protection. Rather it's Total Cookie Protection With Some Exceptions, Handled Automatically – not exactly the sort of branding that rolls off the tongue. As the trio of Mozillans explain, "Total Cookie Protection makes a limited exception for cross-site cookies when they are needed for non-tracking purposes, such as those used by popular third-party login providers."

Mozilla's implementation tries to handle exceptions automatically using rules to detect legitimate (non-tracking) uses of browser storage by third-parties such as the Single Sign-On, so it can grant access accordingly.

But this is only intended to be a temporary solution until the [6]Storage Access API , a proposed JavaScript API to handle legitimate exceptions to privacy protections like SSO usage, sees wider adoption. Currently, the API is supported in Edge, Firefox, and Safari, and is accessible in Chrome by setting a feature flag.

The three Mozillans contend that Total Cookie Protection, in conjunction with the [7]supercookie protection that debuted last month in Firefox 85 will "prevent websites from being able to 'tag' your browser, thereby eliminating the most pervasive cross-site tracking technique."

[8]

Meanwhile, Google and its ad tech frenemies are [9]racing to develop various Privacy Sandbox proposals so they can implement behavioral ad targeting [10]"without needing to collect a particular individual’s browsing history." ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YDYxzsxDfmn5SW0RiYp9wAAAAEw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YDYxzsxDfmn5SW0RiYp9wAAAAEw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[3] https://blog.mozilla.org/security/2021/02/23/total-cookie-protection/

[4] https://www.theregister.com/2021/01/27/firefox_85_crumbles_supercookies/

[5] https://2019.www.torproject.org/projects/torbrowser/design/#identifier-linkability

[6] https://privacycg.github.io/storage-access/

[7] https://www.theregister.com/2021/01/27/firefox_85_crumbles_supercookies/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YDYxzsxDfmn5SW0RiYp9wAAAAEw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2021/01/25/google_targeted_advertising/

[10] https://github.com/WICG/floc

[11] https://whitepapers.theregister.com/

Don't understand

StrangerHereMyself

Firefox already had a setting that blocked third-party cookies, but they replaced it with its Tracking Protection setting.

Thing is, I don't really know what it does, and which third party cookies are henceforth blocked. If they only block a known subset it becomes an arms-race with trackers continuously coming up with new cookies and tracking schemes.

Re: Don't understand

John Robson

Of course it's an arms race.

The question is:

login.company.com is probably the same domain as company.com

But what about fb.company.com, which when you look it up is actually a reference to faecebook. Faecebook can then set a cookie that *looks* like a cookie from company.com, but is actually a third party cookie.

Re: Don't understand

Charlie Clark

I'm not sure how many companies would approve such sub-domains – there are definite legal ramifications – but even so DNS checks for the ip-addresses would soon indicate the real owner.

Re: Don't understand

Androgynous Cupboard

More than you'd think, apparently. There's a whole article on the topic: [1]https://www.theregister.com/2021/02/24/dns_cname_tracking/

As for DNS checks to identify the owner, not really. It resolves to Amazon Cloud - now what? Is it the a cloudy server for the domain I intended to visit, or a cloudy server for some adslinger?

[1] https://www.theregister.com/2021/02/24/dns_cname_tracking/

Re: Don't understand

Greybearded old scrote

Well, it is explained in the article. There are some cases when you might want a third party cookie to function, such as a single sign on. That's still a 'turkeys voting for christmas' situation, but if the turkeys want the convenience there it is.

FB will still be able to track you on those sites, or else it can't work.

Only one buttock?

Mike 137

This, yet again, seems a half arsed solution to only part of the problem.

Under European Directive 2002/58/EC (implemented in the UK as the Privacy and Electronic Communications Regulations 2003) there is a distinction made between cookies essential for providing a service to the user (e.g. shopping cart purchase lists) and other cookies. This is regardless of whether [a] they are literally "cookies" or any other kind of tracker, and [b] they are first or third party in origin. At the risk of over-simplification, essential cookies are allowed automatically, but informed user consent is required for non-essential cookies.

So measures that only address literal cookies but not other trackers, or that only distinguish between first and third party trackers, do not protect user privacy to any useful extent.

Re: Only one buttock?

Charlie Clark

I don't agree. While this doesn't prevent tracking per se, it does significantly limit tracking across websites, which is what most of the trackers are interested in. Also, as a browser setting, it overcomes user inertia when it comes to handling cookie settings: most will go with "accept all" to continue with whatever they're doing.

ExampleOne

Blocking cookies simply stops the easiest and laziest way of tracking people. It isn't hard to track by abusing the browser cache.

Of course, I have rarely seen a discussion of alternative methods of tracking, it is all about the cookies.

Dan 55

Firefox reduced browser fingerprinting when they did the [1]Tor uplift project and again in [2]FF 72 . And probably other times as well.

[1] https://www.theregister.com/2017/10/30/firefox_canvas_privacy_tor/

[2] https://www.theregister.com/2020/01/08/firefox_72/

Time to take Single Sign On out of the hands of Google and Facebook

Howard Sway

Make them pay for a non profit, security and privacy focused independent org that has sole responsibility for SSO authentication and tokens, that they are not allowed to have any influence over. They've abused their dominance of SSO to track people for profit, and have therefore forfeited the right to stay in the game.

"And remember: Evil will always prevail, because Good is dumb."
-- Spaceballs