Attached: 2 images
Did you know? Despite claiming to block *all* cross-site cookies out of the box, Firefox automatically allows Google to use them in your browser should you log in to one of their services (I only use YouTube, but I'd assume it's the same with anything that needs a Google account)...
Did you know? Despite claiming to block all cross-site cookies out of the box, Firefox automatically allows Google to use them in your browser should you log in to one of their services.
The browser only lets you know about this once it happens, and it's on you to notice the permissions icon appearing in the URL bar. There is a link to a paragraph on a help page explaining this behaviour, but it seemingly goes unmentioned pretty much everywhere else on the internet.
This surprised me, especially considering Firefox's stance on privacy. I was even more surprised that this is done without consent. If this is for usability, Firefox should at least warn the user before this happens.
People have been up in arms for every new "flavor of the month" browser that boasts better security, or some new privacy thing, and Firefox not offering it. Also, the freakout about Mozilla enabling "ad-tracking" was wildly misunderstood and overblown by the privacy nuts, but started a slew of these "WELLFFDIDTHISTHINGBLETRRGGHWAAAHHHHHHH"
the moment I saw login im like um yeah I bet same with microsoft or any other login that is across. wait for it. sites. login to outlook.com and then go to 0365
If you access Google sites only in a special Firefox container, that still isolates your Google cookies from the rest of your tabs? Or does it just add a “you don’t get this from me” flag when it gives Google your user cookie, so it can pretend to not recognise you as it adds your web-browsing history to your ad-targeting profile (flagged appropriately as to keep it deniable, of course)?
Yes.
I have a google container for one account.
If I open a google site in another container it will be as if the account didn't exist.
The containers are all partitioned.
You can also partition off the cookie/storage per site by proxy used (in about:config).
So, you could create a container for google account 1 using proxy 1 and another container for google account 2 using proxy 2 and they will never have access to the data stored by either.
Out of curiosity, do you know if these containers also obfuscate browser and device fingerprinting? Separating cookies is important but unless it also blocks fingerprinters (in a different way for each container) the site will instantly know the same person is using both accounts.
I think the "rest of your tabs" would have to be sites that already include google js (e.g. for "sign in with google" type stuff) to even know you have a google cookie (otherwise what's the point of FPI/ETP/TCP/network partitioning/no-3rd-party-cookies/etc.), but I could be wrong.
Is it sufficient to set the Enhanced Tracking Protection to "Strict" (which claims to block cross-site cookies in all windows), or is there something else you have to do?
Not sure. It’s unverified speculation. People are weirdly attached to software these days. My answer to problems like these is to find something else. Tor seems decent.