Firefox to auto-block third-party ad cookies by summer
Online advertising exec calls move 'nuclear first strike' against industry
Computerworld - Mozilla will automatically block third-party cookies starting with Firefox 22, which is slated to ship this summer, according to the Stanford University researcher who coded the change.
The move, which will make it more difficult for online ad networks to track users' activities, was only the latest skirmish in a war between advertisers and some browser makers.
In a blog post and on Twitter, Jonathan Mayer, a graduate student in computer science and law at Stanford University, and one of two researchers at the school who created the HTTP header implementation that signals a user's "No Dot Track" preference, announced the new Firefox cookie policy.
Mayer kick-started the change last December when he submitted code to the Bugzilla bug-tracking database operated by Mozilla. It was Mayer's first contribution to the open-source Firefox.
"The default Firefox cookie policy will, beginning with release 22, more closely reflect user privacy preferences," Mayer claimed in a post to his blog last week.
Mozilla has added the cookie change to Firefox's "Nightly" channel, the browser's roughest-edged version. Unless the modification is sidetracked or Mozilla changes its mind, the new policy will first appear in a final release of Firefox on June 25.
Cookies are used by online advertisers to track users' Web movements, then deliver targeted ads. The new Firefox policy will allow cookies presented from domains users actually visit -- dubbed a "first-party" site -- but will block those generated by a third-party domain unless the user had previously visited the cookie's site-of-origin.
Examples of first-party cookies are those placed in a user's browser by sites like Amazon.com to identify the customer on repeat visits, letting him or her skip the log-on sequence. Third-party cookies, however, are often placed in ads on first-party sites so that advertisers and online ad networks can track a browser's past activity.
When the new policy goes into effect, Firefox users will need to clear all cookies to start with a fresh slate. Doing so, however, requires a user to laboriously reenter usernames and passwords to again access websites.
Although Mozilla has not publicized the change, developers and company executives, including Brendan Eich, Mozilla's CTO, and Asa Dotzler, the Firefox desktop product manager, debated the new policy on a discussion thread for several weeks before approving the change.
"I'm in favor of moving forward on this, cautiously," Dotzler said Feb. 11 on the thread. "As long as we have confidence at each step of the way that we're not breaking significant numbers of users or sites, this is a good move."
Mozilla will be following in the footsteps of Apple's Safari, which also blocks third-party cookies by default. "The new Firefox policy is a slightly relaxed version of the Safari policy," said Mayer in an FAQ published on his personal blog.
Even so, at least one online ad official slammed Mozilla for making the change. "Firefox to block 3rd party cookies? This default setting would be a nuclear first strike against ad industry," said Mike Zaneis, general counsel for the Interactive Advertising Bureau (IAB), on Twitter Saturday. The IAB is one of several advertising organizations that has been fighting other privacy moves by browser makers, including Microsoft's decision to set "Do Not Track" on by default in Internet Explorer 10 (IE10).
"Second strike, technically (Safari)," retorted Justin Brookman, director of consumer privacy at the Center for Democracy and Technology, also on Twitter.
All browsers, including Firefox, have settings that let users manually switch off all cookies, or refuse those from third-party sites. But only Safari currently blocks all third-party cookies by default. Safari's small share -- in January, Net Applications pegged it as just 5.2% -- was likely too low to trigger the online ad industry's concern. Firefox is a different beast: According to Net Applications, Firefox was the second-most-used browser last month, with a 19.9% share globally.
But Mozilla didn't view the change as a first strike of any kind, nuclear or otherwise, aimed at online advertising. "We are not trying to stop tracking with this feature," Mozilla's Dotzler said on the discussion thread Sunday. "We are trying to make tracking relationships more obvious to the user."
It would not in Mozilla's self-interest to disrupt the online ad industry, as it generates the bulk of its revenue from a deal with Google, which pays the browser maker a reported $300 million a year for setting Google's search engine as Firefox's default.
The Nightly build of Firefox for Windows, OS X and Linux can be downloaded from Mozilla's website.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer, or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@ix.netcom.com.
Browser wars
- Mozilla to Firefox: 'Browser, heal thyself'
- Best case, Mozilla's Firefox for Windows 8 will ship in October
- Microsoft's browser auto-update pays off as IE10 share doubles
- Sued Opera designer fingers Mozilla's 'Search Tabs' as root of $3.4M claim
- Update: Opera slaps former designer with $3.4M lawsuit for spilling secrets
- As browsing goes mobile, Apple wins, Mozilla loses
- Mozilla pulls tracking trigger for Firefox 22, ignores ad industry attacks
- Mozilla refines Firefox's private browsing, patches 13 browser bugs
- Mobile's browser usage share jumps 26% in three months
- Mozilla again rejects porting Firefox to iOS
Read more about Internet in Computerworld's Internet Topic Center.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Is Your Service Desk Falling Behind? Read this use case document to understand how social IT collaboration can breathe new life into your existing service desk or ITSM installation...
- Three IT Imperatives CIOs Use To Drive Change Throughout the Enterprise CIOs who have been successful in bridging the divide between IT operations and business did it by accelerating the transformation of IT.
- Improving Change Management Through Collaboration Read this use case document to explore a real-world example of how social knowledge collaboration improves the accuracy and speed of change planning.
- Defending Against Today's Targeted Phishing Attacks Learn guidelines on how to recognize advanced threats and protect yourself from them.
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in...
- Enterprise File Sharing: All You Need to Know Security. Scalability. Control. These are just some of the many benefits of enterprise cloud file-sharing that you'll discover in this KnowledgeVault, packed with... All Internet White Papers | Webcasts
Our weekly newsletter will cover a wide range of topics and trends related to consumerization. Stay up to date with news, reviews and in-depth coverage of BYOD, smartphones, tablets, MDM, cloud, social and how consumerization affects IT. Subscribe now!
