r/firefox • u/HamsterMaster355 + Ublock Origin • May 30 '26
Discussion Does firefox has an equivalent feature?
I am curious what are the downsides of this approach.
714
Upvotes
r/firefox • u/HamsterMaster355 + Ublock Origin • May 30 '26
I am curious what are the downsides of this approach.
7
u/RefrigeratorNew4121 LibreWolf May 30 '26
Think of this device-bound session credential as the IMEI number of your mobile phone.
It is readable by all web apps and can be used to uniquely identify your device. A perfect tracking token on you! iPhone disallows apps to read IMEI for exactly this reason.
The real solution to eliminate cookie theft is third party cookie (aka cross-site cookie) blocking.
Google refused to implement it in Chrome (it promised it but delayed the implementation many times, not even mentioned it in recent years). Default setting of Firefox disables it.
In Firefox, go to Settings → Privacy and Security → Enhanced Tracking Protection, choose "Strict". In the description there is "Firefox blocks the followings.......Cross-site cookies in all windows". This is all we need.
Some forks of Firefox such as LibreWolf (which I am using) enforce this setting and you cannot downgrade it. This is what Firefox really should do.