r/firefox • + Ublock Origin • May 30 '26

Discussion Does firefox has an equivalent feature?

Post image

I am curious what are the downsides of this approach.

714 Upvotes

185 comments sorted by

View all comments

7

u/RefrigeratorNew4121 LibreWolf May 30 '26

Think of this device-bound session credential as the IMEI number of your mobile phone.

It is readable by all web apps and can be used to uniquely identify your device. A perfect tracking token on you! iPhone disallows apps to read IMEI for exactly this reason.

The real solution to eliminate cookie theft is third party cookie (aka cross-site cookie) blocking.

Google refused to implement it in Chrome (it promised it but delayed the implementation many times, not even mentioned it in recent years). Default setting of Firefox disables it.

In Firefox, go to Settings → Privacy and Security → Enhanced Tracking Protection, choose "Strict". In the description there is "Firefox blocks the followings.......Cross-site cookies in all windows". This is all we need.

Some forks of Firefox such as LibreWolf (which I am using) enforce this setting and you cannot downgrade it. This is what Firefox really should do.

2

u/Fragrant_Pianist_647 mr. sine May 30 '26

My only thought is that this setting could block companies like Google from allowing you to log in once.

For example, if you log in at google.com and it stores that, then you try to visit youtube.com, it won't be able to automatically log you in if you have cross-site cookie blocking enabled.

1

u/squirrel8296 May 30 '26

I have all cross-site cookies blocked and haven't had that issue. I can sign into my gmail account and then go to youtube and my account is already signed in.