this post was submitted on 06 Sep 2024
34 points (92.5% liked)

Firefox

20351 readers
140 users here now

/c/firefox

A place to discuss the news and latest developments on the open-source browser Firefox.


Rules

1. Adhere to the instance rules

2. Be kind to one another

3. Communicate in a civil manner


Reporting

If you would like to bring an issue to the moderators attention, please use the "Create Report" feature on the offending comment or post and it will be reviewed as time allows.


founded 5 years ago
MODERATORS
 

As far as my understanding go, Private State Tokens is supposed to be a huge improvement over cookies in terms of security and privacy, which make ask about the reason they are not implemented on Firefox.

top 5 comments
sorted by: hot top controversial new old
[–] CountVon@sh.itjust.works 51 points 10 months ago (1 children)

Private State Tokens are Google's implementation of the IETF Privacy Pass protocol. Apple has another implementation of the same protocol named Private Access Tokens. Mozilla has taken a negative position against this protocol in its current form, and its existing implementations in their current forms. See here for their blog post on the subject, and here for their more in-depth analysis.

[–] isVeryLoud@lemmy.ca 1 points 10 months ago (1 children)

tl;dr why have they taken a stance against it?

[–] CountVon@sh.itjust.works 2 points 10 months ago (1 children)

Tl;Dr the protocol requires there to be trusted token providers that issue the tokens. Who do you suppose are the trusted providers in the Google and Apple implementations? Google and Apple respectively, of course. Maybe eventually there would be some other large incumbents that these implementers choose to bless with token granting right. By its nature the protocol centralizes power on the web, which would disadvantage startups and smaller players.

[–] isVeryLoud@lemmy.ca 1 points 10 months ago

Ah yes, the RCS problem. Thanks for the clarification!

[–] kitnaht@lemmy.world 25 points 10 months ago

The web needs ways to establish and convey trust signals which show that a user is who they say they are

Because it's just a convenient way to track people, confirm they are not bots, so that information can be sifted and sold.