Saturday, February 9, 2008

merlin history sniff post

personally i do think history sniffing is crossing the privacy line… i used to let it slide but facebook and zappos pretty much changed my mind when they wanted to tell all my contacts i bought some new shoes… kinda freaked me into really changing my browsing habits. at least facebook made the “beacon” sniffing visible… i revisited the paranoia of how much secret sniffing must go on.

but i know history sniff can be used for good and not just evil. for this, the firefox plugin SafeHistory is a fitting compromise, which implements same origin policy on history. see also SafeCache for cache sniffing (which i think is actually worse than history sniffing… mostly just evil and no good).

note for both of these, you need to make sure the same origin policy is enabled (network.cookie.cookieBehavior=1)… normally the policy just applies to cookies but these plugins conveniently refer to this centralized toggle.

one final tangent, i believe same origin used to be the default in firefox, but since 2.0 it is not nor is it even accessible in the standard conf screens… now you can only set it with the about:config . i find this somewhat disturbing… same origin really seems like it should be standard practice.