Firefox/Feature Brainstorming:Privacy: Difference between revisions
(Changes and additions to Privacy>History suggestions) |
No edit summary |
||
| (7 intermediate revisions by 4 users not shown) | |||
| Line 43: | Line 43: | ||
The idea is simple: protect ALL firefox profile data (cookies, historic, etc...) and not only passwords of password manager with an encryption system. It would be very secure... <br> It is interesting for security because a true security protects all data and there is more than a way to hack a computer: all data is useful for an cracker. | The idea is simple: protect ALL firefox profile data (cookies, historic, etc...) and not only passwords of password manager with an encryption system. It would be very secure... <br> It is interesting for security because a true security protects all data and there is more than a way to hack a computer: all data is useful for an cracker. | ||
| | |||
|- | |||
| | |||
;Allow users to edit the key/value pairs of cookies | |||
Users should be given the ability to not only delete, but edit any cookies stored within Firefox. This would both be a boon to developers (I've load count of the number of times this feature would've been useful) and would also give the users more control over what data websites store on their PC. | |||
| | | | ||
| Line 114: | Line 122: | ||
*Note: this would break a lot web analytics packages, since so many of them (if not all) use tracking. gif techniques. - sherman | *Note: this would break a lot web analytics packages, since so many of them (if not all) use tracking. gif techniques. - sherman | ||
*That's the point. However, image tracking is only one method. Better would be to have an option to not load ANYTHING from a third-party domain, unless specifically allowed. - Meneth | *That's the point. However, image tracking is only one method. Better would be to have an option to not load ANYTHING from a third-party domain, unless specifically allowed. - Meneth | ||
| | | | ||
|- | |||
| | |||
;Selectively disable offsite images. | |||
*Useful for e.g. webmail accounts that do not allow (anti-spam etc.) image blocking in received emails. Analogous to the Accept Cookie / Exceptions dialog, this feature would allow the user to specify certain sites (e.g. webmail.myisp.com) where offsite requests within a page (i.e. domain != myisp.com) would be blocked. Is this workable ? Not supported by existing addins, which block specific external sites, or, ALL images. | |||
| | |||
|- | |- | ||
| | | | ||
| Line 159: | Line 176: | ||
*Implement a "private browsing" mode that prevents collection and recording of data. When privacy mode turned off previous history should be preserved. | *Implement a "private browsing" mode that prevents collection and recording of data. When privacy mode turned off previous history should be preserved. | ||
*Expand 'Private Browsing' mode to be available on a page by page or site by site basis (including child tabs). See Privacy>History for full suggestion. | |||
| | | | ||
| Line 191: | Line 209: | ||
*Ability to put a page on a blacklist (i.e. never show it in the history) | *Ability to put a page on a blacklist (i.e. never show it in the history) | ||
**Should apply to all records including cookies, cache, login details, etc. | **Should apply to all records including cookies, cache, login details, etc. | ||
**Should apply to individual pages or whole sites by user's choice | **Should apply to individual pages or whole sites by user's choice, and any child tabs | ||
**Effectively allows for a 'Private Browsing' session on a page by page or site by site basis. | **Effectively allows for a 'Private Browsing' session on a page by page or site by site basis. | ||
**Would be useful to prevent blocked pages or sites showing up on a list of blocked pages and sites - otherwise it defeats the purpose! Perhaps no list, just a one-time thing; or perhaps a password would give access to the list? | **Would be useful to prevent blocked pages or sites showing up on a list of blocked pages and sites - otherwise it defeats the purpose! Perhaps no list, just a one-time thing; or perhaps a password would give access to the list? | ||
**Could be paired with 'Clear Recent History' exemptions (see Privacy>Secure Storage and Clearing of Private Data) to make three types of page or site: Block from storage, Normal, Keep Always | |||
*Ability to disable the history for the current session with a click/keycombo | *Ability to disable the history for the current session with a click/keycombo | ||
| | | | ||
| Line 207: | Line 222: | ||
;Password management | ;Password management | ||
*While Firefox/Thunderbird is running, open password databases exclusively (lock for read/write), so that other applications (Trojans) cannot access or copy them. | |||
*Improve Master Password entry when viewing saved passwords. | *Improve Master Password entry when viewing saved passwords. | ||
**Redundant master password entry fields: If the user has opted to set a master password for their browser's stored passwords, they have to enter it twice to actually view and show the passwords (once to View Saved Passwords, and then AGAIN to actually Show Passwords of those accounts). This redundancy is unnecessary. | **Redundant master password entry fields: If the user has opted to set a master password for their browser's stored passwords, they have to enter it twice to actually view and show the passwords (once to View Saved Passwords, and then AGAIN to actually Show Passwords of those accounts). This redundancy is unnecessary. | ||
| Line 235: | Line 251: | ||
|- | |- | ||
| | | | ||
;Secure and | ;Secure and Insecure Passwords | ||
*2 separate password stores. One would require the Master password to access, the other would not. This would be useful to users who want convenience storage of simple passwords they do not care about exposing, but also have sensitive passwords. This would prevent the Master Password dialog from popping up for non-sensitive passwords. A use case is a user with all of the following examples on a laptop used at work and home, and left unattended at both as well. | *2 separate password stores. One would require the Master password to access, the other would not. This would be useful to users who want convenience storage of simple passwords they do not care about exposing, but also have sensitive passwords. This would prevent the Master Password dialog from popping up for non-sensitive passwords. A use case is a user with all of the following examples on a laptop used at work and home, and left unattended at both as well. | ||
| Line 262: | Line 278: | ||
**#melt, dissolve, or powderize the hardware -- protects against everyone | **#melt, dissolve, or powderize the hardware -- protects against everyone | ||
**Multiple overwrite is not stronger than merely zeroing the file. It is an attempt to beat the rare case of somebody who can examine the disk surface, but it fails because modern disks will commonly write to different locations. Disks do sector/track substitution and they have write heads that wander a bit. | **Multiple overwrite is not stronger than merely zeroing the file. It is an attempt to beat the rare case of somebody who can examine the disk surface, but it fails because modern disks will commonly write to different locations. Disks do sector/track substitution and they have write heads that wander a bit. | ||
*Ability to exempt certain web sites or individual pages from being cleared when 'Clear Recent History' is used, so that regularly used pages do not get removed when others are, eg search engines, email sites, news sites, social networking sites, etc. | |||
**Should apply to all records including cookies, cache, login details, etc. for that page or site. | |||
**Could have an option in 'Clear Recent History' to override this. | |||
**Could be paired with page/site history blacklist idea (see Privacy>History) to make three types of page or site: Block from storage, Normal, Keep Always | |||
<br> | <br> | ||
| Line 393: | Line 413: | ||
|} | |} | ||
---- | |||
'''"Master password logout option"''' | |||
After entering master password some times I have to give my pc to somebody and they can easily view my password for particular website like by using firebug simply by opening the website's login page and change password field type from "password" to something different and anybody can view the password, we can not even close the browser for giving pc to somebody to use, so there should be a master password logout option so that we just have to logout and that password will not be visible to anybody using firebug. | |||
--[[User:Pankajk|Pankajk]] 10:04, 5 July 2010 (UTC) | |||
---- | |||
Latest revision as of 22:55, 23 February 2012
« Firefox/Feature Brainstorming
| Specific features | References |
|---|---|
Safari is more choosy in deciding whom it passes cookie information out to, apparently. For this reason, Phorm spyware can't serve users of Safari targeted ads, although data can clearly still be intercepted. See Guardian article for reference: Disallow third-party domains to be able to set cookies by default. | |
It is very common for users of firefox to encrypt/tunnel their traffic using SSH proxies. I think a great feature for future versions of firefox would be a built-in SSH engine. For example, here's a typical setup: 1) Run "ssh -D [port] u...@host.com" 2) Enter password 3) Open up the firefox options, and switch to use SOCKS on the port specified in (1). 4) Browse securely 5) Close the ssh connection 6) Re-adjust the firefox options for normal internet connection With a built in firefox SSH mechanism, it could work like this: 1) Click a "Tunnel Traffic ON" button in firefox. (SSH accounts and passwords would be pre-setup)
2) Browse securely 3) Click "Tunnel Traffic OFF"
This feature would be phenomenal, and would allow users to quickly secure their information when browsing on public terminals. This feature will probably not be possible using extensions to firefox. |
|
The idea is simple: protect ALL firefox profile data (cookies, historic, etc...) and not only passwords of password manager with an encryption system. It would be very secure...
|
|
Users should be given the ability to not only delete, but edit any cookies stored within Firefox. This would both be a boon to developers (I've load count of the number of times this feature would've been useful) and would also give the users more control over what data websites store on their PC. |
|
This could be something like if a user is going to an online banking thing like ebay, paypal or citibank or whatever is there in a whitelist. He will be informed that he is at the right location. This will make anti-phishing easier. This can also be extended for a lot of other site like google and yahoo. Only on the right pages can u enter the sensitive information. Else the user is given a warning that "It might be a phishing page". Better and do able. I would like to work on this feature. You can contact me for future discussions at (the100rabh)....emailat....(gmail)..doitat..(.com)....Address is in parenthesis
|
|
Not Required any more as its already been done via an extension "View Cookie CS" This is already possible in Firefox 1.0, 1.5 and 2.0 without any extension. However it would be nice to be able to mark cookies from a site "not to be deleted" without having to open the preferences dialog. --Dikrib 13:48, 17 December 2006 (PST) |
|
|
Only allow cookies from sites you navigate to Add an option to the cookie preferences menu that only allows the storage of cookies from sites you navigate to. In this way, e.g. cookies from advertisers on those sites will not be stored. |
Camino ([1]) and Safari both have this feature. |
It would be useful to have a "one-click" method of doing a security and privacy audit. Have it check for disabled or "unused" security and privacy features, check for non-secure or not up-to-date software and plugins, and provide an up-to-date report of known security defects or issues. Provide recommendations for those who are non-technical. |
Kind of a corny example, but perhaps something conceptually similar to the final audit in TurboTax. |
The thing about privacy controls is occasionally forgetting to turn them on.
|
|
Many firewall and antivirus applications have features to deny access to entire websites based on URL matching which is based on wildcards and regular expressions. i have long wanted something similar in Firefox's cookie manager. It would reduce a lot of overhead on the Exceptions List, keep it somewhat more tidy and manageable. Also, a better organizer for the EL would be nice: group by base site instead of absolute alphanumeric. For example:
Would make things easier to find, and make troubleshooting sites easier by being able to determine if a cookie exception is preventing proper functionality of the site (blocking some subdomain cookie that is required for login, etc.). |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Despite this separation is not implemented internally in FF 1.5.* or FF 2.0.* it's achieved by CookiePie extension.--User:Swain |
|
1 bug 285790 already exists for form history |
|
n/a |
|
bug 227880 about password autocomplete notification. |
|
|
|
|
|
|
It would be nice if there was a search functionality on the cookie exceptions list. This is useful when someone wants to quickly find out about the status of a site without having to search through the entire exceptions list. |
|
Certain sites have cookies which are stored in the browser only as long as it does not exit. To logon to sites again we need to enter the password once more. It would be great if cookies for selected sites do not expire as the sites set then to. User must be able to override these settings.
|
|
It should be possible to selectively delete history / private data of certain pages or even subpages. This could even be as fine-grained as to only allow deletion of a certain type of history data (like images, data entered in forms, search bar), in the case of forms and search bar even single entries. On top of that it would be useful to be able to specifically allow and/or deny to store certain data in the first place (with opt-in and opt-out options to store data in general with respect to defined exceptions).
|
|
| General tasks | |
|
N/A |
| |
|
BugZilla for Auto Cache Clear |
| |
| |
|
|
|
|
Similar to the the user-agent features in Opera and Konqueror, a user should have the ability to turn off user-agent broadcasting or change the browser's to a different FF version, OS, or other browser. Also allow for memory of individual sites and what identity to use for each site. |
|
An option under Clear Private Data to clear the search bar contents. Currently, the last item searched is visible, and previous items are visible through Ctrl+Z. |
|
In the "security warnings" dialog, add an option "Warn me when sending unencrypted passwords". |
|
"Master password logout option" After entering master password some times I have to give my pc to somebody and they can easily view my password for particular website like by using firebug simply by opening the website's login page and change password field type from "password" to something different and anybody can view the password, we can not even close the browser for giving pc to somebody to use, so there should be a master password logout option so that we just have to logout and that password will not be visible to anybody using firebug. --Pankajk 10:04, 5 July 2010 (UTC)