Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #207732 > unrolled thread

Re: firefox > Preferences > When Firefox starts.

Started bypeter@easthope.ca
First post2019-04-21 16:50 +0200
Last post2019-04-28 23:10 +0200
Articles 20 on this page of 27 — 9 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: firefox > Preferences > When Firefox starts. peter@easthope.ca - 2019-04-21 16:50 +0200
    Re: firefox > Preferences > When Firefox starts. Curt <curty@free.fr> - 2019-04-21 18:10 +0200
      Re: firefox > Preferences > When Firefox starts. peter@easthope.ca - 2019-04-22 04:30 +0200
        Re: firefox > Preferences > When Firefox starts. Curt <curty@free.fr> - 2019-04-23 16:10 +0200
    Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-21 23:20 +0200
      Re: firefox > Preferences > When Firefox starts. peter@easthope.ca - 2019-04-22 06:20 +0200
        Re: firefox > Preferences > When Firefox starts. Greg Wooledge <wooledg@eeg.ccf.org> - 2019-04-22 15:10 +0200
          Re: firefox > Preferences > When Firefox starts. "der.hans" <deb-user@LuftHans.com> - 2019-04-23 17:40 +0200
            Re: firefox > Preferences > When Firefox starts. Curt <curty@free.fr> - 2019-04-23 18:00 +0200
              Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-23 19:30 +0200
                Re: firefox > Preferences > When Firefox starts. "der.hans" <deb-user@LuftHans.com> - 2019-04-23 20:20 +0200
                  Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-24 17:20 +0200
                    Re: firefox > Preferences > When Firefox starts. "der.hans" <deb-user@LuftHans.com> - 2019-04-24 18:30 +0200
                      Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-25 05:30 +0200
              Re: firefox > Preferences > When Firefox starts. "der.hans" <deb-user@LuftHans.com> - 2019-04-23 19:40 +0200
        Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-22 20:50 +0200
          Browser usage; was "Re: firefox > Preferences > When Firefox starts." peter@easthope.ca - 2019-04-22 22:50 +0200
            Re: Browser usage; was "Re: firefox > Preferences > When Firefox  starts." Curt <curty@free.fr> - 2019-04-23 09:40 +0200
              Re: Browser usage; was "Re: firefox > Preferences > When Firefox starts." rhkramer@gmail.com - 2019-04-23 17:40 +0200
                Re: Browser usage; was "Re: firefox > Preferences > When Firefox  starts." Reco <recoverym4n@enotuniq.net> - 2019-04-23 18:10 +0200
          Re: firefox > Preferences > When Firefox starts. <tomas@tuxteam.de> - 2019-04-23 09:30 +0200
          Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-24 17:40 +0200
            Re: firefox > Preferences > When Firefox starts. Lee <ler762@gmail.com> - 2019-04-24 20:30 +0200
              Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-25 07:10 +0200
                Re: firefox > Preferences > When Firefox starts. Lee <ler762@gmail.com> - 2019-04-25 18:30 +0200
                  Re: firefox > Preferences > When Firefox starts. David Wright <deblis@lionunicorn.co.uk> - 2019-04-28 02:40 +0200
                    Re: firefox > Preferences > When Firefox starts. Lee <ler762@gmail.com> - 2019-04-28 23:10 +0200

Page 1 of 2  [1] 2  Next page →


#207732 — Re: firefox > Preferences > When Firefox starts.

Frompeter@easthope.ca
Date2019-04-21 16:50 +0200
SubjectRe: firefox > Preferences > When Firefox starts.
Message-ID<xPlX4-35r-9@gated-at.bofh.it>
    From: Cindy Sue Causey <butterflybytes@gmail.com>
    Date: Fri, 19 Apr 2019 12:41:45 -0400
> * Is that the only live tab for each new session, ...

Sorry to say, I don't understand the question.  I don't understand "live tab".
Firefox should just open the static local page.  Shouldn't take more than a 
second or two even when the system is bogged.

> * Can you tell if this has something to do with Firefox crashing, ...

Will consider that, thanks.  It would imply two bugs.  The first causing 
firefox to crash.  Failure to open the specified page at startup would 
be a 2nd bug.

> * Can you try opening it via a terminal over your next few browsing
> session startups ...

I need to make a habit of starting it from a terminal until this is solved.
Otherwise will miss the incident too often.

> ... STILL be "alive" after a full reboot.

To my knowledge the only thing running on an unpowered PC is the clock.  
Some exotic machines might be able to run the BIOS or a Forth 
PROM from the backup battery or cell.  I don't know about that.

On most machines, no process survives a cold reboot.  If that appeared 
to happen, the process number must have been saved in a non-volatile store
and applied to a new process after the reboot.  Seems perverse.

Firefox now has too much automation and it's causing trouble.  We 
need a way to disable some of this paraphernalia.  Or a simpler browser.

Can the automatic search capability of the URL bar be disabled?
Other ideas?

Thanks,                      ... Peter E.
-- 
Message composed and transmitted by software designed to avoid the 
complication and vulnerability of antivirus software.

[toc] | [next] | [standalone]


#207733

FromCurt <curty@free.fr>
Date2019-04-21 18:10 +0200
Message-ID<xPnct-40H-5@gated-at.bofh.it>
In reply to#207732
On 2019-04-21, peter@easthope.ca <peter@easthope.ca> wrote:
>     From: Cindy Sue Causey <butterflybytes@gmail.com>
>     Date: Fri, 19 Apr 2019 12:41:45 -0400
>> * Is that the only live tab for each new session, ...
>
> Sorry to say, I don't understand the question.  I don't understand "live tab".
> Firefox should just open the static local page.  Shouldn't take more than a 
> second or two even when the system is bogged.
>
>> * Can you tell if this has something to do with Firefox crashing, ...
>
> Will consider that, thanks.  It would imply two bugs.  The first causing 
> firefox to crash.  Failure to open the specified page at startup would 
> be a 2nd bug.

The message "Sorry. We're having trouble getting your pages back" means
exactly that Firefox believes it crashed or failed to recover
successfully from a crash, AFAIK, in which case it tries to restore the
state of the browser at crash time (and does not load the user's home
page, local or not, as if it hadn't crashed and was starting up
normally).

I've read that setting "Clear history when Firefox closes" is one way to
obviate the problem (you might not want to lose your history, though).
Another is to set "browser.sessionstore.max_resumed_crashes" to false in
'about:config'.

I guess we can assume safely that you're closing your browser sessions
"normally."

Good luck.

[toc] | [prev] | [next] | [standalone]


#207756

Frompeter@easthope.ca
Date2019-04-22 04:30 +0200
Message-ID<xPwSt-1qz-1@gated-at.bofh.it>
In reply to#207733
    From: Curt <curty@free.fr>
    Date: Sun, 21 Apr 2019 16:08:49 -0000 (UTC)
> I've read that setting "Clear history when Firefox closes" is one way to
> obviate the problem (you might not want to lose your history, though).

Losing the history wouldn't be so bad but I don't see how firefox would 
have a chance to clear history when crashing.

> Another is to set "browser.sessionstore.max_resumed_crashes" to false in
> 'about:config'.

The default value is 1.  Changing it to 0 seems reasonable.

> I guess we can assume safely that you're closing your browser sessions
> "normally."

I close each tab with a click on the x symbol.

Thanks,           ... P.

-- 
Message composed and transmitted by software designed to avoid the 
complication and vulnerability of antivirus software.

[toc] | [prev] | [next] | [standalone]


#207796

FromCurt <curty@free.fr>
Date2019-04-23 16:10 +0200
Message-ID<xQ4hs-4YS-5@gated-at.bofh.it>
In reply to#207756
On 2019-04-22, peter@easthope.ca <peter@easthope.ca> wrote:
>
>> I guess we can assume safely that you're closing your browser sessions
>> "normally."
>
> I close each tab with a click on the x symbol.

As FF has been known to handle SIGTERM ungracefully (which may account
for its periodic delusions of crash in your case), you might want to try
Ctrl+Q or quitting by the 3-bar menu instead. 

> Thanks,           ... P.
>


-- 
“Let us again pretend that life is a solid substance, shaped like a globe,
which we turn about in our fingers. Let us pretend that we can make out a plain
and logical story, so that when one matter is despatched--love for instance--
we go on, in an orderly manner, to the next.” - Virginia Woolf, The Waves

[toc] | [prev] | [next] | [standalone]


#207750

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-04-21 23:20 +0200
Message-ID<xPs2t-6V3-7@gated-at.bofh.it>
In reply to#207732
On Sun 21 Apr 2019 at 07:11:36 (-0700), peter@easthope.ca wrote:
>     From: Cindy Sue Causey <butterflybytes@gmail.com>
>     Date: Fri, 19 Apr 2019 12:41:45 -0400
> > * Is that the only live tab for each new session, ...
> 
> Sorry to say, I don't understand the question.  I don't understand "live tab".
> Firefox should just open the static local page.  Shouldn't take more than a 
> second or two even when the system is bogged.

AIUI, the "correct" behaviour when starting FF is a Home Page (your
choice), a blank page (mine), or the situation that pertained when you
last closed down (perhaps Cindy's choice). This last might involve
?hundreds of Tabs judging by Cindy's posts in the past.

> > * Can you tell if this has something to do with Firefox crashing, ...
> 
> Will consider that, thanks.  It would imply two bugs.  The first causing 
> firefox to crash.  Failure to open the specified page at startup would 
> be a 2nd bug.

I run two instances of FF, one as me (for banking etc) and one as
another user (for browsing). I just checked out clean shutdowns
and restarts with my own instance of FF and it's all OK.

As for my browsing, I always crash it at close down, either by
terminating X (Ctrl-Alt-Backspace) or by   sudo /root/shutdown.
The effect of either is the same: FF started with "firefox" produces
a single Tab saying "Sorry. We're having trouble getting your pages
back" as you reported. Pressing Return (or clicking the button)
restores (inactively) all the Tabs that were present in the last
session: just what I want. (I don't want to have to dig them all out
of the browser History.)

> > * Can you try opening it via a terminal over your next few browsing
> > session startups ...
> 
> I need to make a habit of starting it from a terminal until this is solved.
> Otherwise will miss the incident too often.

Not running a DE, I always start it from a little xterm that's there
for just that purpose and for receiving any error messages. The jessie
version of FF spewed errors constantly, but stretch is much quieter.

I have a load of bash functions for suchlike, eg:
$ my-aptitude-doc-on-flashfirefox
$ my-deblis-on-flashfirefox
$ my-forecast-on-flashfirefox
$ my-hotmail-on-flashfirefox
$ my-python-doc-on-flashfirefox
$ my-radar-on-flashfirefox
$ my-weather-on-flashfirefox
and the effect of these is to produce two Tabs, the one requested here
and the one with "Sorry. …". (Any of the bash functions will take a
URL argument that overrides the default address.

> > ... STILL be "alive" after a full reboot.
> 
> To my knowledge the only thing running on an unpowered PC is the clock.  
> Some exotic machines might be able to run the BIOS or a Forth 
> PROM from the backup battery or cell.  I don't know about that.
> 
> On most machines, no process survives a cold reboot.  If that appeared 
> to happen, the process number must have been saved in a non-volatile store
> and applied to a new process after the reboot.  Seems perverse.

It's possible to set up the system so that it restarts all the
sessions automatically when you reboot. I think one calls it a
"kiosk" system, and I remember someone on this list wanting to
set one up. The process numbers aren't saved. If they are, it's
likely a suspend/hibernation has been misdiagnosed.

> Firefox now has too much automation and it's causing trouble.  We 
> need a way to disable some of this paraphernalia.  Or a simpler browser.

It's a compromise. The more paraphernalia you cut out, the more pages
that will not work. Does the behaviour reported in your OP cause you
*great* concern? There is a button with a little house on it if you
specially want your Home Page (available at any time).

As you can read here, I'm perfectly happy with the behaviour described.¹

> Can the automatic search capability of the URL bar be disabled?
> Other ideas?

Sure: Edit→Preferences→Search→Provide search suggestions.

This *might* only stop locally generated suggestions. To stop, say,
Google from suggesting as well, you might have to set an option
on Google's search page. ("Other search engines are available.")

You might find other options in Edit→Preferences that can give
you a "simpler" browsing experience.

¹ I tried Opera on a slow laptop as it's reported to be faster.
It was, in normal use. However, when you started it the next day,
it would try and restore all the active Tabs as soon as you
started it, which was a disaster. I'd sit there waiting for the
weather forecast to appear while, say, 20 Tabs from yesterday
were clogging it up.
OTOH, FF only restores each Tab when you actually switch to it,
so my-forecast-on-flashfirefox gives me what I want immediately.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#207758

Frompeter@easthope.ca
Date2019-04-22 06:20 +0200
Message-ID<xPyAX-2x8-3@gated-at.bofh.it>
In reply to#207750
    From: David Wright <deblis@lionunicorn.co.uk>
    Date: Sun, 21 Apr 2019 16:13:11 -0500
> I run two instances of FF, one as me (for banking etc) and one as
> another user (for browsing).

Interesting.  Thanks.  For banking & etc. you have a dedicated user id 
and login?

Drifting off the subject, but the banking I use invokes javascript. I 
would have thought that unnecessary.  Should be possible to accomplish 
the results with processing on the server and HTML5 on the client.
Technology bloat?

> I just checked out clean shutdowns and restarts with my own 
> instance of FF and it's all OK.

OK, thanks.  The complaint at firefox startup here is probably only 
following a crash of firefox.   Curt's suggestion to set 
browser.sessionstore.max_resumed_crashes to 0 seems appropriate.

> Does the behaviour reported in your OP cause you *great* concern?

No.  Just wastes time.  Opening a simple local HTML home page requires 
roughly a minute rather than roughly a second.

> I tried Opera on a slow laptop ...

Thanks for mentioning that.

Regards,                   ... Peter E.


-- 
Message composed and transmitted by software designed to avoid the 
complication and vulnerability of antivirus software.

[toc] | [prev] | [next] | [standalone]


#207768

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2019-04-22 15:10 +0200
Message-ID<xPGRP-7y8-5@gated-at.bofh.it>
In reply to#207758
On Sun, Apr 21, 2019 at 08:30:53PM -0700, peter@easthope.ca wrote:
> Drifting off the subject, but the banking I use invokes javascript. I 
> would have thought that unnecessary.  Should be possible to accomplish 
> the results with processing on the server and HTML5 on the client.
> Technology bloat?

It has been my experience that the more IMPORTANT a web site is
(government, bank, insurance, etc.), the WORSE it is.

Eventually I got to the point where I simply GAVE UP trying to use any
important web sites under Firefox + NoScript.  Even if I allowed all
the dozens of foreign Javascript domains that each web page relied on,
it would still fail due to <https://noscript.net/abe/> violations.

Your dream of a banking site that uses competent, non-broken web technology
is going to have to remain a dream, I'm afraid.

[toc] | [prev] | [next] | [standalone]


#207800

From"der.hans" <deb-user@LuftHans.com>
Date2019-04-23 17:40 +0200
Message-ID<xQ5Gx-5HH-5@gated-at.bofh.it>
In reply to#207768

[Multipart message — attachments visible in raw view] — view raw

Am 22. Apr, 2019 schwätzte Greg Wooledge so:

> On Sun, Apr 21, 2019 at 08:30:53PM -0700, peter@easthope.ca wrote:
>> Drifting off the subject, but the banking I use invokes javascript. I
>> would have thought that unnecessary.  Should be possible to accomplish
>> the results with processing on the server and HTML5 on the client.
>> Technology bloat?
>
> It has been my experience that the more IMPORTANT a web site is
> (government, bank, insurance, etc.), the WORSE it is.
>
> Eventually I got to the point where I simply GAVE UP trying to use any
> important web sites under Firefox + NoScript.  Even if I allowed all

Have you tried uMatrix? I love NoScript, but uMatrix also handles cookies
and has an easier to use UI.

> the dozens of foreign Javascript domains that each web page relied on,
> it would still fail due to <https://noscript.net/abe/> violations.

uMatrix doesn't have ABE. I don't know about CSRF attack protection, etc.

I am certain that rejecting 3rd party JavaScript and cookies reduces
tracking and attack surface.

> Your dream of a banking site that uses competent, non-broken web technology
> is going to have to remain a dream, I'm afraid.

Unfortunately :(.

I use different Firefox profiles for banking to improve isolation, so at
least they won't be attacked by a retailers tab.

I'm experimenting with Firefox containers for the isolation.

ciao,

der.hans
-- 
#  https://www.LuftHans.com   https://www.PhxLinux.org
#  "Eternal vigilance is not only the price of liberty;
#  eternal vigilance is the price of human decency." -- Aldous Huxley, 1965

[toc] | [prev] | [next] | [standalone]


#207803

FromCurt <curty@free.fr>
Date2019-04-23 18:00 +0200
Message-ID<xQ5ZT-5Op-5@gated-at.bofh.it>
In reply to#207800
On 2019-04-23, der.hans <deb-user@LuftHans.com> wrote:
>
> I use different Firefox profiles for banking to improve isolation, so at
> least they won't be attacked by a retailers tab.
>
> I'm experimenting with Firefox containers for the isolation.

Looks interesting. I've just enabled it in 'about:config' 

 privacy.userContext.enabled       true

I now have a contextual menu entry "Reopen in Container" when
left-clicking on a tab, which lists the four default containers. The
wiki doesn't explain the difference between these pre-defined
containers, though (Home, Work, Banking, and Shopping) or whether you
can create your own (apparently "custom" containers is a future option).

https://wiki.mozilla.org/Security/Contextual_Identity_Project/Containers

Thanks for the heads up.

> ciao,
>
> der.hans

[toc] | [prev] | [next] | [standalone]


#207806

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-04-23 19:30 +0200
Message-ID<xQ7oZ-6Mu-7@gated-at.bofh.it>
In reply to#207803
On Tue 23 Apr 2019 at 15:53:50 (-0000), Curt wrote:
> On 2019-04-23, der.hans <deb-user@LuftHans.com> wrote:
> >
> > I use different Firefox profiles for banking to improve isolation, so at
> > least they won't be attacked by a retailers tab.
> >
> > I'm experimenting with Firefox containers for the isolation.

What experiments have you devised? How do you define "isolation",
and what are the criteria by which you judge whether their scheme
is succeeding or not?

> Looks interesting. I've just enabled it in 'about:config' 
> 
>  privacy.userContext.enabled       true
> 
> I now have a contextual menu entry "Reopen in Container" when
> left-clicking on a tab, which lists the four default containers. The
> wiki doesn't explain the difference between these pre-defined
> containers, though (Home, Work, Banking, and Shopping) or whether you
> can create your own (apparently "custom" containers is a future option).
> 
> https://wiki.mozilla.org/Security/Contextual_Identity_Project/Containers

I can see some usefulness in having separate bookmarks and histories,
particularly the latter as it's not easy to classify in the same way
as bookmarks with its submenus. But I see only convenience, not
security.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#207808

From"der.hans" <deb-user@LuftHans.com>
Date2019-04-23 20:20 +0200
Message-ID<xQ8bn-7ig-5@gated-at.bofh.it>
In reply to#207806

[Multipart message — attachments visible in raw view] — view raw

Am 23. Apr, 2019 schwätzte David Wright so:

moin moin,

> On Tue 23 Apr 2019 at 15:53:50 (-0000), Curt wrote:
>> On 2019-04-23, der.hans <deb-user@LuftHans.com> wrote:
>>>
>>> I use different Firefox profiles for banking to improve isolation, so at
>>> least they won't be attacked by a retailers tab.
>>>
>>> I'm experimenting with Firefox containers for the isolation.
>
> What experiments have you devised? How do you define "isolation",

Thus far my experiments have only been for usability. When I first tried
Firefox containers some time ago I could only open one tab in each
container.

I'm just checking that they work and that I can use the same site multiple
times with different credentials from the same browser instance.

> and what are the criteria by which you judge whether their scheme
> is succeeding or not?

At some point I will need to dive into documentation to see if the design
is to isolate the containers sufficiently for me. Even if it is, I'm
still concerned about a bug allowing container escape or information
bleeding.  Should containers not be sufficient for me, they still look
like a significant improvement for those less tech minded.

I currently run different browser instances for different tasks I want to
isolate.

For instance, I have a profile for one mastodon account and another for
the other mastodon account. My bank gets its own profile, as do my
utilities. Each of those is setup with uMatrix to disallow cookies and
JavaScript not necessary for the particular site to work.

I have over 50 profiles. Only two are allowed flash player and except for
work requirements, I haven't used flash in a long time.

Some profiles are inside containers.

For generic shopping I have an instance that is more lax on cookies and
JavaScript.

My initial use of containers is for that. I would like to have a container
per retailer ( or account required site ) that isolates each site and
where all information about the site is wiped when the container is
stopped/reset.

Banks and social media will certainly continue having their own profiles,
but a third of my profiles could move to containers ( if I start to trust
them ).

As to experiments, I need to see if I can get tools like lightbeam to help
me audit isolation. I'll also passively test by checking for bleedover
from different sessions.

I want to see if I can enable and disable add ons per container. I presume
not, but that would be a useful feature.

ciao,

der.hans

>> Looks interesting. I've just enabled it in 'about:config'
>>
>>  privacy.userContext.enabled       true
>>
>> I now have a contextual menu entry "Reopen in Container" when
>> left-clicking on a tab, which lists the four default containers. The
>> wiki doesn't explain the difference between these pre-defined
>> containers, though (Home, Work, Banking, and Shopping) or whether you
>> can create your own (apparently "custom" containers is a future option).
>>
>> https://wiki.mozilla.org/Security/Contextual_Identity_Project/Containers
>
> I can see some usefulness in having separate bookmarks and histories,
> particularly the latter as it's not easy to classify in the same way
> as bookmarks with its submenus. But I see only convenience, not
> security.
>
> Cheers,
> David.
>

-- 
#  https://www.LuftHans.com   https://www.PhxLinux.org
#  Magic is science unexplained. - der.hans

[toc] | [prev] | [next] | [standalone]


#207822

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-04-24 17:20 +0200
Message-ID<xQrQJ-2pE-3@gated-at.bofh.it>
In reply to#207808
On Tue 23 Apr 2019 at 18:15:03 (+0000), der.hans wrote:
> Am 23. Apr, 2019 schwätzte David Wright so:
> > On Tue 23 Apr 2019 at 15:53:50 (-0000), Curt wrote:
> > > On 2019-04-23, der.hans <deb-user@LuftHans.com> wrote:
> > > > 
> > > > I use different Firefox profiles for banking to improve isolation, so at
> > > > least they won't be attacked by a retailers tab.
> > > > 
> > > > I'm experimenting with Firefox containers for the isolation.

> > > https://wiki.mozilla.org/Security/Contextual_Identity_Project/Containers
> > 
> > I can see some usefulness in having separate bookmarks and histories,
> > particularly the latter as it's not easy to classify in the same way
> > as bookmarks with its submenus. But I see only convenience, not
> > security.
> > 
> > What experiments have you devised? How do you define "isolation",
> 
> Thus far my experiments have only been for usability. When I first tried
> Firefox containers some time ago I could only open one tab in each
> container.
> 
> I'm just checking that they work and that I can use the same site multiple
> times with different credentials from the same browser instance.
> 
> > and what are the criteria by which you judge whether their scheme
> > is succeeding or not?
> 
> At some point I will need to dive into documentation to see if the design
> is to isolate the containers sufficiently for me. Even if it is, I'm
> still concerned about a bug allowing container escape or information
> bleeding.  Should containers not be sufficient for me, they still look
> like a significant improvement for those less tech minded.

My view is that it's easy to test whether unix permissions are working
as the walls are on the local host. But to test whether there's
leakage between containers, you have to either be at the other end of
the connection or be monitoring all the traffic going out from the
local host.

> I currently run different browser instances for different tasks I want to
> isolate.

I'm not sure how to stop different browser commands jumping into an
existing browser instance. I presume there are ways, but I find it
simpler to just use different users.

> For instance,
[ snipped ]
> As to experiments, I need to see if I can get tools like lightbeam to help
> me audit isolation. I'll also passively test by checking for bleedover
> from different sessions.
> 
> I want to see if I can enable and disable add ons per container. I presume
> not, but that would be a useful feature.

Interesting stuff: perhaps the making of a wiki.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#207825

From"der.hans" <deb-user@LuftHans.com>
Date2019-04-24 18:30 +0200
Message-ID<xQsWu-32n-11@gated-at.bofh.it>
In reply to#207822

[Multipart message — attachments visible in raw view] — view raw

Am 24. Apr, 2019 schwätzte David Wright so:

moin moin,

> On Tue 23 Apr 2019 at 18:15:03 (+0000), der.hans wrote:
>> Am 23. Apr, 2019 schwätzte David Wright so:
>>> On Tue 23 Apr 2019 at 15:53:50 (-0000), Curt wrote:
>>>> On 2019-04-23, der.hans <deb-user@LuftHans.com> wrote:
>>>>>
>>>>> I use different Firefox profiles for banking to improve isolation, so at
>>>>> least they won't be attacked by a retailers tab.
>>>>>
>>>>> I'm experimenting with Firefox containers for the isolation.
>
>>>> https://wiki.mozilla.org/Security/Contextual_Identity_Project/Containers
>>>
>>> I can see some usefulness in having separate bookmarks and histories,
>>> particularly the latter as it's not easy to classify in the same way
>>> as bookmarks with its submenus. But I see only convenience, not
>>> security.
>>>
>>> What experiments have you devised? How do you define "isolation",
>>
>> Thus far my experiments have only been for usability. When I first tried
>> Firefox containers some time ago I could only open one tab in each
>> container.
>>
>> I'm just checking that they work and that I can use the same site multiple
>> times with different credentials from the same browser instance.
>>
>>> and what are the criteria by which you judge whether their scheme
>>> is succeeding or not?
>>
>> At some point I will need to dive into documentation to see if the design
>> is to isolate the containers sufficiently for me. Even if it is, I'm
>> still concerned about a bug allowing container escape or information
>> bleeding.  Should containers not be sufficient for me, they still look
>> like a significant improvement for those less tech minded.
>
> My view is that it's easy to test whether unix permissions are working
> as the walls are on the local host. But to test whether there's

Exactly! We have long-standing, testable capabilities :).

> leakage between containers, you have to either be at the other end of
> the connection or be monitoring all the traffic going out from the
> local host.

It really needs inspection inside the browser and auditing via multi-site
testing.

But, $spouse isn't going to set up a bunch of different browser profiles.
If containers would be viable for that use case, then they could be an
improvement if the promise turns out to be at least mostly true.

They would also be an improvement for my generic browser use cases.

>> I currently run different browser instances for different tasks I want to
>> isolate.
>
> I'm not sure how to stop different browser commands jumping into an
> existing browser instance. I presume there are ways, but I find it
> simpler to just use different users.

Do you mean when an application launches a browser?

I haven't found a way to specify the default browser for external apps.
That would be useful.

>> For instance,
> [ snipped ]
>> As to experiments, I need to see if I can get tools like lightbeam to help
>> me audit isolation. I'll also passively test by checking for bleedover
>> from different sessions.
>>
>> I want to see if I can enable and disable add ons per container. I presume
>> not, but that would be a useful feature.
>
> Interesting stuff: perhaps the making of a wiki.

I'm way behind on creating documentation.

I'll add that to my list of things for an upcoming trip.

ciao,

der.hans
-- 
#  https://www.LuftHans.com   https://www.PhxLinux.org
#  "Luckily, this is a comic book, for which no idea is too complex."
#    -- Larry Gonick from The Cartoon History of the United States

[toc] | [prev] | [next] | [standalone]


#207841

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-04-25 05:30 +0200
Message-ID<xQDfb-VD-5@gated-at.bofh.it>
In reply to#207825
On Wed 24 Apr 2019 at 16:20:21 (+0000), der.hans wrote:
> Am 24. Apr, 2019 schwätzte David Wright so:
> > On Tue 23 Apr 2019 at 18:15:03 (+0000), der.hans wrote:

[I agree with you replies, snipped]

> > > I currently run different browser instances for different tasks I want to
> > > isolate.
> > 
> > I'm not sure how to stop different browser commands jumping into an
> > existing browser instance. I presume there are ways, but I find it
> > simpler to just use different users.
> 
> Do you mean when an application launches a browser?

Yes. Usually I start a browser with a bash function as posted
earlier. Sometimes I use a bash function to open a Tab, even
where I could have done it with a corresponding bookmark.

But sometimes I'd start FF by pressing Return on an HTML in mc.
However, for a long time I've closed that off by having mc call
up lynx with localhost or w3m with -dump. Similarly, mutt only
uses lynx in the same manner.

But when I had used FF in such situations, the page always found a
running instance of FF (appropriate to the user concerned).

> I haven't found a way to specify the default browser for external apps.
> That would be useful.

If I'm understanding you, I think this came up here recently: the
links /etc/alternatives/{gnome-,x-,}www-browser should point to
the appropriate binary.

> > Interesting stuff: perhaps the making of a wiki.
> 
> I'm way behind on creating documentation.
> 
> I'll add that to my list of things for an upcoming trip.

You're very public-spirited.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#207807

From"der.hans" <deb-user@LuftHans.com>
Date2019-04-23 19:40 +0200
Message-ID<xQ7yF-6PG-5@gated-at.bofh.it>
In reply to#207803

[Multipart message — attachments visible in raw view] — view raw

Am 23. Apr, 2019 schwätzte Curt so:

moin moin,

> On 2019-04-23, der.hans <deb-user@LuftHans.com> wrote:
>>
>> I use different Firefox profiles for banking to improve isolation, so at
>> least they won't be attacked by a retailers tab.
>>
>> I'm experimenting with Firefox containers for the isolation.
>
> Looks interesting. I've just enabled it in 'about:config'
>
> privacy.userContext.enabled       true

Is it builtin now? I've been installing the add on.

> I now have a contextual menu entry "Reopen in Container" when
> left-clicking on a tab, which lists the four default containers. The
> wiki doesn't explain the difference between these pre-defined
> containers, though (Home, Work, Banking, and Shopping) or whether you
> can create your own (apparently "custom" containers is a future option).

I ignore those and create my own. It looks like it's just a label with
options for specific color and icon. The key is whether or not each is
isolated from the others.

ciao,

der.hans

> https://wiki.mozilla.org/Security/Contextual_Identity_Project/Containers
>
> Thanks for the heads up.
>
>> ciao,
>>
>> der.hans
>

-- 
#  https://www.LuftHans.com   https://www.PhxLinux.org
#  "If you want to build a ship, don’t drum up people to collect wood, and
#  don’t assign them tasks and work, but rather teach them to long for the
#  endless immensity of the sea." - Antoine de Saint-Exupéry

[toc] | [prev] | [next] | [standalone]


#207772

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-04-22 20:50 +0200
Message-ID<xPMaR-2f7-5@gated-at.bofh.it>
In reply to#207758
On Sun 21 Apr 2019 at 20:30:53 (-0700), peter@easthope.ca wrote:
>     From: David Wright <deblis@lionunicorn.co.uk>
>     Date: Sun, 21 Apr 2019 16:13:11 -0500
> > I run two instances of FF, one as me (for banking etc) and one as
> > another user (for browsing).
> 
> Interesting.  Thanks.  For banking & etc. you have a dedicated user id 
> and login?

The other way round: I bank as me, and browse as user "flash", hence
$ my-deblis-on-flashfirefox
which looks after changing user and allowing flash to display on
the X display. (It also checks that I don't try to run a browser if
I'm not using the most recent Debian version on that particular host.)
Thus, my own files are inaccessible by the flash browser.

> Drifting off the subject, but the banking I use invokes javascript. I 
> would have thought that unnecessary.  Should be possible to accomplish 
> the results with processing on the server and HTML5 on the client.
> Technology bloat?

Yes. Banks, like everyone else, seem to feel the need to indulge their
graphics fantasies on their websites. I guess it's pandering to the
smart phone generation. Speaking of which, I guess we're lucky to
still have Internet banking on computers; so much is now aimed at
mobiles. For a period, I had to login to Chase twice to get a
proper interface—the first login would give me the mobile's site,
with just two impotent buttons, period.

> > I just checked out clean shutdowns and restarts with my own 
> > instance of FF and it's all OK.
> 
> OK, thanks.  The complaint at firefox startup here is probably only 
> following a crash of firefox.   Curt's suggestion to set 
> browser.sessionstore.max_resumed_crashes to 0 seems appropriate.
> 
> > Does the behaviour reported in your OP cause you *great* concern?
> 
> No.  Just wastes time.  Opening a simple local HTML home page requires 
> roughly a minute rather than roughly a second.

I tend to forget that, because my /etc/hosts file has ~14000 lines,
pages appear a lot faster here.

> > I tried Opera on a slow laptop ...
> 
> Thanks for mentioning that.

Yes, disappointing. The fix, for me, was /etc/hosts:
http://someonewhocares.org/hosts/
The only downside (which I don't understand) is that
# scp -p <TAB><TAB>
threatens to list ~14000 filename completions
(IOW every hostname in /etc/hosts), but *only* as root.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#207778 — Browser usage; was "Re: firefox > Preferences > When Firefox starts."

Frompeter@easthope.ca
Date2019-04-22 22:50 +0200
SubjectBrowser usage; was "Re: firefox > Preferences > When Firefox starts."
Message-ID<xPO2Z-3qb-1@gated-at.bofh.it>
In reply to#207772
    From: David Wright <deblis@lionunicorn.co.uk>
    Date: Mon, 22 Apr 2019 13:43:46 -0500
> Yes. Banks, like everyone else, seem to feel the need to indulge their
> graphics fantasies on their websites. I guess it's pandering to the
> smart phone generation. Speaking of which, I guess we're lucky to
> still have Internet banking on computers; so much is now aimed at
> mobiles. For a period, I had to login to Chase twice to get a
> proper interface—the first login would give me the mobile's site,
> with just two impotent buttons, period.

A mobile site can be accessible to firefox on a desktop and can be 
more efficient than the desktop site.  Eg.
https://www.envisionfinancial.ca/m/
vs.
https://www.envisionfinancial.ca/Personal/

Can debian imitate a mobile system to a server?

Thanks,                          ... Peter E.






-- 
Message composed and transmitted by software designed to avoid the 
complication and vulnerability of antivirus software.

[toc] | [prev] | [next] | [standalone]


#207784 — Re: Browser usage; was "Re: firefox > Preferences > When Firefox starts."

FromCurt <curty@free.fr>
Date2019-04-23 09:40 +0200
SubjectRe: Browser usage; was "Re: firefox > Preferences > When Firefox starts."
Message-ID<xPYc1-1dt-11@gated-at.bofh.it>
In reply to#207778
On 2019-04-22, peter@easthope.ca <peter@easthope.ca> wrote:
>
> A mobile site can be accessible to firefox on a desktop and can be 
> more efficient than the desktop site.  Eg.
> https://www.envisionfinancial.ca/m/
> vs.
> https://www.envisionfinancial.ca/Personal/
>
> Can debian imitate a mobile system to a server?

It's possible to modify the User-Agent header string in Firefox and pose
as a mobile browser (not necessarily an infallible maneuver).

https://addons.mozilla.org/en-US/firefox/addon/uaswitcher/

> Thanks,                          ... Peter E.

[toc] | [prev] | [next] | [standalone]


#207801 — Re: Browser usage; was "Re: firefox > Preferences > When Firefox starts."

Fromrhkramer@gmail.com
Date2019-04-23 17:40 +0200
SubjectRe: Browser usage; was "Re: firefox > Preferences > When Firefox starts."
Message-ID<xQ5Gx-5HH-3@gated-at.bofh.it>
In reply to#207784
On Tuesday, April 23, 2019 03:31:24 AM Curt wrote:
> It's possible to modify the User-Agent header string in Firefox and pose
> as a mobile browser (not necessarily an infallible maneuver).
> 
> https://addons.mozilla.org/en-US/firefox/addon/uaswitcher/

Do you or anyone else have an example header string?

(I looked at the URL above and see the addon, but didn't want to install it -- 
I didn't see any example header strings.)

[toc] | [prev] | [next] | [standalone]


#207804 — Re: Browser usage; was "Re: firefox > Preferences > When Firefox starts."

FromReco <recoverym4n@enotuniq.net>
Date2019-04-23 18:10 +0200
SubjectRe: Browser usage; was "Re: firefox > Preferences > When Firefox starts."
Message-ID<xQ69z-67b-1@gated-at.bofh.it>
In reply to#207801
	Hi.

On Tue, Apr 23, 2019 at 11:33:45AM -0400, rhkramer@gmail.com wrote:
> On Tuesday, April 23, 2019 03:31:24 AM Curt wrote:
> > It's possible to modify the User-Agent header string in Firefox and pose
> > as a mobile browser (not necessarily an infallible maneuver).
> > 
> > https://addons.mozilla.org/en-US/firefox/addon/uaswitcher/
> 
> Do you or anyone else have an example header string?

https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/User-Agent/Firefox

You'll need Android UA.

Reco

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web