EFForg / privacybadgerfirefox-legacy

LEGACY Privacy Badger for Firefox SEE README
https://www.eff.org/privacybadger
Other
408 stars 68 forks source link

Privacy Badger deleting existing first party cookies #647

Open SwartzCr opened 8 years ago

SwartzCr commented 8 years ago

Tried the latest version to see if the problems with previous versions were fixed and they are not. Installed the extension, browsed around for a while and it deleted all my Google and Tumblr cookies, logging me out of both sites. Seriously, this extension is terrible. Privacy Badger should not touch any cookies that I have explicitly added to my Firefox whitelist.

from: https://addons.mozilla.org/en-US/firefox/addon/privacy-badger-firefox/reviews/754184/

gms77 commented 8 years ago

Hi, that was my review. I created an account here to provide more info.

These steps were performed on a clean new profile. At this point the only extension I installed was Lastpass so I could login to some sites.

Firefox browser settings:

Accept cookies from sites - checked Accept third-party cookies - From Visited Keep until - I close Firefox

Added to exceptions: http://google.com https://google.com http://lastpass.com https://lastpass.com http://youtube.com https://youtube.com

After logging into Google and Youtube everything is working as expected, I can stay logged into my Google related sites even after restarting the browser.

Next, install Privacy Badger.

I then opened these sites in new tabs (all SFW):

http://www.visualglow.com/ http://www.asdaze.com/ http://www.allkpop.com/ http://www.girlsdaydaily.com/ http://www.soompi.com/ http://www.koreaboo.com/ https://kpopinfo114.wordpress.com/ http://moonroknews.com/ http://netizenbuzz.blogspot.co.uk/ http://www.t-araworld.net/ http://arcadey.net/home/ http://fyeahstellar.tumblr.com/ http://stellarnews.co.vu/

Clicking on Privacy Badger settings icon states "Privacy Badger has detected 51 potential tracking domains so far."

Closer browser then reopen. Check the Firefox cookie manager and all my cookies have been deleted except those for Lastpass.

cooperq commented 8 years ago

privacy badger should not ever be deleting existing cookies, by which I mean we do not have any code that deletes existing cookies. This will take some research.

anonsubmitter commented 8 years ago

Keep until - I close Firefox

Closer browser then reopen. Check the Firefox cookie manager and all my cookies have been deleted except those for Lastpass.

Could it be that Firefox deleted the cookies when you closed your browser?

gms77 commented 8 years ago

No, the sites were correctly added to the whitelist in the browser and it works without PB installed. It's only with PB that they are deleted.

I provided the steps to reproduce nearly 2 months ago and nobody has said whether or not it happens to them also.

lbschenkel commented 8 years ago

It happens to me as well. My FF is configured to keep cookies until I close FF (and reject third-party cookies), but I have made exceptions for sites like Google, GitHub and others to allow them to set first-party cookies. When PB is enabled all the first-party cookies are removed every time FF is started; when I disable PB this stops happening. This is happening since PB 1.0 was released (I didn't check earlier versions).

I love PB but I got so annoyed by this bug that I had to disable it for now. Feel free to contact me if you need more info.

fph commented 8 years ago

Same here -- my cookies are configured as "Keep until - I close Firefox", I have added stackexchange.com to the whitelist, but its auth cookie gets deleted on exit anyway. If I disable Privacy Badger, I get the correct behavior; so the bug must be due to interaction with PB. Happens on both Windows and Linux. Feel free to ask for more info or experiments.

fph commented 8 years ago

This issue seems to be a duplicate of #118 (which I just found).