{"id":2747,"date":"2021-06-01T05:55:24","date_gmt":"2021-06-01T12:55:24","guid":{"rendered":"https:\/\/blog.mozilla.org\/security\/?p=2747"},"modified":"2021-06-02T00:35:21","modified_gmt":"2021-06-02T07:35:21","slug":"total-cookie-protection-in-private-browsing","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/","title":{"rendered":"Firefox 89 blocks cross-site cookie tracking by default in private browsing"},"content":{"rendered":"<p>At Mozilla, we believe that your right to privacy is fundamental. Unfortunately, for too long cookies have been used by tracking companies to gather data about you as you browse the web. Today, with the launch of Firefox 89, we are happy to announce that Firefox Private Browsing windows now include our innovative Total Cookie Protection by default. That means: when you open a Private Browsing window, each website you visit is given a separate cookie jar that keeps cookies confined to that site. Cookies can no longer be used to follow you from site to site and gather your browsing history.<\/p>\n<h2>What is Total Cookie Protection?<\/h2>\n<p>In February of this year we <a href=\"https:\/\/blog.mozilla.org\/security\/2021\/02\/23\/total-cookie-protection\/\">introduced Total Cookie Protection<\/a>, a new, extra-strong protection against cross-site tracking cookies. Since Firefox 86, Total Cookie Protection has been available for users who have ETP Strict Mode enabled. Now, with Firefox 89, we are extending this same protection to Private Browsing windows.<\/p>\n<p>To recap: a cookie is a small piece of data that websites can ask your browser to store on your computer. Traditionally, browsers have allowed websites to share cookies in what is effectively a single cookie jar. Firefox\u2019s Total Cookie Protection is a sophisticated set of privacy improvements that enforce a simple, revolutionary principle: your browser should not allow the sharing of cookies between websites. This principle is now enforced in Firefox Private Browsing windows by creating a separate cookie jar for every website you visit, as illustrated here:<\/p>\n<div id=\"attachment_2698\" style=\"width: 2170px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3.png\"><img aria-describedby=\"caption-attachment-2698\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-2698\" src=\"https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3.png\" alt=\"\" width=\"2160\" height=\"1080\" srcset=\"https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3.png 2160w, https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3-300x150.png 300w, https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3-600x300.png 600w, https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3-768x384.png 768w, https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3-1536x768.png 1536w, https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3-2048x1024.png 2048w, https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3-1000x500.png 1000w\" sizes=\"(max-width: 2160px) 100vw, 2160px\" \/><\/a><p id=\"caption-attachment-2698\" class=\"wp-caption-text\">Previously, third-party cookies were shared between websites. Now, every website gets its own cookie jar so that cookies can\u2019t be used to share data between them. (Illustration: Meghan Newell)<\/p><\/div>\n<p>As we <a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/Privacy\/State_Partitioning\">described in February<\/a>, Total Cookie Protection covers not just cookies but a variety of browser technologies that previously were able to be used for cross-site tracking. To ensure a smooth browsing experience, Total Cookie Protection makes occasional exceptions to share cookies between websites when they are needed for cross-site logins or similar cross-site functionality.<\/p>\n<h2>Firefox Private Browsing Windows, now with even more privacy<\/h2>\n<p>With the addition of Total Cookie Protection, Firefox\u2019s Private Browsing windows have the most advanced privacy protections of any major browser\u2019s private browsing mode. The following protections are included in Private Browsing windows by default:<\/p>\n<ul>\n<li aria-level=\"1\"><a href=\"https:\/\/blog.mozilla.org\/security\/2021\/02\/23\/total-cookie-protection\/\">Total Cookie Protection<\/a> isolates cookies to the site where they were created<\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/blog.mozilla.org\/security\/2021\/01\/26\/supercookie-protections\/\">Supercookie protections<\/a> stop supercookies from following you from site to site<\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/support.mozilla.org\/en-US\/kb\/private-browsing-use-firefox-without-history#w_what-does-private-browsing-not-save\">Cookies and caches are cleared<\/a> at the end of every Private Browsing session, and aren\u2019t shared with normal windows<\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/support.mozilla.org\/en-US\/kb\/enhanced-tracking-protection-firefox-desktop#w_standard-enhanced-tracking-protection\">Trackers are blocked<\/a>, including cookies, scripts, tracking pixels and other resources from domains on Disconnect\u2019s list of known trackers<\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/blog.mozilla.org\/security\/2020\/01\/07\/firefox-72-fingerprinting\/\">Many fingerprinting scripts are blocked<\/a><b>,<\/b> according to Disconnect\u2019s list of invasive fingerprinting domains.<\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/blog.mozilla.org\/security\/2021\/03\/23\/introducing-smartblock\/\">SmartBlock<\/a> intelligently fixes up web pages that were previously broken when tracking scripts were blocked<\/li>\n<\/ul>\n<p>If you have Firefox installed, you don\u2019t need to do anything special to benefit from this upgrade to Private Browsing windows. To open a Private Browsing window, click on the Application Menu button (\u2630) and choose \u201cNew Private Window\u201d:<\/p>\n<p><a href=\"https:\/\/blog.mozilla.org\/security\/files\/2021\/05\/Screen-Shot-2021-05-31-at-12.04.24-AM.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-2753\" src=\"https:\/\/blog.mozilla.org\/security\/files\/2021\/05\/Screen-Shot-2021-05-31-at-12.04.24-AM.png\" alt=\"Screenshot of the application menu with New Private Window selected.\" width=\"292\" height=\"188\" srcset=\"https:\/\/blog.mozilla.org\/security\/files\/2021\/05\/Screen-Shot-2021-05-31-at-12.04.24-AM.png 588w, https:\/\/blog.mozilla.org\/security\/files\/2021\/05\/Screen-Shot-2021-05-31-at-12.04.24-AM-300x193.png 300w\" sizes=\"(max-width: 292px) 100vw, 292px\" \/><\/a>Or, if you like keyboard shortcuts, just press Ctrl + Shift + P (Cmd + Shift + P on Mac). When you are done with that private browsing session, you can simply close all your Private Browsing windows. All the cookies and other stored data from the websites you visited will be immediately deleted!<\/p>\n<p>As we continue to strengthen Firefox\u2019s privacy protections, Mozilla is committed to maintaining state-of-the-art performance and a first-class browsing experience. Stay tuned for more privacy advances in the coming months!<\/p>\n<h2>Thank you<\/h2>\n<p>We are grateful to the many Mozillians who have contributed to or supported this new enhancement to Firefox, including Steven Englehardt, Andrea Marchesini, Tim Huang, Johann Hofmann, Gary Chen, Nihanth Subramanya, Paul Z\u00fchlcke, Tanvi Vyas, Anne van Kesteren, Ethan Tseng, Prangya Basu, Wennie Leung, Ehsan Akhgari, Dimi Lee, Selena Deckelmann, Mikal Lewis, Tom Ritter, Eric Rescorla, Olli Pettay, Philip Luk, Kim Moir, Gregory Mierzwinski, Doug Thayer, and Vicky Chin.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>At Mozilla, we believe that your right to privacy is fundamental. Unfortunately, for too long cookies have been used by tracking companies to gather data about you as you browse &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/\">Read more<\/a><\/p>\n","protected":false},"author":1673,"featured_media":2698,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[847],"tags":[21031,465798],"coauthors":[318213],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Firefox 89 blocks cross-site cookie tracking by default in private browsing - Mozilla Security Blog<\/title>\n<meta name=\"description\" content=\"Today, with the launch of Firefox 89, we are happy to announce that Firefox Private Browsing windows now include Total Cookie Protection by default.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Arthur Edelstein\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/\",\"url\":\"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/\",\"name\":\"Firefox 89 blocks cross-site cookie tracking by default in private browsing - Mozilla Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3.png\",\"datePublished\":\"2021-06-01T12:55:24+00:00\",\"dateModified\":\"2021-06-02T07:35:21+00:00\",\"author\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/15615a964e4ede9ff7e63c78ca4d77ed\"},\"description\":\"Today, with the launch of Firefox 89, we are happy to announce that Firefox Private Browsing windows now include Total Cookie Protection by default.\",\"breadcrumb\":{\"@id\":\"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/#primaryimage\",\"url\":\"https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3.png\",\"contentUrl\":\"https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3.png\",\"width\":2160,\"height\":1080,\"caption\":\"Total Cookie Protection gives each website its own cookie jar. (Illustration: Meghan Newell)\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.mozilla.org\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Firefox 89 blocks cross-site cookie tracking by default in private browsing\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#website\",\"url\":\"https:\/\/blog.mozilla.org\/security\/\",\"name\":\"Mozilla Security Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/15615a964e4ede9ff7e63c78ca4d77ed\",\"name\":\"Arthur Edelstein\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/5d0930bdf89967c69e593ea7f0bf4841\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/bd2476f08b12acfeabfd2d91a2552a21?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/bd2476f08b12acfeabfd2d91a2552a21?s=96&d=identicon&r=g\",\"caption\":\"Arthur Edelstein\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Firefox 89 blocks cross-site cookie tracking by default in private browsing - Mozilla Security Blog","description":"Today, with the launch of Firefox 89, we are happy to announce that Firefox Private Browsing windows now include Total Cookie Protection by default.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/","twitter_misc":{"Written by":"Arthur Edelstein","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/","url":"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/","name":"Firefox 89 blocks cross-site cookie tracking by default in private browsing - Mozilla Security Blog","isPartOf":{"@id":"https:\/\/blog.mozilla.org\/security\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/#primaryimage"},"image":{"@id":"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3.png","datePublished":"2021-06-01T12:55:24+00:00","dateModified":"2021-06-02T07:35:21+00:00","author":{"@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/15615a964e4ede9ff7e63c78ca4d77ed"},"description":"Today, with the launch of Firefox 89, we are happy to announce that Firefox Private Browsing windows now include Total Cookie Protection by default.","breadcrumb":{"@id":"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/#primaryimage","url":"https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3.png","contentUrl":"https:\/\/blog.mozilla.org\/security\/files\/2021\/02\/panels-3.png","width":2160,"height":1080,"caption":"Total Cookie Protection gives each website its own cookie jar. (Illustration: Meghan Newell)"},{"@type":"BreadcrumbList","@id":"https:\/\/blog.mozilla.org\/security\/2021\/06\/01\/total-cookie-protection-in-private-browsing\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.mozilla.org\/security\/"},{"@type":"ListItem","position":2,"name":"Firefox 89 blocks cross-site cookie tracking by default in private browsing"}]},{"@type":"WebSite","@id":"https:\/\/blog.mozilla.org\/security\/#website","url":"https:\/\/blog.mozilla.org\/security\/","name":"Mozilla Security Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.mozilla.org\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/15615a964e4ede9ff7e63c78ca4d77ed","name":"Arthur Edelstein","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.mozilla.org\/security\/#\/schema\/person\/image\/5d0930bdf89967c69e593ea7f0bf4841","url":"https:\/\/secure.gravatar.com\/avatar\/bd2476f08b12acfeabfd2d91a2552a21?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bd2476f08b12acfeabfd2d91a2552a21?s=96&d=identicon&r=g","caption":"Arthur Edelstein"}}]}},"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/2747"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/users\/1673"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/comments?post=2747"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/posts\/2747\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/media\/2698"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/media?parent=2747"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/categories?post=2747"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/tags?post=2747"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blog.mozilla.org\/security\/wp-json\/wp\/v2\/coauthors?post=2747"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}