uBlock icon indicating copy to clipboard operation
uBlock copied to clipboard

Firefox + whitelisting and "Private mode" leak information

Open Armonth opened this issue 10 years ago • 3 comments

A long time ago, in Firefox was considered as one bug that "autofill" worked in private mode/other profiles because can 'filter' information of what webs you visit.

Now want to put a similar issue with uBlock:

  1. Enter private mode.
  2. Go to one site you don't want to allow others users of the PC to know you visit (yeah, you thinked same as me, but no: i'm talking of my online bank site :wink:)
  3. Disable uBlock for that site (because that online bank site is stupid and something is blocked by a generic filter).
  4. Close private mode.
  5. That site is still whitelisted in uBlock settings... so people can have access to information you don't wanto they to know.

Expected behavior: forget sites whitelisted in private mode when close the session.

Armonth avatar Apr 20 '15 23:04 Armonth

I don't think private mode was meant to keep extensions from saving their own data, just to keep ordinary website data from being saved, like cookies and cache; this, BTW, is why extensions are disabled by default in Chrome's Incognito mode and you need to check the box under every extension you want to allow in that mode (and you need to turn on the "Developer" view in the Extensions menu just to see the checkboxes).

lewisje avatar Apr 21 '15 06:04 lewisje

@Armonth and other users who don't want changes to be permanent can just use the green column of dynamic filtering pane to whitelist whatever they want, including full sites, and then revert back with the eraser icon or close the browser without saving the changes.

As @lewisje pointed out, extensions are supposed to work normally on private mode, and changing that would be terrible for other users. I use Private Tabs to browse many sites only in private mode and don't want uBlock to stop working as expected on them. Some of my several custom searches/bookmarks with keywords that open in private tabs:

untitled-1

anewuser avatar Jan 08 '16 16:01 anewuser

The dynamic filtering pane suggested by @anewuser is only available for advanced users, but it's the rest of the users that need protection the most. Would it be possible and reasonable for the simple on/off functionality to use that same dynamic filtering logic? That is, the existing whitelist is respected, whitelist changes are kept in memory, an option is provided to save the whitelist. When an explicit "Save" button is clicked, a user should be able to understand that this will continue to be visible after leaving private browsing mode.

hvdijk avatar Oct 23 '16 10:10 hvdijk