Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Firefox Privacy Settings Breakage Study

Firefox Privacy Settings Breakage Study

From July-August 2018, we conducted a study to learn privacy settings effects' on website breakage.

luke crouch

August 17, 2017
Tweet

More Decks by luke crouch

Other Decks in Technology

Transcript

  1. Brought to you by ... Jacqueline Savory Interaction Designer Luke

    Crouch PrivSec Engineer Peter Dolanjski Product Manager
  2. Brought to you by ... Ryan Harter Browser Measurement Ilana

    Segall Data Science Years of awesome Privacy engineers
  3. Existing Claims Tracking Protection breaks websites Broken websites make users

    leave Firefox Some existing prefs could protect users with minimal breakage
  4. About those claims ... Tracking Protection breaks websites Broken websites

    make users leave Firefox Some existing prefs could protect users with minimal breakage
  5. Avg. problems reported per user looks lower for trackingProtection ...

    https://sql.telemetry.mozilla.org/queries/23721#61701
  6. Avg. problems reported per user looks lower for trackingProtection ...

    https://sql.telemetry.mozilla.org/queries/23721#61701 WTF?
  7. Some control users’ problems ... “Something* on the page is

    slowing down the loading speed significantly.” *Spoiler Alert: it’s the trackers “not responsive”, “slow, freezing”, “Took longer than usual for page to load”, “Connection appears slower than usual”, “Pages are scrolling slowly”, “very slow to load”, “long wait for anything to occur”, “the fire fox not always responding”, “page is very slow to load”, “tremendous lag , page loads very slowly”, “page was laggy and didn't respond”, “Sending mail in Gmail is very slow since installation of this study”, “really slow to load”, “video doesn't load fast”, ...
  8. Some common site breakages ... resistFingerprinting causes Facebook problems firstPartyIsolation

    causes YouTube problems https://sql.telemetry.mozilla.org/queries/18276#61772
  9. What % of users leave the study? After reporting breakage

    on certain popular sites https://sql.telemetry.mozilla.org/queries/27989#73748 Don’t break SUMO: 72% of users left Don’t break Google sites: 6 out of top 25 Don’t break email: Yahoo Mail, Gmail, Outlook Live in top 20
  10. What % of users leave the study? After reporting breakage

    on longer tail sites https://sql.telemetry.mozilla.org/queries/27989#73748 Don’t break dev sites? Atlassian, GitHub show up Don’t break porn sites? xvideos show up
  11. Some common breakages firstPartyIsolation causes login failures resistFingerprinting causes flash

    problems https://sql.telemetry.mozilla.org/queries/19634#61483
  12. What % of users with certain breakage disable the study?

    https://sql.telemetry.mozilla.org/queries/20097#51471 94% of users reporting screen breakage disable study 84% of users reporting flash breakage disable study 82% of users reporting login-failure breakage disable study 64% of users reporting payment breakage disable study
  13. What % of users with certain breakage disable the study?

    https://sql.telemetry.mozilla.org/queries/20097#51471 screen and flash are only in resistFingerprinting payment is in control & 3DP cookies branches login-failure in control, 3DP cookies, first-party isolation, & referer branches
  14. 14% of control users report breakage 18% of firstPartyIsolationOpenerAccess users:

    the max recorded in the study https://sql.telemetry.mozilla.org/queries/23644#61485 6 settings are within margin of error of control
  15. .21 avg. problems per control user .25 thirdPartyCookiesOnlyFromVisited .19 trackingProtection

    https://sql.telemetry.mozilla.org/queries/23721#61701 4 settings are within margin of error of control
  16. 5.1% of control users disable study 8.5% of firstPartyIsolation users

    4.7% of originOnlyToThirdParties users https://sql.telemetry.mozilla.org/queries/19633#50159 5 settings are within margin of error of control
  17. “Composite Breakage Score” An index of web breakage % of

    users who report breakage Average breakage reported by each user % of users who disable the protection (presumably because of breakage) * *
  18. Some thirdPartyCookiesOnlyFromVisited users’ problems ... “The message tells me that

    my cookies are blocked even though my settings are to accept cookies.” “Got this message ... Cookies are blocked. … your browser doesn’t allow cookies. ...change your browser settings.”, “Cannot access on onlyine bill pay because it thinks cookies are blocked. I checked an my options say to allow cookies. what is going on?”
  19. User values trackingProtection Blocks known trackers completely Speed boost Very

    little mail breakage Triggers ad-blocker-blocker walls
  20. User values sessionOnlyThirdPartyCookies Limits duration of tracking Very little mail

    breakage Some login and “unexpected signout” failures
  21. Key take-aways Tracking Protection doesn’t seem to “break” websites as

    much as we feared Breaking workflow sites makes users disable the study Yes! Some existing prefs could protect users with minimal breakage
  22. Next Q3-Q4 Tracking Protection opt-out study measuring user engagement &

    retention “Creepy Ads” Experiment|Study to identify trackers involved with creepiest online ads Your idea? Join us in #privacy