Users get more control over data in latest Firefox beta

Users and websites will be able to manage what data is sent to other websites

Mozilla is adding new capabilities in the beta version of Firefox 36 to give users and website owners more control over what data, if any, is sent to other websites during browsing.

When a user navigates to a new website by clicking on a link or pulls an image or video file from another site, the browser typically sends the new site the address of the page that referred it. It's useful for webmasters to see where someone has come from but a privacy worry since other sensitive data can be revealed.

"As the Web got more complex, the amount of information in the referrer header ballooned, leading to bigger privacy problems," wrote Sid Stamm, principal security and privacy engineer at Mozilla.

Just earlier this week the U.S. government health insurance website was found to be sending personal data such as zip codes, income levels and whether users smoke or are pregnant to external sites via referral data sent to trackers in the website.

To help users keep control of such data, Mozilla has been working on changes to Firefox's Gecko rendering engine to make it easier for users or browser extensions to control referrer data.

And it has created a feature called "meta referrer" in the Firefox 36 beta that allows webmasters to include a tag in HTML documents specifying a referrer policy and what data can be sent.

For example, a policy can be set that strips the referrer header of a path, query string or fragment, Stamm wrote. Other policies can block all referrer information, he wrote.

The Electronic Frontier Foundation called the incident a major privacy concern since companies could use it to create profiles for targeted advertising.

But it's unclear if the referrer problem with will be fixed. Aaron Albright, director of the Media Relations Group for the Centers for Medicare and Medicaid Services, wrote via email there is no evidence that third-party companies have misused the information. It was unclear if the issue would be fixed.

"We will remain vigilant and will continue to focus on what more we can do to keep consumers' personal information secure," Albright wrote.

In 2010, Facebook made technical changes after was found sending a person's user ID in a referrer when a person clicked on an advertisement, potentially allowing a company to identify a specific user. Facebook labeled the issue an "unintentional oversight."

Send news tips and comments to Follow me on Twitter: @jeremy_kirk

Join the CSO newsletter!

Error: Please check your email address.

Tags applicationssecuritybrowserssoftwareprivacymozilla

More about Electronic Frontier FoundationFacebookMozillaSid Stamm

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Jeremy Kirk

Latest Videos

  • 150x50

    CSO Webinar: Will your data protection strategy be enough when disaster strikes?

    Speakers: - Paul O’Connor, Engagement leader - Performance Audit Group, Victorian Auditor-General’s Office (VAGO) - Nigel Phair, Managing Director, Centre for Internet Safety - Joshua Stenhouse, Technical Evangelist, Zerto - Anthony Caruana, CSO MC & Moderator

    Play Video

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

More videos

Blog Posts

Market Place