Tiện ích trình duyệt Firefox
  • Tiện ích mở rộng
  • Chủ đề
    • cho Firefox
    • Từ điển & gói ngôn ngữ
    • Các trang web trình duyệt khác
    • Tiện ích cho Android
Đăng nhập
Xem trước Origin Enforcer

Origin Enforcer bởi sje

Restores the control to the user and provides a security sandbox for cross domain and third party calls from websites. Websites now need your permission to make background cross domain calls, protecting you from malware and mass surveillance.

Thử nghiệmThử nghiệm
3.6 (5 reviews)3.6 (5 reviews)
2 người dùng2 người dùng
Bạn sẽ cần Firefox để sử dụng tiện ích mở rộng này
Tải xuống Firefox và tải tiện ích mở rộng
Tải xuống tập tin

Siêu dữ liệu mở rộng

Ảnh chụp màn hình
Look at all the mess of third party calls all blocked now.
You can enable 'akamaized.net' which the site seems to be using for content, which is enough to show the images, but all the other calls can remain blocked!accuweather.com does not even display! Looks at all the third party calls this site tries to make. Ditch this site immediately!Choose which third party domains the site can call. Some are legitimate, such as using another domain for content like images or videos.You can still read news on sites like yahoo.com while blocking all the tracking and surveillance calls to third parties. Here we just accept yimg.com as allowed, since it seems to be a yahoo owned domain for images.The guardian can be read without allowing any thirdparty calls. Images can be added by allowing one domain. If you want to allow images that are not displaying, right click the element, choose inspect element, and look at the image source, then you can enable that domain.Look at all that junk that is blocked! The site is still readable by blocking all that surveillance. Almost every site has google surveillance built in, so always keeep that blocked.Look at all that junk blocked! Can still read the site with all of it blocked.
Về tiện ích mở rộng này
This is what browsers are supposed to do by default. In a proper security model, users have control, and give permissions to the websites to perform background requests to third party servers flowing out of websites. Websites should declare what third parties they use, why, and who owns the domains. But they don't, and calls especially to google and facebook in many sites let them track you everywhere. Websites secretly are making huge numbers of calls with cookies to other places on the internet without you knowing at all.

Users should decide which third party domains are ok! For too long, corporations like google and facebook have undermined internet security and hacked the http protocol to bypass security controls and take away the privacy and security of internet users. They have intentionally violated the basics of user controlled sandbox security model for mass surveillance.

This plugin intends to restore the power to the user in deciding cross domain and third party calls from websites. Websites should only make calls back to themselves, a simple principal called 'single origin' that protects users against viruses, security concerns, and surveillance. In this cross origin sandbox, the websites need your permission to make cross domain calls.

Manage which calls are allowed in the interface. You can upvote domains you allow, or downvote them to. block them. By default, only calls back the websites own domain is allowed. This will break many sites by default. Good sites, like duckduckgo.com work fine. Terrible sites may not come up at all. Some sites may be missing images since they come from another domain. If you want to see blocked images, right click the image, choose inspect element, and see the src, which domain it is coming from. Then you can allow this domain. Some sites will need many third party domains to work unfortunately. This is a simple way to allow everything for each site. You can also choose allow everything except cookies for sites that do not have a login and have should have no need for cookies.

Unfortunately browsers and websites today have granted themselves control to make any calls to anybody with cookies. This is all done under the covers, in secret, and causes a plague of malware, security issues, flood of internet spam calls and mass surveillance. Websites insert tracking and third party cross domain calls without regard, and browsers blindly go ahead and make these calls in secret without consent of the user to enable mass surveillance.

Corporations such as Google (via chrome, android, plugins, etc) and Facebook (via facebook.com and plugins) intentionally violate basic principals of user ownership and control, spread fake plugins, create fake sandboxes, and undermined security and privacy without regard for basic security norms. It is our job to stop them! This plugin restores the basic right that users control what third parties can receive calls from any site. Sites should only call back to themselves... and no others. They should referencing third party software and scripts, not load them from third parties.

This plugin enforces these basic rules regardless of what the websites wants to do, and takes back the control to the user from the broken security model of the browsers and websites. It stops the dangerous and sloppy web coding practices. It also makes visible the sloppy mess of cross domain calls going on behind the scenes on so many websites, showing the shocking state of the situation, and showing what is going on behind the scenes in secret without any user consent.

At a minimum, this plugin will expose the problem, showing the huge number of calls to thirdparties. Any site using many third parties should be rejected. You can fine tune what calls are allowed, such as allowing some needed calls, but rejecting others like to facebook or google or ad services.
Được xếp hạng 3,6 (bởi 1 người dùng)
Đăng nhập để đánh giá tiện ích này
Chưa có xếp hạng nào

Đã lưu xếp hạng sao

5
2
4
1
3
1
2
0
1
1
Đọc tất cả 5 đánh giá
Quyền hạn và dữ liệuTìm hiểu thêm

Quyền hạn bắt buộc:

  • Truy cập các thẻ trên trình duyệt
  • Truy cập dữ liệu của bạn trên mọi trang web
Thêm thông tin
Liên kết tiện ích
  • Email hỗ trợ
Phiên bản
2.0
Kích cỡ
31,52 KB
Cập nhật gần nhất
5 năm trước (1 Thg 04 2020)
Thể loại có liên quan
  • Riêng tư & Bảo mật
Giấy phép
Giấy phép BSD 2-Clause "Simplified"
Lịch sử các phiên bản
  • Xem tất cả phiên bản
Thêm vào bộ sưu tập
Báo cáo tiện ích này
Ghi chú phát hành cho phiên bản 2.0
Added 3 modes :
- the default is enforcing the single origin rules, and allowing you to configure accepted cross origin calls by domian.
- a mode accepting all background requests, but blanket blocking all cookies. this might be useful to quickly enable all the cross origin calls, but still browse more anonymously by blocking all cookies in background requests
- a mode accepting eveything, turning off the origin enforcer for the domain

Added a way to reset the stats for a domain, so blocked calls and blocked cookie counts will reset

Better display

Better tooltips
Tiện ích mở rộng khác của sje
  • Chưa có xếp hạng nào

  • Chưa có xếp hạng nào

  • Chưa có xếp hạng nào

  • Chưa có xếp hạng nào

  • Chưa có xếp hạng nào

  • Chưa có xếp hạng nào

Đi đến trang chủ Mozilla

Tiện ích

  • Giới thiệu
  • Blog tiện ích Firefox
  • Extension Workshop
  • Trung tâm nhà phát triển
  • Chính sách nhà phát triển
  • Blog cộng đồng
  • Diễn đàn
  • Báo cáo một lỗi
  • Hướng dẫn đánh giá

Trình duyệt

  • Desktop
  • Mobile
  • Enterprise

Sản phẩm

  • Browsers
  • VPN
  • Relay
  • Monitor
  • Pocket
  • Bluesky (@firefox.com)
  • Instagram (Firefox)
  • YouTube (firefoxchannel)
  • Riêng tư
  • Cookie
  • Pháp lý

Trừ trường hợp khác đã ghi chú, nội dung trên trang này được cấp phép theo giấy phép Creative Commons Attribution Share-Alike v3.0 hoặc bất kỳ phiên bản nào sau này.