cancel
Showing results for 
Search instead for 
Did you mean: 

Firefox doesn't delete cookies on exit. When will it do?

Highlighted
New User

Firefox doesn't delete cookies on exit. When will it do?

Firefox fails to delete cookies if set to do so on quitting and if the settings 'General->Show my windows and tabs from last time' have been set.

The problem is described e.g. as bug 794253, 443354 and 401187:

https://bugzilla.mozilla.org/show_bug.cgi?id=794253 https://bugzilla.mozilla.org/show_bug.cgi?id=443354 https://bugzilla.mozilla.org/show_bug.cgi?id=401187 .

As a result user tracking through cookies can continue even if Firefox had been closed before. Moreover another user could resume an earlier session and access pages an earlier user had not logged off from.

A work around is also described in https://bugzilla.mozilla.org/show_bug.cgi?id=443354 :
edit direct link to comment -J99 bug 443354 c48

In about:config set browser.sessionstore.privacy_level & browser.sessionstore.privacy_level_deferred to 1 or 2 as described with the bug report.

However, as a general solution this problem needs to be fixed in Firefox since most people will neither be aware of the problem nor of the work around.

Users can vote for this bug in Bugzilla to promote its solution.

17 REPLIES
Site Moderator

Re: Firefox doesn't delete cookies on exit. When will it do?

Hi fkbreitl,

Good post. This is something that is not well documented. Maybe if bug 401187 is not assigned and actioned soon we should consider at least amending Firefox KB articles to include advice on this.

Anyone using session restore from Show my windows and tabs from last time' should bare in mind the security implications, as mentioned in the post above. There are a couple of things you could also try

  1. explicitly LOG OUT of security, financial, or confidential sites as soon as you finish your task.
  2. PRIVATE BROWSING, this is designed to protect you, and does not save cookies or other information

Voting
Anyone following the advice above to vote in the bug please note

  1. the open bug on which you may beneficially vote is
    Bug 401187 - auth cookies remain after restart firefox directly (reword "Keep [cookies] until: I close Firefox")
    ( You will need to register with an email address before voting)
    You are only voting for a change in wording
  2. Please do not add comments to the bugs themselves, they have already had extensive comments from all interested parties over several years !

Workaround
This is probably more suited to advanced users or corporate environments but does stop the cookies being kept.

In about:config set browser.sessionstore.privacy_level & browser.sessionstore.privacy_level_deferred to 1 or 2 as described with the bug report. 

You will need to go into about:config accepting a warning if necessary, then filter to find (or maybe even add) the preference, and amend the preference value. See


STANDARDS

I presume Firefox attempts to remain standards compliant, but standards evolve and real world practices also need to be considered. Bug 443354 c48 mentions

The standards /are/ changing. RFC 2109 from 1997 never quite matched actual behaviour which developed over time

It appears that comment is itself out of date as it seems standards are RFC2109 -> RFC2965 -> RFC6265 . Apparently current proposals are HTTP State Management Mechanism RFC 6265

New User

Re: Firefox doesn't delete cookies on exit. When will it do?

Thanks for your comments.

To the voting: 1. I just corrected in bug 401187 that rewording is no solution. What is needed is a fix in Firefox to delete cookies on quitting as requested by the users. So voting should now be for deleting cookies and not for the rewording.

2. I don't see why people shouldn't express that they care about this important privacy issue by commenting on it. Since this problem is still unfixed after 5 years (e.g. 4011787 was reported as early as Oct. 2007) I would rather conclude that not enough people have commented on it.

Site Moderator

Re: Firefox doesn't delete cookies on exit. When will it do?

You you use "Show my windows and tabs from last time" then Firefox stores the cookies used in the tabs as part of the session data, so these won't get cleared.

You can set the browser.sessionstore.privacy_level pref to 2 (never) or 1 (non-HTTPS) on the about:config page to disable saving cookies via session restore.

The browser.sessionstore.privacy_level_deferred pref is used when you do not reopen the previous session automatically via "Show my windows and tabs from last time" and uses the same values.

New User

Re: Firefox doesn't delete cookies on exit. When will it do?

Yes, I think you understood the bug and the work around.

Site Moderator

Re: Firefox doesn't delete cookies on exit. When will it do?

Lets see if there is any further action in that bug. I suspect it is effectively dead in the water and not going to get assigned or actioned. (I am still in favour of merely attempting to amend KB documentation)

I understand the general idea with bug reports is that most background discussion takes place elsewhere. Ideally the bug is a single and simple solution to a problem, or a request for a clearly specified enhancement.

I am not sure about this subject, and I will leave it to you to do any further research. If you are determined to try the bugzilla approach, you could read up on the related bugs and past decisions, and possibly the course of action may be to consider filing a new bug either

  • asking for a new User Interface or preference option
  • pointing out any recently changed draft proposals that Firefox may be in danger of not meeting unless it changes

A better option may be to find a suitable developers forum/mailing list and petition for some sort of change of direction and only then file a bug for an enhancement once you have supporters.

This forum is not even a good place for such a discussion, although cor-el's your own , and my post above do actually mention workarounds for the problem and that IMHO is valid content for this support forum.


If this thread drifts away from a problem and solution, and into arguments about Mozilla Firefox policies; I or someone else; may be likely to lock it as off topic for this support forum.

New User

Re: Firefox doesn't delete cookies on exit. When will it do?

John, thanks for your comments.

I already filed a new bug report for the issue which is 794253 mentioned above. However, I don't have time for campaigns you mention above. I am just a user reporting a bug and the purpose of my report it in this forum is to help others who realize the same problem.

I also found many other questions about the same problem in this forum, however none were answered with a clear description of the problem nor a reference to a bug report nor a workaround.

Site Moderator

Re: Firefox doesn't delete cookies on exit. When will it do?

I will leave the active bug a week or so to see if there is any activity, then I will see if anything can be done to improve our documentation. (Post back and remind me if you like).

I was aware of the situation with the saved tabs, but until I tried to look did not realise we do not seem to have clearly documented this. To my mind rewording of the options would suffice to make users aware of what they are opting for.

New User

Re: Firefox doesn't delete cookies on exit. When will it do?

The problem is:

Users want Firefox to delete their cookies and they want Firefox to open the last pages they visited. It is an obvious and reasonable user request.

To make Firefox do something different and more sophisticated that most users won't need and that puts their privacy at risk behind their back is a very wrong thing to do.

This is not about rewording or documenting. This is about fixing a bug which originates from misconception in Firefox. If you read the bug reports again you should notice this. Instead of documenting a bug it should be fixed. And a web browser should be Intuitive and not need documentation.

Site Moderator

Re: Firefox doesn't delete cookies on exit. When will it do?

Your title for this question is

  • Firefox doesn't delete cookies on exit. When will it do?

That is a rhetorical question as each of the writers in this thread has shown awareness of the answer:

  • Firefox already does that NOW, if you change settings and preferences suitably (or as I mentioned use PB).

I will reiterate, this forum is dedicated to solving simple and specific user problems with direct advice. It is not for discussion of the merits and finer details of bugs, unless that is to give direct user advice.

Neither is the forum for requesting Firefox changes or enhancements, or providing feedback on its features. Most Firefox developers will never even use or see this forum. Posting here does not help in a campaign for change or enhancement to firefox.

  • Feedback: From a current version try http://input.mozilla.org/en-US/feedback
  • You obviously are fully aware of bugs and bugzilla. The bugs you mention have extensive comments on this subject over several years, and include links to many related or duplicate bugs on the subject

This is starting to get repetitive & difficult to add anything constructive without straying outside of forum guidelines.


The forum has a fairly comprehensive associated Knowledge Base (KB) and whilst this is not really the place to discuss KB edits we could consider editing something to better cover advice available in this situation. Not much other help I can offer.