4 ms·
I use HTTPS Everywhere, uBlock Origin, Random Agent Spoofer with almost everything checked, Self Destructing Cookies and uMatrix. I do not recommend Ghostery a
by emanuelmaues 11y ago
I use HTTPS Everywhere, uBlock Origin, Random Agent Spoofer with almost everything checked, Self Destructing Cookies and uMatrix.
I do not recommend Ghostery at all, since it is closed source and it collects your data through GhostRank, if enabled.
- nextos 11y agoI think this is a good setup. Not leaking metadata is uber uber important [1]. I feel that by revealing my weird setup e.g., mutt as a mail client I'm really easy to track. Getting fingerprinted via font browser metrics is also a major worry of mine [2]. Especially if running an exotic setup, it's easy to stand out. [1] http://www.nybooks.com/blogs/nyrblog/2014/may/10/we-kill-people-based-metadata/ http://www.nybooks.com/blogs/nyrblog/2014/may/10/we-kill-peo... [2] http://www.guanotronic.com/~serge/papers/fc15-fonts.pdf http://www.guanotronic.com/~serge/papers/fc15-fonts.pdf
- ronjouch 11y agoI think too this is a good setup. Self-Destructing Cookies, especially, is rarely mentioned in such discussions, but is a godsend to enable cookies for the convenience of staying logged only in domains you trust (e.g. I have: archlinux.org, feedly.com, mozilla.org, stackoverflow.com, ycombinator.com) but not breaking sites that depend on them (e.g. no gmail if you simply disable them). Also, if you use Firefox, enabling `privacy.trackingprotection.enabled` in about:config is a good no-addon-required first step [1]. [1] https://wiki.mozilla.org/Polaris#Tracking_protection https://wiki.mozilla.org/Polaris#Tracking_protection
- nextos 11y agoYes, but what's the overlap with uBlock Origin of privacy.trackingprotection? It's very unclear to me. After some experiments and log inspections when it was released I concluded uBlock was a superset. Maybe I'm wrong though.
- ronjouch 11y agoAsked myself the same question, did the same experiment, and reached the same conclusion :) . Another unclear thing is the update rate/policy of privacy.trackingprotection's blacklist.
- nextos 11y agoGood to hear :) What's your addon setup then?
- ronjouch 11y agoMostly the same as emanuelmaues above, just a bit lighter: uBlock Origin, Self-Destructing Cookies. Differences: - No HTTPS Everywhere because I (think I) remember to check for HTTPS when it matters, and access those sensitive sites via bookmarks, where I ensure HTTPS is used. - No uMatrix because it's too much of a hassle, I'm okay with the 90% provided by uBlock Origin. - A common custom user agent via (firefox / about:config) `general.useragent.override` rather than Random Agent Spoofer, which pops UAs sometimes so obscure that Google freaks out and serves me a no-js version. I'd use it if it provided a choice like "Random among the last five <Firefox> versions on <any os>", currently to do this I'd have to manually exclude tons of browsers. (Off-topic) out of the privacy stuff and back into regular addons land, - dotjs to spruce up custom js in a few sites. When GitHub Enterprise say "maybe, someday" to your feature request, that means "do it yourself" ^^. - (Not an addon, but worth mentioning) userContent.css to manually uncruft/simplify sites I frequently visit. I prefer this to Stylish, it's all in a single .css file in my profile folder; simple to edit and sync across work/home. - FlashDisable to pretend I do not have flash (to ensure html5 vid is served in priority, many non-top tier video hosts still serve Flash by default) but be able to activate it quickly when needed (flash game, video with no html5 alternative). - HighlightAll because I'm so used to this feature from all text editors that I take it for granted even in a browser. - VimFx to keep my hands on the home row as much as possible. And you, anything crispy to share?
- nextos 11y ago
- skuhn 11y agoSpoofing user agents will sort of defeat UA-based tracking, but so will using the stock UA for the most common version of your browser. I think it would make more sense to find the most common Firefox UA and switch to that. Probably something like this: "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:39.0) Gecko/20100101 Firefox/39.0". The advantage here is that you aren't likely to run across weird behavior from sites that sniff UA to determine feature set. That's clearly gross behavior, but it's also necessary. For instance, there's no way to determine if a browser supports JPEG2000 other than to sniff the UA for Safari -- it doesn't send an appropriate Accept header. Likewise for many other situations.