4 ms·
> Applying all of the changes at this list will harm users and increase the chances of threats compromising the browser. How so?
by jake_the_third 8y ago
> Applying all of the changes at this list will harm users and increase the chances of threats compromising the browser.
How so?
- floatingatoll 8y agobrowser.safebrowsing.phishing.enabled = false These instructions disable phishing lookups, rather than pointing users to a list of alternatives. This is unsafe and harmful to bury in this list. network.cookie.alwaysAcceptSessionCookies = false They will immediately lose the ability to login to their password manager, which requires session cookies. browser.cache.disk.enable = false browser.cache.memory.enable = false They will start loading every resource on a page on every visit to every page, as no resources will be cached. One hour of browsing will use a month's data quota and the glorious no-caching detail of every pageview will be closely observed by the server-side logging metrics that are so desperate these days to extract targetable marketing data. webgl.force-enabled = true Browsers disable WebGL in some scenarios to protect users from hardware, software, and/or driver bugs that cause crashes when WebGL is enabled. This setting overrides that which increases their risk of GPU, browser, and system crashes. Additionally all crashes are either "exploitable" or "not exploitable", so bypassing crash mitigation processes increases your risk of one such vector being used against your browser. network.dns.disableIPv6 = true Over the next ten years, the user will see that more and more of the web breaks down and mysteriously fails in their browser. Sites only load partially, videoconferencing never works properly, video streaming is jerky and slow. Providers shipped IPv6 to their customer endpoints years ago. Disabling it has potential downsides and no upsides either for "privacy settings" or anything else.
- moosingin3space 8y agoNot to mention the infamous `privacy.resistFingerprinting` option, which leads to a lot of random breakage and confused users. It's not ready for non-Tor Browser users yet, or else it would be default!
- guilhas 8y agoThis is HN. Advanced knowledge is not an issue. People making changes to user.js will have some knowledge of what they are doing, and handle the issues. The post points some security/privacy extensions to complement. Nothing that a user changing user.js wouldn't already know.
- floatingatoll 8y agoPresuming intimate knowledge of second- and third-order consequences from seemingly-innocuous preference changes is guaranteed to be a losing bet, even among tech enthusiasts and experts. I missed the high risk resist-fingerprinting setting and had no idea it would cause so many problems. Those problems certainly are not documented in the gist and I would have fallen prey to them if I had applied it unaware. Advanced knowledge is not the issue. Misrepresented knowledge is the issue. A document about “privacy settings” contains non-privacy settings and does not contain any mention of the lasting harmful side effects due anyone who uses any of the settings within it. EDIT: This is how to approach changing one of these settings with the respect and care due to such a suggestion: https://news.ycombinator.com/item?id=17944991 https://news.ycombinator.com/item?id=17944991
- guilhas 8y agoSo that's you, but don't say that they should not share their knowledge because it does not follow your standards. I'm more than happy to see someone experience on this, what what worked for them, compare with mine. Better have something than nothing, not everyone have time to write a blog post every time they change one setting. You change it. Have issues. Realize it does not work for you. Change it back. If you're not sure or don't have time to deal with it, don't do it. Not difficult is it? Ans a said previously the responsibility is in the person making the change to their browser, no one is forcing them. This is my preferred approach: https://github.com/ghacksuserjs/ghacks-user.js https://github.com/ghacksuserjs/ghacks-user.js https://github.com/pyllyukko/user.js https://github.com/pyllyukko/user.js
- floatingatoll 8y ago