13 ms·
Firefox Privacy How-To Guide
- AdmiralAsshat 7y agoAnd Firefox refuses to load the page because of a cert error. Oh, the irony!
- danShumway 7y agoWorks for me on the most recent version of Firefox. Might be a clock issue? Regardless, Outline link for anyone who can't read: https://outline.com/T3fGAk https://outline.com/T3fGAk If Outline doesn't load, try enabling referrer headers. I always forget to do that and get annoyed when Outline links break. I should probably just switch to a different service at some point, since I refuse to leave referrer headers enabled permanently.
- tialaramex 7y agoThat's quite a clock issue given the cert is valid from May 2018 to May 2020, so the entire year is wrong on their system.
- taco_emoji 7y agoSame here except in Chrome - error is NET::ERR_CERT_AUTHORITY_INVALID and issuer is "Cisco Umbrella Secondary SubCA chi-SG". Windows is saying "the issuer of this certificate cannot be found".
- tialaramex 7y agoYou (or your employer) have Cisco Umbrella, which is MITMing your network connection. You can read about Cisco's Umbrella product by Googling for it. You should comply with your employer's rules about non-work browsing. You could try asking IT support to "fix" the problem if you want, although if what you're doing is against policy they probably won't. Or - very much less likely - a bad guy is attempting to MITM you and they've decided to imitate Cisco Umbrella so that people aren't interested in helping you because they assume you're just at work goofing off on someone else's network.
- taco_emoji 7y agoGood info - yes my employer MITM's certs, but this is the only site I've run into with this. If I visit a site which violates policy, there's an error page that specifies which policy has been violated, it's not an obtuse cert error.
- flywithdolp 7y agoSomeone can explain what's the reason to disable telemetry? Telemetry data is anonymized and important for Firefox development. What and how is transferred is documented well. If certain measures are suggested, there should be given a reasoning.
- gnode 7y agoWhile nice for supporting the development of Firefox, it adds nothing to your subjective browsing experience. As far as I understand, disabling it is also not a data point by which you could be fingerprinted. You're taking it for granted that the reported data is adequately anonymized to the point of being impossible to make any inferences about individuals, which is a huge leap, not only in trust, but data science. As mentioned later in the article, Mozilla is based in a country with sweeping surveillance legislation, and so should not be trusted to hold or process [potentially] personally identifying data, no matter how well intentioned they themselves may be.
- vinylkey 7y ago> You're taking it on trust that it's anonymized to the point of being impossible to make any inferences about individuals, which is a huge leap, not only in trust, but data science. I don't doubt that someone at Mozilla could de-anonymize that data, but I have enough trust in the organization that they won't
- zAy0LfpBZLC8mAC 7y agoSo, you trust that the key people at Mozilla will go to jail rather than de-anonymize your data?
- tialaramex 7y agoHave a look through about:telemetry and let us know what you think the US government thinks is so valuable they would threaten powerful people with jail time to find out. Whether my CPU has MMX? Maybe times so far in this session there was auto-starting audio playback which you allowed even though Firefox defaults to never allowing this? I can /maybe/ if I squint really hard, imagine some murder detective figuring out a way that a value in their suspect's telemetry data helps prove they did it. Only thing is, the murder cop can just ask a judge to let them go take the suspect's whole PC, no need to bother any Mozilla employees with crazy requests.
- danShumway 7y agoThis is pretty good -- there are a number of config options here that I didn't realize existed. My only real quibble is that I don't think people should turn on DNT if they can help it. Most sites don't respect it, and for some sites it's actually another tracking vector on its own. I believe if you turn on fingerprinting protection in Firefox it gets automatically enabled, so this isn't a suggestion anyone can practically act on. But if I had the choice to disable DNT, I would. I think we should deprecate any tracking protection that relies on good actors respecting our choices. But overall, good article.
- user9361 7y ago> DNT Leaving it as default makes you hide in the crowd
- danShumway 7y agoI'm pretty sure that DNT is off by default in Firefox. That's what I mean when I say that turning it on can be an additional tracking data point.
- Santosh83 7y agoEven if you have tracking protection enabled you can still turn DNT off by toggling "privacy.donottrackheader.enabled" in about:config.
- Grollicus 7y agowere DNT anywhere near widely accepted it would probably be possible to enforce it via GDPR. (That is, report the pants off websites that show GDPR popups as you've already told them you don't want that)
- LinuxBender 7y agoAre there any privacy laws the mention DNT yet?
- fzzzy 7y agoIronically, making changes like this makes you far, far more fingerprintable, as the vast majority of users don't make changes like this. Thus, the users that do stick out like a sore thumb. The article does mention this.
- user9361 7y agoThat's true. I use as many default options I can. But there are good points in the article
- danShumway 7y agoA lot of Firefox's fingerprinting protection is genuinely helpful because the stuff it's blocking can be used to very, very precisely target you. Canvas/WebGL fingerprinting is a good example of this. Yes, very few people block it, but the fingerprinting for canvas is so individualized to each device that there is no hiding in the crowd if you leave it enabled. You're hiding in a crowd of size 1. Think of it like wearing gloves during the summer. Yes, that's unusual. But a human fingerprint (except in rare-ish cases) will usually be good enough to track an individual person. In a world where people are regularly collecting fingerprints or tracking them around town to figure out who's been in what stores, being unusual is preferable to being unique. There are a few settings (normalizing screen sizes) where the benefits aren't so clear-cut. But at the very, very least, you should be doing stuff like turning off webRTC/webGL/canvas. The majority of changes being listed here are strict improvements to privacy.
- rwmurrayVT 7y agoI have only just taken an interest in the canvas fingerprinting. My understanding is that it relies on a unique hash of an "image" created using HTML5, including the time it takes to draw. Is it not possible to alter this hash by throttling or slightly modifying some GPU settings? I know this is a weird and most likely highly technical question. I'm just curious.
- danShumway 7y agoShort answer, I don't know, but probably not? Long answer, I'm also curious about this. I feel like the future of fingerprinting resistance isn't refusing to give up information (since sites can block you or force you to turn the settings back on) -- it's lying. Don't block microphone access, just feed it white noise. Don't block the location, just spoof it. BUT, a bunch of people who are smarter than me have decided that zeroing out the canvas is better than making it return random values, so for the moment, I assume there's something they know that I don't.
- nominated1 7y agoMany of these sites suggest making edits via “about:config”. The problem is it’s difficult to keep track of which settings you’ve altered. I highly recommend you use a user.js [1] file. The best part is you can make notes so later you knows why a setting was enabled or disabled. The only downside is if you decide to undo a setting in user.js you’ll also have to make the same change in about:config. [1] http://kb.mozillazine.org/User.js_file http://kb.mozillazine.org/User.js_file
- leeoniya 7y agostart with https://github.com/pyllyukko/user.js/ https://github.com/pyllyukko/user.js/
- ilikenwf 7y agoI counter with https://github.com/ghacksuserjs/ghacks-user.js https://github.com/ghacksuserjs/ghacks-user.js
- george_perez 7y agoModified about:config settings appear in bold, though. It's good for a quick glance, but yeah not much after that.
- mackrevinack 7y agoand I remember one time being able to reorder the list so it shows all the modified items at the top
- floatingatoll 7y agoSigh, yet another “privacy” guide that has you enable options like DNT that make you easier to fingerprint. And it suggests you disable HTML5 EME, which has nothing to do with privacy at all. Whatever your views on DRM, that’s not a privacy concern. This is yet another “opinionated guide to Firefox” that misleadingly uses privacy to convince people to read it. Do not harm your friends and family’s experience by making the changes suggested in this guide.
- JoshMnem 7y agoIt looks like DNT is turned on automatically if tracking protection is on, so it probably doesn't identify you any more than "a Firefox browser with tracking protection on".
- gruez 7y agoI just tested. With standard settings for "Content Blocking" (under "Privacy and Security") and "Only when Firefox is set to block known trackers" selected, Firefox does not send the DNT header in regular windows. It only sends it in private windows. Therefore if you don't want to stand out, you should not enable DNT.
- floatingatoll 7y agoIndeed. If you don’t want to stand out, you should use the defaults. Anything non-default will stick out as a 1%-or-less marker. Three or more non-default might well uniquely fingerprint you.
- kbenson 7y agoBy that reasoning, what would be best would be to identify a few items of information exposed that are commonly used for tracking but that have little or no effect on browsing, and randomly alternate them between the default value and 1 or more other (or random) values. If the data can't be relied on to contain any specific useful information (even whether it's default or not), then it's effectively useless for tracking, and you've not just hidden yourself in the largest category for those bits of tracking data, you've effectively made them entirely useless for tracking you (which is more effective than hiding in the biggest group).
- romkin 7y agothis article doesn't address the main issue with firefox and privacy: it sends your very complete fingerprint to google on its very first launch, before you get the chance to change any privacy settings. from that moment on, unless you have JS disabled, google will know your every move one way or another. all their talk about privacy is hot air as long as that is true.
- Uhuhreally 7y ago"it sends your very complete fingerprint to google on its very first launch" sorry could you explain in more detail please ?
- romkin 7y agoyou install firefox and launch it for the first time. immediately, a page with google analytics opens up and google gets to fingerprint your browser and hardware before you've had a chance to implement any privacy measures. I find it rather unlikely that mozilla needs GA on that page, considering that firefox is sending tons of telemetry to their own servers.
- kbrosnan 7y agoGA was removed from the first run page https://github.com/mozilla/bedrock/pull/7621 https://github.com/mozilla/bedrock/pull/7621
- superkuh 7y agoStep 1. Stop using browsers that don't respect user freedoms. There are plenty of good firefox forks out there.
- paulcarroty 7y agoThis howto isn't helpful on first run when Firefox sends tons of telemetry to Google: https://twitter.com/jonathansampson/status/1165858896176660480 https://twitter.com/jonathansampson/status/11658588961766604...
- cookie_monsta 7y agoThere are so many hardware and OS level fingerprinting vectors that software tweaks like these are only marginally useful. Once you've done your tweaking, have a look at https://amiunique.org/ https://amiunique.org/ to see how anonymous you really are.
- 0-_-0 7y agoamiunique.org only checks whether your fingerprint is unique, but if some data that was used to create your fingerprint was random (as common with some anti-fingerprinting methods) then that doesn't mean you're identifiable.
- SCdF 7y agoHas anyone worked out if Do Not Track is actually worth it's weight? You're effectively flipping another bit that de-anonymises your browser a little bit more, and I can't why a bad actor (the people you're actually worried about) would honour it.
- oil25 7y agoEnabling DNT is worth it, but not for the reason which seems obvious. The DNT header was created so Internet advertisers could point and say, "only 0.1% of users have enabled DNT - this is evidence that people don't care about or even WANT to be tracked" in the face of scrutiny by regulators. It's a single extra bit of information about your request; I wouldn't worry about "de-anonymization" resulting from enabling it, but would suggest enabling it as a token gesture anyway.
- programmertote 7y agoMaybe a bit tangential, but I have been having a difficult time using Google Sheets lately in Firefox (like starting about 2-3 months ago). I keep track of my expenses (like groceries) in Google Sheets and always use Firefox to do data entry. Nowadays, Firefox browser freezes for a minute or two when I load/modify cells in Google Sheets. I only have one extension, 'muBlockOrigin', installed in Firefox and have been using that for many years, so I'm sure the extension is not getting in the way of loading Google Sheets. So that leads me to believe that Google is probably supporting less and less of Firefox.
- mackrevinack 7y agoquickest fix if the top of my head would be to stop using google sheets :D if you only need basic functionality then libreoffice would be a good place to start since it's cross platform and if youre running Windows then there's a portable version that you can bring around on a usb. I use syncthing myself to sync my documents between all my devices. but there lots of other options around like resilio sync, nextcloud etc there's not really much of a reason to be tied to Google anymore
- degenerate 7y agoGoogle products (Sheets/Analytics/Gmail) simply run slower on FF these days. It's clear that Google optimizes their products to run well on Chrome, and doesn't bother benching performance on FF. I have a chromium portable laying around for the sole purpose of logging into google products that I need to access for work, and access everything else in FF. I don't think Google is maliciously making FF slower on their products, but I believe they simply don't care to tweak/tune performance on FF like they would have years ago. As everything else google does, the devs metaphorically cover their ears and proclaim "lalalalalala we are google we don't care!" ...and it's more telling every passing year.
- floatingatoll 7y agoCreate a fresh profile and install nothing into it and don’t change any defaults at all. If the problem still occurs, open a Webcompat issue about it. If the problem goes away, it’s either the addon or some sort of non-default config settings.
- ma2rten 7y agoabout:config shows a screen that says "This might void your warranty.". Is this supposed to be a joke? Which warranty is being voided here?
- floatingatoll 7y agoThere are settings in there that can^ lock you out of the browser UI and/or potentially destroy your profile data, if you are especially unlucky, potentially months or years after you made the change and since forgot that you did so. It’s usually possible to recover and it’s usually not so bad, but I imagine that’s why it’s a very scary warning. ^ webrender gfx all, for example, seems to break my Firefox Nightly every few months, which I duly report and see fixed the next day or so, but one time it took a couple weeks for them to find the crash!
- rahuldottech 7y agoYeah it's a joke. These settings might break a few websites, although I don't recall that ever happening to me. And any websites these settings break shouldn't be websites you're visiting anyway.
- cyphar 7y ago> dom.event.clipboardevents.enabled = false This breaks copy-paste for quite a few rich text editors (it was the reason why pasting into Riot didn't work for me for several months). So, some of these options can subtly break harmless websites.
- ilikenwf 7y agoThis is an ok guide for people who don't know what to do, however I'd argue using ghacks userjs, and also disabling the built in content blocking and safebrowsing entirely is in order, along with disabling captive portal detection, and dns over https. These all call back to google and/or mozilla, cloudflare. https://github.com/ghacksuserjs/ghacks-user.js https://github.com/ghacksuserjs/ghacks-user.js
- PeterisP 7y agoA word of caution, some of these settings break stuff. I don't remember the exact items anymore, but seemingly innocous privacy-related changes I did some time ago from a list very much like this broke the ability to paste to google docs (which was a bit confusing, since I noticed it weeks later when it "just" didn't work with no messages hinting why) and the integration for the Evernote WebClipper plugin; and it was a bit of a hassle to find which changes I need to revert.
- johnp_ 7y agoLikely `dom.event.clipboardevents.enabled`: https://developer.mozilla.org/en-US/docs/Mozilla/Preferences/Preference_reference/dom.event.clipboardevents.enabled https://developer.mozilla.org/en-US/docs/Mozilla/Preferences... If someone else is in the habit of randomly selecting text and they're using linux, they may want to disable at least `clipboard.autocopy` if they don't use it. No reason to simply tell websites every selection you do, IMHO.
- romaniitedomum 7y agoIronically, uBlock flags this site leaking tracking cookies to two third-party sites, getclicky.com and presidium.com. Who watches the watcher, eh? But there's no denying that site is a good handy guide to things in Firefox that can be tweaked to suit one's privacy stance.
- yCloser 7y agoprivacy.resistFingerprinting = true breaks whatsapp web login page, interesting
- bvinc 7y agoCaution: I kept having problems in websites where timestamps were hours off, and every captcha was super annoying. It took me a while to figure out it was due to the fingerprint protection that I had enabled.