66 ms·
The Mullvad Browser
- hotpathdev 4y agoAs I suspected, this browser, just like the Tor browser, does NOT protect you from basic browser leaks. There are gaping issues and after looking at the github issues, the maintainers are certain that their current strategy is effective. This makes me continue to question this project and Mullvad.
- sodality2 4y agoWould you mind providing any links for what you’re saying?
- hotpathdev 4y ago[1] WebGL finger print is device specific and persistent. [2] Font finger print is device specific and persistent. [3] TLS finger print is device specific and persistent. [4] DNS is routed into USA by default. Incidentally, there are frequent dropped requests using this browser [5]. These are just a few that I spotted. Let's proceed with the discussion as though the above issues were not present. After looking at the issue tracker, this project wants each Mullvad Browser user to look the same, per OS [6]. Blending into a crowd on the surface seems like a good idea, assuming the crowd was large enough, but that "per OS" detail is a big gotcha. I personally don't see why a source-modified browser shouldn't be able to achieve perfect uniformity. It's especially suspicious to me that the Tor project never achieved it, despite having had multiple years of developer effort dedicated to this goal, and backed by funding. IMO, browsers should never have been flooded with so many uncontrolled privacy breaking features in the first place. Modification of the browser is discouraged for any reason, including enhancing privacy features [6]. Now read that again, and this time assume hostile intent. I mentioned in a different comment that the alternative to uniform blending is randomness. Some of the fingerprints in the browser are already randomized. Plausible randomness is far superior to trying to build up a large enough crowd and simultaneously solving the uniformity issues. The entire javascript engine should be ripped apart and reassembled so that all privacy invading features can only function for client-side specific tasks but cannot speak with the networking and storage features. [1] https://browserleaks.com/webgl https://browserleaks.com/webgl [2] https://browserleaks.com/fonts https://browserleaks.com/fonts [3] https://browserleaks.com/ssl https://browserleaks.com/ssl [4] DNS Leak test: https://browserleaks.com/ip https://browserleaks.com/ip [5] https://github.com/mullvad/mullvad-browser/issues/23 https://github.com/mullvad/mullvad-browser/issues/23 [6] https://github.com/mullvad/mullvad-browser/issues/1 https://github.com/mullvad/mullvad-browser/issues/1
- genjii931 4y agoNo Android version is a real bummer.
- archon810 4y agoInstalled it on Windows and just get this error on start: "Profile Missing Your Mullvad Browser profile cannot bе loaded. It mау bе missing оr inaccessible." https://i.imgur.com/HV3YRw5.png https://i.imgur.com/HV3YRw5.png There is also no trace of Mullvad in the installed programs list, so I can't uninstall it properly. Not a good experience to say the least.
- dijit 4y agoSeems like it's hug of death'd. https://web.archive.org/web/20230403101515/https://mullvad.net/en/browser https://web.archive.org/web/20230403101515/https://mullvad.n...
- politelemon 4y agoWorking fine here in UK.
- archb 4y agoIs okay to me as well in California, USA.
- doodlesdev 4y agohttps://archive.ph/NTerI https://archive.ph/NTerI
- ugurnot 4y agoI hope there will be a mobile version too at some point.
- archb 4y agoI'd especially be interested in seeing how they implement on iOS, with Apple considering opening up options beyond WebKit: https://hn.algolia.com/?dateRange=pastYear&page=0&prefix=false&query=apple%20webkit&sort=byPopularity&type=story https://hn.algolia.com/?dateRange=pastYear&page=0&prefix=fal...
- esskay 4y agoBoth Chrome and Firefox are working on native iOS versions in preperation for the expected opening up of iOS this year so would imagine they can just fork that and release their version.
- UncleSlacky 4y agoI'm not sure if it's the same org behind it, but there is a Mull browser available on F-Droid: https://f-droid.org/en/packages/us.spotco.fennec_dos/ https://f-droid.org/en/packages/us.spotco.fennec_dos/
- doodlesdev 4y agoIt's not. Mull browser is a Fennec fork [0] maintained by DivestOS [1] (Android ROM). [0]: https://gitlab.com/divested-mobile/mull-fenix https://gitlab.com/divested-mobile/mull-fenix [1]: https://gitlab.com/divested-mobile https://gitlab.com/divested-mobile
- hotpathdev 4y agoThe last time I tried the Tor browser, it did not sufficiently handle browser finger prints. I don't have high expectations out of this project either, but at least they offer a firefox extension. I'd have to dig into it to determine how effective it is, but as it stands there are other firefox extensions that already do an excellent job.
- Eisenstein 4y ago> The last time I tried the Tor browser, it did not sufficiently handle browser finger prints. Can you expound on this?
- hotpathdev 4y agoSimply download the Tor browser and evaluate its performance on one of the many browser fingerprint [1][2] and browser leak [3][4] web services. The last time I checked, it didn't pass every test. [1] https://www.amiunique.org/fp https://www.amiunique.org/fp [2] https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/ [3] https://browserleaks.com/ https://browserleaks.com/ [4] https://www.dnsleaktest.com/ https://www.dnsleaktest.com/
- Eisenstein 4y agoIsn't passing every test going to make the browser uniquely unique? My impression is that they want it to be 'fingerprinted' but look like 1,000,000 other Tor browsers so they can't be told apart.
- hotpathdev 4y agoYes either you want everyone to look the same, or you want every page request to be totally random.
- fiso64 4y agoIndeed, my fingerprint in https://www.amiunique.org/fp https://www.amiunique.org/fp appears to be unique when using the Mullvad browser.
- Player6225 4y ago"The Mullvad Browser is a privacy-focused web browser developed in a collaboration between Mullvad VPN and the Tor Project. It’s designed to minimize tracking and fingerprinting. You could say it’s a Tor Browser to use without the Tor Network." https://github.com/mullvad/mullvad-browser https://github.com/mullvad/mullvad-browser So basically like... hardened Firefox?
- Player6225 4y agoHmm looking the settings I saw a search engine I didn't recognize... I guess they also have a google proxy? https://leta.mullvad.net https://leta.mullvad.net So I guess now you can go full Mullvad.
- archb 4y agoThis is super interesting. From Leta FAQ[0]: Did you make your own search engine from scratch? We did not, we made a front end to the Google Search API. Our search engine performs the searches on behalf of our users. This means that rather than using Google Search directly, our Leta server makes the requests. Searching by proxy in other words. [0]: https://leta.mullvad.net/faq https://leta.mullvad.net/faq
- medstrom 4y agoA hardened Firefox config exists: https://github.com/arkenfox/user.js https://github.com/arkenfox/user.js But it needs tech skill to adopt, so even if this Mullvad Browser is basically just prepackaged Arkenfox, that's great to drive adoption.
- thunderbong 4y agoI couldn't quite se it in the article - Is it based on Chromium or Firefox? If it's Firefox, that'll be a great win! Edit: Use Player6225 mentions it could be a hardened Firefox because it's based on the Tor browser
- archb 4y agoIt's based on Firefox, and I am able to install Firefox extensions. With 1Password on it now, I think I am going to try this browser for a while.
- A_No_Name_Mouse 4y agoThe question not answered: won't I stick out like a sore thumb if only 1 in 10000 people uses this browser?
- esskay 4y agoStick out to who? Just set the useragent to a default firefox one (assuming its not already set) and you're golden.
- archb 4y agoI decided to test it out on a website[0] and it does seem that the useragent goes by the Firefox name: Mozilla/5.0 (Windows NT 10.0; rv:102.0) Gecko/20100101 Firefox/102.0 On my Firefox: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/110.0 It's interesting to note that the Mullvad browser seems to be based off on Firefox 102.0, which came way back on June 28, 2022: https://www.mozilla.org/en-US/firefox/102.0/releasenotes/ https://www.mozilla.org/en-US/firefox/102.0/releasenotes/ [0]: https://gs.statcounter.com/detect https://gs.statcounter.com/detect
- daveoc64 4y agoFirefox 102 is current Extended Support Release (ESR): https://www.mozilla.org/en-US/firefox/102.9.0/releasenotes/ https://www.mozilla.org/en-US/firefox/102.9.0/releasenotes/
- deleted 4y ago[deleted]
- xeeeeeeeeeeenu 4y agoYou can see in the "About" window that it's based on Firefox 102.9, which is the latest ESR version. It masks the minor version in the UA string.
- doodlesdev 4y agoThat's because it's a fork of the Tor browser, meaning it's based on Firefox ESR, which is currently on version 102.
- controversial97 4y agoSo ... it is a fork of Mozilla Firefox with privacy-friendly settings by default, some script blocking, and dns lookups done via Mullvads encrypted dns service Sounds ok to me, I have a longish and probably out of date list of settings that I like to chance in a new instance of firefox. I trust mullvad to not log dns more than I trust my ISP and I live in the UK so unencrypted dns here is being logged and stored by order of the government. Keeping a fork of firefox in sync with mainline firefox to get security fixes is a load of work, it is good that somebody is doing it, in this case I think the tor project is doing a lot of the work.
- tomxor 4y ago> I have a longish and probably out of date list of settings that I like to chance in a new instance of firefox Not a user but part of the purpose of the TOR fork is settings, anything that is detectable via JS is supposed to remain default to prevent fingerprinting. It's partly why it's not widely popular, I don't know if this is still true but it used to be that it was supposed to be run at a specific viewport resolution regardless of your device. All in the name of making your fingerprint as close to the same as all other TOR browser users.
- encryptluks2 4y ago[dead]
- dathinab 4y ago> run at a specific viewport resolution regardless of your device. It's more like pretending to the website that your screen has a "common" resolution etc. which is nearly but not quite the same as what you said. In the past they semi required you to keep your tor window in a specific window size for this, which just didn't work well in practice. By now they better integrated that in the browser from what I heard, so you can resize it however you want but websites might have an "empty" border are to the left/right/bottom depending on you screen resolution, windows size etc. from what I have heard. With a typical maximized window on 1080p you won't really notice it, on 4k you might notice that it's just "dump" up scaled from 1080p, but the person I spoke with wasn't sure if maybe they have a set of supported common resolutions instead of just one. And on a 4:3 screen he said it's quite noticeable.
- zamnos 4y agoHm that seems like a mistake. If I'm reading the docs right, the Mullvad browser will let you browse the web without using their/any VPN, which mean that it's entirely possible to accidentally surf to a site without having your VPN up, and reveal your IP address to that site. To contrast, there's no way to use the Tor Browser without using the onion network so it's ~impossible to accidentally browse to site and reveal your IP address, and not just the IP address of the exit node. OpSec is hard, and tools letting you shoot yourself in the foot doesn't help. There are plenty of other browsers out there that don't offer VPN integration, so (imo) they should have made the browser a paid feature for customers, instead of giving it away for free like the market has demanded since IE6.
- udev4096 4y agoI think the reason that they have made it free is to combat fingerprinting more efficiently. It would be easy to fingerprint if they have a very limited amount of users
- warner25 4y agoThat makes sense except for the fact that servers can still identify the smaller set of actual Mullvad VPN users by their IP address(es).
- MikusR 4y agoThey advertise their VPN as having a working Split tunnel feature. That is also false, at least on Windows.
- paulryanrogers 4y agoCitation?
- MikusR 4y agoMe. It leaks.
- DrBazza 4y agoCan anyone explain how this won't, putting it diplomatically, attract certain 'dark web' types, and in turn bring mullvad under the microscope of law enforcement?
- hotpathdev 4y agoThis isn't useful to 'dark web' types. This is at best useful for 'mom and pop' who heard about 'china tiktok' on the news.
- traveler01 4y agoIf you do something useful it will probably attract criminals, nothing we can do about it.
- KoftaBob 4y agoCouldn't you say that about any VPN? Why would Mullvad's browser be unique in this regard?
- sneak 4y agoYou can't browse the dark web with this browser.
- jraph 4y agoI guess why not. This is an open source, rebranded Firefox and Firefox-like browsers could use some publicity. It promotes privacy and privacy can use some publicity too. Tor too. Mullvad seems to be honest in the fact that their business model is selling VPNs and it's nice they are saying it's not enough. They are not saying that you might not need one though. We need a Firefox with good defaults and it seems like this browser is such a thing. I'd prefer these privacy features to be in upstream Firefox but I guess world is not perfect and that Firefox still relies on revenues from Google so can't be as privacy-focused as it should. My little concern I guess is that this browser will push for their service so it's a bit like an ad for them, at least with its name. But fair enough, and at least the business model seems healthy. With Mullvad already being a Mozilla partner for their branded VPN, all this actually look good. They seem to be spending their money on worthy stuff.
- thejosh 4y agoI quite like Mullvad. I haven't needed to use them much (mostly when my ISP has wonky routing and I need something semi-urgent), but their service is pretty good, their website feels like it's designed for the more "techy users". Their billing is the least sketchiest of VPN providers, with no ticking clocks, no upsell and other nonsense. I also like they provide a Wireguard file and a way to filter it, so it's super easy to get started.
- enlyth 4y agoI share a VPN subscription with my father, I use it for torrenting so my ISP can't snoop on me, and he uses it to bypass geo blocking to watch UK shows (things like BritBox, Netflix, BBC etc.) in another country. Unfortunately, there is no way to legally pay for most of these services and watch them from abroad. I tried to get us to use Mullvad, as it was perfect for me, but for him it was constant problems with the services he used, whereas the sketchier providers like NordVPN and ExpressVPN always worked without issues.
- highhedgehog 4y agodoes it work to bypass geoblocking of Netflix? i cannot access the us catalog from Italy for instance
- Eisenstein 4y ago> Dns Over HTTPS (DoH) > Mullvad Browser is configured to use Mullvad DoH for all DNS requests, without fallback. In the settings, you can also configure it to use Mullvad Adblocking DoH. about:config DOH entries screenshot here: * https://imgur.com/a/evd9OzN https://imgur.com/a/evd9OzN Can anyone knowledgeable comment on the security implications of this?
- nextaccountic 4y agoIf you trust Mullvad to see all your traffic (including every IP you connect to), it seems okay to trust them to see your DNS queries (that will return the very same IPs you will later connect to)
- Eisenstein 4y agoI don't though. I don't use Mullvad VPN.
- nextaccountic 4y agoOkay so probably this browser isn't for you
- mackie_roy 4y agoYou can actually disable DoH by going to: Settings > General > Network Settings > Settings Then either untick "Enable DNS over HTTPS" or add a custom DoH.
- lofaszvanitt 4y agoWhy not sprinkle it with something like grsec? Now that would be a secure browser and would really upset a lot of shady people.
- sampa 4y agoclearly, you don't know what grsec is
- lofaszvanitt 4y ago[flagged]
- sneak 4y agogrsec are patches for the kernel. The main exploit risk to a modern browser is javascript JIT.
- lofaszvanitt 4y agoAnd? Is it considered secure or the threshold just pushed higher so the exploitation is not for everyone?
- udev4096 4y agogrsec isn't free anymore
- lofaszvanitt 4y agoWindriver, hm?
- detrites 4y agoFrom the FAQ [0]: > Why is the time is wrong? > The timezone is spoofed, to combat fingerprinting. > What's this weird spacing around the websites? > It’s called letterboxing, a function to combat fingerprinting (using your browser window size to identify you together with other measures). > How do I stay logged into specific websites between sessions? > It’s not possible. It’s an action to combat tracking. Not sure if there are other measures, other than that the browser itself doesn't track anything. Looking much better than a stock firefox, and presumably will improve over time. [0] - https://mullvad.net/en/help/tag/mullvad-browser/ https://mullvad.net/en/help/tag/mullvad-browser/
- ta1243 4y agoExcept most of the time I don't want to spoof my timezone, don't want weird spacing around websites, and do want to remain logged in to websites. > How do I stay logged into specific websites between sessions? > It’s not possible. It’s an action to combat tracking. Turns me off immediately
- archb 4y agoI thought it'd be possible by simply turning off "Always use private browsing mode" setting, but it doesn't seem to work. Sessions are still cleared upon browser exit. In my case, I had to turn off that setting because without it, 1Password wouldn't work.
- encryptluks2 4y ago[dead]
- detrites 4y agoWell, some of us don't want to be tracked, don't want to be tracked and don't want to be tracked. Given your stated preferences, are you actually looking for a privacy-focused browser?
- ramraj07 4y agoSome people just want everything, no compromises.
- mcsniff 4y agoHere's to hoping they maintain this for a while. There are a lot of "hardened Firefox" forks around, none of them that I would trust to follow upstream for a long enough time to switch. I already trust Mullvad enough to use as VPN, and am likely willing to extend that trust to a fork of Firefox they manage, but truthfully, I always concerned when achieving goals means new ventures and projects as it may mean resources are moving to other areas and may impact their code product. I like my core providers to do one thing and do it well. Edit: I hope they bring this to Android also!
- sacrosanct 4y ago> There are a lot of "hardened Firefox" forks around Sticking with LibreWolf for now, which has updates disabled in the policies section, but I frequently ping their Gitlab for new releases. It's annoying having to do that, but if it means I get security patches in time, I do it.
- brucethemoose2 4y agoFirefox runs like cold molassas on Android, unfortunately. Bromite seems like its sticking around, fortunately.
- handedness 4y ago> Bromite seems like its sticking around, fortunately. Only barely, unfortunately. I've since moved to Vanadium for anything untrusted and/or critical. It's still missing some features I'll enjoy seeing added, but it's improved considerably lately.
- _rdvw 4y agoBromite has not been updated since December 12th 2022 per my history here: https://divestos.org/misc/ch-dates.txt https://divestos.org/misc/ch-dates.txt
- brucethemoose2 4y agoOh dear, you are right. Last commit was in January. Thorium was comatose for awhile but come back, so I am keeping my fingers crossed.
- the_common_man 4y agoIsn't Firefox already reselling mulvad for their VPN?
- archb 4y agoThey are. Mullvad browser seems to be aimed at users that want a hardened Firefox out of the box with additional Mullvad extensions, while Firefox with Mullvad installed manually is all manual setup.
- ajdude 4y agoI welcome all new non-chromium based browsers.
- Proven 4y agoSignatures don't validate, I guess I'll pass for now. $ gpg --verify mullvad-browser-linux64-12.0.4_ALL.tar.xz.asc gpg: assuming signed data in 'mullvad-browser-linux64-12.0.4_ALL.tar.xz' gpg: Signature made Fri 31 Mar 2023 01:15:54 AM CST gpg: using RSA key E53D989A9E2D47BF gpg: Can't check signature: No public key
- josephcsible 4y agoDoesn't that just mean you forgot to import the signing key?
- archb 4y agoAs a DuckDuckGo fan as well, I'd have loved to see them/DuckDuckGo develop their browser on the top of Firefox with Mullvad as a partner with deep integrations.
- craigjennings 4y agoLooks like they're getting closer: https://duckduckgo.com/mac?ref=duckduckgo https://duckduckgo.com/mac?ref=duckduckgo
- shp0ngle 4y agoIsn't Tor using always out-of-date Firefox, for minimizing tracking on versions? Wouldn't this affect the security angle?
- abbe98 4y agoIt is based on Firefox ESR(Extended Support Release) which gets security fixes backported.
- ddtaylor 4y agoI like Mullvad but it can actually be challenging to purchase a subscription in the US. Most prepaid cards block the purchase. Sure, you can use it with a fully tracked card etc. but that's not really the target audience.
- dtx1 4y agobuy prepaid cards on amazon
- ramraj07 4y agoIsn’t this like the one legitimate use for Monero?
- s777 4y agoIt is, although then the next problem is getting Monero in the US with their clutterfuck of cryptocurrency regulations, so you have to find an exchange that works with Monero and actually works in the US, then give them your identity and bank account information and hope they don't think you're suspicious and block you.
- sputter_token 4y agoYou could acquire a different crypto on a US exchange such as BCH and then use a DeX which doesn't require any personal information to swap into Monero. You could buy a Mullvad giftcard on Amazon but then Amazon would know that someone at your address has a Mullvad subscription.
- drexlspivey 4y agoThey accept bitcoin and even offer a discount
- hairofadog 4y agoThey also accept cash.
- ilikehurdles 4y ago
- mugr 4y agoPlease add support for ARM.
- lysecret 4y agoHmm I am sure this is well intentioned, but I am a bit scared this will just further chip away on FireFoxes market share which doesn't look good to begin with.
- hardwaresofton 4y agoReally would have loved if this could have been a partnership with Mozilla...
- crop_rotation 4y agoI am disappointed to see that it doesn't integrate with Mullvad VPN at all. I have Mullvad VPN but I use it too less because I don't want all traffic on my mac going via VPN (e.g all kinds of random IDEs and websites). All I want is one browser which always uses VPN. But Mullvad has no split tunneling on mac AFAIK, and on windows also you can only block some apps from VPN, instead of saying that only this application will use VPN. This is one feature I really miss from PIA.
- anotherhue 4y agoIt bundles their extension which allows for socks5 connection, so you should be good.
- piaste 4y agoWhy don't you want random traffic to go through the VPN? Mullvad is quite fast.
- crop_rotation 4y agoIt's not about speed. There are many websites where your identity is linked in some fashion (e.g Your bank). I don't want my bank to block my account because I was in one continent in the morning and another in afternoon. The same goes for other critical accounts. I know I know, this is all unlikely, but why bother with it if it can cause a lot of headache. e.g. I know of people whose facebook accounts got blocked and were asked to provide some id since the accounts were opened from two different geographies. Basically sending all traffic via VPN seems a big headache to me.e.g. Using gmail from a VPN doesn't help me at all.
- dns_snek 4y agoFirefox allows you to assign proxies to individual containers. You could create a "Mullvad" container, set it to use Mullvad's SOCKS proxy and then configure a list of websites to always open in that container. That should allow for nice segregation on the level of individual tabs. They haven't documented this feature [1], but it's part of the official "Multi-Account Containers" extension. It can be found in MAC -> Manage Containers -> Select -> Advanced Proxy Settings at the bottom. [1] https://support.mozilla.org/en-US/kb/containers https://support.mozilla.org/en-US/kb/containers
- amsterdorn 4y agoIs this just Brave for FF minus the crypto?
- jxi 4y agoHow does this compare with Brave in terms of privacy?
- beaker52 4y agoI wonder how many VPN providers are going to turn out to be honeypots in the long run. Every time they make it easier, I get more suspicious about the privacy really being provided. Perhaps I’m just really distrustful and cynical.
- hotpathdev 4y agoBingo.
- dymk 4y agoMullvad has been around for quite a long time, and regularly releases third-party security audits. Is there anything they've done that comes off as a red flag to you? > Perhaps I’m just really distrustful and cynical. That's fine, but you should have a good reason for it
- hotpathdev 4y agoLong-term services are great targets for governments. If you were to looking for some trust in a VPN, you would want them to offer locations in privacy friendly countries, and highlighting them as such. That would potentially funnel more used to those servers which would be beneficial. You would also want the VPN to ensure the servers in those countries are run by companies based in that country, and not be head-quartered in some other country.
- lazyeye 4y agoNone of these things prevent tracking. In fact they are are an attractive intelligence asset precisely because people believe they are more secure. Crypto AG https://en.m.wikipedia.org/wiki/Crypto_AG https://en.m.wikipedia.org/wiki/Crypto_AG
- hotpathdev 4y agoI didn't say it prevents tracking, I was offering a litmus test for a VPN to the question of red flags. If it doesn't pass the litmus test, preventing tracking is the least of your concerns.
- ementally 4y agoIf a lot of non-Mullvad users use it, it will create a nice pool of people with at least the same browser fingerprint. Basically, it seems like a good choice if you are already a Mullvad user and your threat model does not require the use of a Tor browser. However, if there's a significant non-Mullvad user base using it, it won't do much, as you'll just stand out as the only person using the Mullvad browser without Mullvad VPN.
- AccountAccount1 4y agoThe browser fingerprint is so crazy... I don't understand how they don't regulate this shit.
- anigbrowl 4y agoThe people you are looking to to regulate it are the same people who would exploit it. I also think this approach of expecting the general public to adopt a borked browser to give deniability to people using it strategically is extremely naive. Human psychology just doesn't work like that, you might as well ask schools of fish to swim differently to hinder shark learning. To be frank, this seems like it will just create confusion vs telling people to use Tor browser. The way to improve privacy is to provide a tool that actively enhances something incredibly well, and does everything else at least as well. If all browsers are hopelessly compromised, make something that isn't based on HTML and builds cool user interfaces directly from API calls like a videogame UI, for example.
- AccountAccount1 4y agoCan you say more about the API calls, what would that be exposing of the user? I think it's difficult since most new apps are using Electron, or V8 scaffolds... but really nice idea
- 3np 4y ago> However, if there's a significant non-Mullvad user base using it, it won't do much, as you'll just stand out as the only person using the Mullvad browser without Mullvad VPN. That should be "unless there's a significant...."
- nigamanth 4y agoWhy do you think the Tor project team is releasing it together? Isn't Tor private enough? Or do they want higher privacy without onion browsing?
- rootsudo 4y agoIt wouldn't be higher privacy per se, it's just a fork of the firefox browser that perhaps could carry on TOR in case it ever shuts down or such.
- unsupp0rted 4y agoI'd love to get this on mobile. How does it compare to DDG's browser?
- kmfrk 4y agoI'd really like a VPN service to recommend streamers where they don't automatically show your location and IP if you happened to not be logged in for whatever reason. It's a UX that lands a lot of people in trouble when they visit the websites to check them out on stream. Ironically streamers with VPN sponsorships, too. Be nice if this stuff were hidden by default with some reveal button to show the information, both on the website and browser extension as an alternative to the other options out there. Otherwise I love recommending Mullvad to everyone.
- reisse 4y agoQuite sad Mullvad doesn't have the donations page. One of the rare projects I'd actually like to donate. Guess buying a few more VPN keys will count though...
- andai 4y agoCurious how usable it is for anything with CloudFlare. CloudFlare doesn't like browsers that block fingerprinting, and it doesn't like Tor Browser in my experience, and when I use Mullvad I also get way more CloudFlare Captchas, often getting stuck in an infinite loop. I'm focusing on CloudFlare because it seems half the sites I use are behind their firewall now. (e.g. I have to switch from Brave to Firefox every time I want to use ChatGPT...)
- s777 4y agoI use LibreWolf (hardened Firefox) with Mullvad VPN and in my experience have hardly had any issues with Cloudflare (occasionally I might get a single Cloudflare captcha but this doesn't happen often). Tor browser, on the other hand, gives me tons of captchas and is barely usable.
- andai 4y agoDear customers of Cloudflare: an appeal regarding Tor (2018) https://news.ycombinator.com/item?id=17750801 https://news.ycombinator.com/item?id=17750801
- zelphirkalt 4y agoShould this be concerning?
- zelphirkalt 4y agoCloudflare is bad for the web by now. There is way too much in their hands as well. I observe the same as you, infinite loops, that make me leave the sites where it happens. Probably many others experience the same, but the website owner will never know, because they put the blindfolds on. Unfortunately it is hard to suggest alternatives. But maybe HN has some ideas how to self host something effective to avoid having to use something like Cloudflare?
- minipark 4y agoChecking with https://www.amiunique.org/ https://www.amiunique.org/ resulted in a unique fingerprint for me. The "Canvas" and "Media devices" attributes are unique on their own. I had not expected this.
- notRobot 4y agoTry restarting your browser and see if the fingerprint changes. If it does, that means you can't be tracked across sites using this mechanism.
- triihart 4y ago"The account number is the only thing you need to connect to Mullvad VPN. We ask for no email, no phone number, no personal information whatsoever." yeah, also they get my bank card info, I become easily trackable if need arises
- silentsanctuary 4y agoFor this reason they do encourage you to anonymously pay with cash.
- stainablesteel 4y agothey don't save this information, they used to then ended up removing the process to do so 1-2 years ago
- asenna 4y agoThey launched the Mullvad cards being sold on Amazon[1], you can ask a friend in a different country to buy one for you. [1] https://www.amazon.com/Mullvad-VPN-Windows-Android-SCRATCH/dp/B092M55HJ2/ https://www.amazon.com/Mullvad-VPN-Windows-Android-SCRATCH/d...
- dns_snek 4y agoUsing your card is a choice, you can pay with Monero or send them cash in an envelope.
- aprilnya 4y agoyou can pay with cash or crypto
- the_duke 4y agoI use a custom Firefox config that tweaks and disables lots of features, based on this template: https://github.com/arkenfox/user.js https://github.com/arkenfox/user.js . Fun fact: this makes you extremely easy to identify, because it gives your browser a very unique fingerprint. If JS is enabled, that is, which you can disable by default, but JS is simply a requirement for many websites to function. I wonder how they approached this problem this for the Mullvad Browser.
- deleted 4y ago[deleted]
- fefe23 4y agoWhy should I put any faith in this VPN company if I don't even trust my own ISP?
- jonfw 4y agoMullvad's entire business is based around privacy, so they have a strong incentive to not collect your data. Your ISP does not have that incentive
- simon1573 4y agoIn Sweden (where Mullvad has its origin) IPSs are forced to keep data on its users, see Datalagringsdirektivet. It does not apply to VPN providers.
- altairprime 4y agoIf the third party security audits aren’t convincing, then you shouldn’t. That’s your choice to make.
- MrAlex94 4y agoInteresting! A few years ago I started a similar project, essentially a clearnet fork of Tor called Aegis. Problem was, it makes a lot of the modern web very broken. A very niche corner of the web browser market - but a lot of things like WebRTC and Widevine (unfortunately) are what most users would expect. I'd imagine there's the possibility there will be no H264 support either? Nice to see more Firefox related forks though, hopefully help gain more ground on the web for alternative engines.
- throwaway2056 4y agoFinally something that beats... https://fingerprint.com/demo/ https://fingerprint.com/demo/
- JustSomeNobody 4y agoI think I personally would find this more useful on my phone than on my desktop or laptop. I like Mullvad, they're my goto for VPN service when I'm out and about.
- sylware 4y agoI wonder if one day we'll get a group of devs with the balls to propose the world with a real disruptive web engine (instead of using vanguard/blackrock ones): for instance plain and simple C + assembly.
- vrglvrglvrgl 4y ago[dead]
- astrostl 4y agoDo I correctly understand that it does not have a mechanism by which to connect to Mullvad, much less mandate it? The only thing I see is the ability to manually detect externally-initiated VPN status. This seems like a key and significant departure from Tor Browser to me in terms of protection.
- notRobot 4y ago> Do I correctly understand that it does not have a mechanism by which to connect to Mullvad, much less mandate it? No. It comes with their extension with contents to the VPN via socks5.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- astrostl 4y agoAn extension that has no user prompting or even status indicator, and that will permit the user to browse the web without a VPN connection or warning by default. It appears that the process is to 1) open Mullvad Browser 2) (externally) open Mullvad VPN and connect to it 3) click on the Mullvad Browser Extension icon and connect it to the Mullvad proxy. Only after this will the proxy be used and the connection secured. Contrast this with Tor Browser's process of 1) open Tor Browser. It will only work after it automatically connects to Tor and secures the connection. Do you see the significant difference?
- brewdad 4y agoMullvad wants this browser to use usable even by people who don't use their VPN. Tor Browser is never intended to be used outside the Tor network.
- Fervicus 4y agoI am a happy LibreWolf [0] user. Wonder how they compare. [0] https://librewolf.net/ https://librewolf.net/
- mdasen 4y agoLooking at their FAQ, Mullvad Browser makes some different connections than LibreWolf (https://mullvad.net/en/help/tag/mullvad-browser/#93 https://mullvad.net/en/help/tag/mullvad-browser/#93, https://librewolf.net/docs/faq/#does-librewolf-make-any-outgoing-connections https://librewolf.net/docs/faq/#does-librewolf-make-any-outg...). The big difference seems to be the Mullvad connection since LibreWolf does make connections for Mozilla's protection/certificate stuff and for uBlock Origin. It looks like they might use Mullvad's DNS Over HTTPS by default in the Mullvad browser and this would probably be the biggest privacy thing, but whatever your default DNS is might be a larger privacy thing. Your ISP or Google's 8.8.8.8 traveling unencrypted is probably a bigger issue. It looks like Mullvad is also based off the Firefox ESR (extended support release) version that the Tor Browser uses while LibreWolf would be more up-to-date: https://news.ycombinator.com/item?id=35421718 https://news.ycombinator.com/item?id=35421718
- tyjen 4y agoThey've been my go to VPN service for years, since PIA was bought out, so this is a welcomed surprise. Hope it's as good as their service.
- webmobdev 4y agoImportant Note: Tor browser isn't truly private as it connects to Firefox services on start-up, even if you disable all options that require these. (Unlike zero telemetry / "no automated connections" browsers like the Orion browser - https://browser.kagi.com/ https://browser.kagi.com/ - or the PaleMoon browser - http://www.palemoon.org/ http://www.palemoon.org/ that actually do respect your browser settings). This seems deliberate as no attempts have been made to fix this despite repeated highlighting of this issue online by many concerned users. (I haven't verified if the Mullvad browser has the same problem).
- josephcsible 4y agoDo you have any evidence to back up this claim?
- webmobdev 4y ago- Tor Browser 11.0.4-11.0.6 phoning home: https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/40788 https://gitlab.torproject.org/tpo/applications/tor-browser/-... - Bug: Tor Browser 11.0.9 tries to connect to firefox.settings.services.mozilla.com on startup: https://tor.stackexchange.com/questions/23114/bug-tor-browser-11-0-9-tries-to-connect-to-firefox-settings-services-mozilla-co https://tor.stackexchange.com/questions/23114/bug-tor-browse... - Tor Browser phoning home to "firefox.settings.services.mozilla.com": https://forum.torproject.net/t/tor-browser-phoning-home-to-firefox-settings-services-mozilla-com/4450 https://forum.torproject.net/t/tor-browser-phoning-home-to-f...
- ShaurAsar 4y agoSimple and straightforward language makes it easy for users to understand the features and functionality of the extension. Screenshots of the extension in action, which helps users get a better idea of what to expect when using it. Overall, the Mullvad browser extension is an excellent resource for anyone interested in enhancing their online privacy and security. The page is well-designed, informative, and easy to use, which makes it an ideal choice for users looking for a reliable and effective VPN browser extension.
- markrankin 4y agoThey don’t have an iOS app like Firefox Focus. Are they working on an iOS app?
- jack_riminton 4y agoMullvad is the swedish name for a mole incase you were wondering. Source: wikipedia https://en.wikipedia.org/wiki/Mullvad https://en.wikipedia.org/wiki/Mullvad
- Waterluvian 4y agoI was wondering! For an English-speaking audience it feels like it might be a poor brand. It's not exactly a "nice-sounding" name. Though to be fair, they might not be trying to win mindshare, so careful branding might not be a concern. I appreciate that to a technical audience this can usually feel like a super pedantic bit of nonsense. But for the other 99% of browser users, this kind of thing can matter! "You should try out the Mullvad browser!" "The what?"
- brewdad 4y agoIs it really any worse than living on the Edge?
- Waterluvian 4y agoTo be fair, this is a very pseudosubjective thing. I know my data point. And I feel my data point is plausible as a trend. For example, you don't need to do studies to know that "Diarrhea Browser" would be a bad name. Edge? I think it's sharp and techy and modern. So it seems at least... valid. But it also screams, to me at least, the classic Microsoft branding thing of, "this feels like a bunch of 50 year olds in a room declared what they believe to be cool and hip." Then again. `iPad` was broadly laughed at when it was announced, and through sheer repetition it has been accepted and I don't really even notice the weirdness of the name anymore. So maybe with enough success, Mullvad would be adopted.
- cpeterso 4y agoI bet “should begin with the letter E” was one of Microsoft’s requirements for selecting a new browser name so they could continue to use IE’s familiar “e” app icon.
- nbzso 4y agoNo computer in my office is running without Mullvad VPN. No mac without Little Snitch.
- ravewithme 4y agoControlling browser + vpn - not a good idea. i turst the tor browser because of the protocol it uses (the onion protocol), not because of the browser i use it with. Even if mullvad is fully open-source and very transparent about it, i think it is not a good idea to use a browser and a vpn from the same vendor. They have full access to your internet data, and they now (if you use this browser) full controll over the browser you use.
- coppsilgold 4y agoYou can run the tor browser without tor. env TOR_SKIP_LAUNCH=1 TOR_TRANSPROXY=1 about:config extensions.torlauncher.start_tor = FALSE network.dns.disabled = FALSE
- Sporktacular 4y agoRight. I'm struggling to understand the need for this. Does this browser provide some seamless access to some free-tier Mulled service? If not then it seems like a marketing difference to the TOR browser, which can be used with a VPN and have the TOR bit switched off.
- sputter_token 4y agoThis page[0] lists the differences from the Tor browser[0]. It has the Tor specific features removed, different default extensions, enabled webRTC, and added Mullvad's DoH resolver. [0] https://mullvad.net/en/browser/hard-facts https://mullvad.net/en/browser/hard-facts
- lurtbancaster 4y ago> "Works on Windows 10 or later " Why? Firefox hasn't dropped support for Windows 7/8 yet. If you are somebody using Windows 7/8 etc and want Tor Browser but without Tor, then add the following to your `user.js` user_pref("network.proxy.socks_remote_dns", false); user_pref("extensions.torlauncher.start_tor", false); user_pref("network.dns.disabled", false); user_pref("browser.aboutConfig.showWarning", false); user_pref("network.proxy.socks", " "); That should give you all the anti-fingerprinting measures of Tor Browser but without Tor.
- brewdad 4y agoIf a user cares about privacy and security why would they be using an outdated, unsupported OS? That would be like double dead bolting the front door but leaving the window next to it wide open.
- lurtbancaster 4y agoMy point is that if it's just Tor Browser without Tor, then there's functionally no reason to have that build be incompatible with Windows 7. Unless they deliberately coded it in like if OS=Win7/Win8 ; then Crash ; else Run Which would be a dick move, especially because Firefox, on which Tor Browser and Mullvad Browser are based, still supports Windows 7. --------- Now to your point. It is absolutely possible to run Windows 7 reasonably securely. Well..., depends on your usecase. But the way in which I keep it secure might be a little cumbersome to some. My router runs PFSense with Suricata, and I encrypt my DNS traffic. I run a combination of Peerblock(while no longer maintained, it works splendidly in whitelist mode)[1], and Simplewall Firewall[2]. I run a combination of uMatrix(which again, while no longer maintained, it works great in whitelist mode)[3], and NoScript[4] on my Firefox web browser which I run inside Sandboxie[5]. There are also various services that are insecure and must be turned off - UPnP, Print Spooler, RDP etc. I run mostly FOSS software. The few proprietary closed source software(Games, Sublime Text) that I do run, I run them in SandBoxie or QEMU. Here are my reasons for not upgrading: I've modified my `UXTheme.dll` to significantly change my "Desktop Environment" to suit my workflow, and I've heard from people I know to be credible, that latter Windows versions(8 onwards) break system UI modifications when they update, and they don't work quite as well afterward. My modified Win7 UI is way too important to my workflow. Python have stopped releasing binaries for Win7 after 3.8.10[6] but I'm okay with it. If I do need the newer Python versions for something, I'll just use my Linux Desktop or run Linux in a virtual machine for a Python quickie. Windows 7 is extremely stable. While not as stable as Linux, I often have uptimes of over 350 days, before a BSOD, by which point I can foresee a crash coming and reboot. To lean into your metaphor, Microsoft is now shipping operating systems with "open windows" everywhere(way more open windows than my "insecure" Windows 7 has), and we, as users, are having to rebuild the ISOs they release, to make them more "privacy friendly"(yes I'm aware of the difference between privacy and security but they're really interchangeable here), and even then, we're having to use 3rd party "de-bloaters" and Batch/Powershell scripts off of Github, just so the majority of those proverbial windows are closed back up again. This really shouldn't have to be the case, but it is. Microsoft have decided that they would rather their bread be buttered by advertisers than by the actual users of their software. With Windows 7, I know there's an open window that I can't shut, but I have an electrified fence surrounding my compound, with security cameras and loaded turrets pointed towards that open window and other open windows in my house. I know where Windows 7's security limitations are, and I can mitigate against that, elsewhere. But I will admit, I don't go around recommending laypeople to use Windows 7 though, as the barrier to securing it is high. Even after securing it, the user has to be careful. In my humble opinion, Windows 7 was the last true Microsoft Operating System. It simply does what is asked of it, and moves out of the way. All Microsoft need have done was support Powershell, DirectX, give Win7 a "security updates as a service" business model(which I would've gladly paid for), and make WSL for it(Cygwin is excellent but WSL would be nicer). I know there is 0Patch, a 3rd party company who sell security updates for Windows 7, but I would've appreciated official Microsoft security updates. I would switch to Linux, if there was a robust equivalent to Autohotkey on Linux, and the games I want to run, worked on it. So yeah, I still run Windows 7. I can't see myself ever upgrading to another Microsoft OS, ever again. And I am, and I cannot emphasize this enough, exceedingly happy with it. [1] https://www.peerblock.com/ https://www.peerblock.com/ [2] https://github.com/henrypp/simplewall https://github.com/henrypp/simplewall [3] https://github.com/gorhill/uMatrix https://github.com/gorhill/uMatrix [4] https://noscript.net https://noscript.net [5] https://github.com/sandboxie-plus/Sandboxie https://github.com/sandboxie-plus/Sandboxie
- uconnectlol 4y agoa derivative of tor and mullvad, when tor browser is already second rate software (tor itself seems fine) and mullvad can't possibly be good since it's part of the "vpn as privacy mechnaism" fad. pass there's no fixing web browsers.
- pphysch 4y agoPros: - Makes it hard for advertisers to target you with ads Cons: - Funded by the State Department via Tor Project
- fuddle 4y agoI'd love to see a more technical write up on the Mullvad Browser.
- hooverd 4y agoIt's nice to see a Firefox based alternative browser.
- akomtu 4y agoGood stuff. They should make a mobile version with extensions: mobile firefox is surprisingly hostile to extensions beyond a small whitelisted set.
- AtNightWeCode 4y agoWhy not. I have a crazy idea. How about building an edge service that renders pages on the edge on identical HW and SW and then just stream it to end users. Could be built with Cloudlfare workers and Puppeteer for instance. People are already doing crazy things in automatic tests so I don't think there is a need to shy away because of the need for client side scripts. Or just run a Chromium instance.
- AccountAccount1 4y agoThere's already some work to that direction with cloudflare workers... but I really differs on why people would look for that; in a bit more convoluted case, for example, it would be destined for browsing nested pages of instagram, facebook, reddit, and so on... so it's bit difficult to that, especially with things that require auth... much more a coordination problem that an engineering one
- AtNightWeCode 4y agoMy example is simple. This is for tracking and fingerprinting. At the same time. This all may soon fall into the mobile tracking problem. Like in my country. By having a mobile turned off is in itself a tracking point.
- AccountAccount1 4y agoSorry, you are def right; could you expand a bit on how -what you mention- works? How come that by having a mobile turned off is in itself a tracking point? ty
- AccountAccount1 4y agoHaven't read any comment that points to a user actually trying it; does someone have a link? Or has tried it?
- raindear 4y agoIt's not available for smartphones.
- medill1919 4y agoBeware, there does not seem to be a way to uninstall this conventionally.
- 1101010010 4y agoAnother useless skinjob of Firefox for folks too conditioned and paranoid to use Tor Browser or know how to edit about:config themselves, by a company selling literal snakeoil ("trustworthy VPN").
- pnt12 4y agoUnlike other VPNs, Mullvad states what they protect against and what they don't. This browser seems to bridge the gap about what they previously couldn't. Considering there's no vendor lock-in and the browser is open source, I think your criticism is completely unwarranted.
- 1101010010 4y ago> Mullvad states what they protect against and what they don't. Where? Certainly not on https://mullvad.net/en/why-mullvad-vpn/ https://mullvad.net/en/why-mullvad-vpn/ which is filled with virtue signalling nonsense. > we encourage anonymous payments with cryptocurrency Implying crypto (based on a literal public and immutable ledger of transactions) is anonymous. > we don’t log your activity No way to validate this claim, but easy to make it. > The laws relevant to us as a VPN provider based in Sweden Sweden is part of 14 Eyes and almost all of the privacy legislature (like GDPR) doesn't apply to foreigners. Plus they use appear to use OpenVPN which is a dumpster fire of vulnerabilities. Oh, and I love this normalization of ignoring security warnings: > I get warnings when installing your software! > That's OK. Allow the software to install.
- bragadiru_mafia 4y agoAll you smart asses making recommendations on alternatives, shush. The moment it gets on their radar it’s compromised in 3 ..2 ... Take your obscure html rendered and live in peace brother .
- anigbrowl 4y agoI don't get it, why not just use Tor browser?
- mulle_nat 4y agoMullvad also states that it disabled the Firefox password storage feature, because it's supposedly insecure. But the articles supporting this view (i read) seem to be written by third-party password storage friends. Their arguments are weak (like "some managers used to do bla bla, which was insecure") and don't apply to Firefox. Is there a strong argument specifically against Firefox passwords and password sync ?
- EastSmith 4y agoHmm, I just gave it a try with https://fingerprint.com/ https://fingerprint.com/ and each time I restarted the browser it says it is my first visit. This is really a nice surprise, as fingerprint.com tends to always recognize your previous visits. Update: "In permanent private browsing mode, cookies and site data will always be cleared when Mullvad Browser is closed." It has this setting ON by default.
- dean2432 4y agotry this one. add a signature and see if it can detect you across sessions. https://abrahamjuliot.github.io/creepjs/ https://abrahamjuliot.github.io/creepjs/
- protoster 4y agoMullvad doing a fantastic marketing job on HN. 2-3 articles every month, without fail.
- plaguepilled 4y agoI have mixed feelings about this. On the one hand, this seems like a legitimately good product. On the other, I can't help but feel this would have had greater impact had the Mullvad team collaborated with the LibreWolf project. Sure they wouldn't be able to market it as directly, but I think their user base would be much bigger. Edit: it seems NoScript is also included which... I'm not sure I personally agree with? But I'm also not a privacy expert so maybe I've missed something, but ublock origin should cover that operability. Someone with experience please correct me if I'm off base here.
- zelphirkalt 4y agoNoScript blocks scripts, unlike uBlock Origin, which blocks whole domains. Both can be had from uMatrix, but I think it is unmaintained now.
- SLWW 4y agoI gotta say I have found Mullvad to be refreshing; they have good apps (you can get it running on most Linux systems with very little work) and I don't have to remember a password, just an ID number. Stupid simple stuff, been using them for a long time (and guess what? no info shared, they don't EMAIL me every time they have a discount for a 3 year subscription discount like some VPN companies) They just seem very honest and straight forward with their marketing. Never a bad moment.
- JaggerFoo 4y agoAnyone else unable to gpg verify the browser download. When I downloaded the VPN gpg verify was OK. Nevermind, I had to follow instructions from the github page to download the TOR Browser Signing Key and verify.