22 ms·
Hardening Firefox – a checklist for improved browser privacy
- dotcoma 1y agoShouldn’t Firefox come hardened out of the box ?
- amarder 1y agoYes, but a lot of Mozilla's money comes from Google. https://www.pcworld.com/article/2772034/googles-search-monopoly-breakup-could-mean-the-death-of-firefox.html https://www.pcworld.com/article/2772034/googles-search-monop...
- 50208 1y agoIsn't that just to provide the search engine default? Which is easily changed?
- jdlshore 1y agoThere’s tradeoffs between privacy and convenience. Mozilla makes a particular set of tradeoffs, based on their judgment of what the average user will put up with; checklists like this allow you to make more aggressive tradeoffs.
- 50208 1y agoThat would be a great move by Mozilla. Have a "secure" version: Firefox, Firefox ESR, and Firefox SECURE. Or maybe just provide a switch to turn on.
- 542458 1y ago90% of the stuff in the OP will break certain sites… The problem is that non-technical users will think “oh, privacy, that’s good” (which it is, don’t get me wrong), click the “max privacy” option, but then be unable to fix things when they don’t work and switch back to Chrome.
- amarder 1y agoThis checklist is a work in progress, would love to hear your feedback.
- Bender 1y agoGood work. There are some hardening options that you may be able to glean from ArkenFox [1] and Betterfox [2]. Another addon to consider listing is CSS Exfil protection [3a] CSS Exfil Test Site [3b]. [1] - https://github.com/arkenfox/user.js https://github.com/arkenfox/user.js [2] - https://github.com/yokoffing/Betterfox https://github.com/yokoffing/Betterfox [3a] - https://addons.mozilla.org/en-US/firefox/addon/css-exfil-protection/ https://addons.mozilla.org/en-US/firefox/addon/css-exfil-pro... [3b] - https://www.mike-gualtieri.com/css-exfil-vulnerability-tester https://www.mike-gualtieri.com/css-exfil-vulnerability-teste...
- amarder 1y agoAwesome, will check these out, thank you!
- trod1234 1y agoThis is quite a rudimentary checklist, and it won't provide much in terms of privacy protections, but it will break a number of sites. The current state of browser-fingerprinting is off-the-rails, where they deny service if they don't get those fingerprints, and the browser to a lesser degree has had its securities/privacy protections gradually degraded. Stock Firefox will not be able to provide any sufficient guarantees. There are patches that need to be re-compiled in, because there have been about:config options removed. I highly suggest you review Arkenfox's work, most of the hardening feature he recommends will provide a better defense than nothing. He regularly also contributes to the Mullvad browser which implements most of his hardening and then some but also has some differentiation from the Tor Browser, but many of the same protections. The TL;DR of the problemscope is that there are artifacts that must be randomized within a certain range. There are also artifacts that must be non-distinct so as to not provide entropy for identification (system fonts and such that are shared among many people in a cohort). JS, and several other components, if its active will negate a lot of the defenses that have been developed to-date. Additionally, it seems that in some regional localities Eclipse attacks may be happening (multi-path transparent MITM), by terminating encryption early or through Raptor. At a bare minimum, there seem to be some bad actors that have mixed themselves into the root pki pool. I've seen valid issued Google Trust certs floating around that were not authorized by the owner of the SAN being visited, and it was transparent and targeted to that blog, but its also happened with vendors (providing VOIP related telco services). It seems Some ISPs may be doing this to collect sensitive data for surveillance capitalism or other unknown malign purposes. In either case TLS can't be trusted.
- mixmastamyk 1y agoThere are things I also do like removing sponsored links on the about page and url bar. Also disable type-ahead to search engine. My understanding is that Privacy Badger no longer learns by default. I never wanted that, just block known things, like search engine click hijacks. I’m not sure what to do about the user agent header. Changing or simplifying it tends to break sites. Also I’d like to promote Linux there but that’s at odds with privacy.
- mixmastamyk 1y agoSorry, not the about page, the newtab page.
- temp0826 1y agoI just want something (config or extension or instructions or whatever) to give me the best (rather, most common/average) fingerprint possible according to that EFF tool. Does that exist?
- olivergregory 1y agoThat’s the extension Privacy Badger.
- HelloUsername 1y ago> Privacy Badger UBO is enough; https://github.com/arkenfox/user.js/wiki/4.1-Extensions#-dont-bother https://github.com/arkenfox/user.js/wiki/4.1-Extensions#-don...
- efilife 1y agoThis probably won't be perfect on the EFF tool but try arkenfox
- temp0826 1y agoI think it just makes me a little sad that despite the effort I've put in, that tool (called Cover Your Tracks btw, or other ones like amiunique) still report that I am indeed unique.
- ranger_danger 1y agoIMO the EFF tool is a bad test because it only compares you against other people that have used the tool. A better test would be CreepJS in my opinion: https://abrahamjuliot.github.io/creepjs/ https://abrahamjuliot.github.io/creepjs/ I'm not aware of any FOSS browser setup that can actually result in a random FP ID shown in creepjs on every page load (please prove me wrong).
- henrixd 1y agoYou have to choose from one of two strategies, either you go with tor-browser (also includes Mulvad-browser) route and try make your browser indistinguishable from others or you randomize values to make stable fingerprinting impossible. When trying to be similar to everyone else, even small changes to the browser, like changing window size, can make you easily identifiable from everyone else. Randomizing will allow you to modify your browser. None of the fingerprinting protections matter if you use your browser and session to login to some sites. I use multiple browsers. One is for login to sites and tor-browser is for most of my browsing. This is easily the best fingerprinting extension that I have found so far: https://jshelter.org/ https://jshelter.org/
- olivergregory 1y agoSet the browser.ml.chat.enabled and browser.ml.enabled to false as they intensively use the processor and drain the battery. All that to just find the best name for your tab groups. I prefer to have my laptop last one more hour instead.
- yunruse 1y agoI took a brief gander at its code [0] and saw it mainly focusses on k-means clustering algorithms (in JS, no less). To my ken this is likely for suggesting new tabs, something a user is even less likely to use than renaming them. Its constant drain even when not 'in use' seems to imply it's classifying tabs as they change page (though it might be telemetry or uncommented testing). If so, it's an example of premature optimisation gone very wrong. It's a shame, because it overshadows the fact that naming tab groups is a perfect use case for an LLM, alongside keyboard suggestions and reverse dictionaries [1]. I'm ardently distrustful of LLMs for many, many purposes, but for the tiny parameter and token usage needed it's hard to not like. Which is a shame it's (somehow) such a drain. [0] https://github.com/mozilla-firefox/firefox/blob/7b42e629fdef2bf85c53556c0b29208621a290a9/browser/components/tabbrowser/SmartTabGrouping.sys.mjs https://github.com/mozilla-firefox/firefox/blob/7b42e629fdef... exports a SmartTabGroupingManager, though how or why that is used without being asked eludes me [1] https://www.onelook.com/thesaurus/ https://www.onelook.com/thesaurus/ Can be helpful in a pinch when a word's on the tip of your tongue, though its synonyms aren't always perfect.
- aragilar 1y agoI recall an extension (I think by a Mozilla dev) which could do automatic grouping of tabs (back before tab groups was removed). I'm surprised this hasn't come back.
- l8rlump 1y agoTab grouping is here, but not sure about automatic grouping. https://news.ycombinator.com/item?id=43834101 https://news.ycombinator.com/item?id=43834101
- 1y ago
- piskov 1y agoAfter the shit Mozilla pulled with ad/tracking this summer, the first step for improved privacy should be to delete firefox and switch to brave / what have you.
- creesch 1y ago> switch to brave Fun suggestion to switch to a browser that has a company behind it that has pulled a lot of shady stuff related to ads and tracking. A company where privacy is more marketing than a core value. Edit: Since people are going to ask anyway, here is an article that covers a lot of the shady stuff brave pulled https://thelibre.news/no-really-dont-use-brave/ https://thelibre.news/no-really-dont-use-brave/ If you are one of those folks who don't care about the political arguments, feel free to skip over paragraph one and two. Paragraph three till ten cover actual shady stuff done by brave the company itself. There is one more thing I can add to the list, though it wasn't as widely published about. At some point the team behind Brave decided to implement browser extension support from scratch and only support specific extensions. Which sounds okay in theory until you realize how they did so. Without involving the extension creator they would fork a version of the extension and bake that into Brave. They did so without informing the extension creator, meanwhile users would still go to the extension creator for support who couldn't fix a thing. Every time one of these things come up, the Brave team either is irked (but changes it anyway) or goes "oh, yeah we'll remove it in the future". This to me indicates a company culture where there is no thinking ahead about the impact of features or where they simply don't care as long as they aren't called out on it. This consistent pattern over a period of years has, to me anyway, shown that issues such as privacy or even being user centered are not a core part of their thinking but merely a marketing gimmick. And to be ahead of the curve on some other things I have heard people say over this. Just that Mozilla sucks doesn't mean alternatives can't be worse.
- piskov 1y agoCould you actually cite some from Brave’s privacy policy (as firefox has now) to corroborate these claims
- 1y ago
- geekamongus 1y agoI've been a Firefox die-hard since it was called Phoenix a couple decades ago. That said, over the last two months I've been testing Orion Browser (from Kagi, to which I subscribe), and am smitten with it. It's Apple only at the moment, which is a drawback, but if you live in that ecosphere, it's worth a look. Orion is Webkit-based, can install extensions from Chrome OR Firefox, privacy respecting, and a whole lotta niceties for per-website tweaks and other customizations. [0] https://kagi.com/orion/ https://kagi.com/orion/
- iknowstuff 1y agoI just need it to stop using Safari’s slow ass animation for the two-finger trackpad swipe back gesture
- thisislife2 1y agoOrion indeed is a decent option for the privacy conscious as it is one of the few browsers that doesn't make any automated connections on startup (with the right config). But, if I remember right, they are still trying to get Ublock Origin to work perfectly on it (i.e. WebExtension support is still not fully supported on Orion). PaleMoon ( http://www.palemoon.org/ http://www.palemoon.org/ ) is a hard fork of Firefox, with a mix of old tech (XUL) and new tech (from current codebase of Gecko), that is another full-featured zero-telemetry browser that doesn't make any automated connections. But on this too, the full features of uBlock Origin isn't supported as it is based on the abandoned uBlock Origin (legacy) codebase (though the legacy codebase has been updated by some PaleMoon developers, the original developers of uBlock Origin do not wish to support PaleMoon as it doesn't support WebExtension. Then there's the Tor Browser ( https://www.torproject.org/ https://www.torproject.org/ ) - it is a soft fork of Firefox, that supports the Tor network and has been configured by default to be "privacy hardened" - it has none of the crap that Mozilla bundles into Firefox, like Pocket, AI, Ads etc. The Tor software bundled in it can be easily deleted, to use it as privacy hardened Firefox. However, there are two issues with it - it does make unauthorised and unwanted automated connections (to SecureDrop) and you can no longer remove the NoScript browser extension that is bundled in it (you could from previous versions). When a browser maker forcefully bundles something in it, (however useful it may be), and does not allow you to modify it, that's well-founded ground to be suspicious of it. (Note: I did finally figure out that one can stop automated phoning to SecureDrop, after disabling it in about:rulesets ). As the tor browser laid a good foundation to create a privacy hardened Firefox, there are many other browsers that are Forks of the Tor browser - the Mullvad Browser ( https://mullvad.net/en/browser https://mullvad.net/en/browser ) is a popular one, and Mullvad bundles its VPN service in it instead of the Tor network. Last I checked, it made some automated connections on startup, so I didn't bother to explore it further).
- navigate8310 1y agoOr use LibreWolf and call it a day.
- mixmastamyk 1y agoIt’s not directly in popular distributions unfortunately.
- backscratches 1y agoTrue but the next best thing is arkenfox which is even more of a pain. Librefox makes a lot of the flags toggleable/visible in settings which is convenient too.
- pndy 1y agoIt's available as flatpak for a while - if that changes anything
- Dwedit 1y agoLibrewolf randomizes your time zone data on every page load, screwing with websites. It's on by default, and can be turned off.
- 50208 1y agoThanks for this ... great start. Mozilla Firefox COULD be an even more powerful source for good. Stop focusing on BS VPN, AI, etc ... focus on great browser, security, privacy. There is a possible niche for a centrally managed, security focused browser for companies ... like the Island Browser ... as an option.
- userbinator 1y agoIf the first item isn't "whitelist JS", you're doing it wrong. So many problems arise from letting any site run programs on your computer that it's best to reserve the privilege to the most trusted of sites.
- stusmall 1y agoMeanwhile if I see that I just move on. It just isn't practical to have a workable browser with JS whitelisting for the general case. I doubt people who do this actually do any kind of thoughtful review before hitting "accept". It just adds manual toil with limited benefit. If they are doing meaningful review, I question how much they actually get done in life.
- braiamp 1y agoI have NoScript by default set to no run. Some sites work better without it.
- userbinator 1y agoI very clearly remember, many years ago, a site (which was otherwise perfectly usable) nagging me to "enable JS for a better experience"; curious, I did and was immediately assaulted with all manner of hostile and irritating crap like popups, text selection hijacking, and even attempts to disable the right-click menu. Hurriedly disabled JS again to regain sanity. Nope. I'm never falling for that again... Of course the problem these days is with sites that don't work at all without JS even if they're just static content, and I suspect part of the reason is to force-feed you the crap along with the real content.
- integralid 1y ago>and I suspect part of the reason is to force-feed you the crap along with the real content. Insert the quote about being malicious and incompetent. Modern frontend frameworks like react make sure that your site won't work without js at all, unless you intentionally put some work for that 0.1% of internet users who browse with js disabled
- 1oooqooq 1y agoremember that "firefox -p" opens the profile manager so you can have one profile without the last two items on that list, just for when you need one or two sites that have broken login code that requires 3rd party cookie (it's always for malicious reasons rather than incompetence, but if you have to login you have to login)
- panarky 1y agoHypersegregate browsing with profiles. One profile for banks, a different profile for Amazon, a third profile for Google sites, a fourth for news sites I log into, a fifth for news sites I don't log into, a sixth that automatically forgets everything on exit for sites that UBO breaks. Then delete all data on each profile periodically, weekly for news sites, monthly for Amazon and banking sites. It's a giant pain in the ass juggling all these profiles. Seems like there should be a browser that automatically and transparently isolates every site in its own profile.
- pndy 1y agoMozilla introduced new profile manager for Firefox somewhere around May. This thing uses new storage format and ignores already existing "old" profiles, except for the default one. Data remains untouched, profiles created in the past are still here accessible by about:profile and if you don't want to use that new profile manager set browser.profiles.enabled entry to false. From what I've seen around people using the popular customized Firefox variants, like Floorp, Librewolf were surprised by this and not fond of the change.
- gdgghhhhh 1y agoAlso consider putting Firefox itself into a jail. E.g. using bubblewrap on Linux: https://gist.github.com/richardweinberger/cae9edeafeec4cdf657f9bdae00be241 https://gist.github.com/richardweinberger/cae9edeafeec4cdf65...
- heresie-dabord 1y agofirejail https://wiki.archlinux.org/title/Firejail https://wiki.archlinux.org/title/Firejail
- Dwedit 1y agoHow would you know if DuckDuckGo actually respected privacy? It's a black box.
- mixmastamyk 1y agoDDG reports all clicks to links.duckduckgo.com and improving.duckduckgo.com, etc. Which AdGuard seems to block, and maybe one of my browser settings/extensions as well.
- Dwedit 1y agoAllegedly they do that for "referer protection" reasons to hide the search term that was used to get to the site.
- wizzwizz4 1y agoThis is separate to referrer protection, which is only active as-needed – in most modern browsers, DuckDuckGo's referrer protection never kicks in, because they support rel="noopener noreferrer".
- rsync 1y agoA fools errand. No matter how effective this list is, the settings will either revert, change, or be silently undone. New settings will alter the efficacy of the old ones. Existing settings will disappear. The behavior you hoped to configure changed to its opposite. Remember: there was one morning when we all woke up and saw every dns query sent to cloudflare doh by default, and with no opt-in.
- merek 1y agoWill enabling "HTTPS-Only Mode" block http://localhost? If so, it would interfere with web development.
- Refreeze5224 1y agoNo, you can always continue on to non-HTTPS pages.
- sltkr 1y agoNo, it doesn't block localhost. Also you can add exceptions, so if you have e.g. a HTTP-only server on your local network, you can whitelist it manually.
- qingcharles 1y agoCan you create some certs for yourself?
- henrixd 1y ago[dead]
- nilslindemann 1y agoNotice, if you have all these settings enabled, you can still be fingerprinted. Test here: https://fingerprint.com/ https://fingerprint.com/ In my tests only Tor was able to prevent that, but using Tor will give you bad rankings on payment sites like PayPal, you may even get banned there. I learned this from here: https://news.ycombinator.com/item?id=35243355 https://news.ycombinator.com/item?id=35243355 That site is now black, surely a coincidence. Here the archive.org link: https://web.archive.org/web/20250801173508/https://www.bitestring.com/posts/2023-03-19-web-fingerprinting-is-worse-than-I-thought.html https://web.archive.org/web/20250801173508/https://www.bites... Have a local copy.
- 4gotunameagain 1y agohttps://amiunique.org/ https://amiunique.org/ is scary.
- LeoPanthera 1y ago> fingerprint dot com Is this an ad? Of all the things I was expecting to see when I clicked that, "Contact Sales" was not one of them.
- styanax 1y agoUse the EFF version, it's been around a long time: https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/
- mzajc 1y agoAFAIK none of these check for changing fingerprints. Your browser could report a very unique screen resolution, but could be configured to change it periodically. How much does that fool fingerprinting algorithms?
- nilslindemann 1y agoI guess it would, but the problem of getting "bad karma" points on payment processors, etc. remains. Further, this is not the only form of fingerprinting, there is also e.g. TLS fingerprinting [1]. Programmers should tell people that browsers and the internet are not private, and that everyone who claims otherwise does not tell the truth. There should be more discussions between people more skilled than me, if and how such methods can be prevented. And that should be documented well. Including how to prevent getting blocked on sites. A creative attempt would be when millions or billions of users have a software (self chosen!) which randomly visits sites, when the computer is not busy. This would not prevent fingerprinting, but the collected data would be useless (Someone in the other thread suggested that). Another method would be to declare it illegal and require workers to report such methods to the authorities. [1] https://roundproxies.com/blog/what-is-tls-fingerprint/ https://roundproxies.com/blog/what-is-tls-fingerprint/
- cookiengineer 1y agoThis is kind of a stupid ChatGPT article. No, this will not effectively help to reduce the fingerprint of your Browser. A LOT more tracking services are integrated into the Firefox browser in various places (like New Tab page, Sync, Pocket, Shavar, Google Safebrowsing, OSCP, etc pp). I wrote a more detailed article about this, and got an "as good as possible" as a result. But yeah, please please start to use a Host Firewall where you can block on a per-domain and per-port and per-process basis (like LittleSnitch, OpenSnitch etc) to validate your assumptions. UIs will always lie to you, including the one from Firefox. [1] https://cookie.engineer/weblog/articles/firefox-privacy-guide.html https://cookie.engineer/weblog/articles/firefox-privacy-guid...
- mahoro 1y agoNeat article. I would add `layout.css.font-visibility=1` to hide all non-default fonts (makes a canvas font rendering test less useful).
- binaryturtle 1y agoYes, sadly Little Snitch (or a similar app) is required to tame Firefox. It's a real shame since they use "Privacy" as selling point, but for me that starts with being transparent about what they do behind the users' backs with very clear ways to disable any nonsense (no about:config or policy BS, but proper GUI exposed options), or even better with a proper opt-in to those "security" and comfort features. It pretty much eroded any trust I had in this browser and Mozilla (they are no more better than Google, Meta, Apple in that regard.) If it wasn't for uBlock Origin and availability for older OSX versions I would ditch it (the Dynasty build is the only option I have for a recent browser on my old Mac.)
- gruez 1y ago>No, this will not effectively help to reduce the fingerprint of your Browser. Ironically many of your fingerprinting tweaks in your article make your more fingerprintable, because disabling random web APIs makes you stick out like a sore thumb (think https://xkcd.com/1105/ https://xkcd.com/1105/). Besides, most of the configs you're modifying for anti-fingerprinting purposes are already covered by RFP. >A LOT more tracking services are integrated into the Firefox browser in various places (like New Tab page, Sync, Pocket, Shavar, Google Safebrowsing, OSCP, etc pp). Can you elaborate on how these services are "tracking"? Except for maybe safebrowsing, and OSCP, none of these services actually send information on what sites you visit. Unless you mean "tracking" to mean "make connections to the internet".
- captainepoch 1y agoIf you want a hardened version of Firefox, download LibreWolf.
- BaudouinVH 1y agoor Waterfox
- procaryote 1y agoYeah, librewolf does a lot of the article's suggested things by default and is less likely to introduce new misfeatures to opt out from
- positron26 1y agoMy entire feeling about privacy is that, while surveillance economy tends to amplify the worst parts, ultimately, Richard Thieme's presentation is right: https://www.youtube.com/watch?v=atDgnkvzD8I https://www.youtube.com/watch?v=atDgnkvzD8I Thought experiment: in 100 years or even ten, can you imagine that there will not be tiny little camera robots that can get into the home of every person alive? Wouldn't every single living person be prone to having nude and unflattering, private moments leaked all over the internet? Socially, if privacy is a construct, then so is the fallout we expect others and ourselves to feel when privacy is violated. To some extent, not all, this is self-inflicted Victorian thinking. To the extent that it's true, part of the answer is, in the words of the brave (lol) Michael Cohen, "So what?" Really, so what? I hope we can get to that kind of reaction to adults having their privacy upended because it just takes so much of the bite out of the problem, the shame that relatively innocent people would experience for something completely out of their control. As far as the getting it back under control thing, we may also be coming to a point that more technologies are so dangerous or impactful that there becomes a need for more strict control so that powerful tech like miniaturization produces paper trails and the use of such technology comes with an implicit requirement for openness. I don't really care that people can use miniaturization, but I care if they can anonymize it to the extent that we create a lawless society with no remaining means of accountability. What *will* Russia and North Korea do when it becomes plausible to unleash little robot assassins either in small numbers to target individuals or mass numbers to carry out what is essentially nuclear scale death without nuclear scale fallout and destruction? It is plausible that this is a new facet of WMDs and MAD-based deterrence. Privacy, robots, and the inevitable slide into world war 3.
- cxplay 1y agoFirefox doesn't "help your privacy" and make promises just because it's developed by Mozilla, and Chromium doesn't become worse than Firefox just because it's developed by Google. As others have said, this article feels like it was written in LLM.
- bmacho 1y agoBasic things that browsers lack: - hooks between network steps - hooks between steps while rendering/interacting with a website Things that I want to do but I can't: - catch a request and modify it, e.g. when a webpage tells my browser to visit ajax.googleapis.com/jquery.js then my browser SHOULD NOT DO IT. Seriously, just don't start running shit on my computer when I click something. Noone wants that, apart from Google. Not the users. I should be able to modify that request, and serve jquery from somewhere else. - stop the browser's javascript execution - run my own javascript (these two are currently unavailable together, if you don't allow javascript on a webpage, then you can't run your own) (or modify HTML/DOM in some other language) I don't think Firefox is worth supporting, I believe it is a Trojan Horse of Google (or at least a Useful Idiot), and its existence is the main reason we have exactly 0 browsers (open source or proprietary) right now. It should die, so something else might flourish.
- BaudouinVH 1y agoPrivacy Possum is better than Privacy Badger imho
- barnabee 1y agoIt appears not to have been updated since 2019? See https://github.com/cowlicks/privacypossum https://github.com/cowlicks/privacypossum
- BaudouinVH 1y agoOups - I had no idea. Thanks for noticing this. I'm back to the badger. :)
- Pooge 1y agoGood luck remembering to do that every time Firefox updates. Hopefully, that's the only time it changes settings, right? Right...? Go for a Firefox fork and jump ship to Ladybird once it comes out. Forks wouldn't exist if it was trivial to revert Mozilla's mistakes.
- ris 1y agoThe paradox being that every thing you customize about your browser config becomes another thing that can potentially be fingerprinted and makes you stand out as one of the 1% who has ever looked in about:config.
- styanax 1y agoThat's a common thought, but it depends what you touch. I have hundreds of user.js customizations related to local browser behaviour (e.g. null out a lot of upstream URLs, I caught FF making DNS queries to services I disabled) - https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/ reports I have extremely strong anti-fingerprinting. The "failures" are not related to Firefox. Reading the details of the results, my unique values as reported come from factors which are hard to address; I have an Arch Linux user-agent (small population) and I have Linux fonts installed (we'll fail the span-font test easily compared to Windows or macOS) are the two huge outliers. These two are my heavily identified traits, the rest are a wash or normality ("1 in 3"). The fonts one is funny - the span-font metric for my system is 16.82 of 115876.67 kinda showing just how using Fonts you can pick a Linux user out of the results with ease. I have "the usual" font packages installed, nothing too fancy just enough to see CJK / UTF-8 around the web like everyone else. (for completeness I do remap 2 or 3 esoteric fdnts on my side due to a site using them). Side note: I have webgl disabled in user.js; the site reports I'm 1 of 85 statistically, this being the third largest and only outlier in normality.
- integralid 1y ago>factors which are hard to address; I have an Arch Linux user-agent Is this hard to address? Sounds like a easy thing to fix. >These two are my heavily identified traits, the rest are a wash or normality ("1 in 3"). With enough 1-in-3s you can still be unique, sadly. Your fingerprint is AND of every indicator.
- patrakov 1y agoImportant: this is a checklist for privacy, not for general security.
- clircle 1y agoI just install librewolf.