5 ms·
Firefox with extensions ?
by minthd 11y ago
Firefox with extensions ?
- brador 11y agoFirefox has the code that secretly sends a hash of every file you download, with your IP and computer fingerprint, to Google for "verification". I only found out after a post about it here on HN. But I'm interested, what Firefox extensions are good for privacy?
- diafygi 11y agoI think if you uncheck the "block reported forgeries/attacks" options in security settings it won't make the requests.
- wtallis 11y agoBetterPrivacy to manage Flash Cookies Cookie Monster to manage regular cookies HTTPS Everywhere DNSSEC/TLSA Validator RequestPolicy Continued to control third-party requests NoScript for selectively allowing first-party JS, and keeping third-party scripts blocked when other third-party requests are allowed through RequestPolicy, and for its other always-on features like XSS protection, permanently forcing encryption for cookies set over HTTPS, etc. µMatrix has apparently been available for Firefox for a few months now, and is probably a viable substitute for RequestPolicy, but not a complete replacement for NoScript.
- metasean 11y agoLinks to each of the mentioned (and available) add-ons below. Note that they each require a restart. - BetterPrivacy https://addons.mozilla.org/en-US/firefox/addon/betterprivacy/ https://addons.mozilla.org/en-US/firefox/addon/betterprivacy... - Cookie Monster https://addons.mozilla.org/en-US/firefox/addon/cookie-monster/ https://addons.mozilla.org/en-US/firefox/addon/cookie-monste... - HTTPS Everywhere - https://www.eff.org/files/https-everywhere-latest.xpi https://www.eff.org/files/https-everywhere-latest.xpi - DNSSEC/TLSA Validator - https://addons.mozilla.org/en-US/firefox/addon/dnssec-validator/?src=search https://addons.mozilla.org/en-US/firefox/addon/dnssec-valida... - RequestPolicy Continued ??? https://addons.mozilla.org/en-US/firefox/addon/requestpolicy/ https://addons.mozilla.org/en-US/firefox/addon/requestpolicy... - NoScript Suite - https://addons.mozilla.org/en-US/firefox/addon/noscript/ https://addons.mozilla.org/en-US/firefox/addon/noscript/ - µMatrix - couldn't find a Firefox version
- wtallis 11y agoRequestPolicy Continued: https://requestpolicycontinued.github.io/ https://requestpolicycontinued.github.io/ µMatrix: https://addons.mozilla.org/en-US/firefox/addon/umatrix/ https://addons.mozilla.org/en-US/firefox/addon/umatrix/
- lingben 11y agoare you referring to this? https://news.ycombinator.com/item?id=9779440 https://news.ycombinator.com/item?id=9779440 this is the first I've heard of this, could you be more specific?
- brador 11y agoThis: https://support.mozilla.org/en-US/kb/how-does-phishing-and-malware-protection-work#w_how-does-phishing-and-malware-protection-work-in-firefox https://support.mozilla.org/en-US/kb/how-does-phishing-and-m... It sends a hash of the file to Google with your IP/print. Worded like it's anonymous and one way, it's not. The hash is unique to the file, if your file-hash database is large enough (like Googles) you can cross reference to get the details of the original file. From this hash, you can then see the exact file the person is downloading. Great if you want to make a list of who is downloading an unallowed file, like say, a list of missing Chinese citizens or anything from wleaks.
- lern_too_spel 11y agoNothing on that page mentions a hash. There is absolutely nothing misleading in the page you linked.
- brador 11y agoThe metadata sent to Google includes a hash of the file. That's what the metadata part means.
- lern_too_spel 11y agoNo, the metadata means the URL (not hashed). The protocol is linked from the page you posted. It's clear as day, and the only person who would be misled is somebody who didn't read the page at all and claimed it said things it doesn't say.
- lingben 11y agopretty sure you're misunderstanding how firefox handles that, it downloads to local and checks against it, not the other way around
- lern_too_spel 11y agoThere is nothing secret about it.
- brador 11y agoI'd suggest it's purposefully obfuscated. It's certainly not clear this is being done and many users are surprised it exists. Such a possibility would be in line with Mozillas recent actions and allegations made against them.