Live data from Hacker News

Firefox about:config privacy settings

gist.github.com

131–140 of 154 posts

Re: Firefox about:config privacy settings

#131
post #32

> These settings are best combined with your standard privacy extensions (HTTPS Everywhere, NoScript/Request Policy, uBlock origin, agent spoofing, Privacy Badger etc) Side question: how many of these ought to just be standard behavior of the browser? For example, will Firefox's new tracking protection make Privacy Badger obsolete? Should the HTTPS Everywhere extension, which attempts to route any HTTP request to an…

I'm sure plenty of people on here would object to HTTPS Everywhere being default: "but the user typed the HTTP scheme, the browser should do what the user asked!". That said, the bigger problem is that too many things that HTTPS Everywhere tries to upgrade to HTTPS are only partial versions of the site; you'd probably need something more conservative to avoid too much breakage.

I moved from HTTPS Everywhere & Privacy Badger to DuckDuckGo Privacy Essentials. It does the job of both of those with one add-on.

In response to HTTPS Everywhere breaking things, it does, and I've done tests comparing it and DDG PE and and found sites that would break using HTTPS Everywhere did not with DDG PE. They may simply be doing more testing.

Re: Firefox about:config privacy settings

#132
post #115

Earlier quoted context omitted.

What other items do you think fall into this category?

For instance, disabling geolocation. You need to explicitly approve geolocation requests anyway. If you're sure you'll never ever want to share your location with a site, sure, disable it globally. But recommending this to others as a way to protect their privacy is a bit silly.

Well, I for one appreciate the recommendation and will follow it to get rid of annoying messages. To each their own.

Re: Firefox about:config privacy settings

#133

Earlier quoted context omitted.

Dangerous is assuming Mozilla optimized only for privacy and performance. Why would you assume that and discourage people trying to optimize for that? This list wouldn't exist if Mozilla offered an equivalent, optimizing for only those two metrics, and explaining the tradeoffs you're asking for. What you'll find, as has been the case for Mozilla in some recent decisions, is the tradeoff includes (but is not limited t…

Mozilla is optimizing for a weighted sum of privacy and revenues from Google (who still account for >90% of Mozillas income). Therefore manually removing all Google partner tracking features in about:config is a very sane choice.

>who still account for >90% of Mozillas income).

You say still, but this will be the first time in a few years that will probably be true. The details of the Google deal aren't public, but I doubt it forced them to spend the past few months secretly hiding Google tracking into the browser.

Re: Firefox about:config privacy settings

#135

While talking about Firefox I have a quick question I am hoping someone here can help answer. One feature of Chrome I like a lot is the super simple per-site settings options. I use this to disable JS on a number of sites without impacting any other sites. As far as I can tell there is no option built into Firefox that allows me to do this. Does anyone know of a simple way to get per-site JS blocking? I have looked a…

uMatrix lets you set policies per domain / subdomain, while being very easy to use (for someone who knows web technologies). Highly recommend it.

Isn't that the same as blocking scripts with uBlock Origin?

Re: Firefox about:config privacy settings

#136
post #28

Earlier quoted context omitted.

Hysteria or ignorance, as with other items in this list. Safe browsing is designed not to compromise privacy.

Ha! Says Google, right? Anything that gets sent to them is too much.

Says Mozilla, and the source code is available for anyone to double-check. Google doesn't have control over what data Firefox sends to the safe browsing API.

Re: Firefox about:config privacy settings

#137

Seriously, again? Applying all of the changes at this list will harm users and increase the chances of threats compromising the browser. Don’t be shortsighted and use this blindly. Especially do not punish some poor unwary non-tech user by altering these settings on their behalf.

> Applying all of the changes at this list will harm users and increase the chances of threats compromising the browser.

How so?

Re: Firefox about:config privacy settings

#138

Earlier quoted context omitted.

I use Firefox. I've found the big battery hit has come from streaming services (Netflix, Pandora, Spotify, Youtube, etc). One small change I made was streaming music to my phone, and that had a big impact. I know that streaming will use some battery life, but the amount of CPU being used by say, Pandora, was rather extreme.

Sure, those will kill battery usage, but that's not what I'm doing. Typically I'm bouncing between the browser with about 10 informational tabs open, terminal, and sublime text all day long. There's a night and day difference using Safari vs Firefox for just regular browsing. I'm not the only one who experiences this either, I have a coworker who complains about the same issue with his couple year old MBP. Firefox is…

It'd be interesting to monitor Firefox vs Safari using e.g. powertop. Using Linux, I get excellent battery life using Firefox. But it might be the case that safari is still much better, or that it behaves differently on macOS.

Re: Firefox about:config privacy settings

#139
post #138

Earlier quoted context omitted.

Sure, those will kill battery usage, but that's not what I'm doing. Typically I'm bouncing between the browser with about 10 informational tabs open, terminal, and sublime text all day long. There's a night and day difference using Safari vs Firefox for just regular browsing. I'm not the only one who experiences this either, I have a coworker who complains about the same issue with his couple year old MBP. Firefox is…

It'd be interesting to monitor Firefox vs Safari using e.g. powertop. Using Linux, I get excellent battery life using Firefox. But it might be the case that safari is still much better, or that it behaves differently on macOS.

Note that the GL context opacity issue is entirely macOS-specific and does not affect Linux.

Re: Firefox about:config privacy settings

#140
post #60

This list is somewhere between worthless and dangerous. Chesterton's Fence: Presumably Mozilla has already optimized the privacy and performance of Firefox as much as they've felt comfortable doing. If they could change each of those settings as recommended without tradeoffs to help the user, they would have done so. Without listing the tradeoffs for each one, this list cannot be relied upon.

Chesterton's Fence is about a technology somewhere between thousands and tens of thousands years old. Fences are extremely well understood.

All of software has been around less than a century; the concept of personal computers running software that an end-user might adjust settings on is about sixty years old; thinking about Internet security is roughly thirty years old; the modern web ecosystem is no older than JavaScript, 22 years old.

You're still right that blindly changing settings is not a great idea, but the Chesterton's Fence analogy is misplaced.

Post reply on HN