Earlier quoted context omitted.
Forgive my ignorance, but couldn't this be done as an extension? (Maybe even withing uBlock Origin itself, if they were to add an option?) Or do extensions not have access to these settings?
This is exactly the sort of thing one might expect an extension to be able to to, but since the move to web-extensions many of these things aren't possible. For example, you can't change user settings from an extension. Or install other extensions.
LibreWolf – A fork of Firefox, focused on privacy, security and freedom
201–210 of 310 posts
Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom
#202Earlier quoted context omitted.
Doesn’t help if the exfiltration only occurs monthly and you only monitored for a week, or if there’s something locally malicious, or if side channels are involved, or if it’s manipulating data sent to legitimate sites (e.g. instructions to your bank, while logged in as you).
Keep it on, you can keep a firewall on, locally malicious files can be seen on your machine and if they aren't transmitted what is the worry? If its manipulating data sent to legitimate sites you'd notice while you used it. These concerns aren't absent in other official browsers either.
There’s no way I would be able to spot the operation of malware-masquerading-as-browser without committing totally to a forensic examination of every system call it makes. Imagine how much attention you’d have to pay to stop it capturing your bank credentials and then making transactions in an invisible tab (the browser doesn’t have to render a site in order to interact with it).
Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom
#203Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom
#204Earlier quoted context omitted.
Based on their recent design changes (deprecation of compact mode, for example), they are either not collecting enough telemetry about the affected parts of the UI/UX, or they are ignoring what they have collected for whatever reason. Of course, there is a chance that telemetry confirms their vision, but based on the explicit feedback I've been seeing online, I doubt the rationality of their decision-making at least…
How do you compare strong voices of a few on a site like HackerNews or Reddit against many many many millions of data points of users around the world. Should written feedback overrule a bigger data set?
Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom
#205Earlier quoted context omitted.
This is exactly the sort of thing one might expect an extension to be able to to, but since the move to web-extensions many of these things aren't possible. For example, you can't change user settings from an extension. Or install other extensions.
That is part of why FF is having user drops. There should be a way to easily set a bunch of preferences in bulk for privacy/security or whatever one wants.
Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom
#206I examined this and it appears that you can get the same effect yourself by enabling ETP strict mode, disabling telemetry and suggestions, and installing uBlock Origin in Firefox, which is a pretty common configuration for a lot of people. I suppose it's easier to just install this and have that already set up, but it's not exactly hard to do this in Firefox for the average HN reader and you most likely /already have…
I have another profile that I use to is less locked down that use that might need cookies and javascript. One can use plugins like noscript and enable on per site basis.
Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom
#207Earlier quoted context omitted.
Keep it on, you can keep a firewall on, locally malicious files can be seen on your machine and if they aren't transmitted what is the worry? If its manipulating data sent to legitimate sites you'd notice while you used it. These concerns aren't absent in other official browsers either.
Quite right that these concerns apply to any software, but they are significantly mitigated by sourcing software from organizations you trust. There’s no way I would be able to spot the operation of malware-masquerading-as-browser without committing totally to a forensic examination of every system call it makes. Imagine how much attention you’d have to pay to stop it capturing your bank credentials and then making t…
Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom
#208Earlier quoted context omitted.
> there's a bunch of 'features' disabled like […] auto-updates YIKES. Automatic updates are incredibly important for security. Disabling them by default is highly concerning. Does the browser support (manual) self-updates at all, or has that functionality been disabled entirely?
Some of us are responsible software owners who prefer to update on our own terms. I understand the argument that my grandmother should probably enable auto-updates, because otherwise she could easily end up months behind on releases. But I care deeply about my personal computing environment. I notice every minuscule change because I'm on my computer for hours and hours each day. Sometimes I'm in the middle of some im…
Re: LibreWolf – A fork of Firefox, focused on privacy, security and freedom
#209I recently looked at the changes they make to the default preferences and so many are nothing to do with privacy, and some of those that are also reduce the user's safety (e.g. disabling Google Safebrowsing). I'd advise any prospective users to comb over the changes very carefully before using it.
How does google safe browsing make me safer? It’s just sending all my network data to google for them to tell me if it’s safe or not. If you don’t see the issue with sending every website you use to google for them to tell you if it’s safe I don’t know what to tell you. Sending your browsing history to a database has everything to do with privacy.
not even controversial sites landing on blacklists, for reasons of technical errors maintaining those,
or some jurisdictions DMCAing some other site(s),
hosted behind the same IP-range in the same data-center.
Boom. Suddenly the site is gone, or at least you have to click around endless warnings about impending doom if you proceed.
For nothing. This is the same shit like antivirus ware on Windows. Utter non-sense.
Meanwhile, for instance on often visited sites(like weather), the Ads happily delivering malicious payloads.
This also happened many times, but can't blacklist large sites for delivering malware, can we?
Would cost too much ad-value. No-Go!