Would upvote parent more than once if I could.
> I went through a mad phase where I had loads of extensions installed in my main browser. Then all these stories came out about addon authors getting contacted by shady actors who wanted to buy the addon so they could add malicious code that siphons off personal data. Now I just have uBlock Origin and that's it! I trust it NOT to be taken over by bad actors.
Addons increase the number of parties you trust and also can make your browser more vulnerable. As we say in our openening paragraph https://www.privacyguides.org/browsers/
These are our current web browser recommendations and settings. We recommend keeping extensions to a minimum: they have privileged access within your browser, require you to trust the developer, can make you stand out, and weaken site isolation.
- https://en.wikipedia.org/wiki/Device_fingerprint#Browser_fin...
- https://groups.google.com/a/chromium.org/g/chromium-extensio...
> Addons also have exploitable bugs in them, and also having multiple 'privacy addons' can mean some overlap in functionality where the tracking protection is redundant since it's covered by another addon. Like who really needs Privacy Badger, DuckDuckGo privacy essentials, and then uBlock running all together?
Which is why common methodology now is very conservative. If you look at the research Arkenfox has done https://github.com/arkenfox/user.js/wiki/4.1-Extensions they recommend very few extensions.
> And with browsers shipping with fingerprinting mitigation, and having the option to surf strictly HTTPS sites, some addons are becoming redundant, like HTTPS Everywhere & 'useragent spoofing' addons which can actually make you stand out (privacy.resistFingerprinting:true in Firefox FTW). The trick is to blend in with a useragent, not stand out.
RFP does more than just adjust the user agent. User agent spoofing does *not* work.
As soon as you allow javascript there are dozens of metrics that can be used to profile you and to determine exactly what browser you have.