Live data from Hacker News

The Mullvad Browser

mullvad.net

21–30 of 434 posts

Re: The Mullvad Browser

#21
post #19

Can anyone explain how this won't, putting it diplomatically, attract certain 'dark web' types, and in turn bring mullvad under the microscope of law enforcement?

If you do something useful it will probably attract criminals, nothing we can do about it.

Re: The Mullvad Browser

#22
> Dns Over HTTPS (DoH) > Mullvad Browser is configured to use Mullvad DoH for all DNS requests, without fallback. In the settings, you can also configure it to use Mullvad Adblocking DoH.

about:config DOH entries screenshot here:

* https://imgur.com/a/evd9OzN

Can anyone knowledgeable comment on the security implications of this?

Re: The Mullvad Browser

#23

Earlier quoted context omitted.

> The last time I tried the Tor browser, it did not sufficiently handle browser finger prints. Can you expound on this?

Simply download the Tor browser and evaluate its performance on one of the many browser fingerprint [1][2] and browser leak [3][4] web services. The last time I checked, it didn't pass every test. [1] https://www.amiunique.org/fp [2] https://coveryourtracks.eff.org/ [3] https://browserleaks.com/ [4] https://www.dnsleaktest.com/

Isn't passing every test going to make the browser uniquely unique? My impression is that they want it to be 'fingerprinted' but look like 1,000,000 other Tor browsers so they can't be told apart.

Re: The Mullvad Browser

#24
post #19

Can anyone explain how this won't, putting it diplomatically, attract certain 'dark web' types, and in turn bring mullvad under the microscope of law enforcement?

This isn't useful to 'dark web' types. This is at best useful for 'mom and pop' who heard about 'china tiktok' on the news.

Re: The Mullvad Browser

#25

So ... it is a fork of Mozilla Firefox with privacy-friendly settings by default, some script blocking, and dns lookups done via Mullvads encrypted dns service Sounds ok to me, I have a longish and probably out of date list of settings that I like to chance in a new instance of firefox. I trust mullvad to not log dns more than I trust my ISP and I live in the UK so unencrypted dns here is being logged and stored by o…

> I have a longish and probably out of date list of settings that I like to chance in a new instance of firefox

Not a user but part of the purpose of the TOR fork is settings, anything that is detectable via JS is supposed to remain default to prevent fingerprinting.

It's partly why it's not widely popular, I don't know if this is still true but it used to be that it was supposed to be run at a specific viewport resolution regardless of your device. All in the name of making your fingerprint as close to the same as all other TOR browser users.

Re: The Mullvad Browser

#26
post #19

Can anyone explain how this won't, putting it diplomatically, attract certain 'dark web' types, and in turn bring mullvad under the microscope of law enforcement?

Couldn't you say that about any VPN? Why would Mullvad's browser be unique in this regard?

Re: The Mullvad Browser

#28
From the FAQ [0]:

> Why is the time is wrong?

> The timezone is spoofed, to combat fingerprinting.

> What's this weird spacing around the websites?

> It’s called letterboxing, a function to combat fingerprinting (using your browser window size to identify you together with other measures).

> How do I stay logged into specific websites between sessions?

> It’s not possible. It’s an action to combat tracking.

Not sure if there are other measures, other than that the browser itself doesn't track anything.

Looking much better than a stock firefox, and presumably will improve over time.

[0] - https://mullvad.net/en/help/tag/mullvad-browser/

Re: The Mullvad Browser

#29
Here's to hoping they maintain this for a while. There are a lot of "hardened Firefox" forks around, none of them that I would trust to follow upstream for a long enough time to switch.

I already trust Mullvad enough to use as VPN, and am likely willing to extend that trust to a fork of Firefox they manage, but truthfully, I always concerned when achieving goals means new ventures and projects as it may mean resources are moving to other areas and may impact their code product. I like my core providers to do one thing and do it well.

Edit: I hope they bring this to Android also!

Re: The Mullvad Browser

#30

Earlier quoted context omitted.

Simply download the Tor browser and evaluate its performance on one of the many browser fingerprint [1][2] and browser leak [3][4] web services. The last time I checked, it didn't pass every test. [1] https://www.amiunique.org/fp [2] https://coveryourtracks.eff.org/ [3] https://browserleaks.com/ [4] https://www.dnsleaktest.com/

Isn't passing every test going to make the browser uniquely unique? My impression is that they want it to be 'fingerprinted' but look like 1,000,000 other Tor browsers so they can't be told apart.

Yes either you want everyone to look the same, or you want every page request to be totally random.
Post reply on HN