Live data from Hacker News

The Mullvad Browser

mullvad.net

31–40 of 434 posts

Re: The Mullvad Browser

#31

From the FAQ [0]: > Why is the time is wrong? > The timezone is spoofed, to combat fingerprinting. > What's this weird spacing around the websites? > It’s called letterboxing, a function to combat fingerprinting (using your browser window size to identify you together with other measures). > How do I stay logged into specific websites between sessions? > It’s not possible. It’s an action to combat tracking. Not sure…

Except most of the time I don't want to spoof my timezone, don't want weird spacing around websites, and do want to remain logged in to websites.

> How do I stay logged into specific websites between sessions? > It’s not possible. It’s an action to combat tracking.

Turns me off immediately

Re: The Mullvad Browser

#32

So ... it is a fork of Mozilla Firefox with privacy-friendly settings by default, some script blocking, and dns lookups done via Mullvads encrypted dns service Sounds ok to me, I have a longish and probably out of date list of settings that I like to chance in a new instance of firefox. I trust mullvad to not log dns more than I trust my ISP and I live in the UK so unencrypted dns here is being logged and stored by o…

Sounds great for the audience it’s probably intended for.

Re: The Mullvad Browser

#33

> Dns Over HTTPS (DoH) > Mullvad Browser is configured to use Mullvad DoH for all DNS requests, without fallback. In the settings, you can also configure it to use Mullvad Adblocking DoH. about:config DOH entries screenshot here: * https://imgur.com/a/evd9OzN Can anyone knowledgeable comment on the security implications of this?

If you trust Mullvad to see all your traffic (including every IP you connect to), it seems okay to trust them to see your DNS queries (that will return the very same IPs you will later connect to)

Re: The Mullvad Browser

#34
post #17

The question not answered: won't I stick out like a sore thumb if only 1 in 10000 people uses this browser?

Stick out to who? Just set the useragent to a default firefox one (assuming its not already set) and you're golden.

I decided to test it out on a website[0] and it does seem that the useragent goes by the Firefox name:

Mozilla/5.0 (Windows NT 10.0; rv:102.0) Gecko/20100101 Firefox/102.0

On my Firefox:

Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/110.0

It's interesting to note that the Mullvad browser seems to be based off on Firefox 102.0, which came way back on June 28, 2022:

https://www.mozilla.org/en-US/firefox/102.0/releasenotes/

[0]: https://gs.statcounter.com/detect

Re: The Mullvad Browser

#35
post #31

From the FAQ [0]: > Why is the time is wrong? > The timezone is spoofed, to combat fingerprinting. > What's this weird spacing around the websites? > It’s called letterboxing, a function to combat fingerprinting (using your browser window size to identify you together with other measures). > How do I stay logged into specific websites between sessions? > It’s not possible. It’s an action to combat tracking. Not sure…

Except most of the time I don't want to spoof my timezone, don't want weird spacing around websites, and do want to remain logged in to websites. > How do I stay logged into specific websites between sessions? > It’s not possible. It’s an action to combat tracking. Turns me off immediately

I thought it'd be possible by simply turning off "Always use private browsing mode" setting, but it doesn't seem to work. Sessions are still cleared upon browser exit.

In my case, I had to turn off that setting because without it, 1Password wouldn't work.

Re: The Mullvad Browser

#36
post #19

Can anyone explain how this won't, putting it diplomatically, attract certain 'dark web' types, and in turn bring mullvad under the microscope of law enforcement?

You can't browse the dark web with this browser.

Re: The Mullvad Browser

#38

"The Mullvad Browser is a privacy-focused web browser developed in a collaboration between Mullvad VPN and the Tor Project. It’s designed to minimize tracking and fingerprinting. You could say it’s a Tor Browser to use without the Tor Network." https://github.com/mullvad/mullvad-browser So basically like... hardened Firefox?

Hmm looking the settings I saw a search engine I didn't recognize... I guess they also have a google proxy?

https://leta.mullvad.net

So I guess now you can go full Mullvad.

Re: The Mullvad Browser

#39

Why not sprinkle it with something like grsec? Now that would be a secure browser and would really upset a lot of shady people.

grsec are patches for the kernel.

The main exploit risk to a modern browser is javascript JIT.

Re: The Mullvad Browser

#40

Earlier quoted context omitted.

> The last time I tried the Tor browser, it did not sufficiently handle browser finger prints. Can you expound on this?

Simply download the Tor browser and evaluate its performance on one of the many browser fingerprint [1][2] and browser leak [3][4] web services. The last time I checked, it didn't pass every test. [1] https://www.amiunique.org/fp [2] https://coveryourtracks.eff.org/ [3] https://browserleaks.com/ [4] https://www.dnsleaktest.com/

Indeed, my fingerprint in https://www.amiunique.org/fp appears to be unique when using the Mullvad browser.
Post reply on HN