Live data from Hacker News

The Mullvad Browser

mullvad.net

71–80 of 434 posts

Re: The Mullvad Browser

#71
post #40

Earlier quoted context omitted.

Simply download the Tor browser and evaluate its performance on one of the many browser fingerprint [1][2] and browser leak [3][4] web services. The last time I checked, it didn't pass every test. [1] https://www.amiunique.org/fp [2] https://coveryourtracks.eff.org/ [3] https://browserleaks.com/ [4] https://www.dnsleaktest.com/

Indeed, my fingerprint in https://www.amiunique.org/fp appears to be unique when using the Mullvad browser.

I just diffed the fingerprint[0] of 6 Mullvad browser sessions across 2 different devices and it was a unique fingerprint in every case[1]

It mixes a lot - fonts returned, media devices, the canvas ID - it's pretty good and similar to what you expect from the improvements out of Tor Browser

[0] using amiunique and fingerprint.js (now fingerprint.com) - which most of the nefarious ad networks use

[1] not that just as with Tor, you have to quit the browser or click the 'new identity' menu button. just closing a tab/window and re-opening is not enough. I've always believed that there could be a UI hint to this in private browsers with a unique color/background in the menubar as an indicator

Re: The Mullvad Browser

#72
post #40

Earlier quoted context omitted.

Simply download the Tor browser and evaluate its performance on one of the many browser fingerprint [1][2] and browser leak [3][4] web services. The last time I checked, it didn't pass every test. [1] https://www.amiunique.org/fp [2] https://coveryourtracks.eff.org/ [3] https://browserleaks.com/ [4] https://www.dnsleaktest.com/

Indeed, my fingerprint in https://www.amiunique.org/fp appears to be unique when using the Mullvad browser.

This is not necessarily the fault of the browser alone. I‘m also unique on a Safari on an up-to-date iOS, which in itself is not very unique.

Re: The Mullvad Browser

#73
post #40

Earlier quoted context omitted.

Simply download the Tor browser and evaluate its performance on one of the many browser fingerprint [1][2] and browser leak [3][4] web services. The last time I checked, it didn't pass every test. [1] https://www.amiunique.org/fp [2] https://coveryourtracks.eff.org/ [3] https://browserleaks.com/ [4] https://www.dnsleaktest.com/

Indeed, my fingerprint in https://www.amiunique.org/fp appears to be unique when using the Mullvad browser.

Same for me, I am using a VPN provider.

Even after installing Privacy Badger, my fingerprint remained unique and unchanged, with 17.65 bits of identifying information.

For comparison, after I disabled JavaScript, blocked remote fonts, disabled cosmetic filtering, and blocked large media elements using uBlock Origin, my fingerprint was no longer unique, and it dropped down to 9.55 bits of identifying information. Obviously, I don't recommend people do this, but it was fun to check it out.

Re: The Mullvad Browser

#74

I like Mullvad but it can actually be challenging to purchase a subscription in the US. Most prepaid cards block the purchase. Sure, you can use it with a fully tracked card etc. but that's not really the target audience.

Isn’t this like the one legitimate use for Monero?

Re: The Mullvad Browser

#76
post #31

From the FAQ [0]: > Why is the time is wrong? > The timezone is spoofed, to combat fingerprinting. > What's this weird spacing around the websites? > It’s called letterboxing, a function to combat fingerprinting (using your browser window size to identify you together with other measures). > How do I stay logged into specific websites between sessions? > It’s not possible. It’s an action to combat tracking. Not sure…

Except most of the time I don't want to spoof my timezone, don't want weird spacing around websites, and do want to remain logged in to websites. > How do I stay logged into specific websites between sessions? > It’s not possible. It’s an action to combat tracking. Turns me off immediately

Obviously you're not the target audience for a privacy focused browser

Re: The Mullvad Browser

#77
Hmm I am sure this is well intentioned, but I am a bit scared this will just further chip away on FireFoxes market share which doesn't look good to begin with.

Re: The Mullvad Browser

#78
post #34
post #17

Earlier quoted context omitted.

Stick out to who? Just set the useragent to a default firefox one (assuming its not already set) and you're golden.

I decided to test it out on a website[0] and it does seem that the useragent goes by the Firefox name: Mozilla/5.0 (Windows NT 10.0; rv:102.0) Gecko/20100101 Firefox/102.0 On my Firefox: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/110.0 It's interesting to note that the Mullvad browser seems to be based off on Firefox 102.0, which came way back on June 28, 2022: https://www.mozilla.…

Extended releases are counted a bit differently, it will jump from 102 to 115.

Re: The Mullvad Browser

#79
post #39

Why not sprinkle it with something like grsec? Now that would be a secure browser and would really upset a lot of shady people.

grsec are patches for the kernel. The main exploit risk to a modern browser is javascript JIT.

And? Is it considered secure or the threshold just pushed higher so the exploitation is not for everyone?

Re: The Mullvad Browser

#80
post #25

So ... it is a fork of Mozilla Firefox with privacy-friendly settings by default, some script blocking, and dns lookups done via Mullvads encrypted dns service Sounds ok to me, I have a longish and probably out of date list of settings that I like to chance in a new instance of firefox. I trust mullvad to not log dns more than I trust my ISP and I live in the UK so unencrypted dns here is being logged and stored by o…

> I have a longish and probably out of date list of settings that I like to chance in a new instance of firefox Not a user but part of the purpose of the TOR fork is settings, anything that is detectable via JS is supposed to remain default to prevent fingerprinting. It's partly why it's not widely popular, I don't know if this is still true but it used to be that it was supposed to be run at a specific viewport reso…

> run at a specific viewport resolution regardless of your device.

It's more like pretending to the website that your screen has a "common" resolution etc. which is nearly but not quite the same as what you said.

In the past they semi required you to keep your tor window in a specific window size for this, which just didn't work well in practice.

By now they better integrated that in the browser from what I heard, so you can resize it however you want but websites might have an "empty" border are to the left/right/bottom depending on you screen resolution, windows size etc. from what I have heard.

With a typical maximized window on 1080p you won't really notice it, on 4k you might notice that it's just "dump" up scaled from 1080p, but the person I spoke with wasn't sure if maybe they have a set of supported common resolutions instead of just one. And on a 4:3 screen he said it's quite noticeable.

Post reply on HN