I guess why not. This is an open source, rebranded Firefox and Firefox-like browsers could use some publicity. It promotes privacy and privacy can use some publicity too. Tor too. Mullvad seems to be honest in the fact that their business model is selling VPNs and it's nice they are saying it's not enough. They are not saying that you might not need one though. We need a Firefox with good defaults and it seems like t…
I'm quite surprised nobody mentioned Librewolf yet. https://librewolf.net/ It's a custom build of Firefox with somewhat sensible, sometimes strict, privacy respecting default settings. There's also the Arkenfox user.js which you can put on top of vanilla Firefox, aiming for the most privacy and security possible. https://github.com/arkenfox/user.js
The Mullvad Browser
321–330 of 434 posts
Re: The Mullvad Browser
#322Another useless skinjob of Firefox for folks too conditioned and paranoid to use Tor Browser or know how to edit about:config themselves, by a company selling literal snakeoil ("trustworthy VPN").
Unlike other VPNs, Mullvad states what they protect against and what they don't. This browser seems to bridge the gap about what they previously couldn't. Considering there's no vendor lock-in and the browser is open source, I think your criticism is completely unwarranted.
Where? Certainly not on https://mullvad.net/en/why-mullvad-vpn/ which is filled with virtue signalling nonsense.
> we encourage anonymous payments with cryptocurrency
Implying crypto (based on a literal public and immutable ledger of transactions) is anonymous.
> we don’t log your activity
No way to validate this claim, but easy to make it.
> The laws relevant to us as a VPN provider based in Sweden
Sweden is part of 14 Eyes and almost all of the privacy legislature (like GDPR) doesn't apply to foreigners.
Plus they use appear to use OpenVPN which is a dumpster fire of vulnerabilities.
Oh, and I love this normalization of ignoring security warnings:
> I get warnings when installing your software!
> That's OK. Allow the software to install.
Re: The Mullvad Browser
#323Earlier quoted context omitted.
It annoys me that the only way to access iPlayer from abroad is via a VPN. Surely opening it up and allowing international customers to pay some form of license fee could be a nice little revenue stream for the BBC? I'm guessing the reason is just "licensing issues" but if they're making the programmes then what's the problem? I'm sure there's an international market for watching the world class output from the BBC.
a few years ago I moved outside the UK and spent the best part of 3 months (on and off) trying to access BBC content, legally, still holding residency, paying domiciliary and employment taxes, and paying for a bladdy TV loicence of course, I wanted to do this for as close to free as possible, since plugging an aerial into a tv at home also cost next to nothing VPNs were already being detected and banned. I tried at l…
A shame BBC can't accommodate its paying customers who happen to be abroad.
Re: The Mullvad Browser
#324Here's to hoping they maintain this for a while. There are a lot of "hardened Firefox" forks around, none of them that I would trust to follow upstream for a long enough time to switch. I already trust Mullvad enough to use as VPN, and am likely willing to extend that trust to a fork of Firefox they manage, but truthfully, I always concerned when achieving goals means new ventures and projects as it may mean resource…
"Avoid Gecko-based browsers like Firefox as they're currently much more vulnerable to exploitation and inherently add a huge amount of attack surface. Gecko doesn't have a WebView implementation (GeckoView is not a WebView implementation), so it has to be used alongside the Chromium-based WebView rather than instead of Chromium, which means having the remote attack surface of two separate browser engines instead of only one. Firefox / Gecko also bypass or cripple a fair bit of the upstream and GrapheneOS hardening work for apps. Worst of all, Firefox does not have internal sandboxing on Android. This is despite the fact that Chromium semantic sandbox layer on Android is implemented via the OS isolatedProcess feature, which is a very easy to use boolean property for app service processes to provide strong isolation with only the ability to communicate with the app running them via the standard service API. Even in the desktop version, Firefox's sandbox is still substantially weaker (especially on Linux) and lacks full support for isolating sites from each other rather than only containing content as a whole. The sandbox has been gradually improving on the desktop but it isn't happening for their Android browser yet."
Re: The Mullvad Browser
#325Re: The Mullvad Browser
#326Earlier quoted context omitted.
Shows are often made by production companies on contract and licensed for domestic distribution. Licensing for international distribution might be significantly more expensive.
Yes but they would get more revenue from it too.
Re: The Mullvad Browser
#327Earlier quoted context omitted.
I don't care about Brendan Eich quite as much as I care about the Google / Chrome monopoly, and Brave just makes this monopoly stronger by depending on Chrome. By being Chrome, actually. I want the web to be built around something else than ad-/tracking-supported software and Brave is being very self-contradictory with this. Don't use Brave if you care about the global picture / tracking around the globe.
Brave is a separate fork and completely unreliant on Chrome. It also is the most privacy-focused browser so it's the opposite of "tracking-supported software".
If Chrome disappears, Brave ceases to exist. Brave totally relies on Google developers working on Chrome and do the vast majority of what it takes to build the browser. Brave only does superficial work in comparison. Brave may itself be privacy-focused but only exists thanks to Google's business model which is mostly tracking the world.
So, yes, Brave is mostly funded by tracking since it is mostly Chrome with some lightweight work on top of it.
Re: The Mullvad Browser
#328Here's to hoping they maintain this for a while. There are a lot of "hardened Firefox" forks around, none of them that I would trust to follow upstream for a long enough time to switch. I already trust Mullvad enough to use as VPN, and am likely willing to extend that trust to a fork of Firefox they manage, but truthfully, I always concerned when achieving goals means new ventures and projects as it may mean resource…
Firefox runs like cold molassas on Android, unfortunately. Bromite seems like its sticking around, fortunately.
Only barely, unfortunately.
I've since moved to Vanadium for anything untrusted and/or critical. It's still missing some features I'll enjoy seeing added, but it's improved considerably lately.
Re: The Mullvad Browser
#329From the FAQ [0]: > Why is the time is wrong? > The timezone is spoofed, to combat fingerprinting. > What's this weird spacing around the websites? > It’s called letterboxing, a function to combat fingerprinting (using your browser window size to identify you together with other measures). > How do I stay logged into specific websites between sessions? > It’s not possible. It’s an action to combat tracking. Not sure…
Except most of the time I don't want to spoof my timezone, don't want weird spacing around websites, and do want to remain logged in to websites. > How do I stay logged into specific websites between sessions? > It’s not possible. It’s an action to combat tracking. Turns me off immediately
Re: The Mullvad Browser
#330> "Works on Windows 10 or later " Why? Firefox hasn't dropped support for Windows 7/8 yet. If you are somebody using Windows 7/8 etc and want Tor Browser but without Tor, then add the following to your `user.js` user_pref("network.proxy.socks_remote_dns", false); user_pref("extensions.torlauncher.start_tor", false); user_pref("network.dns.disabled", false); user_pref("browser.aboutConfig.showWarning", false); user_pr…
If a user cares about privacy and security why would they be using an outdated, unsupported OS? That would be like double dead bolting the front door but leaving the window next to it wide open.
Unless they deliberately coded it in like
if OS=Win7/Win8 ; then Crash ; else Run
Which would be a dick move, especially because Firefox, on which Tor Browser and Mullvad Browser are based, still supports Windows 7.---------
Now to your point.
It is absolutely possible to run Windows 7 reasonably securely.
Well..., depends on your usecase.
But the way in which I keep it secure might be a little cumbersome to some.
My router runs PFSense with Suricata, and I encrypt my DNS traffic.
I run a combination of Peerblock(while no longer maintained, it works splendidly in whitelist mode)[1], and Simplewall Firewall[2].
I run a combination of uMatrix(which again, while no longer maintained, it works great in whitelist mode)[3], and NoScript[4] on my Firefox web browser which I run inside Sandboxie[5].
There are also various services that are insecure and must be turned off - UPnP, Print Spooler, RDP etc.
I run mostly FOSS software. The few proprietary closed source software(Games, Sublime Text) that I do run, I run them in SandBoxie or QEMU.
Here are my reasons for not upgrading:
I've modified my `UXTheme.dll` to significantly change my "Desktop Environment" to suit my workflow, and I've heard from people I know to be credible, that latter Windows versions(8 onwards) break system UI modifications when they update, and they don't work quite as well afterward. My modified Win7 UI is way too important to my workflow.
Python have stopped releasing binaries for Win7 after 3.8.10[6] but I'm okay with it. If I do need the newer Python versions for something, I'll just use my Linux Desktop or run Linux in a virtual machine for a Python quickie.
Windows 7 is extremely stable. While not as stable as Linux, I often have uptimes of over 350 days, before a BSOD, by which point I can foresee a crash coming and reboot.
To lean into your metaphor, Microsoft is now shipping operating systems with "open windows" everywhere(way more open windows than my "insecure" Windows 7 has), and we, as users, are having to rebuild the ISOs they release, to make them more "privacy friendly"(yes I'm aware of the difference between privacy and security but they're really interchangeable here), and even then, we're having to use 3rd party "de-bloaters" and Batch/Powershell scripts off of Github, just so the majority of those proverbial windows are closed back up again. This really shouldn't have to be the case, but it is. Microsoft have decided that they would rather their bread be buttered by advertisers than by the actual users of their software.
With Windows 7, I know there's an open window that I can't shut, but I have an electrified fence surrounding my compound, with security cameras and loaded turrets pointed towards that open window and other open windows in my house. I know where Windows 7's security limitations are, and I can mitigate against that, elsewhere. But I will admit, I don't go around recommending laypeople to use Windows 7 though, as the barrier to securing it is high. Even after securing it, the user has to be careful.
In my humble opinion, Windows 7 was the last true Microsoft Operating System. It simply does what is asked of it, and moves out of the way. All Microsoft need have done was support Powershell, DirectX, give Win7 a "security updates as a service" business model(which I would've gladly paid for), and make WSL for it(Cygwin is excellent but WSL would be nicer). I know there is 0Patch, a 3rd party company who sell security updates for Windows 7, but I would've appreciated official Microsoft security updates. I would switch to Linux, if there was a robust equivalent to Autohotkey on Linux, and the games I want to run, worked on it.
So yeah, I still run Windows 7. I can't see myself ever upgrading to another Microsoft OS, ever again. And I am, and I cannot emphasize this enough, exceedingly happy with it.
[1] https://www.peerblock.com/
[2] https://github.com/henrypp/simplewall