* Privacy Badger
* Disconnect
* CanvasBlocker
Can anyone recommend any more? * Privacy Badger
* Disconnect
* CanvasBlocker
Can anyone recommend any more?Clean links - removes redirects from search engines, facebook, twitter etc to hide a fact that you clicked a link, google doesn't know what link you clicked from search results, so if you block GA, it can't track you https://addons.mozilla.org/en-US/firefox/addon/clean-links/
HTTPS Everywhere https://www.eff.org/https-everywhere
uBlock Origin : https://github.com/gorhill/uBlock
uMatrix : https://github.com/gorhill/uMatrix
I have used Noscript, AdBlockPlus and Ghostery before but found they where lacking functionality, flexibility and performance. I used Privacy Badger too but if I remember well, it is based on the same engine as ABP and suffers for the same performance problems.
What exactly does it do?
After years of using uMatrix (formerly HTTP Switchboard), many sites "just works" wrt Youtube, Vimeo and similar even without first-party javascript enabled.
I've considered sharing parts of my global ruleset so others can just copy-paste the sections/sites they want to whitelist without having to discover what's required themselves.
Check out panoptoclick[1], to see your fingerprint. Someone should make a series of common groups, and those who care should stick to just those.
I think this is a topic that gets discussed by (for example) the Firefox developers, but I get the feeling that this is one of the hardest problems to fix.
I would like to see a browser mode akin to the privacy mode most browsers feature that reduces the number of identifying variables (at the cost of features). So instead of telling the world that my time zone is CET and I prefer English (GB) as language, it would select a random time zone and locale (although this does inconveniently mean that sites might suddenly serve me content in Portuguese).
Come to think of it, TOR Browser probably does a couple of these things. Disabling Javascript is surely the biggest factor, although that does make the modern web pretty much unusable.
It'd have to be more like a VM running the OS with the highest market share (Windows), the browser with the highest market share (Internet Explorer), with the most common language used, with the most common time zone of users of the site you're accessing (varies by site and time of day), etc.
Anything else and you could stand out in the crowd. Using Linux or OS X, for example, really make fingerprinting easier for sites, which is quite disturbing.
Randomizing the values of certain attributes, as you've described, may help a lot if more people adopt it and make fingerprinting a futile exercise to those using it. :) If the people doing the fingerprinting see millions being successfully tracked with just a handful they're unable to track, they wouldn't even care. It's kinda like ad blocking. A few do it and it's not seen as a problem. If the majority does it, then the sites take notice. For a larger scale effect, browser makers should get into this. Mozilla, Apple, Microsoft and Google, in that order (with Opera somewhere in the middle), may be interested in thwarting browser fingerprinting.
* RequestPolicy: No longer developed, but still works for me
https://addons.mozilla.org/en-US/firefox/addon/requestpolicy...
* RequestPolicy Continued
https://requestpolicycontinued.github.io/
* Policeman: Haven't tried it, but AFAIK it also filters by data type (e.g., allow media requests from x.com to y.com, but not scripts)
https://addons.mozilla.org/en-US/firefox/addon/random-agent-...
Now I use Self Destructing Cookies, uBlock Origin and HTTPS Everywhere. That works just fine without taking the fun out of the web.
https://distrinet.cs.kuleuven.be/software/CsFire/
https://addons.mozilla.org/en-US/firefox/addon/csfire/
CsFire is the result of academic research, available in the following publications: CsFire: Transparent client-side mitigation of malicious cross-domain requests (published at the International Symposium on Engineering Secure Software and Systems 2010) and Automatic and precise client-side protection against CSRF attacks (published at the European Symposium on Research in Computer Security 2011)
//no 3p cookies
network.cookie.cookieBehavior;1
//less referer headers
network.http.referer.XOriginPolicy;2
network.http.referer.spoofSource;true
network.http.referer.trimmingPolicy;2
//etc
beacon.enabled;false
dom.event.clipboardevents.enabled;false
dom.enable_performance;false
dom.network.enabled;false
dom.battery.enabled;false
dom.vibrator.enabled;false
dom.storage.enabled;false
dom.indexedDB.enabled;false
From what I have read that can break quite a few things in Firefox, becarefule
* Better privacy
* uBlock with EasyPrivacy list
* Https everywhere
Chrome gives you the option to delete cookies on quit and has exceptions for whitelisting, is "Self destructing cookies" any different?
This looks amazing. Any particular setting one should be aware of or must change to keep things less annoying and smooth?
PS. If you need a favicon from any site for a plugin or otherwise, easiest way I've found is https://www.google.com/s2/favicons?domain=duckduckgo.com. Will grab it from wheverever the sysadmin decided to put it.
[0]https://duckduckgo.com/params [1]http://mycroftproject.com/submitos.html
https://addons.mozilla.org/en-US/firefox/addon/privacy-setti...
HTTPS: Everywhere
uMatrix (used to use NoScript, but I prefer this now)
Self-Destructing Cookies
Better Privacy
There's really no reason for privacy conscious individuals to use Ghostery when uBlock Origin can do the exact same thing.
[1] https://www.ghostery.com/intelligence/consumer-blog/consumer...