This is what I use. I have everything that I log into google for in one container, social media in a second, and everything else is nicely sand-boxed away from those horrors.
[0] https://addons.mozilla.org/en-US/firefox/addon/multi-account...
Personally, if I was dealing with someone who wasn't already using strong unique passwords for everything, and didn't want the burden of having a password manager, I would absolutely recommend relying on Chrome's built in password manager and having to be signed in to Chrome everywhere. This might actually be one of the use-cases that triggered the 'auto sign into Chrome when you sign into a Google product in a tab' feature, which didn't go down very well in some circles.
I believe (re)using relatively weak passwords on multiple sites is a bigger risk to privacy than Google tracking every page I visit. I would assume they track every page I visit regardless of whether I'm signed in to Chrome or not.
EDIT: Note that I'm assuming this feature in Chrome is similar to the feature in Safari, where Safari suggests strong passwords, but this doesn't prevent those passwords from being stored in your password manager of choice.
If you start using Google's password manager with their auto-suggested long complex passwords, there is no way you can remember the passwords yourself. You'll need to be logged into Google Chrome to have access to the password. Therefore, you'll need to be logged into Google Chrome to log into any website. Currently, there is not way to export passwords from one browser to another, so if all your long complex random passwords are in Chrome, as a practical matter, you won't be able to use Firefox, Safari, or Internet Explorer, you'll be required to use Chrome.
The apprehension over the feature is not about security at all (in fact, this system is likely more secure). It's about control. If you allow Google to manage all of your passwords, then you'll need Google to do anything.
Per my previous, Safari has a similar feature, which streamlines the process of generating secure passwords without needing to switch to the password manager to generate the password, and upon submission, it gets stored in the keychain, and also pops up the ability to store into 1Password via the usual extension.
Sure, all those passwords in the keychain are locked to Safari only, so Chrome, Firefox, etc are unable to access them, but that's what external password managers are for.
It absolutely nudges people away from password managers and on to Chrome. You now you have two options... (1) get a password manager on all of your devices that properly syncs with Chrome; or (2) only use chrome on your devices.
Many people are going to choose option #2. This will lead to more people relying on Google Chrome and Google Accounts, and will now you'll need to be logged into Chrome to log into any other site. It's a way for Google to become requisite, and add more power when they already have so much.
Coupled with clearing history, this should be fairly close to a much more stricter private mode.
I never made a separate browser profile for Facebook, but the moment Firefox's Containerisation was available in Test Pilot, I made a container for all things Facebook.
Or, if you'd like, you may disable auto-update.
Now in the era of WebExtensions (which are SOOO much more secure!!!) it seems they finally approved a version published by those bad actors. No idea tho if and what tracking is in there and if mozilla stuck to their guns and made them remove tracking or not.
Is there a source you're using for this info? As I visited a couple times during that period (including mid this year) and saved a personal copy of the Versions URL which listed multiple versions post acquisition available [1].
[1] Specifically: 2.1.1 (2017-10-31), 3.0.1 (2017-11-10), and 3.1.1 (2018-05-23).
You can review it yourself. There is not a whole lot of code here.
(Or human reviews are now allowed after publishing when an extension passes automated review - I'm not sure.)
On iOS, install Firefox Focus, and in Safari settings enable FF provided Content Blocker.
guess if you wait 10yrs for something as simple as an ad blocker, your expectations will be very low anyway
But yeah there is always nitpicking to do when it comes to security. No one is ever truly secure.
All this without breaking user privacy.
That being said, Brave is pretty upfront about the security of their software. They've paid $25k in bug/security bounties so far and their browser is open source. So if an update turns evil, it stands to reason that someone is going to notice.
Two points against it:
1. You stand out from the crowd with this User-Agent, easy to fingerprint you.
2. Chromium is Google (Ad company) software, like Android. Un-googling it may not be complete or full. Safest way is not using any Google software.
https://addons.mozilla.org/en-US/firefox/addon/facebook-cont...
FF extensions just have too much power and too little end-user control. At a minimum I'd like to be able to selectively disable them in private browsing mode, as Chrome allows.
Enter your credit card details to check if they've been stolen!
> Email me to subscribe to my anti-spam service!
This is precisely what haveibeenpwned asks for, as your parent wrote.
By the way, if someone from firefox team is reading this : I would _really_ love to be able to just load directories from my FS as extensions rather than having to trust someone on the internet that it does what it says it does. I love building extensions myself, but I just don't install extensions from the web anymore because I don't know what's in there (note that referring to a github repos is not enough : I have no guarantee the content of the extension is the same).