Firefox Privacy How-To Guide
restoreprivacy.com
restoreprivacy.com
The only downside is if you decide to undo a setting in user.js you’ll also have to make the same change in about:config.
Another benefit to using a user.js file is that your changes are persistent. If Mozilla changes a setting via an upgrade, like they did with experiments and plan to do with DoH, your changes aren’t overridden.
> The only downside is if you decide to undo a setting in user.js you’ll also have to make the same change in about:config.
You could change it to the inverse/default explicitly in user.js?
And it suggests you disable HTML5 EME, which has nothing to do with privacy at all. Whatever your views on DRM, that’s not a privacy concern.
This is yet another “opinionated guide to Firefox” that misleadingly uses privacy to convince people to read it.
Do not harm your friends and family’s experience by making the changes suggested in this guide.
DRM requires proprietary software, and effective DRM requires obfuscated proprietary software. How do you know it's not harming your privacy, even accidentally?
If the data can't be relied on to contain any specific useful information (even whether it's default or not), then it's effectively useless for tracking, and you've not just hidden yourself in the largest category for those bits of tracking data, you've effectively made them entirely useless for tracking you (which is more effective than hiding in the biggest group).
To summarize and clarify, I applaud their actions wholeheartedly. :)
Does the DRM really not leak data about the content you're watching to the license server?
https://www.aliexpress.com/item/32678087225.htmlYou're taking it for granted that the reported data is adequately anonymized to the point of being impossible to make any inferences about individuals, which is a huge leap, not only in trust, but data science.
As mentioned later in the article, Mozilla is based in a country with sweeping surveillance legislation, and so should not be trusted to hold or process [potentially] personally identifying data, no matter how well intentioned they themselves may be.
Firefox decision makers actively consult the telemetry data when making decisions. If you've disabled telemetry and I haven't then my experiences count double and yours are discarded entirely.
For example, TLS 1.0 (and 1.1) is deprecated and will be disabled by mutual agreement among browser vendors in 2020. On the road there, Firefox are watching their telemetry to determine how many users are affected and how much effort it's appropriate to put into mitigating difficulties for those who have systems that can't be upgraded.
For me this will go fine, I don't have any systems that aren't capable of TLS 1.2 and very few that can't do TLS 1.3 so my telemetry data will show all is well. Maybe you are not so lucky. Too bad, you've disabled telemetry so nobody is coming to help. Bye.
Yours won't count double unless there are only two users, in which case decision makers will likely disregard telemetry data all together.
You're right that the individual's usage pattern isn't directly considered, but for most users that won't matter because their usage patterns aren't uncommon. If you're one of a small group of users that do $weirdThing and that group is so small that your individual telemetry data contributes significantly, a) that group will likely be ignored and b) anonymizing is a problem you may not want to be involved in as a user.
I've not worked at Mozilla, but that's how I've seen it happen just about every time I ever saw telemetry get cited in situations I had some insider insight into.
Edited to add: my comment makes it sound like there is some other way to tell from telemetry data which users are more socially influential. That's not the case as far as I know.
A single power user who happens to be a system administrator for a public school district has the power to install or uninstall hundreds of firefox instances. And it was power users that spread word-of-mouth awareness of firefox the most during the days when firefox was actually growing. Continue to treat them as equals to all other users and I predict firefox will continue its tragic slide into obscurity.
The way I see it, "data driven" design is often similar to an over-reliance on standardized testing or zero-tolerance policies; a way of abdicating responsibility for a decision and covering your own ass. "Users hate this but I'm not to blame because I was just going off the data" has become the new "Sure everything ended up going sideways, but can you really blame me for buying IBM? Nobody gets fired for buying IBM."
Where is the data to suggest that data-driven design actually produces the desired results? That seems to be missing.
It increases the chances that Firefox developers address performance and other problems that are affecting you. If you disable telemetry, your problems "don't count" when doing data-driven prioritization of development work. (note: I'm a Mozilla employee, working on gecko)
[1] https://www.gijsk.com/blog/2018/10/firefox-removes-core-prod...
But when the matter is less concrete because the value of one particular minority demographic is hard to pin down in the collected data (from what in the mozilla's telemetry data can you persuasively derive the value of power users who tell their friends and family to use firefox? Uncovering those relationships would certainly violate users' privacy..) then "data driven" decision processes will by default assume all users have equal worth.
I think that even if telemetry had had different results, they would have then just ignored it for making that decision. Or they would have changed the interface to hide a feature, and then when users used it less, they would use that as justification to remove something.
There was really no good reason to remove it. They quantified the costs of keeping it at something like $5000. How much do they spend translating Firefox into obscure languages that nobody downloads? Or on catering for their galas and fundraisers? Or any other stuff not related to writing software?
There is much more robust discussion on this already. https://news.ycombinator.com/item?id=18202028
I don't doubt that someone at Mozilla could de-anonymize that data, but I have enough trust in the organization that they won't
> Mozilla is based in a country with sweeping surveillance legislation, and so should not be trusted to hold or process [potentially] personally identifying data, no matter how well intentioned they themselves may be.
Even if Mozilla are completely trustworthy, nothing is stopping them from being forced to give up all that data with a national security letter (accompanied with the customary gag order), to be mined for insights by alphabet agencies.
I can /maybe/ if I squint really hard, imagine some murder detective figuring out a way that a value in their suspect's telemetry data helps prove they did it. Only thing is, the murder cop can just ask a judge to let them go take the suspect's whole PC, no need to bother any Mozilla employees with crazy requests.
"Boss, I just got done with that $500Bn compute job to work out a guy's password as you recommended, rather than just resetting it by email as I'd originally thought of doing. As you pointed out the government can just raise income taxes to pay for it"
"Cool, OK, now I want you to go threaten this company CEO. They collect optional telemetry data and we'd like to extort that CEO into telling us whether a user with this IP address has an Intel or AMD processor"
"Shouldn't I just get them to export the data from their software directly rather than bother with all this? Or just use any of these broadly available malware techniques to get the answer for the user we care about?"
"No, that would be simpler and cheaper, if we do it this way only a true genius like zAy0LfpBZLC8mAC would realise what we're up to, as ever our goal is collect anything but only in the most elaborate way possible so that it's tremendously expensive and difficult"
"OK, but what if the user has disabled telemetry?"
"Then we'll have to think of an even more expensive and elaborate way to collect data. We have a programme to teach goldfish to swim differently depending on whether they have recently seen anybody wearing a T-shirt with a specific logo design on it."
That one pissed me off, just on principle.
I'm not sure exactly what's happened in the last 10 years or so but, at some point, everyone apparently just decided it was okay to start spying on their users (read: "telemetry"). Mozilla and some others, at least, allow you to "opt out" -- although you should never have to! -- as if that somehow makes it okay.
Then, a while back, they decided they were going to go ahead and send in some "telemetry" even if the user has explicitly disabled telemetry!
I can easily remember a time -- and it wasn't that long ago! -- when slipping in even the slightest hint of "telemetry" without a clear, explicit "opt-in" from the user would have been absolutely unheard of.
Mozilla doesn't have much of a user base left. You'd think they would try to avoid alienating us and pissing us off.
---
On a related note -- and with the above in mind -- I recently (within the last several days) started working on my own .js "preferences" to lock Firefox down as much as I can. I've just posted it [1] if anyone is interested (a lot of it was taken from [2]).
Disclaimer: it's very much still a work-in-progress, likely breaks things that I haven't noticed yet, and almost certainly is not what you want to use. I'm fairly happy with it at the moment, however. (There's a bunch of "notes to self" in there that I tried to remove; if I missed any, please just ignore them!)
[0]: https://blog.mozilla.org/data/2018/08/20/effectively-measuri... (see the "Telemetry Coverage" section)
And where, and when. That's pretty sensitive information.
Both can be addressed by batching uploads, as described in the gp comment.
> the clientId, a UUID identifying a profile and allowing user-oriented correlation of data
[1] https://firefox-source-docs.mozilla.org/toolkit/components/t...
On line anonymity is a myth. Why do we keep spreading it?
Online anonymity is an entirely different topic than whether this one data set collected here is effectively anonymized.
> Technical data: Firefox sends data about your Firefox version and language; device operating system and hardware configuration; memory, basic information about crashes and errors; outcome of automated processes like updates, safebrowsing, and activation to us. When Firefox sends data to us, your IP address is temporarily collected as part of our server logs.
> Read the telemetry documentation for Desktop, Android, or iOS or learn how to opt-out of this data collection on Desktop and Mobile.
If that's OK for you, fine. Not for me.
My only real quibble is that I don't think people should turn on DNT if they can help it. Most sites don't respect it, and for some sites it's actually another tracking vector on its own.
I believe if you turn on fingerprinting protection in Firefox it gets automatically enabled, so this isn't a suggestion anyone can practically act on. But if I had the choice to disable DNT, I would. I think we should deprecate any tracking protection that relies on good actors respecting our choices.
But overall, good article.
Leaving it as default makes you hide in the crowd
Canvas/WebGL fingerprinting is a good example of this. Yes, very few people block it, but the fingerprinting for canvas is so individualized to each device that there is no hiding in the crowd if you leave it enabled. You're hiding in a crowd of size 1.
Think of it like wearing gloves during the summer. Yes, that's unusual. But a human fingerprint (except in rare-ish cases) will usually be good enough to track an individual person. In a world where people are regularly collecting fingerprints or tracking them around town to figure out who's been in what stores, being unusual is preferable to being unique.
There are a few settings (normalizing screen sizes) where the benefits aren't so clear-cut. But at the very, very least, you should be doing stuff like turning off webRTC/webGL/canvas. The majority of changes being listed here are strict improvements to privacy.
Long answer, I'm also curious about this. I feel like the future of fingerprinting resistance isn't refusing to give up information (since sites can block you or force you to turn the settings back on) -- it's lying. Don't block microphone access, just feed it white noise. Don't block the location, just spoof it.
BUT, a bunch of people who are smarter than me have decided that zeroing out the canvas is better than making it return random values, so for the moment, I assume there's something they know that I don't.
WebGL fingerprinting, in my investigation, seems to be identifiable by gpu vendor, and potentially by generation, but not individual GPU.
So there's still bits of info, but not as bad as they used to be, or as bad as people generally fear.
Any chance you could point me to a source on this?
You're confusing privacy and anonymity. They can be mutually exclusive.
Improving anonymity is reducing the odds that data can uniquely identify you. Making changes to Firefox harms anonymity because very few people deviate from defaults.
For example, turning off Javascript prevents a site from knowing much at all except header information like User-Agent. So it can't draw a canvas fingerprint nor measure your screen resolution, but it can still record the fact Javascript was disabled - a rare event.
OP is correct: the changes make one 'stick out like a sore thumb'; but incorrect in asserting users are 'more fingerprintable'. Improving privacy may reduce anonymity, but losing anonymity does not necessarily affect privacy.
While anonymity and privacy are theoretically separate concepts, many current techniques used to compromise privacy on the internet are dependent on de-anonymization.
None of the data your browser leaks is being used to directly compromise privacy. Your screen resolution, user-agent, canvas fingerprints, etc aren't private information. Their only utility is to support de-anonymization, which in turn allows a compromise in privacy by aggregating your behavior.
I only have one extension, 'muBlockOrigin', installed in Firefox and have been using that for many years, so I'm sure the extension is not getting in the way of loading Google Sheets. So that leads me to believe that Google is probably supporting less and less of Firefox.
I don't think Google is maliciously making FF slower on their products, but I believe they simply don't care to tweak/tune performance on FF like they would have years ago. As everything else google does, the devs metaphorically cover their ears and proclaim "lalalalalala we are google we don't care!" ...and it's more telling every passing year.
if you only need basic functionality then libreoffice would be a good place to start since it's cross platform and if youre running Windows then there's a portable version that you can bring around on a usb.
I use syncthing myself to sync my documents between all my devices. but there lots of other options around like resilio sync, nextcloud etc there's not really much of a reason to be tied to Google anymore
I don't remember the exact items anymore, but seemingly innocous privacy-related changes I did some time ago from a list very much like this broke the ability to paste to google docs (which was a bit confusing, since I noticed it weeks later when it "just" didn't work with no messages hinting why) and the integration for the Evernote WebClipper plugin; and it was a bit of a hassle to find which changes I need to revert.
https://developer.mozilla.org/en-US/docs/Mozilla/Preferences...
If someone else is in the habit of randomly selecting text and they're using linux, they may want to disable at least `clipboard.autocopy` if they don't use it. No reason to simply tell websites every selection you do, IMHO.
all their talk about privacy is hot air as long as that is true.
so this pretty much invalidates my other two comments here.
sorry could you explain in more detail please ?
I find it rather unlikely that mozilla needs GA on that page, considering that firefox is sending tons of telemetry to their own servers.
You're effectively flipping another bit that de-anonymises your browser a little bit more, and I can't why a bad actor (the people you're actually worried about) would honour it.
Regardless, Outline link for anyone who can't read: https://outline.com/T3fGAk
If Outline doesn't load, try enabling referrer headers. I always forget to do that and get annoyed when Outline links break. I should probably just switch to a different service at some point, since I refuse to leave referrer headers enabled permanently.
Or - very much less likely - a bad guy is attempting to MITM you and they've decided to imitate Cisco Umbrella so that people aren't interested in helping you because they assume you're just at work goofing off on someone else's network.
These all call back to google and/or mozilla, cloudflare.
Once you've done your tweaking, have a look at https://amiunique.org/ to see how anonymous you really are.
But there's no denying that site is a good handy guide to things in Firefox that can be tweaked to suit one's privacy stance.
privacy.resistFingerprinting = true
breaks whatsapp web login page, interestingThis breaks copy-paste for quite a few rich text editors (it was the reason why pasting into Riot didn't work for me for several months). So, some of these options can subtly break harmless websites.
^ webrender gfx all, for example, seems to break my Firefox Nightly every few months, which I duly report and see fixed the next day or so, but one time it took a couple weeks for them to find the crash!
There are plenty of good firefox forks out there.