Firefox for Mobile now supports NoScript, PrivacyBadger, HTTPS Everywhere
blog.mozilla.org
blog.mozilla.org
Same for Firefox on Linux btw.
On mobile, for example, I sometimes get blank pages when trying to visit a website and it will stop working until I restart the phone (internet is good because any other browser works). It is very rare to happen but it does.
BUT, I am also using uBlock Origin with Javascript blocked by default. This makes a huge difference.
Otherwise the current Firefox mobile is considerably slower for me than Chrome, especially on uncached sites. Haven't tried Preview yet.
I'm a lot less interested in the mechanics of using F-Droid than I am in the no-malware guarantee that F-Droid effectively provides.
PS: I just checked - uBlock is available in Preview, woohoo, I can try it more now :) . Strange that it is the only addon available in my app, no NoScript, Badger and HtttpsE there (latest version).
More recently it also stopped crashing with a lot of tabs "bookmarked" (and does not loose them on a crash).
Also good luck tapping on a small link in Firefox mobile, tap targets are bigger in Chrome than in Firefox.
It’s interesting to see a relative to that sentiment show up about browser addons. Thank you for sharing!
I really wish people would say what they mean when they make comments like this. It's extremely vague and some of the obvious meanings are either subjective or can be easily shot down:
* It has more / better features? No, it seems to have fewer features, at least if add-on support is a good indication.
* The GUI is better? Subjective at best, I find it worse.
* Web pages load faster / JS execution is faster? This is also subjective unless objective measurements are used, but this is what people most often mean.
I've attempted to measure the objective speed of the browser myself. I've consistently found: Javascript performance is not significantly improved by the new browser. As measured by Speedometer [1], the new Firefox is less than 10% faster than the old one, and both are barely half as fast as Chrome on the same device. The performance of the GUI is also lacking: it takes so much more time to open menus and use GUI features that the difference is actually clearly visible to the eye. [2]
Basically, I think it's very easy to be deceived by placebo effects when what we're talking about is the apparent performance of a browser. The objective metrics I've been able to capture often show the new FFA to be as slow or slower than the previous version, and when it's faster, it's not by much, at least (in my opinion) not close enough to catching up to Chrome to justify a complete browser rewrite, with everything that has entailed.
[1] https://browserbench.org/Speedometer2.0/
[2] See: multiple open issues for animation jank. I found these with a quick search. https://github.com/mozilla-mobile/fenix/issues/10065 https://github.com/mozilla-mobile/fenix/issues/7797 https://github.com/mozilla-mobile/fenix/issues/8863 https://github.com/mozilla-mobile/fenix/issues/9746
Perception is all that matters with software anyway. Even if it isn't technically faster, it can still be better if it feels faster, which it does to me.
I guess what I'm concerned is illustrated by the following thought experiment. Suppose you took the old Firefox for Android code base, and re-released it as "Firefox Preview" with a prominent badge "now 20% faster!". Would you see glowing reports by users on forums talking about how much better it is? I think you would. The only way around that (as far as I can see) is to try to do objective measurements or screen recordings and find out if there's a real difference.
Again, not intending to put a damper on your personal experience with and enjoyment of the new browser. Just some thoughts about what's a fairly common comment on articles like this one.
Btw if you take "nobody argued with me" as evidence that you're right, you're gonna end up with a warped worldview.
It sucks that this cannot be available on iOS because of Apple’s restrictions.
But I’m happy with Firefox Focus, which is my daily driver browser on iOS (and what I’m using to write this too). It has a built in content blocker. It doesn’t upgrade HTTP requests to HTTPS, like Brave does.
For ad and tracker blocking at the DNS level, I use NextDNS with some blocker lists enabled for my account (I recommend you check it out). It has made things better on other apps too.
Apple users have exactly what they want. It doesn't "suck": it's the very definition of walled garden. Your device is not yours, you are just allowed to play in there, under adult supervision. If you do not want walled gardens, just stop paying for them.
There is no "just stop" for people who need or want capabilities that only Apple devices have, but don't want the walled garden. It is not a free choice, not what those people want, and therefore sucks.
The brutal fact is there are only two mobile OSes where essential apps are available (such as banking), and Android being the other one, is not suitable for all users and has its own walled garden issues.
"We’re happy to confirm that GeckoView is currently building support for extensions through the WebExtensions API. This feature will be available in Firefox Preview, and we are looking forward to offering a great experience for both mobile users and developers. Bringing GeckoView and Firefox Preview up to par with the APIs that were supported previously in Firefox for Android won’t happen overnight. For the remainder of 2019 and leading into 2020, we are focusing on building support for a selection of content from our Recommended Extensions program that work well on mobile and cover a variety of utilities and features."
https://blog.mozilla.org/addons/2019/10/23/fx-preview-geckov...
https://blog.mozilla.org/addons/2020/02/11/faq-for-extension...
My guess would be that they'll try to make it curated-only unless users complain too much. Or maybe allow other extensions behind serious warning screens.
If that ends up being the case, depending on their review process, it kinda sucks for any potential new extensions created after the ecosystem lockdown, that won't get a chance to attain enough popularity to be relevant - unless Mozilla agrees to do a review for any project that asks, which doesn't seem likely.
All software stores can be pressured to remove content. Keeping the ability to load non-store extensions fixes that specific deplatfoming problem.
Making them explicitly type out "YES I AM AWARE THIS EXTENSION COULD EASILY CONTAIN MALICIOUS CODE AND I TRUST THE SOURCE: " + the domain name, in all caps before proceeding could be enough to catch most cases (unless too much legit software gets forced behind such warnings, where it would lead to that fatigue problem again).
Desktop Chrome doesn't let you have an outside extension without showing a warning on every single startup (even if it's an extension you are currently developing), but that could be because on a desktop OS, other applications could add such extension into Chrome without a user action. On mobile, where apps are isolated from one another, that problem doesn't exist, so maybe such strict restrictions shouldn't be necessary.
I know we often say "the user is dumb, therefore software should patronize them", but that really only goes so far.
On hindsight it looks like a balancing act where single features are evaluated for their danger, etc.
Then, at some point, there's no software left that allows users to achieve their goals, because "you wouldn't want to do that", "stupid people could accidentally use it", "your use case is too fringe to justify catering to it anymore", etc.
We're pretty much at this point now regarding browsers on Android, where there's only Chrome and it's skins (that let you do nothing) and Firefox.
I can't believe the sensible thing to do would be to cut uncurated, non-store extensions from Firefox as well.
It would be a huge loss for the whole ecosystem just to make a few Firefox installs (from an already small install base) a tiny bit less compromisable.
It's not just a saying, it's supported by real-world situations that actually happened, and that you can be pretty sure will happen again. That's the context for the decisions that platform owners have to make.
E.g. not too long ago, Dark Reader users received this notice https://darkreader.org/blog/attention/ about malware clones of the real extension that apparently thousands of people had installed (from the stores). It is events like this that influence these decisions.
>Then, at some point, there's no software left that allows users to achieve their goals, because "you wouldn't want to do that", "stupid people could accidentally use it", "your use case is too fringe to justify catering to it anymore", etc.
That's basically the Apple mindset. It's a well known fact (e.g. his biography) that Steve Jobs didn't even want any third party apps (other than super limited web-"apps") on iOS initially, and had to be convinced otherwise.
I argued they shouldn't do it despite knowing that people will have the ability to compromise themselves.
If too many users install a crappy, buggy extension that slows everything down, they know they will get a reputation for being a buggy and slow browser, regardless of whether it's their fault or not. It also creates incentives for extension authors to follow best practices where possible.
For people who really care about choices for themselves, it's an open source project, it's not that hard to make an unrestricted fork under a different name that automatically tracks the upstream (as long as Android sideloading stays intact, plus it could also be published in Play Store as long as you don't use any of their trademarks). As far as I know there is nothing unique in the official branch that you would miss out on (when compared to e.g. missing out on Netflix or voiding warranty with custom ROMs - there are no such tradeoffs with simply using a fork of a browser).
It only creates a much higher barrier to adoption for unapproved extensions (because you now have to convince users to install another browser), so many developers simply won't bother, but that's not an issue if I understand your argument correctly.
Even without the linked FAQ it appears to be pretty straightforward that Mozilla values control given that they're about to change an open, decentral system to a tightly controlled curated app store.
It's just that this wasn't always the case. See, for example, point 5 of their manifesto where Mozilla states: "Individuals must have the ability to shape the Internet and their own experiences on the Internet." or in point 6 where they emphasize: "decentralized participation worldwide"
> If too many users install a crappy, buggy extension ... they will get a reputation for being a buggy and slow browser ...
I have two concerns with this argument: The first is practical:
Is that a big problem? Are there numbers about large amounts of sideloaded extensions causing the reputation of firefox for android to drop? AFAIK sideloading is neither very common nor particularly rich of scandals. And even your earlier example was concerned with malicious extensions in Mozillas own extension store.
The old "Firefox for Android" enjoys a 4,4 star Play Store rating, compared to Previews also excellent 4,2 Star rating.
The second one is ethical:
Mozilla does not try to be the most successful browser at any cost. They provide valuable capacities to the Android ecosystem and drastically increase software freedom on the platform. If their goal were popularity, they would be much more successful by adopting Chrome under the hood and spending all their money on marketing.
Even your later argument features the condition "as long as Android sideloading stays intact" which itself already shows how dependent on a few central features the platforms freedom already is.
> it's not that hard to make an unrestricted fork under a different name
I don't see how trusting users to recompile an unrestricted firefox fork goes well together with not trusting users to sideload a browser extension.
> As far as I know there is nothing unique in the official branch that you would miss out on.
Right now it's soft paywall blockers that are left out. (They just change referrers and cookies for specific sites.) But potentially it's all extensions, since Mozilla the corporation can be pressured into legal compliance.
In the future this might very well interfere with peoples ability to avoid censorship.
At the time at which centralizing a system is suggested it's almost never problematic, because problems only get apparent after centralization went into effect.
I'm not aware of any, but that could be because alternative browsers are not that popular on mobile in general.
The reputation of Android itself has definitely suffered due to sub-par apps (battery draining, slowdowns etc.) and downright malware (sometimes promoted via Google's own ad network).
>And even your earlier example was concerned with malicious extensions in Mozillas own extension store.
It seems they disabled sideloading on their desktop browser some time ago, so that was the only way it could've happened anyway.
https://blog.mozilla.org/addons/2019/10/31/firefox-to-discon... https://blog.mozilla.org/addons/2020/03/10/support-for-exten...
I don't know whether they currently do any review for extensions in the store (even automated one), or just manually ban bad actors.
(There is an additional reason to disable sideloading on desktop that I mentioned in a previous comment - other destkop apps installing shit without user action/approval, which cannot happen on mobile due to app isolation).
>I don't see how trusting users to recompile an unrestricted firefox fork goes well together with not trusting users to sideload a browser extension.
- Their name wouldn't be on it. To publish in Play Store, a fork would have to scrub all Firefox branding from the app (see Iceweasel), and would then assume all responsibility.
- Let's be honest, in practice, such a fork would be mostly used by highly technical users who are more likely to know what they're doing. Non-technical users would be far less likely to install it than some random 3rd party extension they come across. The Firefox name is fairly well known outside of tech circles. The name of some random fork would not be.
>In the future this might very well interfere with peoples ability to avoid censorship.
I agree that there is a risk that their official binary distribution could gain exclusive abilities in the future which are not part of the open source version (at which point Firefox would technically no longer be open source, e.g. Chrome vs. Chromium). Care should be taken that that doesn't happen.
Anyway, at the moment I'm far less concerned about extensions that they specifically want to ban/censor, and far more about 3rd party developers potentially losing the ability to innovate, if the review process is only practically available to popular established players (who got popular while the ecosystem was still open) - because then how would a new project even get to that phase? That may or may not be an issue though, we'll see how it turns out.
So I misunderstood (only skimmed through) those 2 links about desktop Firefox sideloading, they use a different meaning of that term than what it commonly means on Android.
They only blocked 3rd party apps from installing extensions by themselves (which is good). User-installed extensions from outside of the Mozilla store are still allowed on desktop Firefox.
I'm curious whether the ability to add arbitrary extensions is just ifdef'd out of the play store version, or whether this feature is just fundamentally unimplemented. I don't intend to switch to a different browser from current FF on Android that does not support the extensions I use.
And now all the Apple fans can tell me why it's so great that only WebKit is allowed on iOS. I'd like to run those extensions an on iOS browser and others but to do that I'd have to actually be able to ship a different browser engine.
I’ll keep using Firefox on desktop for as long as it exists, but I kind of just faced the music on Firefox for iOS.
Beta? Nightly? Preview? Preview Nightly? (The other one is the stable branch)
"Firefox" / "Firefox beta" / "Firefox nightly for developers"
"Firefox Focus"
I'm not sure if this means that Focus will be deprecated in favour of Preview, or will it remain a stripped down version of Preview.
I'm under the impression Firefox Focus on Android uses the native (Chrome) renderer, not the the Gecko engine.
Preview on the other hand is the name of a 100% different app (new codebase): it is intended to eventually replace the legacy Firefox app
Transitions/migrations can be confusing times
Opera (5): https://play.google.com/store/search?q=opera&c=apps&hl=en_US
Chrome (4): https://play.google.com/store/search?q=chrome&c=apps&hl=en_U...
Currently there is kiwi browser on Android not sure if they have for ios as well, which is chromium based and support extensions.
Recently the developer also make it open source. Shout out to the devs. https://github.com/kiwibrowser/android
I have trouble getting used to the new UX.
I keep hitting the address bar to open a site from my top sites in the current tab. That used to work, now it just opens the search interface. Instead you have to hit the -- much smaller -- tab overview button to open a top site in a new tab. Which means I end up having to manually close old tabs all the time now, something I don't remember doing. (To be fair, Chrome works the same way.)
I don't know how I'm supposed to use the new Collections feature. It's extremely prominent in the UI, I assume everybody else must be finding it super useful?!
They broke the offline reading list? You used to be able to bookmark a page in Reader Mode and have it available even when there is no connection (subway, airplanes). Instead of promoting this really neat (and given that Reader Mode is still a thing, cheap) feature, I think they just got rid of it. I had like a dozen of long articles in that list I still wanted to read (I think the bookmarks are still there). Hopefully they'll restore it before it transitions from Beta to Release, but who knows.
I've wanted a feature like this for years but I had no idea it already existed! Thank you for this info. And yes, please don't break it, Mozilla.
You can run a browser in an interpreter but anything modern would be very unpleasant to use that way.
> apple won’t let you publish an app that can
Agreed, but we're talking about whether you can technically make such an app, say to run in dev mode on your own personal device.
https://siguza.github.io/psychicpaper/ is a recent writeup that includes more details on (escaping) the limitations.
Safari is a special case. It is allowed to use JIT and writable executable pages, but this is not allowed for third party apps.
It is definitely technically possible on iOS, but a significant challenge for third party developers unless using a jailbroken device.
It's still built on WebView.
iOS devices are just not suitable for browsing the internet as we know it I'm afraid.
I will get another device for internet browsing on the go just because this is so annoying. Not even on iPad where you kind of have the real desktop browser experience you can use add-ons.
If you’d rather just use Safari instead of a branded skin, you can install your own content blockers.
The app HTTPS4All uses the same rule set as HTTPS everywhere:
https://github.com/bouk/HTTPS4All
For script blocking, AdGuard for iOS supports custom rules. Try:
*$script
And to whitelist: *$script,domain=~example.com,~example2.com
Kind of a hassle. Again, Firefox could just include this in their skin of Safari.1. Firefox: end-of-life browser built on legacy Firefox engine
2. Firefox Preview: work in progress, soon to replace the old Firefox, rebuilt from scratch on new engine
3. Firefox Focus: a minimal/reduced/simplified browser first developed to pilot the new engine
Klar is just the German name for Focus.
For example Firefox Lite: https://play.google.com/store/apps/details?id=org.mozilla.ro...
It appears to be an "Emerging Market Experiment" run by Mozilla Taiwan[0]
It also appears to be heavily based on or be a fork of Firefox Focus/Klar[1]
You can also try an ad blocking app like AdGuard.
Or set up something like PiHole at home (or VPS) and use a VPN to connect to your home network (or VPS).
https://www.infoq.com/news/2019/08/geckoview-firefox-preview...
https://old.reddit.com/r/firefox/comments/ep3tbx/eli5_what_h...
GeckoView is completely orthogonal to Project Quantum. (I work on the GeckoView team).
According to this GH issue[1] it is possible at least for the sync server part (not for the full account management), but I don't know if it made it into a stable release.
Turns out "now" => "soon". The extensions in question, linked in the post, still display the same message of not being available for Android, and the article says the change will be within a few weeks:
"These add-ons will be available in Firefox Preview within the next 2 weeks."
Edit: Sorry, I was referring to Firefox mobile, and this is regarding Firefox preview, which I don't have any actual experience with. I'm not sure how much applies.
"With Dark Reader, websites on mobile will be easy to read when the lights are dim. The extension automatically inverts bright colors on web pages to offer an eye-pleasing dark mode. There are a number of configuration options allowing you to customize your experience."
At that point I'm just going to switch to Brave.
Experience on the mobile website is shit in comparison especially on slow devices. I use Firefox mobile with the same extension + ublock origin but, as someone who hates installing apps when websites should do, do yourself a favor and don't ditch Firefox for Brave, try NewPipe, it's worth it :-)
Same thing for the Slide app to go to Reddit by the way.
This looks very positive but I don't understand it, I have the extensions installed on my mobile since ages. So I look at the text and it says that it is based on recommended extensions. Recommended on what criteria I always wondered ? Business or security friendly? Or user friendly? How come uBlock is not recommended? That means that "recommended extensions" is not only a label for user assistance but also part of Firefox strategic decision making, oh my.
Is it a ploy to finally embed them to the severely limited IPhone experience as preexisting features rather as extensions, a long con to bypass Apple restrictions through initial Android introduction?
As I said I don't see what will change for me, I have already installed them for years. And they will stay installed until they become unavailable due to one strategic decision or another.
My major complaint is the tab management and the New Tab page. To be honest it is the worst I've ever seen. I hope that Mozilla invest much more on UI/UX.
[1]: https://microsoft.github.io/microsoft-ui-xaml/img/performanc... (drawing a heart over a picture of a dog)
https://search.f-droid.org/?q=firefox
(edit: confusion)
Another vendor would be bragging about how much of third-party functionality they have built in.
The app HTTPS4All uses the same rule set as HTTPS everywhere:
https://github.com/bouk/HTTPS4All
For script blocking, AdGuard for iOS supports custom rules. Try:
*$script
And to whitelist: *$script,domain=~example.com,~example2.com
Kind of a hassle. Mozilla could just include something like this in their iOS browser skin of Safari.Has this changed?
Also browser extensions aren't allowed on iOS due to Apple's policy. AFAIK you can't build your own browser engine that does JIT, you can't do remote code execution.
And yes, Safari’s content blocking is very limited. You couldn’t inject any of no-script’s neutered scriptlets, for example.
In this sense, Android has an advantage over iOS because it isn’t so restrictive.