So my setup is:
- uBlock Origin [0]
- Cookie AutoDelete [1]
- Firefox's "Enhanced Tracking Protection" set to "Strict" [2]
- DuckDuckGo as the default search provider
[0]: https://addons.mozilla.org/en-GB/firefox/addon/ublock-origin...
[1]: https://addons.mozilla.org/en-GB/firefox/addon/cookie-autode...
[2]: https://support.mozilla.org/en-US/kb/enhanced-tracking-prote...
Against anti-adblock, Nano Defender is the thing. (There's an uBlock Origin mode in that.)
They're not popular extensions (11K and 6K users respectively) and aren't being reviewed by Mozilla. I'm certainly not going to review them myself, and I see no reason to trust their developers and their personal security practices.
- Firefox > Preferences > Privacy & Security > Delete cookies and site data when Firefox is closed
- Firefox > Preferences > Privacy & Security > Delete cookies and site data when Firefox is closed > Manage Exceptions
Also, what is DDG? It has its own crawlers (DuckDuckBot) like Google and Bing have (assuming Bing has, haven't read on it)? Or DDG (or DuckDuckBot) just filters/parses results from Google et al?
No script is a pain to begin with, but you come to find out that google and facebook are everywhere constantly watching. It's incredibly unsettling.
uBlock Origin is many times better (and faster)
This is not NoScript's fault of course. Some websites are including 20-30 different domains (check out maperformance.com for example) and picking and choosing to get something to work is a nightmare.
Another option is to use another web browser for online purchasing.
jomashop for instance...
Here is the source code for ublock: https://github.com/gorhill/uBlock which is GNU GPL v3.0
Adblock is run by Wladimir Palant's Eyeo GmbH. It used to be an open source project but was rewritten to what it is now and is tied to "acceptable advertising" policies and is run by a for-profit company. As always, if you aren't paying for it, you should be asking who is.
Without the preset lists of filters, this extension is nothing. So if ever you really do want to contribute something, think about the people working hard to maintain the filter lists you are using, which were made available to use by all for free.
You can contribute by helping translate uBlock Origin on Crowdin: https://crowdin.net/project/ublock
It's why we want to be good users of open source and contribute back, whether that's donating or helping write documentation, manage issues, etc.
The cost of open source is the direct cost - what it takes to build an adblocker in this case. The cost of a for-profit product is the direct cost and the profit margin - a higher number in every situation. Instead of the for profit company paying that, it's some external party and if that isn't you it's.. well, still somebody. As the saying goes, if you aren't the customer, you're the product.
Privacy badger and ublock origin seems to break almost nothing.
Adding umatrix blocks additional stuff but breaks sites. And worth running a pihole too. It seems to catch a lot even with adblockers enabled
So if blocking a doubleclick tracker will stop a video from playing on some page/site, an exception will get added to the block list to just allow it on that page/site.
It makes it 'just work', but imo it's not clear enough in the UI that this is happening and I would guess that most users don't even know.
Don't disagree there.
> Also noscript has some pretty shady sht in its history.
I haven't heard anything about that. Could I get some more info? I use NoScript pretty much everywhere and would like to know if I need to stop.
Edit: Punctuation
At the most extreme using Tor Browser and its defaults maximises privacy for any general loginless browsing.
If you're logging into services with accounts then a mix Firefox containers, uBlockOrigin, ClearUrls and Smart Referer provides pretty decent privacy.
See also: https://panopticlick.eff.org
> System Fonts Arial, Bitstream Vera Sans Mono, Bookman Old Style, Century Schoolbook, Courier, Courier New, Helvetica, Monaco, Palatino, Palatino Linotype, Times, Times New Roman (via javascript)
But as a Linux user, those are all mapped by Freetype (some to the same typeface) as many of those are copyright (? encumbered, not freely licensed) fonts:
$ for zzz in Arial "Bitstream Vera Sans Mono" "Bookman Old Style" "Century Schoolbook" Courier "Courier New" Helvetica Monaco "Palatino Palatino" Linotype Times "Times New Roman"; do fc-match "$zzz"; done;
LiberationSans-Regular.ttf: "Liberation Sans" "Regular"
.. 12 more lines of font replacement maps...
This website javascript test is measuring a heuristic, giving it a very high score (almost twice as high as anything else, "Hash of canvas fingerprint" is next) but that measurement is patently false compared to the real data. (it also reports no Ad Blocker used and I have uBlock-O fully enabled).It's almost like how Airwolf used to toss out chaff left and right to escape the bad guys, I have Earnest Borgnine in the back going "Why can't we hover like regular helicopter people?" as Firefox tosses out fake font results to Javascript sniffers.
The Resist fingerprinting and Third party isolation settings is also worth a try, it doesn't stop everything but it does prevent some of it. For usability I usually install the corresponding add-ons so I can toggle them with a button (these settings tends to break stuff).
LocalCDN may also help a bit by using local copies of commonly used resources.
I used to have an add-on that could spoof the font detection by making small random changes to font sizes, but it stopped working and I haven't found a replacement.
Then there is CSS exfiltration and rectangle readout...
I use the following extensions for browsing "security" (ha!):
Disable WebRTC
Canvas Blocker
Firefox Multi-Account Containers
LocalCDN
Privacy Badger
uBlock Origin
Disabling WebRTC isn't as much as an identifier, I imagine.
It doesn't seem possible with any of the mainstream browsers to avoid a "unique" fingerprint. RSS is a good counter-tactic.
In the end, if I have to apply defensive tactics just to read information, I will stop visiting. When I enter a store, I am unique. But I don't let the store cover me with tracers.
Then I think about how it is that adverts might zonk out my brain, thereby rendering me unable to write helpful pleasant comments that are hopefully well received by the content creators. So being an advert blocking person isn't all that bad if you contribute with engaged comments.
Last time I saw plain old http was quite a while ago.
Privacy badger
Ublock
Cookie autodelete
HTTPS everywhere
Decentraleyes
DuckDuckGo (extension) (it auto sets DDG as the browser search engine, but you can disable that)
Multi account containers - 1 for every frequently visited site. There’s an extension called temporary containers that’s interesting too
I don’t but should use noscript
Canvas blocker would freeze my browser so I don’t use it.
NextDNS is installed on every device and the router.
For mobile (ios) I use safari with Firefox focus set as the content blocker.
https://git.synz.io/Synzvato/decentraleyes
Is there an official announcement somewhere? The website doesn't indicate anything.
"uBlock Origin" is the original and real deal. The other one is a scam.
https://github.com/gorhill/uBlock (mentioned multiple times in these threads)
Discussion about the two: https://news.ycombinator.com/item?id=14335190
- uBlock Origin, most lists enabled, 3rd party iframes blocked
- Privacy Settings
- Multi-Account Containers, Temporary Containers
- Decentraleyes
I do this:
VPN on at all times
Firefox as the main browser
Firefox enhanced tracking protection set to Strict
Firefox containers enabled to isolate specific sites when I do want to log into them (Google...)
Everything set to be deleted (cookies, cache etc) when I close Firefox
Allowed cookies for a handful of sites I want to keep being logged into
DuckDuckGo as the main search
uBlock Origin on with default blocklists. I really love the "element picker" feature which allows me to remove annoying elements
- uBlock Origin
- Facebook Container
- Decentraleyes, ClearURLs
- HTTPS Everywhere
- Privacy Badger.
- Redirect AMP to HTML
- Terms of Service; Didn’t Read
- Smart Referer
- User-Agent Switcher
Next to that I'm using Bitwarden and Floccus (Nextcloud Bookmarks) for self-hosted decentralised password and bookmarks sync.