Iceraven – Firefox for Android fork with more add-ons and configuration options
github.com
github.com
One thing that is still missing from Iceraven, Mull, etc. is the ability to sideload add-ons that are not published on addons.mozilla.org. Currently, anyone who wants to use a private Firefox add-on that is not suitable to be published on AMO must install v68 of Firefox or v68 of a fork like Fennec F-Droid.
Edit: In one of the Iceraven issues on GitHub (https://github.com/fork-maintainers/iceraven-browser/issues/...), someone recommended a Firefox for Android fork called SmartCookieWeb-Preview for sideloading .xpi add-on files into Firefox from arbitrary URLs: https://github.com/CookieJarApps/SmartCookieWeb-Preview/. The preview app is not available on F-Droid yet, but I'm going to try it out.
Edit 2: It worked in SmartCookieWeb-Preview. I had to go into about:config and set "xpinstall.signatures.required" to "false" before sideloading the add-on in the settings (Advanced settings > Sideload XPI). I hope this app makes it into F-Droid soon.
The other part of the issue is that I don't think I should have to ask Mozilla for permission to use a private add-on in Firefox on my own device, or show Mozilla the source code to the add-on before I can install it. What I do in a web browser on my device is not really Mozilla's business. Mozilla lists privacy as Principle 4 in its manifesto, so I think they should be able to understand this reasoning:
> Individuals’ security and privacy on the internet are fundamental and must not be treated as optional.
1. Visit the addons.mozilla.org page of any add-on. Example: Cookie AutoDelete - https://addons.mozilla.org/en-US/firefox/addon/cookie-autode...
2. If you are on a mobile browser, switch to desktop mode.
3. Tap or click "Add to Firefox".
Results:
- Prompt to install add-on: Firefox v68 (Android), Fennec F-Droid v68, Firefox v95-97 (desktop, all channels)
- Prompt to download .xpi file: Firefox v95-97 (Android, all channels), Iceraven v1.14, Mull v95, Fennec F-Droid v95
The results are exactly the same for any .xpi (signed or unsigned) that I self-host on another website. If you get different results, or if I'm doing it wrong, please correct me.
- Add-on: https://addons.mozilla.org/en-US/firefox/addon/bypass-paywal...
- Source: https://gitlab.com/magnolia1234/bypass-paywalls-firefox-clea...
It's included in Iceraven's default add-on collection.
I'm very surprised this one is available in the mozilla catalog and the original isn't.
USER=16201230
COLLECTION=What-I-want-on-Fenix
cd /data/data/org.mozilla.mozilla.firefox/files
curl -o mozilla_components_addon_collection_*.json "https://addons.mozilla.org/api/v4/accounts/account/$USER/collections/$COLLECTION/addons/?page_size=50&sort=-added"
touch -a -m -t 203012300130.00 mozilla_components_addon_collection_*.json
edit: remove fennec fdroid because TIL that it already has the same add-on override that the FF nightly has. So there is no need for this hack if you have fennec.Thank you!
The biggest thing I miss is full add-on support. Not having CleanURLs and an AMP redirector suck despite add-ons existing for desktop that don't really need a mobile UI.
Which filter list is this? I didn't realize ublock has link rewriting functionality.
You can create a custom collection on a desktop and then override that Mozilla's collection within mobile Firefox's settings: https://blog.mozilla.org/addons/2020/09/29/expanded-extensio...
You can install any add-on available on the desktop like that, but your mileage may vary of course.
I don't see how that's arbitrary, I see it as a well thought out process, even if I wish more add-ons were added to that collection.
I agree that there should be more allowed add-ons. Engineering didn't put in all the effort to implement the add-ons APIs on Mobile only for it to be restricted to such a small set. Unfortunately that's a product decision.
I would assume running nightly is less than ideal for regular browsing
They're not maintained by Mozilla, but they're "recommended" and are reviewed more thoroughly.
(I used to work on Firefox for Android)
Can you offer any insignt into why Mozilla makes up jump through all these hoops just to install extentions?
- they don't want expand that process further, because it's counter to the direction that AMO has been moving (from manual pre-publication review of all public add-ons towards automated checks and only manual post-publication spot checks)
- running add-ons in a separate process as on Desktop isn't possible, because on Android secondary processes can get killed at any time, which add-ons aren't set up to handle correctly
For some reason I've only seen this explanation buried somewhere inside some Mozilla's Discourse forum (I think, if I remember correctly), but I think not much (if at all) as an explanation in the Github issue tracker and certainly never on the official Add-ons blog.
Though I have to admit that even if the above explanation was given a wider airing, for me it already smacks too much of "the safest computer is one you never turn on" and I'd still be unhappy about the add-ons situation and continue complaining.
That's true (though it will probably improve as WebExtensions evolves toward service workers), but engineering wasn't hung up on that.
https://blog.dbmiller.org/2021-08-19-using-fennec-or-mull-fo...
Fennec is also great because it doesn't include Mozilla's sponsored stuff as well.
F-Droid sort of breaks the signature enforcement model because apps on F-Droid are signed by the F-Droid server, rather than the individual app developers.
If you trust the app developer (as you should, especially with proprietary software, but also with complex/harder-to-audit open source software like web browsers), the "developers sign their own apps" model is probably ideal. Android's strict sandbox and permission model reduces the amount of trust you need to place in individual developers anyway.
On the other hand, if you trust F-Droid, you can be reasonably confident that the APK file you receive from F-Droid corresponds to the source tarball from F-Droid, and you can inspect the source to verify that the APK doesn't contain malware. Additionally, the F-Droid team manually reviews the source code for each app before approving it. But keep in mind that if F-Droid were compromised, it would be easy to sneak malware into any app on the store.
Overall, I would trust F-Droid for most purposes and think it's probably a better place to install apps than the Play Store. I still prefer APK files signed directly by the original developer for critical apps like Signal. In fact, one of the reasons Signal isn't on F-Droid is because the developer doesn't believe it provides enough security. [3] You can download the Signal APK from their website rather than from the Play Store, and it even has an auto-updater built in.
[1] https://source.android.com/security/apksigning
[2] https://guardianproject.info/apps/info.guardianproject.check...
[3] https://github.com/signalapp/Signal-Android/issues/281#issue...
https://blog.mozilla.org/addons/2020/09/29/expanded-extensio...
userid: 16201230
name: What-I-want-on-Fenix
Is this a pagination issue or something?
[0] https://addons.mozilla.org/en-US/firefox/collections/1620123...
Or rather, if you just want extension support, don't use FF. (I for one am very happy with Kiwi. OP fork also sounds nice.)
I prefer my software stateless, having me register accounts adds work and seems to me to be at best a silly workaround.
I found myself accumulating 100s of tabs that I would supposedly get back to, and it was causing anxiety. Firefox focus is ephemeral and your tabs will disappear. It doesn't permanently store cookies. It has a built in ad blocker. It's perfect to keep me "focused" on the task at hand.
I keep about 20 tabs open in normal browsing for easy reference. Incognito for most browsing. And Firefox Focus for even more ephemeral stuff, copied links I don't want to touch my other browsing, and screenshots. It sounds a little crazy to write it out, but it works for me.
There's this home screen that is central in the UX that lists top sites and collections and that is the primary way to open things you frequently access. If you have zero tabs or open firefox mobile, that's the screen you see first.
However, I stopped using collections because they somehow got it in their heads that the user wants to add a specific, cached version in time of a website. So I add HN to a collection and then access it and I get a 3 month old version of HN because that's when I added it. That probably makes as much sense to me as it does to you. You can reload the page as "fix". Collections are not bookmark folders. They are not synced as part of your bookmarks. They are not accessible on desktop. They are mobile only. They are completely useless as far as I'm concerned. If you make the mistake of using them, get used to stale content or obsessively refresh every tab manually right after you open it. Seriously WTF?!
Because they have that broken/half assed collection concept in the UX, bookmarks are not very prominent and accessing them is unnecessarily hard. Bookmarks are actually synced and you can access your desktop bookmarks that way. But you have to dive deep into a menu to access them and adding new bookmarks is basically not supported: you can't "star" them like you would on the desktop version. There is no option to add a bookmark for the website you are looking at that is obvious to me other than actually going to the bookmark manager and creating a bookmark by manually copy/pasting the url from the url bar.
As an alternative you can add websites to "top sites", which are not bookmarks (why?!), which is not part of a collection, and which are also not synced. But at least they show you the current version of a web site. Conceptually it's kind of exactly the same as the bookmark toolbar in the desktop version. If you click a top site, it opens a new tab. Always. This is annoying.
I still use it because I like having a working ad blocker and at least some basic protection against google tracking everything I do. But the UX is not a selling point right now. I've used a lot of browsers and mobile browsers over the years and this is probably the worst one in terms of bookmarks, which is a basic feature that even Mosaic had back in the day.
Simple obvious fix: Deprecate collections and replace them with bookmark folders. Implement starring/bookmarking (how is that not a thing?). Make top sites just another bookmark folder (just like the desktop bookmark toolbar). Make collections sub folders of those. It all syncs. It all works.
That also opens the door to supporting firefox containers, which I love and use all the time on desktop. I'd love to have full access to that on mobile.
Are you sure you're on the latest version? I'm on the latest version, and when I press the 3 dots next to the URL bar, I can 'star' it (create a bookmark) from there, bookmarks are shown on the firefox-'homescreen'
Both are fully compiled from source and available on F-Droid.
I personally cannot recommend Iceraven as it is consistently behind updates, something you don't want for a browser.
Even though I like the project, I consider that it's what FF for Android should have been, I returned to FF because nowadays a browser needs frequent security updates and Iceraven is not staffed to have frequent releases.
[1] https://github.com/fork-maintainers/iceraven-browser/issues/...
I'm not sure if this is the fork you want, but to get some of the features that Firefox used to have for years you can't use the normal stable build anymore.
And of course they've always sold access to the list of default search engines.