Firefox about:config Menu Shortcut
github.com
github.com
On about:config to the right of the search bar at the top is a checkbox "Show only modified preferences".
The notes idea would be interesting though ideally the names of the key and values would be descriptive enough the reasoning for the change is obvious in 95%+ of cases (the other 5% being noting a bug workaround). As is the key names are usually pretty good but some of the opaque enum values could definitely use a note (or text based values instead) e.g. things like TRR mode being set to 2 vs 3 is always a google search.
What are you looking for which the “show only modified preferences” button doesn't provide?
In this profile I have 230 modified preferences. I'm pretty sure scanning the list in "show only modified" that it is all of those. The vast majority were autoset by Firefox or Firefox extensions.
What I would love to find is prefs that I explicitly set manually in about:config. Those are the ones I realllly wanna find later if I messed something up. It would also be nice to have those explicitly set by a user action in Settings too.. Elsewhere contravariant mentioned "user.js" I'll look into that and it'll be super helpful on the desktop. Less so on Android where, thankfully, about:config is still accessible in the F-Droid Fennec firefox build (unfortunately they can't do anything about all my useful addons that were removed or removal of prior functionality but I'll take what I can get).
Things handful of things I the user have actually set to be a certain value not the hundreds of things that are not the initial value the instant you launch the browser for the first time or the hundreds more that change from normal use after that. Just the 3 or 4 I have actually changed.
Chrome scripts require careful security analysis, just like software that runs with root privileges.
Firefox ships with zillions of lines of chrome script, and none of those zillions of lines "downgrade" any security features. Software isn't automatically secure simply because it came from Mozilla. Microsoft tried the same nonsense to scare people out of using Linux at one point... you'd have to be nuts to run kernel code that didn't come from Redmond!
https://searchfox.org/mozilla-central/source/dom/security/ns...
Those are useful mitigations, but disabling them for some custom user-chrome is unlikely to have a meaningful impact on your browser's security.
[0] https://searchfox.org/mozilla-central/source/dom/security/ns...
[1] https://searchfox.org/mozilla-central/source/dom/security/ns...
[2]: https://blog.mozilla.org/attack-and-defense/2020/06/10/under...
https://github.com/mozilla/policy-templates
It's from Mozilla.
2. That's not a good analogy. If we're looking at a single choice in isolation, it's true that opting into DNT (or RFP) makes you stick out compared to everyone. There's only two options (DNT header being present or not), and one option is obviously more common than the other. However, the difference with RFP on/off is that there aren't really two options. Yes, RFP can only be on/off, and "on" is much more rare than "off", but leaving it "off" also uniquely identifies your device through fingerprinting. You're not really choosing to blend into the "all the people with RFP on" group vs "all the people with RFP off" group. You're choosing to blend into the "all the people with RFP on" group vs "all the people with RFP off and has the fingerprint as you" group[1]. Whether that's more or less identifiable is unclear. If you have the most run of the mill setup[2], then RFP might indeed make you stick out more compared to your normal setup. However, if you have an uncommon setup, it might make you stick out less, because the amount of RFP users is greater than the amount of users with the same fingerprinting attributes as you.
[1] in reality it's not really one group for RFP users and separate groups for everyone else. There are fingerprinting attributes that RFP doesn't block, so it's more like a set of groups for RFP users, and a separate set of groups for non-RFP users, but there are less distinct elements in the RFP set, since various fingerprinting attributes are spoofed to be the same.
[2] see https://wiki.mozilla.org/Security/Fingerprinting for list of features that are spoofed, and make your own determination how common your setup is.
> So in short: your normal browser does not have to be honest about it's properties, but it won't make you more anonymous because you still stand out from the other people and content on the web will break. Tor works because everyone has the same properties, including resolution. You can surely change your resolution, but there is just simply a chance that you will be standing out from other people. It's just safer to keep it the way it is.
If the "resist fingerprinting" feature changes anything in the data that is read by trackers, you will stand out like a sore thumb among the millions of browsers with the default settings.
Most people do not change default options, so just turning on that option is something that identifies you.
To my knowledge, resistFingerprinting mostly does the latter.
The tool I used before [1] https://github.com/satyr/uc hasn't been updated since 2016, and http://userchromejs.mozdev.org/ is entirely gone.
If there is even the tiniest syntax error in policies.json, Firefox silently ignores the entire file. The only way to know this happened is by checking about:policies.
Mozilla had to be dragged, kicking and screaming, into providing any kind of stability guarantee for configuration options. "Policies" are just configuration options that have been blessed with this stability guarantee. But Mozilla is still throwing a tantrum over having to provide it...
That's funny, I didn't see any tantrums about policies when I worked there. Citation needed.