My essential Firefox fixes in 2022
rubenerd.com
rubenerd.com
Even with telemetry off, all kinds of information about my browsing behavior from the myriad connections it makes upon start and exit can be gleaned. Certificate chain updates, etc can be delayed until a secure connection is requested by me.
The amount of unsolicited and virtually uncontrollable network traffic from macOS, Microsoft Office, Adobe Creative Suite, etc is bad enough, I expect more from Mozilla that never stops marketing its privacy features.
I believe I have the right to control when and for what purpose the computer and software that I own communicates with third parties.
In combination with tabs defaulting to unloaded in a new instance of the browser, this adds some control over memory consumption and network activity.
The thing with right to control, though, is that someone, somehow has to develop a browser and make ends meet.
No, but seriously, Mozilla — I'll pay you real dollars for this.
they fired a ton of engineering talent working on exciting tech (servo) to chase some bundled vpn rebrand. what a misguided move, like most everything they've done in non-engineering space. sad.
before, i would have donated hundreds or more if there was a way to pay directly for firefox and thunderbird. but not anymore.
at least the CEO's salary keeps going up: https://news.ycombinator.com/item?id=24563698
Unfortunately, there's no such option for Firefox.
(Cue complaints about it not being the right way to fund Firefox, because it’s not a pure donation. Before you go down that road, tell me: what evidence do you have that pure donations would get enough transactions to be worth the overhead? Have they ever worked at scale for any other software?)
I pay for lots of software I use, and do so happily if it delivers value — it would be extremely easy for me to justify paying for what's probably one of the apps I use the most. Why can't we pay for good browsers, that put the focus squarely on being the best tool to access the www? Why can't that money be used to hire back some of the talent Mozilla has been letting go? I say it elsewhere in this thread — Mozilla should let us pay for the bloody thing.
Make it open source, but have the official download for builds (and source code?[0]) be payed. Bonus points if the download bundle includes source code and a simplified build process.
[0] obviously it'll be mirrored in 2 seconds, but still.
Might as well just ask for donations.
I’m not sure what in my brain says “Telemetry? Absolutely not”, but that’s how it is for me (and why I don’t use the Developer Edition).
However, I respect the “Telemetry? Absolutely not” stance and can only hope and pray that Firefox PMs use telemetry as only ONE among a whole host of other signals to support decision-making.
The rest, outside of core, seem to write code as you mention. Product additions which most always give zero real value, no income, and even detract from the brand.
No, you can't maintain an entire modern browser (25 million lines of code) with 6 people.
You probably can't even maintain a complete multi-architecture, JIT-enabled Javascript engine with 6 people. Or GPU-accelerated rendering that works across thousands of hardware / software combinations. Much less that plus all the other things a browser has to do.
See the sections "How will my donation be used?" and "Don’t Mozilla products, like Firefox, earn income?" here: https://donate.mozilla.org/en-US/faq/#item_8
How do you propose notifications for new YouTube videos or tweets to work then?
Do yt, twitter really have to live in the browser?
I also find it very strange that so many people here disable telemetry. Really weakens complaints about removed features, if you're disabling the primary way that shows you're using it.
What's happening under the surface is that the project has reached the maximum complexity it ever can, after which it collapses being unable to maintain even low-maintanance features, let alone add new ones. Complexity unlike funding is fundamental, and just throwing money at it will not halt the process. Seeing rude obstructionist PR types showing up on bugzilla was the first outward facing symptom there was a cultural problem driven by an underlying material problem. An insider could probably tell you an even earlier warning sign.
As the project collapses it will grow tumors (eg Pocket). Totally random pieces of junk code which don't coherently belong to the base project. In the terminal stage it loses its ability to even remove features, or bolt on tumors. Tweaking the logo, churning the UI, and redesigning the website are the only actions the zombie project is physically able to take. So that's what it does.
If they do then it always was just a question of time for them to be found out, as just adding a webrtc session to the website makes their ip transparent again. Same with unique dns queries etc
"Reductio ad absurdum"
https://en.m.wikipedia.org/wiki/Reductio_ad_absurdum
Or "Logical Extreme"
On the one hand, stretching consequences is bad. On the other hand, thinking about a "one in a million" consequence isn't stretching when something affects a million people.
Maybe that example is closer to "one in a billion" or higher? We can hope so.
IMHO, such comments are so tired, poisonous, and add so little that if I were king of HN, I would ban them. They may be hard to define, but 'no hyperole' is a start.
That is quite the hyperbole and under your own rules you would be banned.
There is no limit to what can disgusting thoughts could be posited in a hypothetical.
I agree that the underlying problem is that extensions were disabled without user notification. The correct behaviour is simple enough: if any extension gets disabled for ANY reason other than manually by the user, the browser should lock out ALL network connections until the user has acknowledged this change of state. Someone should submit this to bugzilla as a high priority fix, if it hasn't already been done.
Not gonna happen. These days Mozilla doesn't even pretend to give a damn about user control. "We know better than you" has been the watchword for a while now.
Not gonna happen? If you refuse to partake in the most minimal of engagement with the process, don't complain if you don't like the outcome.
What's your criteria for things that actually matter? For example, as an adblocking, scriptblocking person, whether or not a company tracks me has no impact on my life whatsoever. What does have an impact on my life is my web browser being half-crippled and my mobile browser being a pile of half-working shit that soft-locks if I open it too quickly after closing it.
How should auto-updater work then?
Users should and regular people should:
* not smoke
* not drink
* eat healthy food in moderate amounts
* ...
"Should" almost never works, especially at scale.
And now every language ecosystem has one or more package managers for development libs - pip, conda, cargo, npm, opam, dub, etc. - and then optional package managers like choco, homebrew, and probably some others I missed. It’s a huge mess. So instead we throw up our hands and just bundle everything we need in a container and duplicate the _whole distro_ because the “package” ecosystem is such a disaster.
The sane way to handle software installs and uninstalls would have been cp/rm.
Every one of these uses different flags too, so for someone who uses a number of different distros it’s a huge pain to remember them and switch back and forth.
FreeBSD at least uses the eminently sensible “pkg” command with flags like “search” and “add.”
You don't own Firefox. You have a license to use it. Background network traffic is not a big deal. Ignoring downloading important updates the bandwidth the requests use is not significant. In such a large and complex piece of software as a web browser I do not understand why traffic should be associated with UI interactions. How is the browser supposed to show a notification when someone tweets? Would you prefer to hit a "Check for Notifications" button or would you prefer to just get a notification. The latter option has a million times better UX.
I would a love a button for every action. Particularly for things like check for notifications. The current problem is that someone else believes they know what a better UX is, any by better they mean better for the company for whatever reason.
firefox --offline --no-remote --profile <path where throwaway profile folder can be created>
The `--offline` argument is quite strange for a several reasons:
1. it is quite undocumented, but works from what I've tried. It is not even exposed in `firefox --help | more`. It used to be mentioned at MDN page [1] but that is gone now.
2. From what I've tried now, offline mode lets you browse localhost, what seems super useful but I don't recall it have always been this way.
3. Also browsing properly cached pages seems to work super well; not sure it is due service workers finally caught up and works or proper HTTP headers are used nowadays. Interesting is that even the hard refresh of cached page gives you cached version in offline mode. (Again, I'm not sure it used to be this way in the past. I remember that nearly no webpage worked well in offline mode few years back.)I have not run any network traffic audit so I cannot verify it really does not attempt to reach for something outside localhost.
[1] http://web.archive.org/web/20210530092017/https://developer.... (I have a super murky memory it might be me who added it there, but today I had to find SU answer mentioning it [2] to even try that) [2] https://superuser.com/questions/1691419/how-to-start-firefox...
(Update) And one more thing: when using Profile Manager there is a nifty "Work offline" checkbox in there. Run
firefox --profilemanager
There is also checkbox "Use selected profile without asking" that when unchecked presumably adds [General]
StartWithLastProfile=0
to the `<appdata>\Mozilla\Firefox\installs.ini`. I've found this handy to do if you occasionally mess with various Fx versions and want to be sure you will not unintentionally load "nightly" profile with "stable" executable.Theoretically we already have this control. We can edit the Firefox source to disable the undesired traffic before compiling. In practice it takes me more time and resources to compile Firefox than it does to compile the kernel for the host OS (NetBSD). Most Firefox users probably use binaries and do not compile from source.
I would prefer to see a smaller, less featureful additonal version of Firefox that compiles faster and with fewer required resources. For advanced users, this would remove the friction against making source changes and compiling as opposed to using binaries. It would also potentially open up an opportunity for others to create customised versions of Firefox with, e.g., reduced attack surface, less need for "updates" and better suited to avoiding telemetry, and internet advertising-related surveillance.
The actual or effective inability to compile from source places more control with Mozilla and less control with the user. Thus we continually find Firefox users on HN pleading with Mozilla to make changes instead of making the changes themselves.
-- Disable accessibility services https://www.ghacks.net/2021/08/25/firefox-tip-turn-off-acces...
-- Enable webrender all https://www.ghacks.net/2020/12/14/how-to-find-out-if-webrend...
-- Disable Pocket https://support.mozilla.org/en-US/kb/disable-or-re-enable-po...
-- Add Ublock Origin https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...
-- Disable Telemetry https://www.howtogeek.com/557929/how-to-see-and-disable-the-...
Do you know if this includes all of the bells and whistles for webrenderer? I still see many webrenderer releated about:config options with false
I hate to say it but the best vertical tab implementation I've seen is in Edge. Easily toggle-able between horizontal/vertical tabs, there's a way to collapse it to just favicons, you can use collections to group tabs together (like in Chrome). It's honestly one of the features that keeps me coming back to Edge, privacy be damned.
I think the only feature I really miss from Firefox is container tabs.
For many users this is TST's main benefit.
$ cat userChrome.css
/* Hide horizontal tabs at the top of the window */
#main-window[tabsintitlebar="true"]:not([extradragspace="true"]) #TabsToolbar > .toolbar-items {
opacity: 0;
pointer-events: none;
}
#main-window:not([tabsintitlebar="true"]) #TabsToolbar {
visibility: collapse !important;
}
/* Hide the "Tree Style Tab" header at the top of the sidebar */
#sidebar-box[sidebarcommand="treestyletab_piro_sakura_ne_jp-sidebar-action"] #sidebar-header {
display: none;
} extensions.pocket.enabled = false
extensions.pocket.onSaveRecs = false
It sort of annoys me that 'pocket' can't just be disabled from the UI bar to hide it everywhere, but that's not nearly as annoying as the last link you provided...The Telemetry stuff is insanely invasive and really needs to all have one _system_ level toggle for it rather than the like _twenty_ different flags and settings (even with the 5 dupes from the article's dump cleaned up)...
about:preferences#privacy
Uncheck all
.
devtools.onboarding.telemetry.logged = false
toolkit.telemetry.updatePing.enabled = false
browser.newtabpage.activity-stream.feeds.telemetry = false
browser.newtabpage.activity-stream.telemetry = false
browser.ping-centre.telemetry = false
toolkit.telemetry.bhrPing.enabled = false
toolkit.telemetry.enabled = false
toolkit.telemetry.firstShutdownPing.enabled = false
toolkit.telemetry.hybridContent.enabled = false
toolkit.telemetry.newProfilePing.enabled = false
toolkit.telemetry.reportingpolicy.firstRun = false
toolkit.telemetry.shutdownPingSender.enabled = false
toolkit.telemetry.unified = false
toolkit.telemetry.updatePing.enabled = false
toolkit.telemetry.archive.enabled = false
devtools.onboarding.telemetry.logged = false
toolkit.telemetry.bhrPing.enabled = false
datareporting.healthreport.uploadEnabled = false
datareporting.policy.dataSubmissionEnabled = false
datareporting.sessions.current.clean = true
.
toolkit.telemetry.server = "" (empty string)toolkit.telemetry.enabled = false
Should disable everything under
toolkit.telemetry.*
Furthermore I would expect the UI flag to disable telemetry to overrule all other settings and globally disable telemetry
toolkit.telemetry.enabled and toolkit.telemetry.unified have a complex relationship.
about:preferences#privacy
Uncheck all
.
toolkit.telemetry.unified = false
toolkit.telemetry.enabled = false
toolkit.telemetry.reportingpolicy.firstRun = false
datareporting.policy.dataSubmissionEnabled = false
datareporting.sessions.current.clean = true
In a couple min of searching it looked unlikely that I'd find any current documentation about these flags, the bhrPing and hybridContent are probably remains, but were still present in my existing profiles. devtools.onboarding.telemetry.logged = false
browser.newtabpage.activity-stream.feeds.telemetry = false
browser.newtabpage.activity-stream.telemetry = false
browser.ping-centre.telemetry = false
toolkit.telemetry.bhrPing.enabled = false
toolkit.telemetry.hybridContent.enabled = false
There are some additional prioping entries under the telemetry module which are associated with Nightly / dev builds.Unlike many Firefox forks, it tracks modern Firefox. I believe they run a similar set of tweaks to Tor browser, just without the Tor. This is quite nice. It’s autoplay blocking has actual teeth: I’m delighted when YouTube’s annoying autoplay-next-video is foiled by it.
Since it is smaller and from a less well-known group of developers, I can totally understand this being untenable. But the added risk is worth it for me, because while it isn’t perfect, it feels like I have gotten a little slice of control back with it.
YouTube has this built-in nowadays. The button is at the bottom of the player, on the right hand side, on the left of the subtitles/captions button.
Though I have that in vanilla Firefox and it works fine for me on YouTube.
Makes me wonder what the web would be like if browsers were never subject to this conflict of interest in the first place and always prioritized keeping the user in control.
This is how it should work. It only doesn’t because autoplay is great for metrics and it’s nice for their metrics that all major browsers allow YouTube to autoplay.
So if you’re, say, opening a video in incognito because you want to watch a single video without that channel being recommended for the next 6 months, that little autoplay button is always toggling itself back on.
And now my best firefox fix is to use librewolf[2] instead of waterfox instead of firefox.
I had enough of mozilla treating me and my business like sh*t when the silently dropped alsa support on a ESR release and justifying by saying linux distro package maintainer should have not disabled our surveillance and tracking and no one wants to work on ALSA as it is a mess, turns mozilla code was a mess and in a matter of days someone came up volunteering to do the works they refused to, but then they switched their stance to say it's too late they're not going back to alsa just deal with it.
So I dealt with it by switching to waterfox which supported alsa with no plan of stopping and allowed firefox extensions to keep working.
When will mozilla stop hurting its own product by trying to make it the same as google's browser and mistreating their user base and supporters ?
I find the experience way better than vanilla youtube in a browser. It allows to remove all youtube annonyances (autoplay, comments, suggestions, ads, in video ads, and more) and tweak a number of things.
Only a couple downside for me, the playlist support is a bit shaky and once in while a video will fail to load or start and requires closing and reopening the window.
uBO pre installed, telemetry turned off, etc are all great steps, but the lack of DRM, for example, makes it a deal breaker for me. Brave, despite their shady practices with their own ads and cryptocurrency, is at the sweetspot balance between privacy and functionality.
I find the time it takes to fine tune my Firefox worth the work, but Librewolf looks like a project I would gladly trust with good privacy defaults.
One thing I've found, is that even if you enable DRM, librewolf sometimes still fails on Netflix. Just the other day I got redirected to a help page about Microsoft silverlight when trying to play a movie, had to fallback to Firefox.
- media.autoplay.default = 5
- media.autoplay.blocking_policy = 2
1. disable Fullscreen "XY is now Fullscreen" text. Set full-screen-api.warning.timeout to 0 2. disable Alt key: set ui.key.menuAccessKeyFocuses to false 3. don't select space after double clicking a word (together with auto highlight selection addon very nice for skimming code in browser like GH): set layout.word_select.eat_space_to_next_word to false 4. reduce forced wait when downloading a file (Download button in small FF-modal takes time to enable/activate, hard to explain, but annoying) : set security.dialog_enable_delay to 300ms 5. disable "This Connection is not Secure" Warning in (for pages like fritz.box together with XCkeepass very annoying) security.insecure_field_warning.contextual.enabled
I remembered reading something about this, and it looks like it's a security feature[0].
[0]: https://security.stackexchange.com/questions/118077/is-the-s...
Can you provide a link to this addon. Couldn't find it.
The specific case I have: I use the URL bar basically as my bookmarks (turned off browsing history and top sites in address bar suggestions), and one of the pages I frequency is https://hackaday.com/blog/ (note that this is distinct from the base https://hackaday.com). In chrome it works fine, if I hit h in the address bar it immediately autocompletes it to the full url, but in firefox it autocompletes it to the base url so I have to hit h then down arrow to get to the site I want.
For the life of me I haven't been able to figure out a way to change the behavior, and it absolutely infuriates me that there is no obvious way to fix it.
1. Base url of a website (in my case, it only searches bookmarks, but if you enable search history it will match to base url of historical searches as well)
2. If it can't find a match, then it defaults to a web search
What I want is for it to match full url's from either the history or bookmarks, but this does not seem to be an option
This workaround isn't perfect, but it has allowed me to switch:
- Bookmark the url
- Go to Bookmarks > Manage Bookmarks > [location of your bookmark]
- In the keywords section, put the first two or three characters (I settled on three) of the domain, so 'hac' in this case
Now when you start typing in the domain and you type those first two or three characters (or however many you want to setup), the first suggestion from firefox will be your keyworded bookmark and you can just hit enter instead of having to hit down!Crazy how Firefox always defaults to the domain instead of the most frequently visited URL for the characters typed in, but this has worked for me.
I was not able to get this to work on my setup. I added a keyword 'uniquekeyword' to the hackaday bookmark, but if I start typing uni... it just tries to give me a web search. I tried enabling/disabling the search bar and messing with my address bar preferences but no dice.
Counter-intuitively, it does sort of work if I put the keyword as a tag. It still tries to offer me a search as the top hit, but the tag result is the second hit.
When searching for a setting to make Firefox work like Chrome, I had found this a while back: https://support.mozilla.org/en-US/questions/1223611
I basically did what was suggested there. (The 2-3 character length I suggested was just from my experience of avoiding collisions with other urls I might visit and was when I wanted to hit return when I started typing.)
Not sure if these settings matter or not. I just tried disabling a few and it doesn't seem to make a difference These are the only ones that seem relevant.
In about:preferences#search I have this enabled:
- Provide search suggestions
- Show search suggestions in address bar results
In about:preferences#privacy I have this enabled (plus a few other things): - BookmarksThe key here is that if firefox sees an exact match to a bookmark keyword, it will put that as the top hit on the address bar. So if you put a short keyword for your bookmark (in this case, ha for the aforementioned hackaday example) you can type in h a {enter} and it will take you to the full url of the bookmark instead of the base.
- uBlock Origin: https://ublockorigin.com/
- Firefox Multi-Account Containers: https://addons.mozilla.org/en-US/firefox/addon/multi-account...
- Sidebery (vertical/tree-style tabs): https://github.com/mbnuqw/sidebery
- and my short userChrome.css file (which primarily removes widgets such as the tab bar that are made redundant by Sidebery): https://gist.github.com/PerpetualCreativity/cfc3ff25acc63db5...
yet another speed dial: https://github.com/conceptualspace/yet-another-speed-dial
buster captcha solver: https://github.com/dessant/buster
Temporary Containers https://addons.mozilla.org/en-US/firefox/addon/temporary-con... is a great addition. It gives you a semi-"private browsing" mode without missing features (some browser features are turned off in the actual private browsing mode). This is great for testing development web apps, as it gives you a fresh start every time.
1. Hide the unnecessarily huge sidebar header (allowing addons to show their own arbitrary fully custom sidebars separate from the official sidebar system could also work)
2. Hide the default tab bar
I currently run a vertical tab setup with Sidebery that looks great with custom userchrome, but the release that kills userchrome will make it too much of a mess to bother with a redundant tab bar and ugly space stealing sidebar header.
Additionally, an “adaptive” theme that pulls colors from the OS like Sublime Text’s adaptive theme does would be greatly welcome. While it’s nice that Firefox comes with a dark theme (and that there are plenty of third party dark themes), it’s irritating that it’s always a different shade than the rest of the OS — both the background colors (which change dynamically with wallpaper-adaptive appearance enabled) and accent colors (which is user specified on both macOS and Windows and soon on Linux with GNOME too).
I’m sure it’ll make waves and be all over the front page of HN when the date is decided upon.
I highly doubt Firefox would ever drop support for userChrome. The themes aren't nearly as powerful and low level. The about:config toggles works as a footgun protection. I have yet to see any technical reason for them to drop support.
That said, Firefox has dropped support for small yet useful features for no apparent reason, so there is a non-zero chance of them dropping support for userChrome customizations.
[1] https://addons.mozilla.org/en-CA/firefox/addon/clearurls/
https://github.com/gorhill/uBlock/wiki/Static-filter-syntax#...
[1] https://www.reddit.com/r/uBlockOrigin/comments/rttrbp/no_lon...
Also, I'd recommend to test Sideberry https://addons.mozilla.org/en-US/firefox/addon/sidebery/ Over its main purpose, there are the most useful container controls
And some other extensions which deserve to mention: Facebook container https://addons.mozilla.org/en-US/firefox/addon/facebook-cont... Search by image https://addons.mozilla.org/en-US/firefox/addon/search_by_ima... Imagus https://addons.mozilla.org/en-US/firefox/addon/imagus/
I wish there was more focus from Mozilla on continuously improving (or atleast keeping stable) Firefox performance, instead of these cycles of degradation, 1 great release to fix issues, and then a few years of ignoring perf again. ;(
If you experience a performance problem, you can use the Firefox profiler to record a performance profile and share it in a Bugzilla bug report. Having a profile makes a performance bug much easier to diagnose and hopefully fix.
The profiler is easy to use: it's just a toolbar button to start/stop recording. Here are the instructions for enabling it:
https://wiki.mozilla.org/Add-ons/Extension_Signing#Unbranded... - the linked 97.0.1 is still exploitable with the xslt bug so you have to dig into the build system at,
https://treeherder.mozilla.org/#/jobs?repo=mozilla-release&s...
And no, running the unstable developer builds is not an option. The dev line goes back to "alpha"/aurora in the old times and it still plays that role. It crashes in my experience on weird setups.
Depending on you OS, it may be easier to eg. use an apt repo if you are running a Debian derivative.
“Security” isn’t even the word I’d use for what extension signing seems to do. After all, full-out malware — the illegal stuff — can replace firefox.exe with their own.
What it really seems to be intended to protect against is legal-but-scummy applications like Oracle Java that installed random toolbars and add-ons that almost nobody wants. They can legally install an add-on, but patching Firefox itself would be a clear-cut trademark violation, so they won’t do that. Since the Java installer ran with the same permissions that a regular user runs as, they can’t really stop that thing without stopping you.
The phrase I’d use to describe this is brand protection, not security.
However, recent Firefox has this annoying feature where if you type in the search box on the main page it redirects your typing into the URL bar instead of the search box, making it then fail because a search is not a URL.
browser.newtabpage.activity-stream.improvesearch.handoffToAwesomebarNow I just click through the options on a new setup and disable various things I don't like, remove the search engines and enable the search bar again. After installing Ublock Origin of course.
I removed Decentraleyes and just have FPI enabled.
Also, this is pretty much I do after installing Firefox. https://github.com/arkenfox/user.js/wiki/4.1-Extensions
Is there an equivalent extension for Chrome that you know of?
Probably only a problem for people with lots of tabs.
One problem I have with some applications these days, and now Firefox as well, the techniques they use internally affect rendering which I find gives me more eyestrain. 88 is comfortable for me to use, 99 is tiring. Maybe it promotes too much acutance around letters, I don't know, but it seems like it's flickering subtly like a refresh rate. I've had this problem with other browsers too, sometimes it is fixed by newer versions. It's frustrating.
I doubt WebRender itself is to blame (though it's possible) - there is so much other stuff that can go wrong with the layers of graphics code between a browser and your screen, and GPU drivers and differences in text rendering between different methods would be the first thing I'd suspect.
For addons in general I recommend sticking to this: https://github.com/arkenfox/user.js/wiki/4.1-Extensions
For Firefox on Android I maintain Mull for 4+ years now:
- https://f-droid.org/en/packages/us.spotco.fennec_dos/
- Comparison: https://divestos.org/index.php?page=browsers
browser.download.alwaysOpenPanel
Thanks to a thread a couple weeks ago I also managed to make the scrollbars wider with widget.non-native-theme.scrollbar.size.overrideHas been proven to be one of the best extensions I discovered in the last few years.
Enable 15s autodelete and only set exceptions for the few sites that you really need it.
I’m not judging you for not caring about giving people permission to track you in whatever way they choose, but at least be informed about what you do.
[0]: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
[1]: https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32...
I've been considering https://github.com/sienori/Tab-Session-Manager, not sure if folks have tried that and would/would not recommend.
As for password manager, I'm happy with Bitwarden. I came across https://github.com/dani-garcia/vaultwarden recently, but I'm not currently self-hosting.
if i remember correct it is very unclear that when you share tabs with a specific person, it also posts it on the web for everyone to see. So people are publishing their tabs while unaware of this.
Here's a list of people's shared tabs:
https://www.google.com/search?q=site%3Ahttps%3A%2F%2Fwww.one...
All kinds of personal things in there, like bookmarks to bank accounts and such if you change the search parameters to something creative :-)
>Information about your tabs are never transmitted or disclosed to either the OneTab developers or any other party. The only exception to this is if you intentionally click on our 'share as a web page' feature that allows you to upload your list of tabs into a web page in order to share them with others.
That's like making an unlisted pastebin or youtube video. It is accessible by anyone but will be public only if you make it (e.g. sharing the URL in a forum). Maybe there should be a confirmation.
I understand, however sharing a link with someone specific (usually you need the specific url to access this) is not the same as publishing for the entire internet/search engines.
It's not a problem if they do this, but at least they should make people unaware of it. Looking at some of the private bookmarks that are being shared, it seems people are unaware.
https://treeherder.mozilla.org/#/jobs?repo=mozilla-release&s...
Releasing libre unbranded builds was part of the compromise everyone agreed to when Mozilla took over the browser in version 37 and locked users out from editing things in Firefox proper.
And instead of the bad UX about:config page, every tweak is in a configuration text file and you can easily override them.
https://addons.mozilla.org/en-CA/firefox/addon/yet-another-s...
its oepn source, and feedback always appreciated!
Link seems wrong.
chrome://browser/content/places/places.xhtml
Unfortunately changing new tab to a custom page is no longer possible. chrome://browser/content/places/bookmarksSidebar.xhtml
chrome://browser/content/places/historySidebar.xhtml
I ended up writing my own newtab page that lists selected bookmarks folders by recent.
https://github.com/Zren/NewTabRecentBookmarks(Name of setting NEW VALUE original value, description below it)
media.peerconnection.enabled FALSE true
Disables WebRTC, which blabs identifying info
gfx.downloadable_fonts.enabled FALSE true
Disables downloading of fonts in favour of system fonts - no download delay
webgl.disabled TRUE false
Disables WebGL, which blabs identifying info
browser.sessionhistory.max_entries 2 50
Disables tab history to prevent snooping by websites
browser.sessionhistory.max_total_viewers 1 -1
Reduces ram use on lesser machines
fission.autostart TRUE false
Enhances site isolation for security
browser.cache.disk.enable FALSE true
Disables local disk cacheing for speed
layout.css.visited_links_enabled FALSE true
Disables visited links data for privacy
dom.storage.enabled FALSE true
Disables local storage - Warning: breaks some sites!
> Disables tab history to prevent snooping by websites
How does this accomplish that? Websites can't access your browser history.
Fix is media.ffmpeg.vaapi.enabled = false.
Also note that your Firefox might have been collecting gigabytes of logs since the latest release because of this bug that you can clear.
Anyway, my first reaction to this article was: They did WHAT to the search box and toolbar?? Another change I didn't ask for and will inevitably revert when I (maybe) update someday.
I used Firefox for years with no complaints. I don't need or want UI churn in something that worked fine already. Extremely frustrating to have these changes forced on me with little recourse (talking mostly about the proton crap here).
Slowly over time my bar is growing to 80% icons, where I can barely see the url now.
While I dont use the icons all the time, I still want fast access to click them when needed. The overflow isn't the best option for me.
https://github.com/black7375/Firefox-UI-Fix
It is a userchrome hack rather than an extension though, so I guess its time is limited.
firefox --screenshot ~/s.jpg https://example.com
Used to work nicely in older versions.
-- about:profiles is actually a useful way to manage multiple logins. I used to have one set of accounts in ff, another in chrome. But now I just have multiple windows open in different profiles (and themes to distinguish) each with different login states.
You could also use firefox containers: https://addons.mozilla.org/en-US/firefox/addon/multi-account...
(XUL-supporting browsers still exist, but they're unfunded and far behind the state of the art. http://thereisonlyxul.org/ )
- I use the dark theme. However, that makes lots of pages use dark theme as well, so I've changed layout.css.prefers-color-scheme.content-override in about:config to not follow my theme, but my OS settings. (So I can have dark themed web pages during evening, but not all the time)
- And I use containers a lot. Very well integrated with Sidebery I feel.
* Horizontal Wood is a nice theme but still too dark for me, makes text hard to read. It did inspire me to look around a bit and I found BoryWood that is still readable and adds a bit of color:
https://addons.mozilla.org/en-US/firefox/addon/referercontro...
The big caveat is that the new browser policies will only default to origin if the website didn't specify the header, which means the website owner is still in control of whether it gets shared with the third party.
When the web extension change was new and people were complaining I wondered if this sort of patch would replace some extensions, but it seems that hasn't happened. I guess distribution is too painful?
- uBlock Origin - Firefox Multi-Account containers - Facebook container - Simple Tab Groups -> Allows to organize Tab on different groups. Great to avoid getting the tab bar fill with little icons. On my case, I have a tab group set for working, and another for misc stuff, other for gamedev stuff, etc. Works great with Total Suspender - Total Suspender -> Better autosupend of tabs. I actually would have around 170 tabs, and the Firefox ram footprint it's ridiculously small (~300 MiB) - PronounDB - Enhancer for Youtube -> Mainly because gives me better control of Youtube. Specially about the auto play next video. - Clickbait remover for Youtube - Don't Track me Google
For work stuff, I have VUE devtools and AXE Accessibility dev tools
- Change the executable file to get rid of support for HSTS.
- Disable JavaScripts in web pages (mostly).
- Request/response rewrite engine.
- Restore the status bar.
- Get rid of all toolbar buttons and features other than the URL itself; no search, back/forward, etc.
- Make the URL bar display only ASCII characters, and always display the full URL.
- Make URL entry relative instead of absolute (e.g. CTRL+L and then / and then ENTER will navigate to the root of the current domain).
- Use bitmap fonts for tab titles and URL bars.
- Make tabs display only the title and not icons or other things.
- Disable favicons completely.
- Modified SQL schemas.
- Implement text/gemini file format.
- Disable external font loading.
- Get rid of many animations (unfortunately, many web pages still have animations that this doesn't get rid of).
- Using SQL to access bookmarks using command-line.
- Cookie editor.
- Many other things.
Some things I had not managed to do (yet):
- Implement Gemini protocol.
- Table of contents window.
- Changing behaviour of many Web APIs.
- Changing meaning of some HTML/CSS.
- ARIA view.
- Using bitmap fonts in more places.
- Time limits for rendering using CSS.
- Save/recall form data in local files.
- Changing the default save file name to use the actual file name instead of the title.
- Capability to be used with other programs on the computer with pipes.
- Many other things.
I tried to change the scrollbar behaviour to be more like X Athena widgets, but it doesn't work properly.
1) Why are the extension settings intentionally buried? Takes 4 clicks to get to them.
2) I wish I can right click the extension icon and temporarily disable without laboriously going into the settings to do that.
Some slightly dated discussion about this on Reddit; not much seems to have changed to make LocalCDN compelling: https://www.reddit.com/r/privacytoolsIO/comments/fc05uh/just...
It's a pain to go through all of it the first time, less so with subsequent updates, but it's extremely comprehensive for most Firefox issues.
Then, I run uBO, uMatrix, NoScript, and Temporary Containers.
This being said, I'm interested in LibreWolf and how much user.js manipulation they make unnecessary.
Has Keypass improved a lot in recent years. I always found it incredibly clunky and ugly and getting it to work with browsers a real pain.
Bitwarden seems like a steal at 10 bucks a year and avoids the stress of trying to self hoist the keys to the kingdom myself.
But I see such love for Keypass and wonder.
the reason i switched to keepass was i wanted to use autofill desktop passwords as well. ive mainly been using keepassxc for a few years which is not too ugly i don't think, but have been trying out keeweb recently which is a lot more minimal.
a neat feature with keepass is autotype. i have mine set to alt+x so its easy to activate and using the "add url to window title" extension means there's no connection between your vault and the browser.
https://github.com/erichgoldman/add-url-to-window-title
another idea i had recently was to create a second vault for passwords that aren't that important. so now they majority of my passwords are in that and the vault master password is shorter so its quicker to type, while anything important goes in my main vault which has a stronger password. its great not having to type a really long password just to unlock my vault so i can log into some random forum! and it also means im less paranoid about leaving the vault unlocked. (when the autotype list pops up you will see sites from both vaults, as long as they are unlocked)
so yea, there's a few things that keepass does that other don't, but the downside like you said is having to manage the file yourself. i already had synching set up on all of my devices anyway so it was trival to sync the file using that
--offline
It’s enough to startup Firefox quietly (including any telemetry, from a Network perspective. Can still use it for localhost and file://.Useful if you’re trying to prep things for testing.
Microsoft claims Edge will "scan for discounts" as you browse shopping items as a selling point on the windows login screen. That means every page you visit gets sent to Microsoft to do with anything they want.
If anyone knows of working alternatives that would be appreciated!
So, so simple and so necessary and so totally ignored even though I keep offering to pay thousands of dollars to have it put in place.
- browser.urlbar.trimURL = false
- browser.urlbar.formatting.enabled = false
- browser.tabs.tabMinWidth = 50
- Customized the response curve of trackpad scrolling. (I think no other browser has this feature? It's actually the top thing keeping me on Firefox). On my specific hardware, something like this is subjectively "snappy" and "precise" and "out of my way":
mousewheel.acceleration.factor = 0
mousewheel.min_line_scroll_amount.factor = -1
mousewheel.default.delta_multiplier_{x,y,z} = 40 40 40
- Disabled all fonts with about:config's 'downloadable_fonts' toggle. (An alternative is uBlock's remote-font preference, which can be toggled on/off per-domain. That's a useful escape hatch). gfx.downloadable_fonts.enabled = false
- Enable uBlock Origin's opt-in "annoyances" filters, which affects maybe half the web including every last GDPR banner:https://github.com/gorhill/uBlock/wiki/Dashboard:-Filter-lis...
- userChrome.css is much more featureful than I understand; I just use it to adjust native widget font sizes:
@namespace url("http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul");
#tabbrowser-tabs .tab-text { font-size: 13pt !important; }
#urlbar { font-size: 17pt !important; }
- Firefox bookmarks can have *keywords* that macroexpand in the URL bar; these lower the friction of casual non-Google queries: en -> https://en.wiktionary.org/wiki/%s#English
man -> https://dyn.manpages.debian.org/jump?suite=bullseye&binarypkg=manpages&language=en&q=%s
hn -> https://hn.algolia.com/?q=%s
- Obscure privacy settings that should have gone into the main privacy panel, IMO: beacon.enabled = false
network.http.referer.spoofSource = true
https://developer.mozilla.org/en-US/docs/Web/API/Beacon_API> Block annoying web elements such as sticky headers, dickbars, floating headers, scrolling headers, fixed headers, scrolling videos, stickynavs, social icons, social share bars, smartphone app banners, app download prompts, cookie notices, GDPR warnings, scroll to top buttons, modal overlays, interstitial site overlays, removed or hidden overflow scroll bars, subscription nags, and generally distracting elements that have increasingly been turning the web into a user-hostile environment.
Not repainting the living room from eggshell white to Greek villa.