As an alternative for the last point, turn the Security Level to "Safest" or however it's worded, then use the included NoScript addon to enable it for just sites that just won't work without JavaScript. You get functional web + JS disabled in most places where you can.
There was one point where my anti-fingerprinting tactics did appear to fool Panopticlick, but that apparently didn't last long. Fingerprinting and anti-fingerprinting are a cat and mouse game, and much worse so than just ad-blocking because there's more at stake than just being annoyed by banners. There's also way too many websites doing everything, and I mean everything with JS. Fricking blog sites half the time display nothing more than a motionless loading spinner if you don't have JS turned on. And if you turn JS on well good luck because lots of things want to use <canvas> to render things that don't even strictly need it, and you're really not going to casually enable canvas for certain things? Even the list of fonts is a decent metric for fingerprinting, yet that's rarely taken seriously because even privacy experts seem to believe that every website needs to display its own fonts for "brand identity."
Though I would stay away from Tor anyway, if I were to use it, JS would have to be turned off entirely.
I think in a years time that will change.
It’s specifically for browsing the web anonymously.
[0] https://github.com/mikeperry-tor/vanguards/blob/master/READM...
[1] https://status.torproject.org/issues/2022-06-09-network-ddos...
It was a good lesson and helped me realize what Tor should really be used for.