The Mullvad Browser
mullvad.net
mullvad.net
This is an open source, rebranded Firefox and Firefox-like browsers could use some publicity. It promotes privacy and privacy can use some publicity too. Tor too.
Mullvad seems to be honest in the fact that their business model is selling VPNs and it's nice they are saying it's not enough. They are not saying that you might not need one though.
We need a Firefox with good defaults and it seems like this browser is such a thing. I'd prefer these privacy features to be in upstream Firefox but I guess world is not perfect and that Firefox still relies on revenues from Google so can't be as privacy-focused as it should.
My little concern I guess is that this browser will push for their service so it's a bit like an ad for them, at least with its name. But fair enough, and at least the business model seems healthy.
With Mullvad already being a Mozilla partner for their branded VPN, all this actually look good. They seem to be spending their money on worthy stuff.
I also like they provide a Wireguard file and a way to filter it, so it's super easy to get started.
I tried to get us to use Mullvad, as it was perfect for me, but for him it was constant problems with the services he used, whereas the sketchier providers like NordVPN and ExpressVPN always worked without issues.
Sketchier VPN providers use "home ips" and rotate them regularly in order to defeat Netflix or other services blocking them.
Often they pay someone to include their code in a "free" software or browser extension (or malware) that allows them to route traffic through the host.
Oxylabs is one of the larger examples whose record is somewhat dubious.
BHProxies is the largest residential proxy provider on the internet and almost all of their proxies are acquired through the botnet above.
https://www.bitsight.com/blog/mylobot-investigating-proxy-bo...
This needs to be on the front page of.... something.
I'd be shocked if any of the major VPN providers were involved with illegal residential proxies. It just doesn't make sense, can you imagine just how unstable and slow those connections would be? Why would they risk being legally liable when there exists legal residential proxy providers that get their IP's from people that voluntarily share their connection (honeygain etc.)? I've never heard of any of the big VPN providers offering residential connections. As I understand the VPN providers that promise support for netflix and similar streaming services just acquire newer IP's from time to time but the connection still goes through a regular datacenter, definitely not from some random dude's home.
The proxy market is more so targeted towards developers who scrape data and criminals that do credential stuffing/other criminal activity.
>can you imagine just how unstable and slow those connections would be
Yes, yes I can and they are. I tried them some time ago before I found out how shady they are and encrypted connections were like 2 Mbit while Mullvad gave me many many times faster bandwidth with higher encryption. Their support was completely useless.
See https://github.com/d2phap/ImageGlass/issues/1252 for an example on how this might happen (spider.com).
Not that it's your point, but, at least in the US, you can pay for BritBox on Amazon: https://www.amazon.com/gp/video/storefront?contentType=subsc... .
[1] https://en.m.wikipedia.org/wiki/Kangaroo_(video_on_demand)
Given a) they started experimenting with iPlayer pretty early in the streaming came, and b) they have a huge and valuable back catalogue, it's always amazed me that they didn't open up pay-per-view and subscription options for an ex-UK audience.
I've always suspected there's a good reason why not behind the scenes - maybe because a successful PPV operation would lend huge weight to people in the UK seeking to abolish the license fee?
Smart DNS providers like Getflix provide access to BBC Iplayer and a ton of other streaming services too.
Basically you use their DNS servers and they handle the geo-unblocking.
of course, I wanted to do this for as close to free as possible, since plugging an aerial into a tv at home also cost next to nothing
VPNs were already being detected and banned. I tried at least 4 extensively, including tcp, udp, socks, wg, obfuscated servers, etc. to no avail
dodgy residential/mobile proxies were too unreliable for live 720p m3u streams, not to mention expensive
I went through a few cheap linux VPSs with UK ip addresses, forwarding their web streams to my tv outside the UK, until I found one that seemed to work well. so much so I even invested in some fancy routing through intermediary countries for almost jitter-free stability
until a few weeks later, back to the same old shite -- everything 403 Unauthorised
after yet a few more weeks of furious head-scratching shame over the stable-now-vanished CBeebies and BritComs daily consumption, I concluded and confirmed the BBC had just started detecting and banning datacentre IPs more aggressively
it was at this ebb I discovered the wonderful world of illegal IPTV streams and adopted a fuck you too, BBC attitude
Maybe it was something to do with the fact that it was a Proxy and not a VPN, though I'm not sure if this makes it any less detectable. I even had a Firefox extension that automatically turned on the proxy when opening iPlayer tabs! It worked very well, though I wish I could've paid the license fee and just got access.
interesting about Dubai though, makes me wonder if they have some sort of expat or economic deal with them. if Google thinks you're there, you can bet BBC do too. I discovered they use multiple CDNs and delivery mechanisms as fallback/best effort for the gamut of user agents, network health and device capabilities, which sometimes (but not always) sieved most (but not all) VPN and proxy locations in an indeterminate (yet authoritatively intentional) fashion, so perhaps Dubai is whitelisted on one of those. who knows. sometimes it's like rolling dice. inconsistency and implied mischief sure are strong deterrents. might investigate further at some point if I can swallow some bile first
It’s pretty silly though, I would absolutely pay for a TV license if given the opportunity. Dear BBC: Shut up and take my money!
The shell provider I used was Phurix, not if they are still around or not.
A shame BBC can't accommodate its paying customers who happen to be abroad.
I’m French living abroad and have never missed French TV. The quality of the content is just very sub-par compared to American shows. They just don’t have the budget to compete. Is the UK different because it’s English speaking and perhaps it has access to a wider market and thus more capital?
As an example, Doctor Who sometimes releases new episodes. BBC doesn't just have UK television — they have an "on-demand" offering that actually works, and isn't sparsely populated with 15% of the episodes like some other services (cough Xfinity cough).
Would installing WireGuard server on a router directly solve this (like Gl-Inet travel routers)?
The desktop client also supports some obfuscation schemes (UDP over TCP) which is useful when you're in countries which block any kind of VPN. The default smartphone app doesn't support this out of the box, but they have some tutorials to setup Shadowsocks and OpenVPN to route the traffic over https as well
If you're looking such option for Android, you can check out Mull [1] which is available on F-Droid [2] as well and use it along with uBlock Origin.
And more often than not the response has been "well we did investigate Firefox but working with it was pita so we went with easiest option"
Shit dude. You want to start a business so at least do the right thing.
If there are more Firefox forks, like there are chromium forks today, that would normalize Firefox because currently chromium is the de facto web standard.
If Firefox wants to have a competitive market share they should actively compete instead of begging people to increase their market share.
One is actually the right thing to do. The other is how to make more money faster and quicker.
> ...Even in the desktop version, Firefox's sandbox is still substantially weaker (especially on Linux) and lacks full support for isolating sites from each other rather than only containing content as a whole. The sandbox has been gradually improving on the desktop but it isn't happening for their Android browser yet.
More bizarrely, there’s an open Bugzilla and GitHub issue on that, both a few years old.
Obviously I have transferred my entire family and social circle over to Brave. If Firefox won’t make their users secure, I will.
I can understand why it's not a priority at this point, at least, given that Firefox on iOS is currently a reskin of Safari, and the door is reportedly about to open for actual competition among iOS browsers due to increasing anti-trust pressures on Apple.
It would make more sense to me to address this with a real port of Gecko to iOS, and then you can just run the full version of uBlock Origin for Firefox on your iPhone.
Allow me to introduce you LibreWolf https://librewolf.net/
It's a custom build of Firefox with somewhat sensible, sometimes strict, privacy respecting default settings.
There's also the Arkenfox user.js which you can put on top of vanilla Firefox, aiming for the most privacy and security possible. https://github.com/arkenfox/user.js
A lot of sites allow interaction even with the above but they shadowban you without telling you. Craigslist shadow bans and auto-spam-filters any submissions done with a VPN, and then also auto-spam-filters any subsequent submissions on the same account even with the VPN turned off.
Reddit also universally spam-filters any submissions and comments done under a VPN, and rate limits your commenting a shitload on VPNs.
Mullvad, who has a reputation in the HN comments for being just like... over the top amazing + great (they swear up and down they don't store traffic logs and if you don't trust them, you can pay anonymously somehow or whatever), is having a "hard time" being profitable/growing
all while
NordVPN, who has a bad reputation in HN comments for being untrustworthy and "not so anonymous", seems more well known (and therefore most likely has more paying customers and makes more money?)
What is that law called in business? when the "less good" offering wins?
NordVPN has spent an incredible amount of money getting their name out there.
The majority of the population hasn't a clue about what a VPN is or does. The ones that do, their only interface is "its this thing my company makes me connect to"
Of the remaining subset of people who are aware of what VPNs actually do for you, it's likely they can only name 1 or two brands: NordVPN and ExpressVPN.
So if you have the superior product, but the lesser position in the market, then get busy marketing.
Easier said than done I imagine. Big brand VPN providers charge several times more for the "same" service, or make you sign up with 3 year commitment to even come close to Mullvad's monthly pricing.
I think you misspelled "spamming ads everywhere".
But there is a different reason for the popularity:
NordVPN and others spend a lot of money on aggresive and pretty shady advertising, which tricks consumers into all kinds of false assumptions.
The old company: https://www.allabolag.se/5567839807/amagicom-ab
The current company: https://www.allabolag.se/5592384001/mullvad-vpn-ab
> Mullvad [...] is having a "hard time" being profitable/growing
This is how I originally interpreted the parent comment as well, but they actually meant "a VPN is not enough to maintain your privacy, you also need a privacy-respecting browser."
The law that "in a free market, the best product wins" has been beaten by profit-driven companies with billions at their disposal. Sure, you can have a better product. But maybe it's more profitable to have better marketing, or secondary sources of profit.
It's quite telling that VPN providers sponsor so many YouTube videos... Which require login to the biggest ad-driven company... Which will identify users by their login, no matter if they have a VPN or not!
Adam Smith's The Wealth of Nations was published in 1776. I suppose you could say that was "post-fact" as it drew on what was happening at the beginning of the Industrial Revolution and the English and Scottish agricultural revolutions among other things, but "invented" would seem a bit of a stretch.
> The law that "in a free market, the best product wins" has been beaten by profit-driven companies with billions at their disposal.
Of course, given that law then the other possibility you appear to have dismissed is that the market is not free.
But then I'll day: maybe these guidelines are outdated, 250 years later. For example, does the best product win? Not if the product is complex enough and people cannot quickly measure its quality. There's 10$ crap and 100$ crap, and fake reviews, and paid reviews, and swapped products, and misleading marketing.
- available
- at a price that the producer makes a profit
- at a price that the buyer can afford
- and does the job
Many such products may exist in a market, some "better" than others but that would be a subjective opinion. The problem with a non-free market e.g. one with monopolies or interference from governments in the form of subsidies, is that it interferes with the above list and you end up with inferior products (in terms of the above list) to those you would've had in a free market. Even the "producer makes a profit" part would be worse because there are less producers making profits, and thus fewer products, higher prices for those products remaining et cetera.
Advertising is not a bad thing in a free market. Fake reviews and the rest are, but they lead to less trust, as we see occur with Amazon, and you would go to a more trusted competitor but Amazon is a monopoly so…
No it probably won't help if I want to buy fertilizer for a truck bomb.
So, like LibreWolf, Waterfox, etc. ?
There's a ton of those already.
Now, I didn't really know about LibreWolf, I'll look into it for myself.
Why would they?
I don't really blame them for this though. Buyers should also do their homework.
I mean... yeah? What else should it be?
Sounds ok to me, I have a longish and probably out of date list of settings that I like to chance in a new instance of firefox. I trust mullvad to not log dns more than I trust my ISP and I live in the UK so unencrypted dns here is being logged and stored by order of the government.
Keeping a fork of firefox in sync with mainline firefox to get security fixes is a load of work, it is good that somebody is doing it, in this case I think the tor project is doing a lot of the work.
Not a user but part of the purpose of the TOR fork is settings, anything that is detectable via JS is supposed to remain default to prevent fingerprinting.
It's partly why it's not widely popular, I don't know if this is still true but it used to be that it was supposed to be run at a specific viewport resolution regardless of your device. All in the name of making your fingerprint as close to the same as all other TOR browser users.
It's more like pretending to the website that your screen has a "common" resolution etc. which is nearly but not quite the same as what you said.
In the past they semi required you to keep your tor window in a specific window size for this, which just didn't work well in practice.
By now they better integrated that in the browser from what I heard, so you can resize it however you want but websites might have an "empty" border are to the left/right/bottom depending on you screen resolution, windows size etc. from what I have heard.
With a typical maximized window on 1080p you won't really notice it, on 4k you might notice that it's just "dump" up scaled from 1080p, but the person I spoke with wasn't sure if maybe they have a set of supported common resolutions instead of just one. And on a 4:3 screen he said it's quite noticeable.
Bear in mind that it's a minority of people that hit F11 to browse fullscreen, they still have toolbars, so it's not as common as you'd think for the viewport to match a common screen resolution like 1920x1080.
Perhaps it would be better to letterbox randomly with say 20px width and 20px height, so it's just 1 chance in 400 to even return to the same reported screen size? That way you'd be even harder to track than if you are the only person running exactly 1000x800.
So you get all the in-browser tracking protection Firefox has (e.g. against fingerprinting) + the ones only the Tor browser has but without the drawbacks of the tor network and in turn without onion security.
Dear Santa...please stop making a safe & private internet so gosh darn friction-y :(
> Why is the time is wrong?
> The timezone is spoofed, to combat fingerprinting.
> What's this weird spacing around the websites?
> It’s called letterboxing, a function to combat fingerprinting (using your browser window size to identify you together with other measures).
> How do I stay logged into specific websites between sessions?
> It’s not possible. It’s an action to combat tracking.
Not sure if there are other measures, other than that the browser itself doesn't track anything.
Looking much better than a stock firefox, and presumably will improve over time.
> How do I stay logged into specific websites between sessions? > It’s not possible. It’s an action to combat tracking.
Turns me off immediately
In my case, I had to turn off that setting because without it, 1Password wouldn't work.
Given your stated preferences, are you actually looking for a privacy-focused browser?
My understanding is that cookies etc aren't shared between containers, so I can stay logged in, and not be tracked across websites.
If it's achievable, why compromise?
This is a surprisingly effective one when combined with other users of your network. A couple of years ago, I started getting Facebook ads for things I'd never looked at, but that I knew my wife had looked at. We don't share any devices, and she doesn't even have a Facebook account.
It's pretty troubling how invasive shadow profiles are.
Some people just want to pick a different point on the tradeoff between convenience and privacy.
Imagine User A uses Fastmail every day, logging in manually every morning. User B uses Fastmail every day, with a saved login cookie. How is User B's privacy any worse? What would User B gain from not having that choice?
User B's privacy is objectively lessened by allowing tracking cookies, but that is their choice. What is out of the user's control is what mullvad chooses to spend their time supporting.
If mullvad allows users to turn off a privacy feature, now that's a permutation they have to test for. It's also an attack vector they've enabled, either through user carelessness or social engineering. Mullvad wants to be able to say "here's a browser, it's 100% private" and not have to say "as long as you do X, and don't do Y, and...". Every other browser already does that.
Being able to easily reopen a tab in a different "identity" is also a pretty neat feature.
Choose the right tool for the job.
At the end of the day, where there is attention, there will be ads. All you are fighting for should they show you relevant ads or irrelevant ads.
People who live a privileged life and have nothing else important going on in their life choose this hill to die on.
If you have that, you're a minority. And if you believe you have that, but actually you don't, you'll find out only after it's too late to save it. It's prudent instead to assume and act like you don't have it in either case.
Indeed, some of the greatest democracies have been set up precisely to that end.
For many, online privacy isn't at all about advertising. It's about working to a common good of rights and freedom for all.
Rest on your laurels all you like, but don't deride others who refuse to. It is only through the efforts of such people, and in the past those like them, that any of us have the ability to take any such rest at all.
Of course, not in the sense that the FBI, Wagner Group, or the boogy man are going after you today (but you never know what the future holds) - however data brokers and large companies have a financial incentive right now to know as much about everyone as possible and the information they collect is increasingly being used to decide your insurance rates, give you employment, etc.
>People who live a privileged life and have nothing else important going on in their life choose this hill to die on.
I mostly agree, however privacy issues impact the less privileged more, for example women seeking abortions in unfriendly states, teenagers learning about queer issues in a toxic community/family, people fleeing abusive relationships (the effort some stalkers do is truly insanity), minority groups (e.g. undocumented immigrants). Sure these groups can't dedicate lots of mental energy to privacy but plug and play browsers like this one make it easier and even if you are highly privileged protecting your privacy makes it more acceptable for others to do so too.
Edit: As mentioned elsewhere in the thread, there are still plenty of identifying bits.
It seems like a harmless thing to be tracked, but once the likes of haveibeenpwned.com came out and the databases that fuel it, and services that provide search utility to those databases, it should become clear that being tracked across every single website on the internet is probably not what you want.
Scenario: You apply for a job, they look up your totally-clean email address, see the email linked to an ip address on some database from a leaky website you applied for a job on, the ip address is linked to a service where you used a certain password which you used on 6 other services, one of which had a database leak of your system fonts, now you can see all the accounts to services to which your system fonts were identically matched. Oh look, you were 13 years old when you joined stack overflow on an abandoned account and you posted some humorous, incorrect solutions that were down-voted to oblivion. But that's ok, they invite you to the job interview and they make a funny remark about your stack overflow answers and then offer you a job. Do you want to work there now that you know they completely invaded your privacy ?
And yes, performing such searches is trivial.
It's pointless to say the problem is the employer, or the hacker who released the data, or the programmer who relied on bad algorithms, or the admin who didn't secure the data. One way or another, this data will get leaked, the old hashing and encryption techniques will be broken and there will be people searching through it all. Forget about the government, at least they are beholden to law and maintaining the appearance of adhering to it. Substitute employer for neighbor, girlfriend or internet stalker and you have equally valid scenarios which are even more disturbing in my mind.
I already do this for work (for security theatre) so I will skip this
> > The timezone is spoofed, to combat fingerprinting.
The annoying thing about this (assuming it's the same as in Firefox) is that the times displayed in your own local History page are also "wrong" i.e. shown in UTC.
OpSec is hard, and tools letting you shoot yourself in the foot doesn't help. There are plenty of other browsers out there that don't offer VPN integration, so (imo) they should have made the browser a paid feature for customers, instead of giving it away for free like the market has demanded since IE6.
Has this been reported to Mullvad?
Tools I've used to verify:
- https://mullvad.net/en/check
Genuinely curious because I use this setup all the time and want to rest assured it's behaving as I expect.
https://mullvad.net/en/help/split-tunneling-with-the-mullvad...
I can’t experiment with this during my workday, and we’ve reached the limit of information available without running it and testing, so I can’t help resolve this further right now.
I already trust Mullvad enough to use as VPN, and am likely willing to extend that trust to a fork of Firefox they manage, but truthfully, I always concerned when achieving goals means new ventures and projects as it may mean resources are moving to other areas and may impact their code product. I like my core providers to do one thing and do it well.
Edit: I hope they bring this to Android also!
Sticking with LibreWolf for now, which has updates disabled in the policies section, but I frequently ping their Gitlab for new releases. It's annoying having to do that, but if it means I get security patches in time, I do it.
Bromite seems like its sticking around, fortunately.
Only barely, unfortunately.
I've since moved to Vanadium for anything untrusted and/or critical. It's still missing some features I'll enjoy seeing added, but it's improved considerably lately.
Thorium was comatose for awhile but come back, so I am keeping my fingers crossed.
I do not like Brave's business model (replacing web ads with their own, even setting the crypto thing aside), but I will check out your link if Bromite fizzles out.
See https://github.com/uazo/bromite-buildtools/issues/109#issuec... and https://github.com/uazo/bromite-buildtools/issues/76 and https://github.com/uazo/bromite-buildtools/issues/59
"Avoid Gecko-based browsers like Firefox as they're currently much more vulnerable to exploitation and inherently add a huge amount of attack surface. Gecko doesn't have a WebView implementation (GeckoView is not a WebView implementation), so it has to be used alongside the Chromium-based WebView rather than instead of Chromium, which means having the remote attack surface of two separate browser engines instead of only one. Firefox / Gecko also bypass or cripple a fair bit of the upstream and GrapheneOS hardening work for apps. Worst of all, Firefox does not have internal sandboxing on Android. This is despite the fact that Chromium semantic sandbox layer on Android is implemented via the OS isolatedProcess feature, which is a very easy to use boolean property for app service processes to provide strong isolation with only the ability to communicate with the app running them via the standard service API. Even in the desktop version, Firefox's sandbox is still substantially weaker (especially on Linux) and lacks full support for isolating sites from each other rather than only containing content as a whole. The sandbox has been gradually improving on the desktop but it isn't happening for their Android browser yet."
I understand the want to stay close to upstream and requests for such "usability" tweaks this should go to Chromium.
Alas the rigidity of the GrapheneOS project is a double edged sword.
and for Chromium: https://divestos.org/misc/ch-dates.txt
Basically, it seems like a good choice if you are already a Mullvad user and your threat model does not require the use of a Tor browser. However, if there's a significant non-Mullvad user base using it, it won't do much, as you'll just stand out as the only person using the Mullvad browser without Mullvad VPN.
I also think this approach of expecting the general public to adopt a borked browser to give deniability to people using it strategically is extremely naive. Human psychology just doesn't work like that, you might as well ask schools of fish to swim differently to hinder shark learning. To be frank, this seems like it will just create confusion vs telling people to use Tor browser.
The way to improve privacy is to provide a tool that actively enhances something incredibly well, and does everything else at least as well. If all browsers are hopelessly compromised, make something that isn't based on HTML and builds cool user interfaces directly from API calls like a videogame UI, for example.
That should be "unless there's a significant...."
https://github.com/mullvad/mullvad-browser
So basically like... hardened Firefox?
So I guess now you can go full Mullvad.
Did you make your own search engine from scratch?
We did not, we made a front end to the Google Search API.
Our search engine performs the searches on behalf of our users. This means that rather than using Google Search directly, our Leta server makes the requests.
Searching by proxy in other words.
But it needs tech skill to adopt, so even if this Mullvad Browser is basically just prepackaged Arkenfox, that's great to drive adoption.
> Perhaps I’m just really distrustful and cynical.
That's fine, but you should have a good reason for it
If you were to looking for some trust in a VPN, you would want them to offer locations in privacy friendly countries, and highlighting them as such. That would potentially funnel more used to those servers which would be beneficial. You would also want the VPN to ensure the servers in those countries are run by companies based in that country, and not be head-quartered in some other country.
Crypto AG
Opsec is an art, and there are no turnkey solutions to ultimate privacy and security. You gotta put in the effort yourself.
It's just a matter of reducing your surface area: I know for certain my government tracks my unencrypted DNS requests, and I have a static IP, so I'd rather turn Mullvad on if I'm feeling like opening an adult site. They might log my DNS, but it's a little harder for them to correlate my requests than if I were to use my home network. Not impossible, but since I am not at odds with the law, GCHQ is probably not spending billions tracking my every movement across networks.
If you need to send nuclear bomb plans to an enemy government, I hope you have a better plan than trusting the promises of any VPN network.
My threat model is:
ISP that has corrupted my govt to allow them to steal my data. Hide my IP from scummy sites.
My threat model is not:
Keep various TLAs from knowing everything I do online. (because good luck with that)
Basically sending all traffic via VPN seems a big headache to me.e.g. Using gmail from a VPN doesn't help me at all.
They haven't documented this feature [1], but it's part of the official "Multi-Account Containers" extension. It can be found in MAC -> Manage Containers -> Select -> Advanced Proxy Settings at the bottom.
Ah, I see. Unrelated to VPNs, but if you want another anecdote: I had my FB account blocked because I physically moved to another country, and some months in I decided to recover the password to my account (which I hadn't used in a year or more).
Now, I 100% agree that this was a _super_ suspicious-looking series of events, but out of all possible ways to verify my account, how did FB choose to check my identity?
"Please login with a device that you had previously used to access this account. You must do so within 30 days or your account will be permanently disabled." Of course my old devices were in my old place in another country, and I wasn't going back within 30 days.
Fortunately I only used FB to join some IRL groups or to talk to the occasional person who had no other messenger, so it was no great loss, but I can imagine it would have been a major hassle for some people.
Unfortunately it is hard to suggest alternatives. But maybe HN has some ideas how to self host something effective to avoid having to use something like Cloudflare?
Update: "In permanent private browsing mode, cookies and site data will always be cleared when Mullvad Browser is closed." It has this setting ON by default.
I appreciate that to a technical audience this can usually feel like a super pedantic bit of nonsense. But for the other 99% of browser users, this kind of thing can matter!
"You should try out the Mullvad browser!"
"The what?"
Edge? I think it's sharp and techy and modern. So it seems at least... valid. But it also screams, to me at least, the classic Microsoft branding thing of, "this feels like a bunch of 50 year olds in a room declared what they believe to be cool and hip."
Then again. `iPad` was broadly laughed at when it was announced, and through sheer repetition it has been accepted and I don't really even notice the weirdness of the name anymore. So maybe with enough success, Mullvad would be adopted.
env
TOR_SKIP_LAUNCH=1
TOR_TRANSPROXY=1
about:config extensions.torlauncher.start_tor = FALSE
network.dns.disabled = FALSEBe nice if this stuff were hidden by default with some reveal button to show the information, both on the website and browser extension as an alternative to the other options out there. Otherwise I love recommending Mullvad to everyone.
I assume Mullvad browsers has this on by default.
Edit: it seems NoScript is also included which... I'm not sure I personally agree with? But I'm also not a privacy expert so maybe I've missed something, but ublock origin should cover that operability. Someone with experience please correct me if I'm off base here.
Fun fact: this makes you extremely easy to identify, because it gives your browser a very unique fingerprint. If JS is enabled, that is, which you can disable by default, but JS is simply a requirement for many websites to function.
I wonder how they approached this problem this for the Mullvad Browser.
Stupid simple stuff, been using them for a long time (and guess what? no info shared, they don't EMAIL me every time they have a discount for a 3 year subscription discount like some VPN companies)
They just seem very honest and straight forward with their marketing. Never a bad moment.
about:config DOH entries screenshot here:
Can anyone knowledgeable comment on the security implications of this?
Then either untick "Enable DNS over HTTPS" or add a custom DoH.
Can you expound on this?
[1] https://www.amiunique.org/fp [2] https://coveryourtracks.eff.org/ [3] https://browserleaks.com/ [4] https://www.dnsleaktest.com/
It mixes a lot - fonts returned, media devices, the canvas ID - it's pretty good and similar to what you expect from the improvements out of Tor Browser
[0] using amiunique and fingerprint.js (now fingerprint.com) - which most of the nefarious ad networks use
[1] not that just as with Tor, you have to quit the browser or click the 'new identity' menu button. just closing a tab/window and re-opening is not enough. I've always believed that there could be a UI hint to this in private browsers with a unique color/background in the menubar as an indicator
Even after installing Privacy Badger, my fingerprint remained unique and unchanged, with 17.65 bits of identifying information.
For comparison, after I disabled JavaScript, blocked remote fonts, disabled cosmetic filtering, and blocked large media elements using uBlock Origin, my fingerprint was no longer unique, and it dropped down to 9.55 bits of identifying information. Obviously, I don't recommend people do this, but it was fun to check it out.
Most tests are biased to certain methods or do not have a large enough dataset or are only viewed in isolation.
This seems deliberate as no attempts have been made to fix this despite repeated highlighting of this issue online by many concerned users.
(I haven't verified if the Mullvad browser has the same problem).
- Bug: Tor Browser 11.0.9 tries to connect to firefox.settings.services.mozilla.com on startup: https://tor.stackexchange.com/questions/23114/bug-tor-browse...
- Tor Browser phoning home to "firefox.settings.services.mozilla.com": https://forum.torproject.net/t/tor-browser-phoning-home-to-f...
https://i.imgur.com/HV3YRw5.png
There is also no trace of Mullvad in the installed programs list, so I can't uninstall it properly. Not a good experience to say the least.
Nice to see more Firefox related forks though, hopefully help gain more ground on the web for alternative engines.
much more a coordination problem that an engineering one
ty
Guess buying a few more VPN keys will count though...
These are just a few that I spotted. Let's proceed with the discussion as though the above issues were not present.
After looking at the issue tracker, this project wants each Mullvad Browser user to look the same, per OS [6]. Blending into a crowd on the surface seems like a good idea, assuming the crowd was large enough, but that "per OS" detail is a big gotcha.
I personally don't see why a source-modified browser shouldn't be able to achieve perfect uniformity. It's especially suspicious to me that the Tor project never achieved it, despite having had multiple years of developer effort dedicated to this goal, and backed by funding. IMO, browsers should never have been flooded with so many uncontrolled privacy breaking features in the first place.
Modification of the browser is discouraged for any reason, including enhancing privacy features [6]. Now read that again, and this time assume hostile intent.
I mentioned in a different comment that the alternative to uniform blending is randomness. Some of the fingerprints in the browser are already randomized. Plausible randomness is far superior to trying to build up a large enough crowd and simultaneously solving the uniformity issues. The entire javascript engine should be ripped apart and reassembled so that all privacy invading features can only function for client-side specific tasks but cannot speak with the networking and storage features.
[1] https://browserleaks.com/webgl [2] https://browserleaks.com/fonts [3] https://browserleaks.com/ssl [4] DNS Leak test: https://browserleaks.com/ip [5] https://github.com/mullvad/mullvad-browser/issues/23 [6] https://github.com/mullvad/mullvad-browser/issues/1
https://web.archive.org/web/20230403101515/https://mullvad.n...
Nevermind, I had to follow instructions from the github page to download the TOR Browser Signing Key and verify.
I like Mullvad, they're my goto for VPN service when I'm out and about.
i turst the tor browser because of the protocol it uses (the onion protocol), not because of the browser i use it with. Even if mullvad is fully open-source and very transparent about it, i think it is not a good idea to use a browser and a vpn from the same vendor. They have full access to your internet data, and they now (if you use this browser) full controll over the browser you use.
Mozilla/5.0 (Windows NT 10.0; rv:102.0) Gecko/20100101 Firefox/102.0
On my Firefox:
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/110.0
It's interesting to note that the Mullvad browser seems to be based off on Firefox 102.0, which came way back on June 28, 2022:
No. It comes with their extension with contents to the VPN via socks5.
It appears that the process is to 1) open Mullvad Browser 2) (externally) open Mullvad VPN and connect to it 3) click on the Mullvad Browser Extension icon and connect it to the Mullvad proxy. Only after this will the proxy be used and the connection secured.
Contrast this with Tor Browser's process of 1) open Tor Browser. It will only work after it automatically connects to Tor and secures the connection. Do you see the significant difference?
- Makes it hard for advertisers to target you with ads
Cons:
- Funded by the State Department via Tor Project
Considering there's no vendor lock-in and the browser is open source, I think your criticism is completely unwarranted.
Where? Certainly not on https://mullvad.net/en/why-mullvad-vpn/ which is filled with virtue signalling nonsense.
> we encourage anonymous payments with cryptocurrency
Implying crypto (based on a literal public and immutable ledger of transactions) is anonymous.
> we don’t log your activity
No way to validate this claim, but easy to make it.
> The laws relevant to us as a VPN provider based in Sweden
Sweden is part of 14 Eyes and almost all of the privacy legislature (like GDPR) doesn't apply to foreigners.
Plus they use appear to use OpenVPN which is a dumpster fire of vulnerabilities.
Oh, and I love this normalization of ignoring security warnings:
> I get warnings when installing your software!
> That's OK. Allow the software to install.
https://hn.algolia.com/?dateRange=pastYear&page=0&prefix=fal...
It looks like they might use Mullvad's DNS Over HTTPS by default in the Mullvad browser and this would probably be the biggest privacy thing, but whatever your default DNS is might be a larger privacy thing. Your ISP or Google's 8.8.8.8 traveling unencrypted is probably a bigger issue.
It looks like Mullvad is also based off the Firefox ESR (extended support release) version that the Tor Browser uses while LibreWolf would be more up-to-date: https://news.ycombinator.com/item?id=35421718
Overall, the Mullvad browser extension is an excellent resource for anyone interested in enhancing their online privacy and security. The page is well-designed, informative, and easy to use, which makes it an ideal choice for users looking for a reliable and effective VPN browser extension.
$ gpg --verify mullvad-browser-linux64-12.0.4_ALL.tar.xz.asc gpg: assuming signed data in 'mullvad-browser-linux64-12.0.4_ALL.tar.xz' gpg: Signature made Fri 31 Mar 2023 01:15:54 AM CST gpg: using RSA key E53D989A9E2D47BF gpg: Can't check signature: No public key
there's no fixing web browsers.
Take your obscure html rendered and live in peace brother .
Is it based on Chromium or Firefox?
If it's Firefox, that'll be a great win!
Edit: Use Player6225 mentions it could be a hardened Firefox because it's based on the Tor browser
yeah, also they get my bank card info, I become easily trackable if need arises
[1] https://www.amazon.com/Mullvad-VPN-Windows-Android-SCRATCH/d...
The main exploit risk to a modern browser is javascript JIT.
Why?
Firefox hasn't dropped support for Windows 7/8 yet.
If you are somebody using Windows 7/8 etc and want Tor Browser but without Tor, then add the following to your `user.js`
user_pref("network.proxy.socks_remote_dns", false);
user_pref("extensions.torlauncher.start_tor", false);
user_pref("network.dns.disabled", false);
user_pref("browser.aboutConfig.showWarning", false);
user_pref("network.proxy.socks", " ");
That should give you all the anti-fingerprinting measures of Tor Browser but without Tor.Unless they deliberately coded it in like
if OS=Win7/Win8 ; then Crash ; else Run
Which would be a dick move, especially because Firefox, on which Tor Browser and Mullvad Browser are based, still supports Windows 7.---------
Now to your point.
It is absolutely possible to run Windows 7 reasonably securely.
Well..., depends on your usecase.
But the way in which I keep it secure might be a little cumbersome to some.
My router runs PFSense with Suricata, and I encrypt my DNS traffic.
I run a combination of Peerblock(while no longer maintained, it works splendidly in whitelist mode)[1], and Simplewall Firewall[2].
I run a combination of uMatrix(which again, while no longer maintained, it works great in whitelist mode)[3], and NoScript[4] on my Firefox web browser which I run inside Sandboxie[5].
There are also various services that are insecure and must be turned off - UPnP, Print Spooler, RDP etc.
I run mostly FOSS software. The few proprietary closed source software(Games, Sublime Text) that I do run, I run them in SandBoxie or QEMU.
Here are my reasons for not upgrading:
I've modified my `UXTheme.dll` to significantly change my "Desktop Environment" to suit my workflow, and I've heard from people I know to be credible, that latter Windows versions(8 onwards) break system UI modifications when they update, and they don't work quite as well afterward. My modified Win7 UI is way too important to my workflow.
Python have stopped releasing binaries for Win7 after 3.8.10[6] but I'm okay with it. If I do need the newer Python versions for something, I'll just use my Linux Desktop or run Linux in a virtual machine for a Python quickie.
Windows 7 is extremely stable. While not as stable as Linux, I often have uptimes of over 350 days, before a BSOD, by which point I can foresee a crash coming and reboot.
To lean into your metaphor, Microsoft is now shipping operating systems with "open windows" everywhere(way more open windows than my "insecure" Windows 7 has), and we, as users, are having to rebuild the ISOs they release, to make them more "privacy friendly"(yes I'm aware of the difference between privacy and security but they're really interchangeable here), and even then, we're having to use 3rd party "de-bloaters" and Batch/Powershell scripts off of Github, just so the majority of those proverbial windows are closed back up again. This really shouldn't have to be the case, but it is. Microsoft have decided that they would rather their bread be buttered by advertisers than by the actual users of their software.
With Windows 7, I know there's an open window that I can't shut, but I have an electrified fence surrounding my compound, with security cameras and loaded turrets pointed towards that open window and other open windows in my house. I know where Windows 7's security limitations are, and I can mitigate against that, elsewhere. But I will admit, I don't go around recommending laypeople to use Windows 7 though, as the barrier to securing it is high. Even after securing it, the user has to be careful.
In my humble opinion, Windows 7 was the last true Microsoft Operating System. It simply does what is asked of it, and moves out of the way. All Microsoft need have done was support Powershell, DirectX, give Win7 a "security updates as a service" business model(which I would've gladly paid for), and make WSL for it(Cygwin is excellent but WSL would be nicer). I know there is 0Patch, a 3rd party company who sell security updates for Windows 7, but I would've appreciated official Microsoft security updates. I would switch to Linux, if there was a robust equivalent to Autohotkey on Linux, and the games I want to run, worked on it.
So yeah, I still run Windows 7. I can't see myself ever upgrading to another Microsoft OS, ever again. And I am, and I cannot emphasize this enough, exceedingly happy with it.
[1] https://www.peerblock.com/
[2] https://github.com/henrypp/simplewall
In my usecase, it's extremely secure.
But, I'll be back after 5 to 10 years, and if I'm still using Windows 7, and if I remember you, I'll reply to you again, letting you know how well it's been going for me.
I wonder what kind of work flow it is, mind sharing couple of samples?
The video is 1 hours 17 minutes long, so feel free to speed it up a little.
Hope that helps.
Cheers!