Betterfox: User.js to harden Firefox and optimize privacy, security, and speed
github.com
github.com
If it's genuinely just munching CPU if you don't use it, then turning it off by default with a warning that it's going to do that seems pretty reasonable.
(I've not tried their user.js and probably won't, but "realising the accessibility tools thing was important enough to go at the top even if the vast majority of users will care more about other entries in the list" seems like an indication that at least some thought has gone into this)
I also see a disable for 0RTT; why? (Probably for the same reason that disabling TLS 1.2 was popular a few years ago.) Webrender is force-enabled; anyone that this causes startup crashes for is out of luck. Autofill and password saving is disabled; hope you migrated to a third-party app before using this.
I reiterate: Opinionated does not mean Better. It just means opinionated.
Most of the preferences in this will actually reduce the target-able attack surface, and disable some features that could be footguns, but at the same time disable some optimizations that aim to reduce cognitive load on users (which in turns reduces the likelihood that mistakes will be made).
Can you point to anything specific that reduces the attack surface?
When looking at the "securefox" config, it does a bunch of strange things, like enabling embedded TikTok links (https://github.com/yokoffing/Betterfox/blob/443710b0738ebc8f...) and disabling UITour (https://github.com/yokoffing/Betterfox/blob/443710b0738ebc8f...) which Firefox uses to highlight menus and is only accessible by approved Mozilla domains (https://searchfox.org/mozilla-central/source/browser/app/per...).
It's a very strange mix of configs.
Want a mix of speed and privacy, while retaining functionality? Use Betterfox user.js.
Want more privacy and security at the expense of site functionality? Use Arkenfox user.js.
Want Tor prefs but without using its nodes/relays? Use Mullvad Browser.
Want anonymity? Use Tor Browser.
I haven't had a chance to dig though those configs yet, but disabling things like service workers, webgl, normandy/experiments, pocket, and webrtc would be a good start at reducing attack surface
Moreover, it would not decrease your privacy unless:
1. The number of people messing with the setting is very small, AND
2. The default for the setting gives you at least as much privacy as flipping it does.
The second point is not often the case. For example, turning off WebGL provides 1 bit of info ("turned off WebGL"). Leaving WebGL on allows a website to measure your WebGL setup, which is typically far more revealing. Not everyone uses the same GPU hardware and screen, after all.
In general, flipping a setting to off reveals 1 bit of information - but it might indeed be 1 bit that few others know of, thereby reducing your anonymity group in that respect. Leaving a setting on allows a website to probe you further and find out things related to the setting.
See for example amIunique.org -- it tests 4 WebGL parameters, which, for me, have a similarity ratio of 1.17%, 0.94%, 2.68%, and 0.53%. Those are quite horrible numbers and would likely identify me uniquely unless they almost completely overlap.
Is it because we've seen so many let downs? Probably. Can't trust anything or anyone anymore.
Also, mandatory mention: https://librewolf.net/
No, that’s one of the best features!
Edit: The project aims to have the minimum amount of needed changes, but everyone will have a different opinion on what is needed. No one can please everyone, so you have to draw the line somewhere.
Perhaps Betterfox can post a poll and get feedback on how important it is for users.
And with Firefox, the point is not that you can disable these features in about:config (until they remove that ability a few versions later) - the point is why the hell should you have to do any of this for a browser that keeps claiming to be privacy respecting?
And does this turn off wasm or web gpu?
You can make DoH strict by adding user_pref("network.trr.mode", 3); to your user.js. Or you can also go to about:config in the address bar, searching for network.trr.mode, and changing the value to 3.
Just a heads up!
Now somebody else can inform me about the newest one.
#sidebar-box[sidebarcommand="treestyletab_piro_sakura_ne_jp-sidebar-action"] #sidebar-header { display: none; }
Unless something has changed dramatically, the Firefox team (and other teams) test and fuzz Firefox extensively - obviously default prefs and features will get more coverage.
An actual fork like LibreWolf that adds or removes code and ships a different build fundamentally changes how the software is built and invalidates a significant portion of the security work that has been done by the Firefox security team.
I am not arguing that Librewolf or any of the other forks of Firefox[1] are necessarily worse for security, just that browsers are ridiculously complex pieces of software and making claims about security requires more than just gutting or adding features.
[1] other than Palemoon, because screw those guys; when I challenged them on the security program for Palemoon, their loopy leader tried to harass me and other former Mozilla folks. Given their propensity for instability I wouldn't trust them at all.
I should have rephrased my question to: "How do the levels of privacy/security/speed differ between Firefox+Betterfox and LibreWolf?"
I'm sure both have their tradeoffs, but I was just curious if anyone has tried and extensively compared both.
Betterfox is for everyday use cases and should rarely cause site breakage. It also has prefs to prevent annoyances and improve browsing speed.
this is a set of parameters you adjust in firefox..
So, the question is about comparing the settings on both.
Settings for libre wolf are here, https://gitlab.com/librewolf-community/settings
Assumptions
Apply preferences from the common overrides sticky if you want to revert the following behavior:
- Firefox Accessibility Service is disabled to improve resource utilization and security. Override this if you use assistive software.Set keyword searches to true:
user_pref("keyword.enabled", true);
That way it uses your default search engine when searching from the address bar.