If it's genuinely just munching CPU if you don't use it, then turning it off by default with a warning that it's going to do that seems pretty reasonable.
(I've not tried their user.js and probably won't, but "realising the accessibility tools thing was important enough to go at the top even if the vast majority of users will care more about other entries in the list" seems like an indication that at least some thought has gone into this)
I also see a disable for 0RTT; why? (Probably for the same reason that disabling TLS 1.2 was popular a few years ago.) Webrender is force-enabled; anyone that this causes startup crashes for is out of luck. Autofill and password saving is disabled; hope you migrated to a third-party app before using this.
I reiterate: Opinionated does not mean Better. It just means opinionated.
Most of the preferences in this will actually reduce the target-able attack surface, and disable some features that could be footguns, but at the same time disable some optimizations that aim to reduce cognitive load on users (which in turns reduces the likelihood that mistakes will be made).
Can you point to anything specific that reduces the attack surface?
When looking at the "securefox" config, it does a bunch of strange things, like enabling embedded TikTok links (https://github.com/yokoffing/Betterfox/blob/443710b0738ebc8f...) and disabling UITour (https://github.com/yokoffing/Betterfox/blob/443710b0738ebc8f...) which Firefox uses to highlight menus and is only accessible by approved Mozilla domains (https://searchfox.org/mozilla-central/source/browser/app/per...).
It's a very strange mix of configs.
Want a mix of speed and privacy, while retaining functionality? Use Betterfox user.js.
Want more privacy and security at the expense of site functionality? Use Arkenfox user.js.
Want Tor prefs but without using its nodes/relays? Use Mullvad Browser.
Want anonymity? Use Tor Browser.
I haven't had a chance to dig though those configs yet, but disabling things like service workers, webgl, normandy/experiments, pocket, and webrtc would be a good start at reducing attack surface
Moreover, it would not decrease your privacy unless:
1. The number of people messing with the setting is very small, AND
2. The default for the setting gives you at least as much privacy as flipping it does.
The second point is not often the case. For example, turning off WebGL provides 1 bit of info ("turned off WebGL"). Leaving WebGL on allows a website to measure your WebGL setup, which is typically far more revealing. Not everyone uses the same GPU hardware and screen, after all.
In general, flipping a setting to off reveals 1 bit of information - but it might indeed be 1 bit that few others know of, thereby reducing your anonymity group in that respect. Leaving a setting on allows a website to probe you further and find out things related to the setting.
See for example amIunique.org -- it tests 4 WebGL parameters, which, for me, have a similarity ratio of 1.17%, 0.94%, 2.68%, and 0.53%. Those are quite horrible numbers and would likely identify me uniquely unless they almost completely overlap.
Is it because we've seen so many let downs? Probably. Can't trust anything or anyone anymore.
Also, mandatory mention: https://librewolf.net/