Mullvad Browser
blog.torproject.org
blog.torproject.org
- Can we HN users help push Firefox to incorporate better fingerprint circumvention? (more than current) This is, imo, one of the worst technologies that has been developed around the web. This seems like a thing all privacy focused browsers, which includes FF, should be working on together. This seems like a thing that wins by the network effect, but can be done without an authoritative browser. You just need mass numbers, and while FF isn't that large of a user share, it is large enough that probably most local networks have at least a few connections and every ISP has thousands.
FWIW, using amiunique.org I am unique on FF, Safari, Mullvad, Chrome, and Edge on a M2 Air. Mullvad is 0.22% across the board btw, so looks like that's how many Mullvad/Tor users have tried it. Though I am a bit surprised by some of the results. Similarity is very low for: UTC-07 (3% of users are on the... west coast? This can't be right), screen sizes (I thought this was going to be a win because apple consistency, but all values are <0.1% -- except depth, which is best on Safari and identical on FF/Chrome/Edge. Do people not make their browsers the full screen size? (not clicking green expand)).
- Will the browser end up having a Tor connect switch? I'd imagine this would make Tor more accessible and could make the entry via VPN method easier and safer for many users. Is that why they're working together? I guess I'm a bit confused at the collaboration here? But it does seem natural that they could work to set up easy interfaces like x -> Mullvad -> Tor, x -> Tor -> Mullvad, or even x -> Mullvar -> Tor -> Mullvad? Is this the natural extension?
They can't win, no matter what there's going to a subset of sites that simply won't function when you block their fingerprinting techniques, and you'll get people every thread going "Firefox sucks! It doesn't run this website when Chrome happily does!" and then you get everyone on the other side going "Firefox sucks! It isn't as private as Librefox/Tor/my-other-obscure-fork!"
I don't envy their position.
I was just thinking that this could be the strict option or the custom option in the settings.
Making it an option defeats the purpose - but alleviates the hate OP was talking about. It’s a no win
I dunno, seems about right to me. It's only something like 60ish million people and there are somewhere around 5 billion internet users. Obviously who will be checking the site isn't expected to be perfectly even but that's why the number is also 3x higher than plain user count would suggest.
> screen sizes (I thought this was going to be a win because apple consistency, but all values are <0.1% -- except depth, which is best on Safari and identical on FF/Chrome/Edge. Do people not make their browsers the full screen size? (not clicking green expand)).
Screen size, not browser size. Even on the exact same make and model hardware the OS UI scale setting will alter the reported screen dimensions in the browser. The same is true with people who change the default browser zoom in the browser instead.
You know, I feel dumb now that you're pointing this out. I'm not sure why I originally interpreted this value as an "amount of identifiablity" variable rather than the pure amount. You're right to point that this is a variable that can only be used in support of others and not unique in of itself.
> Screen size, not browser size.
I would think this would make it more likely to be less common. Apple has tight control and thus more consistency. But it is a good point, especially considering the prior point. The M2 Air has a different screen size than the M1 Air, which has a different screen size from *-Air which has a different from pros and so on. We don't need to get into UI scaling to change that. I was just thinking about consistency and popularity of the Apple ecosystem, in the West, compared to the variance in Windows machines. For example, I know that canvas fingerprints tend to have lower variance between apple machines of the same model than windows/linux machines of the same model. Just because there is different chip binning. I was thinking about the same thing with screens. But again, I clearly did a major brain fart and I appreciate the correction.
Not sure if this is representative. According to their website, they have collected about 2 Million fingerprints. Firefox accounts for 42% of those fingerprints, which does not reflect the global market share.
Yes, it's OSS and they are very happy to receive third party patches.
I was more suggesting that maybe we can demonstrate the desire of this, to put positive pressure on making this, and other privacy measures, a higher priority of FF
What does masking specifically mean? Is it returning pre-canned responses to those queries that match non mullvad browser users. Because otherwise the absence of these APIs basically fingerprints the user to the Mullvad Browser which, realistically, will always be a small fraction of total browser sessions.
Some amount of research into fingerprinting techniques will always be needed but it seems to me that a far simpler solution would be to randomize the fingerprint for each connection. It doesn't matter if your browser fingerprint is unique as long as it's always changing. That would also make it harder to detect TOR/Mullvad users since they'll look exactly the same as anyone else with a unique fingerprint. It also gives users the ability to modify some of their fingerprint according to their needs without losing protection. For example, they could freely change their useragent for certain websites/requests while still having a unique fingerprint.
The shared fingerprint makes TOR users indistinguishable from other TOR users unless/until a single identifying factor isn't accounted for at which point all TOR users are identifiable on every connection, across time, different domains, etc. The sameness of TOR user's fingerprints + even just one consistent identifying feature means TOR users could be individually tracked.
A unique canvas fingerprint can be used to track you, but as long as it's differently unique on every request it can't be used to track you because the resulting fingerprint will always be different.
The "hide in the crowd" trick of trying to make a bunch of different people's browsers look identical isn't a bad thing, it's just extremely fragile. Still, it's better than nothing. Making all browsers randomize their fingerprint every time defeats tracking just as well as the "hide in the crowd" trick does (when that trick is 100% perfect) but also adds resilience and flexibility
Forgive my naivety, I don't really know Tor that well or even use it, but aren't nearly all exit nodes known and aren't they routinely checked for? It does not seem like a difficult thing to check for. I mean when I googled to check it seems like it is easy and Tor even provides a tool and publishes the 2188 addresses[0,1,2]. So... I'm quite confused about your assumption because a quick googling is leading me to believe that this is a rather known thing and doesn't require anywhere near state level action. I mean people routinely scan the entire internet and those posts don't even make it to HN anymore because they are so easy.
> The shared fingerprint makes TOR users indistinguishable from other TOR users unless/until a single identifying factor isn't accounted for at which point all TOR users are identifiable on every connection, across time, different domains, etc. The sameness of TOR user's fingerprints + even just one consistent identifying feature means TOR users could be individually tracked.
This is a great point, and I get it. But I'm not sure how this is different from normal situation. Doesn't this mean a misconfiguration of the Tor browser? One or two metrics may not be enough entropy to have confidence in an identity, though certainty you're right that it is of concern. I'm just trying to intuit the entropy difference. I'd wager it matters which metric is broken. But the question is when we start undoing Tor fingerprint overrides, at what point does the entropy decease before it starts increasing again? (as you're suggesting) Is that enough information to confidently identify a person? I honestly have no idea. This is a question since you're stating this is a cause for concern.
> A unique canvas fingerprint can be used to track you, but as long as it's differently unique on every request it can't be used to track you because the resulting fingerprint will always be different.
Is that true? I heard that Canvas Fingerprint randomizers actually decrease anonymity for the average user (i.e. done without other measures such as what Tor and Mullvad are doing). Due to noise being information itself, and is thus itself a fingerprint. You just call the function multiple times and look for differences or call different functions and look for similarities (i.e. the return const value). Maybe not as clear of an identifier as a normal canvas fingerprint, but it does constitute good information as most browsers aren't randomizing. I mean one piece of information alone isn't enough, that is why they collect several. You aren't being identified by only your canvas fingerprint.
> isn't a bad thing, it's just extremely fragile. Still, it's better than nothing.
I'm just asking what your alternative is. Btw, Tor and Mullvad __are__ randomizing[3]. So what is your complaint and what is your suggestion?
[0] https://metrics.torproject.org/exonerator.html
[1] https://2019.www.torproject.org/projects/tordnsel.html
[2] https://ipdata.co/blog/tor-detection/
[3] https://mullvad.net/en/browser/hard-facts
> privacy.resistFingerprinting.autoDeclineNoUserInputCanvasPrompts set to true
> privacy.resistFingerprinting.randomDataOnCanvasExtract set to true
Not necessarily. It'd just mean that someone figured out a novel way to coax some bit of data from the browser that hadn't been considered or adequately accounted for.
> One or two metrics may not be enough entropy to have confidence in an identity, though certainty you're right that it is of concern.
It'd be less worrying if TOR users were more common, but since so few people use TOR at all, and fewer still will use it for any given site/service it means that what would be a low confidence metric for normal traffic might be all you need to track a TOR user.
> I heard that Canvas Fingerprint randomizers actually decrease anonymity for the average user...You aren't being identified by only your canvas fingerprint.
Canvas randomizations are likely to increase uniqueness which is different from increasing the ability to be tracked. If it's implemented in a way that makes it detectable and/or predictable it could increase the likelihood of being trackable depending on the situation. Canvas randomization is useful, just less useful for easily identifiable browsers which document that they do it since it can just be ignored in those cases.
> I'm just asking what your alternative is.
I think it'd be a robust system where many values were randomized in ways that were logical and consistent. For example, a user agent that implies a certain OS would expose a randomized set of values typical to that OS (fonts, drivers, add-ons, GPU, etc) and randomizations would be appropriate (even customizable) by context (session, window, tab, domain, request) so a website making multiple calls to a function would see consistent results while another (unrelated) website would see you as someone else entirely.
This way you'd always appear as a new unique visitor and if someone comes up with some clever trick to expose some new bit of data you'd still be indistinguishable from every other unique visitor with that bit of data. The vast majority of users on the internet are basically always showing up as "randomized" on first visit. It'd mean you could visit the same website 4 days in a row, but each time you'd just show up as someone new who stopped by, browsed around a bit maybe, and then never came back.
The devil's in the details though I guess.
[1]: https://support.torproject.org/#about_why-is-it-called-tor
You can sort out your TOR browser traffic by user agent then focus on a single data point to track a small number of those users (probably to the individual level because TOR browser traffic is uncommon) but a website can't always know what's been/being randomized and can't separate out the randomized users from everyone else with a unique fingerprint.
Actually, which other crowd could they even be referring to with "hide-in-the-crowd"?
Here's a complete list of settings and modifications:
https://blog.torproject.org/browser-fingerprinting-introduct...
The Mullvad Browser download page has this to say:
"Strong anti-fingerprinting from the Tor Project
The Tor Project has a proven track record of building a privacy-focused browser. The Mullvad Browser has the same fingerprinting protection as the Tor Browser – it just connects to the internet with (or without) a VPN instead of the Tor Network."
probably more annoying to fingerprint in general, but its own signal in another way
Basically everyone I know, techie or not have many many tabs open, always. I might have 200+ at the moment? Something like that. They are hidden in containers so I don't see them all but in this current window I have maybe 20.
I never liked vertical tabs, takes up too much screen.
Edit: I mean, it's still a session - just a permanent session.
Personally find vertical tabs easier to organise and take up less space: https://gist.github.com/theprojectsomething/6813b2c27611be03...
Don't most people? I basically always do. And yes, I'm a techie, but anecdotally I see many non-techies with zillions of browser tabs open because they barely notice that tabs are even a feature and so they continually allow new ones to be opened without going back and closing anything.
Total Suspender extension is critical if you have lots of tabs open at once.
I can see 40 tabs with 40 characters of tab name in a single window (actually, I pin 3 rows of 8 tabs, which takes up 3 tab spaces, so I can see 24 pinned tabs and 37 full size)
I wanted to love vertical tabs but I just keep going back. If you have multiple browsers open side by side it gets annoying how much screen the tabs take up.
Sidebery can be toggled with ctrl-e. I just enable when I need it. I also the horizontal tab bar with custom css, saving the space.
https://gist.github.com/theprojectsomething/6813b2c27611be03...
[1]: https://www.pcworld.com/article/823939/vertical-tabs-in-fire...
Interesting. I have never had a need to not have the browser take the full width (at least on my 16" MBP. What's the use case / workflow?
On the other hand, I have good tab discipline in general, so vertical tabs would waste even more space by virtue of dedicating a lot of real estate for displaying next to nothing. But who needs all those tabs anyway?
While doing research, each search yields numerous links that I need to evaluate so I'll open them all in tabs and then I go through them as a task list to whittle down.
I have a whole window for just email + comms. I have several different businesses that all use separate email, etc in containers.
I also have several interests where each gets its own window and has up to 24 pinned tabs of key sites for that topic. These are not business, so I don't have time pressure to whittle down the tabs that I open.
I currently have 368 tabs open and they are all easy to access: Select a window by topic (I use the Titler extension to name windows) and I have 3 rows of 8 tabs pinned at the top and up to 37 tabs with 40 characters of tab name space. So in each window, I can see 61 tabs without scrolling.
Why would I ever want "tab discipline?"
“ I can’t imagine why anyone wouldn’t use vertical threads”
“ doesn’t work on small screens”
“Get a bigger screen”
Consider that most people don’t care to even if they have the money. I sure don’t care for a bigger screen. I find myself more productive in a small screen anyway.
For example, I often have my browser on the left side and my editor on the right. With only 50% of the width, I sometimes prefer to reclaim the horizontal space and switch back to horizontal tabs.
What people want to do is fit stuff side-by-side and move up and down, rarely ever the other way around. That's why vertical tabs make no sense in most contexts. It's why narrow-width fonts exist, those columns are valuable real estate as soon as you have another window pulled up to the left or right, there's virtually no case where a few rows made a difference.
Additionally, I'd argue Multi Account Containers + Total Suspender are not either. Even MAC doesn't come by default w/ Firefox, you still need to install it. I'm willing to bit the vast majority of internet users still don't know about it.
And Total Suspender is really a response to RAM use by browsers. It's a great idea, browsers should implement it, but many people still don't know about it and it's not necessarily a deal-breaker.
you can silo websites away from each other. for example, your work uses outlook and slack. a work tab has those logins memorized, but it won't know about your Facebook login.
you could have a banking tab just for logging in to places like that. I'm a fan
In other words: What I want to do is to use one of the Firefox web browsers to connect to my normal ISP and the others traffic to go thru MULLVAD VPN. I know about "split tunnel", but it does not feel optimal, because every single app must be deselected no to use VPN, to just make one web browser use the VPN. And if you want to run another app thru VPN, you must remember to activate it, not only turn on the VPN tunnel. So is there any way an extension could connect Firefox to Mullvad VPN directly or configure some proxies in Firefox that connects to Mullvad VPN app or similar?
if you use their app it depends on your operating system how their whitelisting works, but you can pick apps you don't want to have routed through their vpn (but by default with their app all system traffic will be routed through the vpn except what you explicitly deny).
This way I have a single browser profile that is routed through Mullvad while everything else works normally.
FYI: news from April
Bunch of discussion then: https://news.ycombinator.com/item?id=35421034
Considering your question from a host/website point of view, connections trough TOR endpoints are blocked way more often than connections trough a VPN.
The problem is, when you did that, many websites would break in the most bizarre of ways. Even now, it still breaks a lot of the web. Couple that with a well known VPN and large swathes of the web are going to be difficult to access.
I'm sure this may go down well with the privacy crowd, but for the general user it was and still is a hard pill to swallow. I wound down any attempts, figuring a balance of privacy and usability would be better and if I were to offer this, why not just point users to use Tor instead?
I figure this is a good opportunity for Mullvad to capture its VPN users and shift them onto a platform they control. Not necessarily a good or bad thing, as I know VPN providers try to launch their own browsers and even some browser vendors launching their own VPN to capture the maximum value out of their users.
I feel like the very act of trying to opt out of the web's surveillance is enough to mark you as a second class citizen on the web. You either submit, and let your isp and google resell your most sensitive secrets, or you're effectively shunned.
Regarding tor, it's a great idea tarnished by the fact that it's used for vile illegal activity. There's no way I would ever run a tor exit node. The risk of some 3 letter agency taking all my hardware for a few months while they figure out I'm not the guy they're looking for is too damned high.
Hell I'm using completely unmodified Edge for banking and government agencies because even something as simple as ublock cosmetic filters manages to break them.
I used to use dark.fail but every site they listed has been continually down for the last 2 years due to some widespread DDOS attack on onions, and now dark.fail itself is basically always down too
Is there a good Dread replacement while we are at it?
Did everyone really move to i2p? because I rarely see anyone talking about that network
> It did take setting a couple environment variables, no GUI method
, which is unknown to almost anyone, would scare an absolute majority of non-technical folk away. Even if what mullvad does is relatively small in scope, it can still provide a lot of value to people.
Think of it this way: Mullvad is sponsoring Tor at >=$100,000/year, and in exchange the Tor Browser developers made a slight fork of their codebase that sets a couple of environment variables and changes the branding. Now the fact that it's just a couple of environment variables sounds like a good thing, right?
Librewolf breaks trust (for lack of a better term) by not offering both of those options.
You just have to assume the binary you download isn’t compromised (maybe you could argue checking the hash is enough) and that the third-party updating service won’t serve you a compromised update.
Killed by Mozilla management and stripped for parts to improve Gecko.
I'm curious, what do people mean by this? How is the bank's financial system any less "nonsense" than crypto? Second question: when the banks start using crypto in not too long (via CBDCs), how will that crypto be any less "nonsense" than crypto?
When things go wrong in real money land, we have a whole legal framework with standing precedent and built up processes for resolving them. Nevermind the fact that I can just call up my local pizza place, give them a credit card number, and get a pizza. Over in the crypto-hellscape, ever since the fall of the big darknet markets, the only real use case for cryptocurrency is trying to convince other people that everybody's getting rich, so that you can sell them your cryptocurrency for real money. Or accepting a ransom for your malware attack. When the only three inhabited niches in your ecosystem are "speculator", "con artist", and "criminal", it's safe to write the entire thing off as "nonsense".
It sounds like (correct me if I'm wrong), the "nonsense" that you see consists of two things: (1) a lack of integration with a legal framework, and (2) that your local pizza shop doesn't accept crypto.
Neither of those things are fundamental shortcomings of crypto though, as some pizza shops do accept cryptocurrency (just not as many), and custodial cryptocurrency is a thing if you're not into "being your own bank", which does give you some integration with the legal system (as long as your custodian is a law-abiding entity, like a well known company). As far as I'm aware, Brave's usage falls within that category.
The Silk Road was the last time anybody used cryptocurrency for anything useful, and beyond the criminality of it, crypto wasn't even particularly well-suited for that task. If I ever get asked for cryptocurrency at a pizza place, I suspect they'll have greeted me by inquiring about a fellow named Galt. At this point, nobody in the space is actually exchanging their "currency" for goods and services. They're treating it as a speculative asset. Meanwhile, the entire ecosystem is saturated with criminals, and not even of the kinda fun Silk Road kind. Just con artists, grifters, and the occasional ransomware connoisseur.
I get it, you have a vested interest in people not realizing this and letting the whole "economy" collapse. But as long as the only legal utility in having cryptocurrency is hoping that someone else will be stupid enough to buy it for more than you did, the whole thing is nonsense.
I beg your pardon?
I am very aware of all of the fraudsters and rug pullers in cryptocurrency. Do you think I like them? Just as with the fraudsters in FED-world, I hope they all get sent to jail for the crimes they pull. There are criminals, frausters, and grifters, in any economic system of a meaningful size. It's just reality, and acting shocked about this doesn't make any sense.
As for "letting the whole 'economy' collapse", what on Earth are you talking about? I do not want the cryptocurrency economy to collapse, I want to see it grow. I think it's doing many incredibly important valuable things, like freeing humanity from digital slavery, and securing the Internet's broken X.509 system.
As for using a SQL DB - it sounds to me like you do not understand what cryptocurrencies are, why they exist, and why they are designed the way that they are. There are plenty of high-quality, free explainers out there, so I won't bore you with one here.
"Do not cite the old magic at me, Witch". I am acutely acquainted with the concept of how cryptocurrencies work, which I must assume you aren't by your failure to engage in my very well suited analogy. The blockchain is a database. It's a kinda shitty one, in that there are higher performance, distributed, append-only databases, except for it's unique feature of being trust-less. Cryptocurrency builds on this technology by shoving transaction details in this database.
So, the only thing cryptocurrency has going for it over a well-sharded PostegreSQL DB is that lack of trust. If everybody has to trust one or more parties anyway, then there is no need for a blockchain.
To quickly address your other attempts to refute what I said: I'm not offended that there are fraudsters in the cryptocurrency space. I'm concerned with the fact that there are only fraudsters in the cryptocurrency space. If no one is using cryptocurrency for anything but speculation and crime, then the entire thing is a net harm to society. It's a somewhat-legal pyramid scheme (speculation) containing a multitude of illegal pyramid schemes, in addition to an assortment of other scams.
And I said you, you personally, have a vested interest in cryptocurrency continuing to exist. I'm presuming from your defense of the system that you are, like many others, engaged in the speculation on cryptocurrency. I said I get it: It is in your best interest to disagree with me. Because without those defenses, the market won't be able to attract new ~~suckers~~ sorry, "investors", and the speculation bubble will pop, leaving you holding the bag. I don't wish that upon you, but the longer a pyramid scheme runs, the more innocent people will be hurt when it inevitably collapses under its own weight.
You sound very confused. Everyone does not need to trust one party. The system as a whole is trusted, or should I say, more trustworthy, because of its trustless nature. If you do not trust yourself to be the custodian of your own cryptocurrency, you are free to trust someone else instead.
> I'm concerned with the fact that there are only fraudsters in the cryptocurrency space.
That's just a lie and you know it. It doesn't sound like you are interested in a good-faith discussion, but are interested primarily in hating on cryptocurrencies. Anyway, you will be a user of cryptocurrencies in short time (as I mentioned above: https://news.ycombinator.com/item?id=37163640 and here: https://news.ycombinator.com/item?id=37168477), so this conversation is somewhat silly.
> Because without those defenses, the market won't be able to attract new ~~suckers~~ sorry, "investors", and the speculation bubble will pop, leaving you holding the bag.
This again reveals your ignorance of cryptocurrencies. You are angry at something you do not understand. Do you display this sort of anger towards commodities too? If not, why not? They are no different from many cryptocurrencies. What about dollar bills? Do you start cursing at them?
Don't worry as I mentioned you'll be using it daily soon too, except (unless I'm mistaken), it sounds like you might choose to use a cryptocurrency built from the ground up to surveil and control you, rather than one that's built from the ground up to enable permissionless transactions. To each their own.
The actual reskin is technically not all that challenging, for all that I'd still not want to do it just for fun. I'm sure that if Mullvad wanted to, they could have released a rebranded Tor Browser with their own development team. But that would have meant missing out on what is probably the main point of the exercise, which is giving more¹ money to the Tor project to make things better for everyone.
[1]: See also https://www.torproject.org/about/membership/, wherein we discover that Mullvad gives Tor a minimum of $100k/year for membership.
Options for incrementally improving privacy are still good, even if it doesn't go as far as the normal Tor browser.
This whole thing STINKS.
I think Tor is inferior to be honest.
If someone uses a commercial VPN I think they're privacy conscious. If someone uses Tor I subconsciously assume something else.
I wouldn't be recommending Tor to my friends of family.
Huh? The Tor Project is primarily funded by the US Government.
You might even encourage some of those criminal acts that will be performed through this browser.
Wanting to be criminal also doesn't make you a criminal.
/s