LibreWolf – Custom version of Firefox, focused on privacy, security and freedom
librewolf.net
librewolf.net
Edit: Turning off the anti-fingerprinting feature in LibreWolf is needed for online banking to work.
That said it is possible to have firefox start cleanly with absolutely no network traffic except for sites you visit.
alias workfox="firefox -P work"
alias funfox="librewolf"Don't forget about Firefox profiles though. You can have unlimited, 100% isolated browsers with profiles. I use a few dozen Firefox profiles.
For isolation of cookies but not preferences, you can use Multi-Account Containers within a single Firefox profile. I use this for admin-vs-user accounts at AWS, GitHub, etc.
I do keep a user.js around to speed things up when doing a new install, but it's still annoying to have to read reddit or here to see if an update adds something new to disable.
Mullvad browser is another option for those who enjoy Mullvad. Note that it can be used without Mullvad service.
Could you share, if possible..
hi, do you have a breakdown or some stats for this?
https://assets.mozilla.net/annualreport/2021/mozilla-fdn-202...
They can't take money given to a 501c3 charitable organization and use it to fund the expenses of a for-profit corporation (Mozilla Corp). That would be tax fraud. On the other hand the Mozilla Corp has to exist because otherwise it would be legally challenging to do a lot of things they need to do such as business deals. Exceedingly few Foundations work that way without doing something akin to what Mozilla does.
>Its concerning to me though because that means Google has influence in Firefox, so "using the alternative" still means being affected by Google's decision making. ... They have stood against some of Google's decisions like their web DRM, which is great! But I do wonder if any lower-profile changes might have been pushed through on Google's request.
HNers say this often but nobody has ever freaking pointed to anything. It's nothing but FUD at this point and it's incredibly tiring.
Exhibit A.
Fine, it's a potential conflict of interest. But there's still a step between having a potential conflict of interest and being compromised by Google / influenced by proxy. You don't get to jump from point A to point B. That's FUD.
There are near-monthly examples of Mozilla going against Google on big-ticket items, and nobody seems to be able to point to any examples otherwise, but we're supposed to criticize them for being too dependent on Google while ALSO criticizing them for profitable side-projects or cross-marketing that diversifies their revenue (like VPN, Pocket, the Disney movie thing, etc.)
Simultaneously:
* "how dare they work on something other than Firefox even if it makes money" and
* "how dare they monetize Firefox" and
* "how dare they take so much money from Google"
Yes. Perhaps you've heard of the concept of a non-profit? Specifically a foundation, organized and operated exclusively for charitable purposes?
https://www.law.cornell.edu/uscode/text/26/501, subsection (c)(3).
I'd rather Google does pull that trigger so we can get some anti-trust going. They've been overdue for years on that front.
That thing is so minuscule and more of an everyday feature that I really don't see all the fuss about it.
Also, it is a game theory "both would lose if stopped" situation with google, so no, google has no way to affect Mozilla directly. If they were to stop it, Firefox might stop being developed and Google definitely gets sued, and it is basically free money for Firefox, setting the default search engine is no big deal.
When are we going to get e-commerce & e-banking to stop being so hostile towards consumers?
"We" won't because the vast majority of internet users don't care about privacy. It sucks, but that's the way it is.
You and I, however, are free to vote with our wallets. I literally will not buy from a company or brand that tries to take advantage of me in some way, even if the alternatives are worse somehow. It's a drop in the bucket, but it's all I can do.
(And before someone mentions it, no, shouting about it on social media is not a valid action to take, because social media is where everybody shouts about everything all the time.)
Most often the developers are some random anonymous Joes without CVs or anything proving they have reputation at stake.
Thank you, but no thank you. Even if the official Firefox "leaks" something it's well controlled and well known.
What do these browsers do? I've no idea.
I have LibreWolf installed and I use it from time to time (although I prefer Brave), but I don't have that much trust in project as is. I think if it had sponsorship and could afford to pay a few reputable pro-privacy developers to maintain the project then there's less risk, but as it stands is anyone honestly looking through all the source code to validate their pro-privacy claims? And even if they did, could you trust them or their releases?
Are you really serious? Firefox source is 21 million lines of code.
If it is a random Joe and not, say, a malicious effort of a major government posing as one. That's the problem.
> but the poor non programmer user wouldn't be able to do this
we are on a programmer forum.
Yes, and that same issue stands for extensions that are essential for making the browser usable. Who uses Firefox without uBlock? I won't use a browser that lacks a feature rich vertical tabs solution and that requires me to use sidebery with Firefox. That essentially forces me to trust a host of extension creators that I know nothing about. Yes, source can be reviewed, but I don't have the chops to do it and it doesn't seem like there is a non-profit organization that is taking that on (why doesn't EFF?)
Personally I do try to limit the amount of them I run, stick with recommended and take at least a glance at the source from time to time, but it would not defend against version updates or good efforts to obfuscate bad code. I do feel at least somewhat confident that for recommended extensions with substantial usage the internet would surface funny business quite quickly.
But yes, I would love for some independent third party to have some review program! Unfortunately it's not clear how it would be funded.
To this date not a single extension which has been marked as recommended by Mozilla was found to contain malware.
Google on the other hand while being 1000 times richer has none of it.
I use open source for the vast majority of things I do, but I'm still very selective about what I run. It's not an open source thing -- I also don't go out and grab random closed source executables from people I've never heard of.
People are distrusting unknown software from unknown devs, not open source software.
pick them up individually and maintain your own fork, not that hard
Mozilla doesn't actually care that much about privacy or freedom, it's just marketing to make line go up and to the right while Mozilla staff can keep collecting paychecks for being "the good guys". There's a lot of money involved.
There is a big disconnect between what they say and what they do.
They're not an ad company, so Google/Chrome is obviously worse, but if you care about privacy you don't ship a browser with surveillance features in it (which is what Firefox is).
I am happy this project exists, and I will support them. This is how free software is supposed to work.
I'm personally not crazy about telemetry implying information is uploaded to a software provider, but from experience I know that trying to create a software without getting in-use data is basically flying blind. You cannot expect users to tell you about problems or bugs they have, they will just stop using your software and you will never know why.
Apple was throttling the CPU when the battery was old and could not sustain such power draw peaks in an effort to make the device remain usable for a longer period with a mostly-consumed battery pack. Had they not done so, the device would be unusable sooner.
To assert that it is to make you buy new hardware is a factual error.
You may not force feed me cookies.
Even with all telemetry disabled (including the option "Allow Firefox to send technical and interaction data to Mozilla") and without anything showing on that page, the browser still sends out interaction data by means of so called "pings", URL parameters, etc.
Like what do you even think, Mozilla people are sitting on top of all that sweet
PING www.mozilla.org (3.161.119.172) 56(84) bytes of data.
64 bytes from server-3-161-119-172.vie50.r.cloudfront.net (3.161.119.172): icmp_seq=1 ttl=248 time=4.06 ms
64 bytes from server-3-161-119-172.vie50.r.cloudfront.net (3.161.119.172): icmp_seq=2 ttl=248 time=4.16 ms
64 bytes from server-3-161-119-172.vie50.r.cloudfront.net (3.161.119.172): icmp_seq=3 ttl=248 time=3.64 ms
What the hell would they do with that?Regardless:
The browser asks me if I allow it to make these connections.
I tell it in unmistakable and irrevocable terms that I do not.
The browser makes these connections anyway.
The problem was never the connections or the contents of the data stream. You were aware of this before posting your comment, and yet you commented anyway. You are a troll.
1: https://support.mozilla.org/en-US/kb/how-stop-firefox-making...
The point is, don’t lie about saying you respect privacy with half-baked options and telemetry for me but not for thee bs. If I turn off telemetry, you aren’t allowed to send telemetry. Of any kind. Not a crash log. Not an install token. Not a call home to see if maybe possibly your on an airport wifi and make-our-app-work-edge-case()
When the setting labelled "Allow Firefox to send technical and interaction data to Mozilla" is unchecked, the browser still sends out technical and interaction data through parameters added to various browser-provided/generated URLs (e.g. search results pages from built-in search providers, Firefox documentation links provided by the browser, DevTools compatibility panel links to MDN, etc.), by sending out pings when hovering over or clicking interactive browser-native interface elements, and in several other ways.
In summary: that setting is non-functional and should either be fixed, re-labelled, or removed entirely.
By your logic, realistically, Google invading my privacy isn't a particularly big deal since they know the value of the data they're harvesting and will guard it. And third party data brokers are actually just making my web experience more tailored and relevant, so I should let them have their way with me too. Everyone has a good reason to cram something into my business.
People might still object to diagnostic data and Firefox's handling of it, but it's disingenuous to state that they're the same.
They're both companies spying on people to improve their own products, ostensibly to the customers' benefit.
You have literally no logical or moral delimiter between how Firefox spies on me to improve Firefox and how Windows does it or how ad companies do it. I'm sure you'll move the goalpost now and strain yourself to come up with something ex post facto, let's hear it.
I don't see the difference. In one case you are trying to improve your product using stolen data (which presumably results in your user sat scores and/or userbase going up and you continuing to receive a paycheck, ie monetization), and in the other case you are just selling the stolen data directly.
In both cases you are taking private data without consent and using it to get money, or money-equivalent things (like a better product or more users).
Technically and philosophically there is absolutely no distinguishing feature between opt-out "telemetry" and spyware. Both are using private user activity information, exfiltrated silently and without affirmative consent.
Are countries with opt-out organ donation also evil? Doesn't the litany of saved lives worth more than a post-death "inconvenience"?
Yes, 100%. They should not exfiltrate data without consent. If the owner is fine with it, they can just ask! (I'll let you in on a secret: they don't ask because most users, when asked, do not want to be placed under surveillance!)
> Are countries with opt-out organ donation also evil? Doesn't the litany of saved lives worth more than a post-death "inconvenience"?
You don't need your organs when you are dead. You do need your privacy when you are alive.
> In both cases you are taking private data without consent and using it to get money, or money-equivalent things (like a better product or more users)
This is just word salad. Opting in is consent. You are absolutely free to opt out, by following the clear instructions on the website [0], and you can continue to use the software. Your rights are being deprived here.
Secondly, "money equivalent things" is a reductionist argument. Not everything fits neatly into a black and white "right" and "wrong" bucket, and arguing it does is forgetting about the fact that technology doesn't exist in a vacuum any more than any other product or industry.
> Technically and philosophically there is absolutely no distinguishing feature between opt-out "telemetry" and spyware.
Technically there's no difference between me sending any kind of data to a remote service. Using rote logic to infer behaviour is a fallacy, and when I read comments like this I end up (unfortunately) coming away thinking "this person has no critical thinking skills". I'm aware it's an ad-hominem, but logically there's no other explanation other than you can't possibly understand anything other than your narrow world view.
Telemetry is spyware if it's done without the active informed consent of the user. What the collected data is actually used for isn't relevant. Consent is the relevant factor.
So opt out of it. Calling it spyware is inflammatory, and disregards the reality of the world that we exist in.
> It's just marketing to make line go up and to the right while Mozilla staff can keep collecting paychecks for being "the good guys". There's a lot of money involved.
And makes you sound like a conspiricy theorist.
> They also ship closed source DRM in the browser which infringes on software freedoms.
If FF didn't have media support I would switch to chrome, immediately. This is speaking as someone who has dogmatically used Firefox for 15 years. Software, such as web browsers don't exist in a perfect world that I wish it did. Instead, we have DRM, we have telemetry. A userbase requires marketing, which requires money. I wish it didn't, but it does.
And they blog about all of this, from how the data is used to how you can see it for yourself to what efforts they make to ensure privacy while doing so.
To call it "hidden" is either deliberately ignorant or a lie, I'm not sure which.
https://blog.mozilla.org/data/tag/telemetry/
I thought it wasn't shipped with the browser but the browser asks if you want to download it when you first need it.
But calling it out like that is just scummy, as they don't do anything malicious. All of these are just basic business practices done by most software you have on your computer.
[0] https://www.pcmag.com/news/mozilla-signs-lucrative-3-year-go...
Which makes one wonder if the existence of a competitor is a good measure of whether a monopoly exists. If a company is funding its main competitor, is it really a competitor?
Google has a stranglehold on the browser market.
Mozilla gets a some heat from the tech community for their pretty reasonable business model. I’ve seen Firefox be accused of being just about as bad as Chrome when it comes to user privacy and product monetization.
To me that has always felt like a “both sides are the same” argument.
In other words, not all telemetry is created equal.
Such as?
Also, I really don't get all that fuss about some basic "telemetry", that word became way too overloaded. But the least I can do is like, share some basic data with this open-source project I freely use for many hours each day, e.g. in case of a crash.
I think it’s worth noting that Librewolf provides unsigned binaries and at least on Windows, you need to trust a third party service to provide automatic updates.
Is anyone who is more familiar with Waterfox and LibreWolf able to objectively expand on the differences between these projects?
It sounds like the unsigned binary may be a maturity issue that will get tackled based on the mission statement(educated guess?).
Would greatly appreciate anyone with more knowledge about these projects elaborating.
From a comment[1] I’ve made before for this kind of comparison:
“Now, ignoring feature differences between all the forks out there, I'd like to present a different perspective and consideration that I think gets overlooked when comparing forks like Waterfox to other forks (if I am incorrect regarding Librewolf, someone please correct me).
* Waterfox provides signed binaries for download. Librewolf (and most of the rest) do not. Checksum's are all well and good, but IMO, not enough. Code signing provides trust.
* Librewolf does not provide auto-updates. There are 3rd party tools out there, but IMHO that brings in its own set of problems, and breaks the chain-of-trust.
* The most important one that I believe, maybe apart from Pale Moon, only Waterfox does, is offers accountability. There is (and has been since 2012) a legal entity behind Waterfox. That used to be Waterfox Limited, then it was System1 and now BrowserWorks (the entity I control). Laws must be abided and the end user actually has an entity to hold accountable. GDPR, CCPA, the rest are things that actually need to be followed. The other projects, who are you really going to hold accountable if things go wrong? To me this is super important because a browser is used for sensitive information. It's just not worth the risk otherwise. This also goes hand in hand with the code signing.
* Above all else, Waterfox has been around for 12 years now.
Don't get me wrong, things like EV code signing certs are a bit of a racket, and yeah you can jump in and code audit all those other forks too. But really, push comes to shove, they can just disappear into the aether.”
[1] https://reddit.com/r/waterfox/comments/14seevh/waterfox_or_l...
My use case: I mainly run the Unity desktop on Linux, both on traditional Ubuntu and on the Ubuntu Unity newly-official remix. On other distros, I use Xfce and I am trying to make a macOS-like layout via the Docklike Taskbar and AppMenu panel plugins.
Waterfox works with external global menus, like Firefox used to in the pre-Quantum era when Ubuntu used Unity itself.
LibreWolf does not.
So, I removed LibreWolf.
I don't care much about the telemetry stuff. Waterfox survived the Foxstuck outage fine and unaffected:
https://www.theregister.com/2022/01/18/foxstuck_firefox_brow...
That's a win.
I adopted Waterfox because I made extensive use of XUL extensions and Mozilla disabled them in Quantum. They still worked in Waterfox, for years, so I stayed.
Waterfox seems to work harder for its users. Mozilla doesn't care.
Waterfox: I came for the extensions, but I stay for the UI improvements and greater reliability.
While it's difficult to track Waterfox's stance, this is from one of the earlier blog posts on what appears to be a hot button topic for users:
I’ve never wanted or tried to have Waterfox appear as a privacy tool or anything more than what it is. That’s for hyper specialised tools such as Tor. People have extrapolated more from Waterfox themselves.
I never wanted Waterfox to be a part of the hyper-privacy community. It would just feel like standards that would be impossible to uphold, especially for something such as a web browser on the internet. Throughout the years people have always asked about Waterfox and privacy, and if they’ve ever wanted more than it can afford, I’ve always pushed them to use Tor. Waterfox was here for customisations and speed, with a good level of privacy.
I can respect what the community fights for, but I don’t think I can respect how they sometimes fight for it or how they act when they believe they are wronged. Harassment and foul words seem to be the normal, as I’ve experienced. As far as I’m aware, Waterfox has never been listed anywhere as a privacy tool, and rightly so.
Note the Waterfox commenter in this thread is not calling it "privacy" tool, while focusing on aspects that carry "trust". These are indeed distinct.
And System1 are an “ad-tech” company but the term should be used loosely. The ownership made sense as they are a search engine aggregator and they own a bunch of old school search engines like DogPile, InfoSpace etc. Nothing to do with what people associate ad-tech with, i.e. tracking you across the web or collecting personal data.
Some constructive criticism, if you're open to it: The web page is just a bunch of standard marketing fluff with about 5 download links scattered around. It looks a lot like every other "product" website out there screaming, "trust us, it'll be worth it!"
If you really want to attract people like me to it, you can't just _say_ you're awesome, you need to _show_ us you're awesome. In your blog (which is hard to find), you express great gratitude towards your users and community. Where is this community, exactly? I might like to join it but I can't find it anywhere. I had to scroll all the way to the bottom of the page to find a link to the source code (which just says "GitHub," mind).
I had to search pretty hard to find out that it is open source and apparently actively maintained, so I will check it out after all. But I was seconds away from just closing the tab out of disinterest and not looking back.
Definitely, much appreciated. You aren’t wrong about the fluff. We did user studies and showed people responded really well to this kind of landing page. I’ll see if I can have some more “hard facts”, but the average user doesn’t really understand the terminology which is why it’s dumbed down on this page - which essentially equates to fluff I suppose.
For the blog, it’s in the navigation, not sure how to have it more prominent without it being obnoxiously placed? Open to suggestions.
For the community, good points. I’ll make sure the subreddit and GitHub are more easily accessible as that’s where the community is based around and it’s very active.
https://support.mozilla.org/en-US/kb/telemetry-clientid
Settings -> Firefox Data Collection and Use -> turn off telemetry.
Like all of the settings detailed at the link below:
https://github.com/fork-maintainers/iceraven-browser/issues/...
Full disclosure: I maintain Mull and Fennec F-Droid.
Brave, Librewolf, Mullvad, and Tor hide the user's screen dimensions, whereas Firefox and Chrome don't. I'm curious, how often does that break things? I imagine that quite a few sites use this for choosing how to position things with JavaScript. Certainly not a majority, but with how many websites an average techy visits on an average day, it might still be somewhat frequent that you get ill-fitting content.
Do you use Librewolf, or does someone else use it who can tell?
Pretty much never. They hide it by changing it. This results in a margin around your view port that is fitted to one of several common dimensions. Since they are common, nearly all websites look okay in it.
Their opinion TLDR; no auto-updater (community auto-updater exists), no advantage to config Arkenfox.js by yourself (but why do I need to be a json geek to just use a browser?)
LW the best daily-driver browser for me, they still include the option to use FF Sync, which is supposed to be safe as E2EE. Mullvad Browser is better but hard to daily drive.
Similar to ublock origin advanced mode (which basically is uMatrix continued), be prepared to fix the site by yourself sometimes. But for safety, privacy, anonymity and security, hell yah.
Is anyone out there self-hosting firefox sync successfully? My googling seemed to only bring up a deprecated version so I haven't really tried setting it up yet.
Why safer? Because with your own self-hosting, now you have to have an extra device wide open to the Internet whose safety and security you need to maintain. If it's some shared hosting, you'll have to trust your hosting provider.
Not that you should necessarily rely solely on the VPN for your security, but it helps.
I don't use or recommend exactly what they do but they have a long list of settings you might want to change that is better documented than any other source I've seen and if you click the wiki link there is detailed info about how user.js works.
https://gitlab.com/ac130kz/dotfiles/-/blob/main/configs/user...
Since the Librewolf developers are providing a .deb package themselves, they could apply to become a Debian Maintainer; i.e. be able to upload that package (and no other packages) directly to Debian.
LibreWolf: A custom version of Firefox, focused on privacy, security and freedom - https://news.ycombinator.com/item?id=36921443 - July 2023 (8 comments)
LibreWolf: A privacy-focused Firefox fork - https://news.ycombinator.com/item?id=31894749 - June 2022 (77 comments)
LibreWolf – A fork of Firefox, focused on privacy, security and freedom - https://news.ycombinator.com/item?id=30720301 - March 2022 (217 comments)
LibreWolf – A fork of Firefox, focused on privacy, security and freedom - https://news.ycombinator.com/item?id=29106155 - Nov 2021 (306 comments)
LibreWolf: A fork of Firefox, focused on privacy, security and freedom - https://news.ycombinator.com/item?id=26034774 - Feb 2021 (1 comment)
LibreWolf – A fork of Firefox, focused on privacy, security and freedom - https://news.ycombinator.com/item?id=23901130 - July 2020 (5 comments)
You can deduce a lot with enough data.
For this reason I switched from Homebrew to Nixpkgs.
The example I provide: imagine if you put up a sign at the entrance to a party that said "by entering this party, you are going to be groped".
Telling someone you are about to violate consent is not the same as getting affirmative consent. Equating them is dishonest.
Using the example of sexual assault just makes the issue look more extreme than it is.
You might as well say “By entering this building you consent to be murdered,” but we all know that’s taking the slippery slope too far.
Usage statistics and bug telemetry isn’t the same as getting groped. Homebrew is up front about exactly what is collected: https://docs.brew.sh/Analytics
My computer is not a public space and the software that is installed on it, and when, and the IP address used to do so, are private information. Exfiltrating that data without consent is a violation of my right to privacy, full stop. Nothing that is said, no notice that is provided, can change that.
You could just as well say "by entering this building you consent to be murdered". It illustrates the point similarly: a lack of objection is not affirmative consent.
Every fucking piece of software out there is packed with shady spyware and BS, and everyone thinks he's entitled to treat users as cattle and do whatever he wants to them.
It's probably going to keep getting worse at this rate too. It'll become illegal to do anything privately or anonymously in the name of preventing misinformation and spam/click fraud
If you invite me over for dinner I don’t need to get your consent to wash my hands or use your bathroom. That is implied by inviting me over to dinner.
That’s why I think the “consent to be murdered” argument is such a bad analogy. It assumes the slippery slope goes all the way.
Just because I think (e.g.) Homebrew’s analytics doesn’t need opt-in consent doesn’t mean I believe that all forms of analytics and data collection shouldn’t need opt-in consent.
I think that an application having a default that collects non-personal crash and bug analytics is acceptable, while an application that collects more detailed personal information isn’t.