My practical approach to surfing the web safely
molily.de
molily.de
I've found NoScript actually very usable, as long as you allow yourself to be fairly liberal in marking domains "trusted." I only truly routinely visit a core 10-20 domains that require Javascript, and they're from "reputable" organizations (my bank, employer, etc.) so those all get marked "trusted" quickly and I don't worry about them going forward.
In the "long tail" of random things I click on from HN links, seeing a "You need to enable Javascript to view this app" message is actually a fairly good signal that I don't want to view that app (though you might be surprised how many websites are browsable comfortably---or even more comfortably!---without JS enabled).
One thing I wish NoScript supported was the ability to mark a domain as a "trusted page domain" in the sense of: "HTML served from this domain can load scripts from any domain" (rather than trust being assigned to the domain serving the script itself). Perhaps it has this feature and I just haven't found it.
See also: https://forum.qubes-os.org/t/ultra-minimal-systemd-free-qube...
https://forum.qubes-os.org/t/alpine-linux-template-non-offic...
https://forum.qubes-os.org/t/systemd-inclusion-in-qubesos/22...
The AdminVM is based on Fedora and has systemd, but it has no network and you you shouldn't run anything there. Unless you think that systemd is actively malicious and specifically targets Qubes, any vulnerabilities in it are not exploitable.
Same experience as you, also: many sites actually work well enough without JavaScript, and the ones that do require it to display anything make me pause and ask if I truly want to give that site the privilege of running code on my computer. Majority of the time the answer is no.
Some work better without JS. The most common are information-based sites with a paywall or signup or whatever. The JS loads some huge wall over the content. Bonus, no cookie popups or another annoyances, and most ads are loaded with JS. Popups are getting ridiculous.
It seems like anything that involves sharing a desktop window (e.g. xhost tricks) is not really security worth the effort, I've got to at least stop block any malware that monitors the screen, clipboard, keystrokes that come after the phrase "sudo", etc.
Is this a thing now? I hadn't seen any big browser vulnerabilities recently. Did I miss something? Or are the vendors not releasing horrifying bugs they found internally with AI fuzzing?
https://blog.mozilla.org/en/firefox/privacy-security/ai-secu...
https://hacks.mozilla.org/2026/05/behind-the-scenes-hardenin...
To be honest, I'm not sure how many (if any) of them have actually been exploited, but in any case, it seems like the cost to at least find a vulnerability anymore has really dropped dramatically.
#!/bin/sh
TMPDIR=$(mktemp -d /dev/shm/chrome-XXXXX)
chromium --user-data-dir=$TMPDIR --no-first-run --no-default-browser-check --disable-features=DefaultBrowserPrompt "$@"
rm -rf $TMPDIRI'm a former Mozillian and a lifelong Firefox user (continuously since Firefox has existed, at least). I know Firefox is slower. I can feel it and have felt it on every system I've ever owned, and am constantly reminded once every few months or weeks or so when I open up Chrome to check something and am confronted with how much snappier it is—even without an ad blocker, which I don't have installed because I don't actually use Chrome.
I know all this and I use Firefox anyway because I don't care.
What I don't do is go online and comment about how there's no difference when there is clearly a difference. Pretending things are otherwise comes across as some form of denial or delusion.
Mullvad Browser[1] is an example of just that, ready to go for people in the real world who don't have the time or inclination to mess around with random extensions and `about:config` hacking.
Also surprised the blog author made zero mention of the importance of keeping your OS up to date. Its all very well having a patched and hardened browser but not if you're running it on a vulnerable OS.
You can still install that extension but from the reported issues the functionality and bugs were increasing with every new firefox version. And obviously that setup only helped with the cookie aspects and not necessarily any security issues from javascript and so on.
Another good addon is ClearURLs 1.27.3 which clears suspicious parameters of query strings on everything what's loaded by page. It sometimes break sites.
There's a supposed spinoff @ https://addons.mozilla.org/firefox/addon/auto-clear-site-dat..., but apparently it's not ready for widescale use (and it's not open-source).
This makes you identifiable across containers and subverts the whole idea.
So don't use sync.
Interesting. From the response at bugzilla it seems that the feature is built on top of "FF accounts" (which I'll have to look into) and that the browser communicates directly with the Firefox sync servers. Meaning that only Mozilla would know your sync identity across containers. Did I get that right? Whether that's a privacy concern is something that I'll have to think about. What's your take?
Why?
Still feels unsafe.
isn't firefox like far less secure than chromium? its sandbox pales in comparison, for one thing.
configuring trivalent on fedora-based distros is a good way to get the security benefits of chromium without all the adtech slop.
anybody using firefox should consider the patches by celenity at https://codeberg.org/celenity/Phoenix
And use chromium based browser (I preffer Brave Origin). Using firefox for "secure browsing" does not make much sense in 2026! Mozilla has different priorities! Firefox development is under financed for several years now, and Firefox has weaker security model!