1,506 karma · joined November 12, 2015
https://www.linkedin.com/in/alex-kontos/
Please note some features became available in Firefox after we added them, not related I believe it was just coincidental.
A high level overview of what Waterfox offers vs Firefox:
* DNS over Oblivious HTTP to encrypt and anonymise DNS requests. Currently the only browser on the market to do so by default I believe? Just a note that we've partnered with Fastly for this and they control the "relay" node in the middle, for proper privacy sanitisation. More info: https://blog.cloudflare.com/oblivious-dns/
* In-depth configuration of numerous preferences within the Firefox codebase, striking a balance between privacy and web usability.
* Full support for JPEG-XL (including for animation, alpha, progressive decode, and colour profiles).
* Vertical tabs and sidebar support: https://www.waterfox.net/blog/waterfox-x-treestyletab/
* In-depth UI customisations. Currently working with black7375, on Lepton for customisations specific to Waterfox. You can view all the UI changes not available in Firefox but available in Waterfox at https://github.com/black7375/Firefox-UI-Fix/wiki/Options.
* "Classic" about:config available at about:cfg and "classic" password list at about:passwords
* Removal of all telemetry within the browser.
* Removal of all A/B testing within the browser.
* Removal of all unnecessary external connections (Google, Mozilla, Meta, etc.) where feasible.
Quality of life changes:
* Ability to disable auto-updates (not available in other forks)
* Integration with Ubuntu's Unity menu on Linux
* Ability to "restart" the browser in one click
* Ability to right-click "unload" tabs not in use
* Ability to "copy" tab URLs
* Ability to enable an old-school status bar—allows you to pin functions and addons to the bottom of the browser UI.
* Ability to disable Ctrl+W (or cmd+W) with a preference.
* Ability to play DRM content such as Netflix, Disney+, etc., not available in any other open source forks.
* Private Tabs (you don't need to open a new private window if you don't want; you can instead open a private tab).
* Ability to have tabs above address bar, below address bar, or at the bottom of the browser UI.
* Extensive changes to the about:preferences page, allowing changing of browser settings usually hidden.
* Technical support for Chrome and Opera extensions (this needs work!)
* Usage of a more privacy-centric search engine when in Private Window mode.
There's a bunch more, but still need to collate them more.
Oh and also no AI bullshit that siphons your data off to 3rd party providers. Doesn't mean I'm completely against it, but it has to be local only and performant IF it were to ever make its way to Waterfox.
So I steer well clear.
The irony(?) being we used to be listed on the Mozilla website :) https://web.archive.org/web/20121229210505/http://www.mozill...
It was impossible to get that point across, especially as S1 wanted to have the final say on what was said. A lot of heartache all across the board could've been saved by just being able to say things as a matter of fact.
But unfortunately people jump to conclusions, don't have good faith discussions and loved just get involved in internet drama.
I feel you. Regulatory bodies have definitely fallen short in many cases, and we've seen concerning proposals from governments that threaten digital privacy and freedom. "Who watches the watchmen" seems incredibly apt nowadays.
However, I feel there's a fundamental difference between imperfect accountability and no accountability at all. With a legal entity governed by stated policies, users have:
1. Transparency about who makes decisions and how
2. Clear terms that create binding commitments
3. Legal mechanisms for recourse if those commitments are violated
4. A persistent entity that can't simply disappear overnight
Perfect? Not really. The ICO in the UK, for example, hasn't been amazing at enforcing data protection. But the existence of these frameworks means that accountability is at least possible - there are levers that can be pulled if someone can be bothered to.
In contrast, with software maintained by anonymous or loosely affiliated individuals, there's no structural accountability whatsoever. If privacy promises are broken, users have no recourse beyond abandoning the software.
FOSS and auditability are valuable safeguards, sure, but they primarily protect against unintentional privacy violations that might be discovered in code reviews. They don't address the human element of intentional policy changes or decisions about data collection.
When Mitchell Baker took the reins, Mozilla became rather more heavy-handed towards us - the irony being that Waterfox was once proudly displayed on the Mozilla website under their "Powered By" banner.
I appreciate the constant existential wobble Firefox faces, but they've made some peculiar decisions as of late.
On one hand, they're finally implementing features users have been clamouring for ages (tab groups, vertical tabs and the likes) - on the other, rather odd policy choices.
I should point out, it seems daft to me when others suggest using forks with no well-established governance of their own, essentially shifting trust from an organisation at least answerable to certain regulations, to individuals with no proper framework or guidelines.
I've done my best with Waterfox over the years to have it represented by a proper legal entity with policies to follow; so if anyone is interested take a look.
Edit: FWIW I've written some more thoughts on it here: https://www.waterfox.net/blog/a-comment-on-mozilla-changes/
In theory I suppose that makes running one of the nodes less of an issue.
Would you guys ever be open to hosting a relay for other parties? I’ve been wanting to deploy OHTTP Proxy for Waterfox but have struggled being able to justify running a node myself and finding two separate parties has been a PITA.
As far as I’m aware, Apple do the same with Cloudflare and Akamai, each controlling one relay.
Unless I’m mistaken, you’re both controlling the client software (closed source) and the first relay? As far as I can tell, trust is still essentially put into your organisation since you still control two critical parts of the setup. So maybe better than a traditional VPN provider, but still flawed?
You can execute it on any platform that supports Java, so I have Linux builds cross compiling to windows with clang and then sign with jsign: https://github.com/BrowserWorks/Waterfox/blob/7eda3b998a56ad...
[1] https://trustzone.com/knowledge-base/purchasing-an-ev-code-s... [2] https://trustzone.com/knowledge-base/purchasing-an-ev-code-s...
> “That’s the whole point of it, we didn’t want to do sort of boring techno stuff as well, or jungle, so we picked speed garage, it’s funkier than house and garage.”[3]
[1]: https://en.m.wikipedia.org/wiki/Buck_Bumble
[2]: https://www.youtube.com/watch?v=w8FQ-N0zb2U)
[3]: https://archive.org/details/64-magazine-15/page/n39/mode/1up
[1] https://android-developers.googleblog.com/2020/06/system-har...
Unfortunately not, but I'd hope to see a reduction to under 10 minutes with the M4 Pro at the very least.
> Also, how often do you have to compile a codebase of that size from scratch and why?
Very often; since Waterfox's changes are always rebased on top of Firefox, every time we pull from upstream, the build system will do a from scratch compile.
A full release build takes about 1 hr (due to monolithic LTO and PGO, which requires 2 builds and about 15 minutes of app runtime to profile).
Any reduction in that time saves a lot of my life over a large period of time.
At least, not that I’ve found - would be curious if anyone else has found a similar way?
Genuinely, why not? Open source projects go through ownership changes (as unlikely as they may be), social engineering, etc. In the unlikely chance something were to happen and anything malicious were to occur, what recourse is a user to have? And we are talking about a web browser here, which will be accessing peoples most sensitive data. I don't think this is an unreasonable stance.
> A UK Ltd. is less transparent than Librewolf, an open-source project run by many volunteers without the incentive to make any money.
Well this UK Ltd is still beholden to English law and UK GDPR. You could argue the merits and teeth that GDPR has, but I don't see why it's not a valid comparison? I can't just start processing personal data without complying with GDPR, for example.
> The risks you are talking about are not inherent to Librewolf, but to Linux and open-source, and thus are not legitimate criticisms of Librewolf.
Linux has the Linux foundation, which AFAIK is going to be beholden to California law? I don't see how that can't also be a criticism of Librewolf (and any OSS in a similar spot?).
> Point 3 is no longer true, the installer comes with the option to enable auto-update and on Linux, it also auto-updates, depending on distro, etc.
It seems to me to still true, because the installer is installing WinUpdater. Which, as it seems, is maintained by an individual developer?
> If you want LibreWolf to be automatically updated (recommended), you can choose to install the LibreWolf WinUpdater[1], which is included in the installer.
> Plenty of feature trade offs to compare though with Librefox.
Yes, for sure. Definitively different goal alignments.
I think that's completely valid.
I was just assuming (maybe incorrectly?) we're talking about what should be happening in general (so what the experience for the layman should be). Now whether that applies to Librewolf is another story, but arguably it becoming fairly known, it should.
Side-note: In Waterfox, I've re-added the ability to disable auto-updating completely. I completely understand the want to manually update software.
> Mozilla has been repeatedly resetting "Always check if Firefox is your default browser" option to "yes" with upgrades.
I'm sorry to say this, but this just seems to be misinformation.
I don't see that anywhere in the source code[1]? Anything I can find regarding prompting the user regarding the default browser is hidden behind an if guard to make sure the pref is `true` and not `false`.
The only scenarios I am aware of that will change the pref if the user has toggled one manually is the `_migrationUI`[2] function (as you can see, no changes relating to `browser.shell.checkDefaultBrowser`). Otherwise, untoggled prefs will be changed if the value in `firefox.js`[3] or `all.js`[4] is changed. As you can see, the last time the pref was modified was 2004.
[1] https://searchfox.org/mozilla-central/search?q=browser.shell...
[2] https://searchfox.org/mozilla-central/source/browser/compone...
[3] https://searchfox.org/mozilla-central/diff/94ff451885bb94679...
[4] https://searchfox.org/mozilla-central/source/modules/libpref...
I would also say a web browser should be the one piece of software constantly updated due to the sheer volume of security patches issued every few weeks.
Also, another assumption, but it’s that doc still builds upon the W3C proposal - would it not be worth raising as an issue in the repo? Seems to still be active.
Safari has Private Click Measurement: https://webkit.org/blog/11529/introducing-private-click-meas...
And AFAICT, Mozilla's implementation is technically superior?
Might be worth opening an issue if you believe there's merit to the attack?