4.1 Extensions
github.com
external-link
Firefox privacy, security and anti-tracking: a comprehensive user.js template for configuration and hardening - arkenfox/user.js

I’m sure a lot of us are already using Firefox with uBlock Origin, and I’m also sure that most of us already know about Arkenfox.

Despite this, one thing that I’m still noticing on the internet are people recommending extensions that, as per the Arkenfox wiki, are frankly just not needed anymore.

So people, please stop using:

  • Cookie extensions like Cookie Auto Delete
  • URL cleaning extensions like ClearURLs
  • Anti-fingerprinting extensions
  • Redundant privacy extensions like Ghostery or Privacy Badger
  • NoScript

And also please note that Firefox Multi-Account Containers is probably overkill for most threat models, and that Firefox’s builtin Total Cookie Protection is probably just fine.

I’m deeply unfamiliar with Arkenfox, but does it really supercede NoScript? One of my primary uses for NoScript is bypassing soft paywalls.

deleted by creator

Agreed. Ideally, any such single point of failure needs to be under a distributed or accountable kind of control. Perhaps EFF could take over uBO, for example.

Just use LibreWolf. It has everything already set up and it includes uBlock Origin by default.

@blarp@lemmy.ml
creator
link
fedilink
79M

I used to use Librewolf but found it lagged behind Firefox too much when it came to security updates. But I agree with you that it does take the work out of configuring Firefox, which is convenient.

The update schedule used to be pretty bad, but they have really improved. They usually release patches within 1-2 days, but recently, I’ve often seen them release an update on the same day. It’s not that bad, especially when you combine it with just general good security practices. Block known malware on DNS/firewall level, run your browser in a sandbox and just be cautious when clicking on links. Blocking JavaScript as much as possible also reduces attack surface. For high security stuff I just use Vanadium on my phone which is hardened Chromium by GrapheneOS.

NoScript and Cookies Auto Delete are very much needed. uBlock’s JavaScript control is extremely basic and doesn’t toggle WebGL.

As for cookies, I only set them for sites I have accounts or ones that need to remember user data in Chromium. I personally don’t use CAD but I can certainly appreciate its convenience.

Any references you can give? I would like to research this a bit more.

what if u keep them disabled and only enable when need them? i assume it’s OK. 🤷 sometimes u need other extensions.

Mikelius
link
fedilink
209M

I personally prefer NoScript not for just the privacy stuff, but for the security of knowing that an accidental click to a malicious site using some zeroday JavaScript exploit won’t kick in like it would, had it not been default blocked.

My NoScript profile is also fairly populated with things I’ve trusted over the years, so it’s really only new websites that require JavaScript that I have to worry about.

Maybe just me being over cautious, but just keeps me at ease, personally.

NoScript is fantastic.

As a web developer, I have to build tools for the SEO/ad team to turn my beautiful optimized sites to be ad-filled garbage. And frequently, that involves fetching data from third party sites that even I feel disgusted by, that can be easily blocked with NoScript.

My personal view is that anyone who forks a browser is probably not experienced enough to know how much work it is to patch security holes in a timely manner in such a large code base.

Lemongrab
link
fedilink
39M

Good thing arkenfox is not a FF fork and you still get the same updates from Firefox main.

war
link
fedilink
59M

deleted by creator

How exactly are my URLs going to be cleaned without ClearURLs?

My extensions are:

  • UBlock Origin
  • Dark Reader
  • ClearURLs
  • NoScript
  • Multi-Account Containers
  • Cookie Quick Manager (probably not required since I don’t deal much with cookies other than flushing them)
  • LocalCDN

The option in uBlock Origin should really be baked-in and more prominent IMO, also I think I had some issues with the shortener not working on, e.g. Amazon in the past, but things might be working fine now, idk

Funny how even when I toggle the “advanced user” option on, I still can’t see any interactive menu/console to work with individual scripts. This is what prompted me to install NoScript in the first place. Am I using an old version?

Sorry, don’t know about that, I was talking about the ClearURLs replacement

bob
link
fedilink
39M

According to the wiki through ublock but I honestly don’t know how to do that

Is it possible to limit permissions for an extension to just a few domains? Most of them I’m using just for specific sites

@Melco@lemmy.world
cake
link
fedilink
49M

deleted by creator

Cookie management is now handled by firefox natively. In your FF browser bar, go to about:preferences#privacy and choose Strict. Then you can remove AutoCookie Delete extension. If you want to know more, find the the Firefox blog posts about Total Cookie Protection. There are multiple posts on the topic.

Edit: If you want to be super intense, you can also check the box, “Delete cookies and site data when Firefox is closed” although that isn’t strictly necessary if your ETP is set to strict.

I will add, Librewolf (a firefox fork) auto deletes cookies by default

@Melco@lemmy.world
cake
link
fedilink
39M

deleted by creator

You gotta read the blog posts my dude. I’m not going to type it all out for you.

It just says not everything is supported by those extensions. I use Cookie Auto Delete to log me out automatically out of youtube and stuff. Firefox alone can’t do that.

LoafyLemon
link
fedilink
19M

It can. Just use the built-in containers.

Nice, thanks.

L3ft_F13ld!
link
fedilink
19M

Mine does. There’s a setting to clear all cookies on close. I have to log back into everything every time. Never needed an extension for that.

Yes but Auto Cookie Delete does that on tab close. No need to close the entire browser.

L3ft_F13ld!
link
fedilink
19M

Fair. But I’m okay with it only happening when I close the browser.

Multi account containers are super useful for managing multiple accounts though. Keeping work/personal/hobby stuff separate is awesome.

I find the temporary containers extension essential. Set automatic mode and forget.

Sinnerman
link
fedilink
299M

The link says that NoScript is “redundant with uBlock Origin”

I like NoScript because I can click on its icon on the toolbar, and easily select which scripts on a given page to whitelist, or which to whitelist temporarily (until browser quit.) And on any page, I can select which set of scripts (by domain name) on that page to run or whitelist.

With uBlock Origin, it’s only “all script on the page” or “no scripts on the page”, right?

@PeachMan@lemmy.world
link
fedilink
3
edit-2
9M

Ublock Origin allows that as well, but it’s not as easy as NoScript. So, IMO that’s a perfectly valid reason to prefer NoScript.

Take a look at this documentation, it’s pretty good.

https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-quick-guide

With uBlock Origin, it’s only “all script on the page” or “no scripts on the page”, right?

nope. You should read the uBO wiki’s pages about medium mode and hard mode. You have pretty granular control if you’re using uBO in “I am an advanced user” mode.

Sinnerman
link
fedilink
29M

Oh, thanks, I didn’t realize that about advanced user mode, I’ll look into it!

To add to the other fine points here, I almost exclusively do all my personal browsing on my phone. Arkenfox isn’t designed to work on Firefox mobile.

L3ft_F13ld!
link
fedilink
89M

Like the other poster said, Mull is a fork of Firefox for Android that includes tweaks from the Arkenfox user.js.

@Melco@lemmy.world
cake
link
fedilink
10
edit-2
9M

deleted by creator

Gamma
link
fedilink
39M

Love when you install a boring extension on vscode and it has a telemetry setting…

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 2.44K Posts
  • 57.3K Comments
  • Modlog