We've Teamed Up With Mullvad VPN to Launch the Mullvad Browser | Tor Project - monero.town
monero.town
external-link
Today we announced the launch of the Mullvad Browser, a browser built by the Tor Project team and distributed by Mullvad.

The Mullvad Browser is a privacy-focused web browser developed in collaboration with Mullvad VPN and the Tor Project. It aims to eliminate data collection and provide user-centric browsing services, ensuring online activity remains private and secure. The browser has the same fingerprinting protection as the Tor Browser, but connects to the internet without Tor Network or VPN instead. The Mullvad Browser provides anti-fingerprinting protections.

The idea is to provide one more alternative – beside the Tor Network – to browse the internet with more privacy. To get as many people as possible to fight the big data gathering of today. To free the internet from mass surveillance.

Here: >> mullvad browser official <<

Willard Herman
link
fedilink
110M

I am new to privacy. I am confused about which browsers are Chromium based.

Is Mullvad chromium based browser?

Quick answer: no, it’s based on tor which is based on firefox

@myself@lemm.ee
link
fedilink
2
edit-2
10M

deleted by creator

I hope someone forks this and creates an i2p browser, similar to the Tor browser.

ride
creator
link
fedilink
310M

100% same here

@Pantherina@feddit.de
link
fedilink
10
edit-2
10M

If you think this is a good Browser, keep in mind:

  • this is a fork of Firefox with slower updates
  • its simply hardened Firefox desktop. Mobile needs a seperate app, but for Desktop all you need is a user.js
  • its not isolated from the system it has a Flatpak, which is good. But check its default permissions
  • I think it doesnt use a fake Download, Desktop etc. path

Tor Browser Launcher Flatpak is the most secure Browser afaik.

For Firefox hardening, I made “Arkenfox softening”

Its an approach to download Arkenfox, change it to be usable as a normal browser without leaking more data in any way and automating that process.

Its best to use upstream Firefox, best as Flatpak (prove me wrong) and harden it using this well tested preset.

Its just a little crazy, thats why I read all of it and just change some settings, not reinvent the wheel

The benefit of using a seperate app instead of custom configured hardening is that (1) your hardening auto updates and (2) you’re less prone to fingerprinting. Also it’s easier.

True. Thats why I currently use Librewolf. Not sure if my arkenfox script still works.

But Librewolf has some weird breakages, like Videocalls simply not working lol. Until I need that, I stick with it.

Sonalder
link
fedilink
710M

FlatPak is not the as secure as everyone think it is.

I would be happy to find some sources comparing bubblewrap with native Firefox or Chromium sandbox. Because the Torbrowser flatpak is nearly completely isolated

Sonalder
link
fedilink
210M

I don’t have that comparison but here are some resources that critics FlatPak’s misleading security

https://hanako.codeberg.page/

https://flatkill.org/

https://whynothugo.nl/journal/2021/11/26/the-issue-with-flatpaks-permissions-model/

Okay nothing new, nothing about the actual bubblewrap sandbox afais.

Yes they often have bad permissions, but thats because otherwise they would break.

The process is converting standard apps to Flatpaks, by actually implementing PORTALS. Portals are a special file manager that can open files outside the sandbox and symlink it to the flatpaks internal storage. So you can grant access only to needed files.

ride
creator
link
fedilink
810M

Mullvad Browser is Tor Browser without Tor. TorBrowser evolved over many years, with a very long track record and is recommended uncountable times all over the world. So, if you want the TorBrowser without all the Tor stuff: here is it.

I dont like that they also use private browsing. It sucks, is unnecessary, restricts extensions, containers and disabling it is fingerprintable

ride
creator
link
fedilink
210M

You can still use a other web browser for other special usecases. Mullvad Browser has focus on privacy.

Yes. And private Browsing is useless.

Okay, it seems its not clear what I mean.

The purpose of private browsing:

  • one switch, different UI for the “amnesia mode”, LOCALLY
  • use any persons Computer (probably) or leave no data on a computer others can access
  • maybe leave no trace on your own computer
  • easily cleanup lots of things combined

But the thing is:

  • its useful, but only for this threat model
  • you can delete Cookies, Cache, DOM data, Session, Downloads using seperate switches, most of them GUI
  • private browsing is fingerprintable. If you want to only delete cookies, but with exceptions for sites you trust…
  • if you want to save the session, which is local, does not cache sites and is not fingerprintable…
  • you have to disable private browsing (which is fingerprintable! On a browser that has to ne exactly the same to fulfill its purpose!) And set the settings yourself, possible without GUI as this was deactivated.

I asked the Mullvad devs about this, but they dont care. Private browsing also restricts the browser, for example containers dont work, temporary containers for instant cookie cleaning for example. And it has no purpose! These can be individual settings, and simply enabling Session or reven downloads saving will NOT leak data to the web.

This “leave no trace locally” simply does not work for most people. Its your PC, you are the one accessing it. This keeps people away from the browser, even though Firefox with Arkenfox or Librewolf or Mull are perfectly usable, I use them daily.

And that’s all totally fine. Mullvad is definitely going for the leave no trace local browsing people.

If you need to browser with persistence, you have the options that you outlined.

For people who want a daily driver with no persistence it’s perfect

No it makes no sense… they could simply preset the settings:

  • delete cache
  • delete cookies
  • delelte downloads
  • delete session

And have the same thing, without the private browsing annoyance

But then the data would be written to disk, and then it would be deleted from disk, which would leave a trace.

I get this isn’t your threat model. But for the people whose threat model it is then that’s unacceptable.

Deleting data on disk does not actually remove the data. It’s still persists especially on SSDs.

In private browsing it would not be saved to disk? This is a real difference then.

Its not about “my threat model”, its about if private browsing actually makes sense, or if it just restricts the browsers capabilities.

So in PB everything is kept in RAM? And this cant be reproduced with a setting?

@jet@hackertalks.com
link
fedilink
1
edit-2
10M

https://2019.www.torproject.org/projects/torbrowser/design/#disk-avoidance

If you’re saying private browsing mode doesn’t make sense for anybody, I’m going to disagree with you. If it doesn’t work for you that’s fine. But it is something for other people

@nope@jlai.lu
link
fedilink
110M

How does it compare with LibreWolf ?

ride
creator
link
fedilink
410M

Just do a Fingerprint Test:

coveryourtracks.eff.org

Is the other Browser better?

You will have less privacy due to fingerprinting and Mullvad-Browser has the advanced configurations that are in use for many years by TorProject. I never used LibreWolf but they described it as ‘custom version of Firefox’. They integrated uBlockOrigin extension and if you add further extensions it will make you stand out.

Have been a user of Mullvad. This looks really interesting!!

I missed something like this since a similar project (Secbrowser by Kicksecure) got abandoned. All the security and privacy enhancements of Tor Browser, but without the Onion network. It also helps legitimize the Tor Browser/Mullvad Browser’s fingerprint.

Fat Tony
link
fedilink
210M

Do you need the Mullvad Extension for the sake of privacy?

ride
creator
link
fedilink
4
edit-2
10M

It’s all included. It’s made for using it how it is - without installing AddOns. If you would need other addons you will just use another browser that offers that special usecase, but than with less privacy.

Fat Tony
link
fedilink
110M

Follow-up question: Is installing the duckduckgo extension then still recommended?

ride
creator
link
fedilink
310M

No. No other extension in Mullvad Browser. For other usecases besides of good privacy you should use a other browser.

Em Adespoton
link
fedilink
1010M

What core is it based on/forked from? Is it Firefox like TorBrowser?

And what does Mullvad get out of it? Just name recognition?

tetra
link
fedilink
11
edit-2
10M

There is a FAQ about the Mullvad browser on the Tor Project’s website, which gives a few more details.

ride
creator
link
fedilink
1310M

github.com/mullvad/mullvad-browser Firefox ESR - it’s basically Tor Browser without Tor. Mullvad gets name recognition 100%

Should I be interested in this if I already use hardened Firefox?

If you use Arkenfox without any big changes that are fingerprintable, no.

ride
creator
link
fedilink
410M

Yes, it’s more anonymous than firefox with mods/addons. You can do “fingerprint” tests online to compare how unique your browser is. Just use the Mullvad Browser daily - and if you need something special - than you can still use a other solution for the special case.

@Pantherina@feddit.de
link
fedilink
2
edit-2
10M

Addons yes. But hardened means changing the user.js with arkenfox as base or simply use that premade hardening. Mullvad Browser is nothing but Firefox+arkenfox+fancy UI and no Flatpak available.

Other vectors are fonts, which only work in the Tor browser bundle I think, to really fake being on Windows.

NoJSFingerprint using CSS is also still possible, a way to detect your OS. this is the same on all Browsers.

ride
creator
link
fedilink
210M

Just do a Fingerprint Test:

coveryourtracks.eff.org

Is the other Browser better? No, you will have less privacy protection.

Lemongrab
link
fedilink
810M

Probably. Just keep in mind that letterboxing (grey margina to normalize screen size and avoid fingerprinting) is enabled by default and changing that would also change your fingerprint. I use librewolf atm, but i am considering switching if it wasn’t for letterboxing.

Yes. Compare your Firefox and mullvad browser on fingerprint.com

This browser is a collaboration with the Tor project, I think they white labeled tor browser by making it so you don’t need tor to use it

I use it on Fedora, zero issues

is this meant to dailydrive and be as anonymous as tor or better than firefox, but for real sensitive stuff you should still use tor?

ride
creator
link
fedilink
7
edit-2
10M

Yes, dailydrive. More anonymous than firefox with addons.

Nia [she/her]
link
fedilink
310M

deleted by creator

ride
creator
link
fedilink
310M

Just use the Mullvad Browser daily - and if you need something special - than you can still use a other solution for the special case.

I use it as a daily driver. For anything that I’m not logged into. I try to keep most of my normal browsing logged out anyway. So it’s perfect

No linux support? I didn’t see anything on the site.

deleted by creator

DARbarian
link
fedilink
510M

I know it’s at least supported on Tumbleweed because I use it

download page has windows macos and linux

It’s also on flathub

Craaaaaazy! This is new, awesome!

I must have missed it. I’m using mobile right now. Thanks for pointing it out.

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 57 users / day
  • 383 users / week
  • 1.5K users / month
  • 5.7K users / 6 months
  • 1 subscriber
  • 2.44K Posts
  • 57.6K Comments
  • Modlog