Yesterday I asked you guys what your favorite addons are. Here is a compiled list plus some of my own recommendations:

Essential:

uBlock Origin (ad + malicious content blocker)

Consent-o-matic (auto-decline cookies + tracking) recommended by @slazer2au@lemmy.world

Privacy:

Multi-Account-Containers (isolate tabs and websites) recommended by @Iceblade02@lemmy.world

Temporary Containers (like Multi-Account-Containers, deletes cache & cookies automatically)

uMatrix (advanced content blocker)

ClearURLs recommended by @padge@lemmy.zip

LocalCDN (use local frameworks) recommended by @Kerb@discuss.tchncs.de

CookieAutoDelete recommended by @ooli@lemmy.world

YouTube:

SponsorBlock recommended by @Kelly@lemmy.world

DeArrow (replace obnoxious thumbnails) recommended by @shrugal@lemm.ee

Customization:

DarkReader recommended by @noroute@lemmy.world

Midnight Lizard (like DarkReader with more customization)

nightTab (customizable startpage)

Sidebery (Tab list in sidebar) recommended by @SomeGuy69@lemmy.world

Misc

Bypass Paywalls Clean recommended by @lorkano@lemmy.world

17 points
*

Most of the “privacy” extensions do little to nothing to protecy your privacy as of today, due to them either being abandoned, replaced by features integrated in ublock origin or just not relevant anymore because of the actual fingerprinting strategies employed at the current time.

And it is not “random uhh acktshually🤓 lemmy user” who’s saying this, but the wiki section of the arkenfox user.js project. https://github.com/arkenfox/user.js/wiki/4.1-Extensions

Installing them only expands the attack surface of your browser, consumes resources and makes you more fingerprintable.

They are remnants of a time when you needed a full day and a degree in CS to properly set Firefox for privacy. Luckily, things are more straightforward nowdays.

Temporary containers:

TC is no longer maintained. While TC provides sanitizing, and uses a dFPI-compatible API, this is not why it is recommended as optional […]

️Sanitizing in-session is a false sense of privacy. They do nothing for IP tracking. Even Tor Browser does not sanitize in-session e.g. when you request a new circuit. A new ID requires both full sanitizing and a new IP. The same applies to Firefox.

uMatrix:

No longer maintained, the last release was Sept 2019 except for a one-off patch to fix a vulnerability Everything uMatrix did can be covered by prefs or other extensions: use uBlock Origin for any content blocking.

ClearURLs:

Redundant with uBlock Origin’s removeparam and added lists. Any potential extra coverage provided by additional extensions is going to be minimal

LocalCDN:

Third parties are already partitioned if you use Total Cookie Protection (dFPI)

Replacing some version specific scripts on CDNs with local versions is not a comprehensive solution and is a form of enumerating badness. While it may work with some scripts that are included it doesn’t help with most other third party connections

CDN extensions don’t really improve privacy as far as sharing your IP address is concerned and their usage is fingerprintable as this Tor Project developer points out. They are the wrong tool for the job and are not a substitute for a good VPN or Tor Browser. Its worth noting the resources for Decentraleyes are over three years out of date and would not likely be used anyway

Cookie autodelete

Sanitizing in-session is a false sense of privacy. They do nothing for IP tracking. Even Tor Browser does not sanitize in-session e.g. when you request a new circuit. A new ID requires both full sanitizing and a new IP. The same applies to Firefox

Cookie extensions can lack APIs or implementation of them to properly sanitize e.g. at the time of writing: Cookie Auto Delete

As of Firefox 86, strict mode is not supported at this time due to missing APIs to handle the Total Cookie Protection

Consent-o-matic:

No user.js reference here, but I expressed my doubts about it in the comments yesterday https://feddit.it/comment/6471917

Bypass paywalls clean:

While it’s amazing, it’s also available as a filter list, from the same author

In short, don’t bother with more extensions. Just add ublock filters when/if needed, but this is one case where you get 80% of the result with 20% of the effort (FF strict privacy protection mode, ublock origin, switch search engine)

Also, weirdly enough, nobody mentioned the bitwarden extension. Thanks to that (but not only), they manage to provide an amazing password manager service for free, the paid options are cheap, it’s full featured, well integrated with the browser, open source and self hostable.

permalink
report
reply
4 points

Wow, thank you for your extensive review. So LibreWolf or Firefox with Arkenfox’ config + uBlockOrigin is more than enough I guess.

permalink
report
parent
reply
5 points
*

No problem, glad I could help!

Tbh vanilla Firefox + uBlock configured as advised in that user.js wiki page linked above is more than enough.

Librewolf is preferred but it’s something you need to follow and be aware of. It’s an indiependent fork of a browser, and as such you really don’t want it to be discontinued without you noticing.

Which is why I would advise librewolf over Firefox only if you know you’ll stay updated about the privacy “scene”, if you’re setting it up on someone else’s computer, on a work device or you just want a “set it and forget it approach”, definitely go with vanilla Firefox. Again, 80/20 rule.

About Arkenfox’s user.js I remember reading it was meant to be a starting point, not to be used as it is provided but to be customized for it to suit your needs.

Personally I always thought it was not worth to invest the time, but I guess it’s a good learning experience if you’re interested in it.

permalink
report
parent
reply
3 points

Is there a replacement for uMatrix tho? I still use it because I haven’t found another extension that allows me to disable cookies, JS, and iframes per domain as easily as uMatrix does. And despite being unmaintained since 2019 it still works surprisingly well.

permalink
report
parent
reply
2 points

Cookies (3rd and 1st party) can be disabled per site from your browser settings in any modern browser.

JS can be disabled per site using uBlock origin for sure, and I’m pretty sure you can disable iframes as well

I admit I’ve never used uMatrix, but from what I know ublock is the successor of the project (and is considered the state-of-the-art adblocking software), so I’d assume you can do everything uMatrix can and more.

I suggest looking up some tutorials for uBlock to get the grasp of the possibility of the software

permalink
report
parent
reply
6 points

Oh and also bonus recommendation: LibreWolf (security hardened Firefox)

permalink
report
reply
3 points

Is there something to serve all remote fonts from a local cache?

permalink
report
reply
3 points
*

You can block remote fonts in uBlock Origin. Websites will display your default font. https://github.com/gorhill/uBlock/wiki/Per-site-switches#no-remote-fonts

permalink
report
parent
reply
4 points

Then the page is messed up with mojibake because sites now encode their cutesy icons as fonts. Usually I just deal with it but sometimes the icons are needed to use the site.

permalink
report
parent
reply
3 points
*

I have found this rule template:

[DOMAIN]##*:style(font-family: “[FONT]” , !important; src: local([FONT]) !important;)

Of course you need to install the websites font locally before.

permalink
report
parent
reply
1 point

Did not know that, sorry. Maybe someone else will be able to answer your question.

permalink
report
parent
reply
2 points

noscript

permalink
report
reply
2 points

Big fan of Simple Tab Groups. Puts the tabs to the side and helps organize the 1000 tabs you may have open into different categories. Auto tab discard is a good thing to combo with it

permalink
report
reply

Firefox

!firefox@lemmy.world

Create post

A community for discussion about Mozilla Firefox.

Community stats

  • 431

    Monthly active users

  • 274

    Posts

  • 2K

    Comments

Community moderators