Firefox best practice for security


Hollywood

Well-known member
Member
Local time
6:02 PM
Posts
149
OS
Windows 11
I am very privacy and security minded lately. I use (and like) Firefox as my primary browser and use Chrome only for Facebook. I do not use Edge. I am on Windows 11Pro.

My hope is that Facebook on Chrome can not mine as much data because all of my other web use is on Firefox, but I have no way of knowing if that is correct.

I also want as much privacy as possible without running through hoops. I just put a VPN on my Asus router. I actually have a main router for most smart devices, TVs, and such, and a second router plugged into the first router that routes through the VPN (the VPN is built into the router settings). I believe my data is encrypted from my router to the VPN's server, but ultimately it leaves from my main routers IP address.

I am not in California, but I use a VPN server in Los Angeles. When I go to sites to check my IP address and location, it is not my actual IP and says I am in Los Angeles (like it should).

We know websites mine data. Can websites on one browser mine data from another browser?
How can we be more anonymous without loosing much functionality or ease of use?
Are browsers linked to a machine code of your computer? Is there any way to bypass machine and personal identity?
Does a Private Window protect you from what is sent, or only what might be saved locally?

Although I am not doing anything illicit, I don't like the argument "if you are not doing anything wrong, you have nothing to worry about". Data is BIG business!

I don't want to go through extreme measures (like an Onion browser) or break websites. What methods do forum members use to best protect their privacy and identity? I specifically want to use Firefox, but it could be a variant, extensions, settings, or what ever you use. I look forward to your thoughts!

Thanks!
 

My Computer

System One

  • OS
    Windows 11
The most important for me are:
'user_pref("privacy.resistFingerprinting", true);'
'user_pref("browser.send_pings", false);'
'user_pref("dom.battery.enabled", false);'
'user_pref("dom.event.clipboardevents.enabled", false);'
'user_pref("extensions.htmlaboutaddons.recommendations.enabled", false);'
'user_pref("extensions.pocket.enabled", false);'
'user_pref("browser.urlbar.richSuggestions.tail", false);'

potential breaking may occour with these:
'user_pref("privacy.firstparty.isolate", true);'
'user_pref("privacy.firstparty.isolate.block_post_message", true);'
 

My Computer

System One

  • OS
    W11
    Computer type
    PC/Desktop
    CPU
    I7 6700K
    Motherboard
    ASUS Z170
    Memory
    2X 8GB FURYX
    Graphics Card(s)
    RTX 2060 SUPER
    Monitor(s) Displays
    ACER X34
    PSU
    CORSAIR RM 750X
    Cooling
    GENERIC TOWER
    Keyboard
    RAZER ORNATA CHROMA
    Mouse
    LOGITEC PRO WIRELESS
I've posted this before - this guy has some suggestions (with brief explanations) for improving Firefox privacy-
Firefox Privacy
He cautions that some changes will break some sites.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 5410
    CPU
    11th Gen Intel(R) Core(TM) i5-11320H @ up to 4.5GHz
    Motherboard
    Present
    Memory
    16GB, 2x8GB, DDR4, 3200MHz
    Graphics Card(s)
    Intel(R) Iris(R) Xe Graphics
    Sound Card
    Realtek Audio
    Monitor(s) Displays
    HP 24mh (ext), 14.0-inch FHD (1920 x 1080)
    Screen Resolution
    1920x1080
    Hard Drives
    512GB NVMe BC711_NVMe SK hynix
    Backups - 500GB SimpleDrive (ext), WD 750GB (ext)
    Case
    Slim
    Cooling
    Kootek Cooling Pad
    Keyboard
    Logitech K360 (ext)
    Mouse
    Logitech 510
    Internet Speed
    941.93
    Browser
    Firefox
    Antivirus
    Defender, Malwarebytes
There is a plugin called "Firefox Multi-account Containers" that's supposed to prevent sites from accessing cookies, etc., from other sites. Their product description says it's like using a separate browser for each web site you set-up.

 

My Computers

System One System Two

  • OS
    Windows 11 Pro 22H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Homegrown
    CPU
    AMD 5950X
    Motherboard
    Asus ROG Crosshair VIII Dark Hero
    Memory
    128GB
    Graphics Card(s)
    NVidia RTX 3060TI
    Sound Card
    Built-in Realtec Audio
    Monitor(s) Displays
    2x Dell 27"
    Screen Resolution
    2560x1440
    Hard Drives
    OS = Western Digital Black NVME 2TB
    DATA = Sabrent Rocket NVME 1TB
    2x Samsung SSD (Virtual Machines)
    3x Western Digital (4TB, 6TB & 8TB)
    PSU
    Corsair CM1000
    Case
    Corsair 700D
    Cooling
    Corsair H115i RGB Pro XT
    Keyboard
    Corsair Strafe 2
    Mouse
    Logitech Trackball
  • Operating System
    Pop!_OS 22.04
    Computer type
    Laptop
    Manufacturer/Model
    System76/Gazelle
    CPU
    i7-10750H
    Memory
    64GB
    Graphics card(s)
    NVIDIA GeForce GTX 1650 Ti Mobile
    Screen Resolution
    1920x1080
    Hard Drives
    1TB Samsung 970 Evo Plus
For privacy, make sure you enable secure DNS in the Settings -> General -> Network Settings (Enable DNS over https).

You can also arrange this at the system level. There is a tutorial on this site.

This will encrypt the DNS lookup of the sites you visit (otherwise it is done in clear text and can be captured by a bad actor). Also pay attention to ECH (Encrypted Client Hello) that will be coming in the near future to further secure your web browsing history from bad actors.
 
Last edited:

My Computers

System One System Two

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    DIY Photoshop/Game/tinker build
    CPU
    Intel i9 13900KS 5.7-6GHz P cores/4.4GHz E/5GHz cache
    Motherboard
    Asus ROG Maximus Z790 Dark Hero
    Memory
    64GB (2x32) G.skill Trident Z5 RGB 6400 @6600 MT/s 32-39-39-80
    Graphics Card(s)
    Asus ROG Strix 4070 Ti OC
    Sound Card
    Onboard Audio, Vanatoo Transparent One; Klipsch R-12SWi Sub; Creative Pebble Pro Minimilist
    Monitor(s) Displays
    Eizo CG2730, ViewSonic VP2768
    Screen Resolution
    2560 x 1440p x 2
    Hard Drives
    WDC SN850 1TB nvme, SK-Hynix 2 TB P41 nvme, Raid 0: 1TB 850 EVO + 1TB 860 EVO SSD. Sabrent USB-C DS-SC5B 5-bay docking station: 6TB WDC Black, 6TB Ironwolf Pro; 2x 2TB WDC Black
    PSU
    850W Seasonic Vertex PX-850
    Case
    Fractal Design North XL Mesh, Black Walnut
    Cooling
    EKWB 360 Nucleus Dark AIO w/Phanteks T30-120 fans, 2 Noctua NF-A14 Chromax case fans, 3x50mm fans cooling memory
    Keyboard
    Glorious GMMK TKL mechanical, lubed modded -meh
    Mouse
    Logitech G305 wireless gaming
    Internet Speed
    380 Mb/s down, 12 Mb/s up
    Browser
    Firefox
    Antivirus
    Defender, Macrium Reflect 8 ;-)
    Other Info
    Runs hot. LOL
  • Computer type
    Laptop
    Manufacturer/Model
    Apple 13" Macbook Pro 2020 (m1)
    CPU
    Apple M1
    Screen Resolution
    2560x1600
    Browser
    Firefox
on my phone I use VPN with DuckDuckGo browser.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 9 3900X
    Motherboard
    MSI MPG Gaming Edge Wifi (X570)
    Memory
    32GB Adata XPG DDR4
    Graphics Card(s)
    ASUS GTX 1070 8GB ROG
    Monitor(s) Displays
    LG Ultrawide 34"
    Screen Resolution
    3440x1440
    Hard Drives
    Main Boot Drive : 512GB Adata XPG RGB Gen3x4 NVMe M.2 SSD
    PSU
    EVGA 600 Watts Gold
    Case
    Deepcool Genome II
    Cooling
    Deepcool Fryzen
    Internet Speed
    1Gbps
    Browser
    Chrome
    Antivirus
    "Moderna"
  • Operating System
    Windows 11 Pro
    Computer type
    PC/Desktop
    CPU
    i7-4790K
    Motherboard
    ASRock Xtreme6 Z97
    Memory
    16GB Corsair Vengeance Pro
    Graphics card(s)
    MSI R9 290
    Monitor(s) Displays
    LG Ultrawide 34"
    Screen Resolution
    3440x1440
    Hard Drives
    Samsung M.2
    PSU
    Thermaltake 475 Watts 80 Bronze
    Case
    Thermaltake Commander I Snow Edition
    Cooling
    Deep Cool Archer Air Cooler
    Mouse
    Logitech G402
    Keyboard
    Armageddon MKA-5R RGB-Hornet
    Internet Speed
    1Gbps
    Browser
    Chrome
    Antivirus
    Moderna :)
Some new settings i`ve been using:

user_pref("privacy.resistFingerprinting", true);
user_pref("browser.send_pings", false);
user_pref("dom.battery.enabled", false);
user_pref("dom.event.clipboardevents.enabled", false);
user_pref("extensions.htmlaboutaddons.recommendations.enabled", false);
user_pref("extensions.pocket.enabled", false);
user_pref("browser.urlbar.richSuggestions.tail", false);

# Disable updates
user_pref("app.update.auto", false);
user_pref("app.update.checkInstallTime", false);
user_pref("app.update.auto.migrated", false);
user_pref("app.update.service.enabled", false);
user_pref("app.update.BITS.enabled", false);
user_pref("app.update.background.interval", "999999999");

# Disable cross-domain cookie access
user_pref("privacy.firstparty.isolate", true);
user_pref("privacy.firstparty.isolate.block_post_message", true);

# DNS-over-HTTPS (DoH) encrypt the communication between the client and the resolver to prevent the inspection of domain names by network eavesdroppers
user_pref("network.trr.mode", 2);
user_pref("network.trr.uri", "https://dns.google/dns-query");
user_pref("network.trr.bootstrapAddress", "8.8.8.8");

# Enable Encrypted Client Hello (ECH) on Firefox, to prevent TLS from leaking any data by encrypting all messages;
user_pref("network.dns.echconfig.enabled", true);
user_pref("network.dns.use_https_rr_as_altsvc", true);
 

My Computer

System One

  • OS
    W11
    Computer type
    PC/Desktop
    CPU
    I7 6700K
    Motherboard
    ASUS Z170
    Memory
    2X 8GB FURYX
    Graphics Card(s)
    RTX 2060 SUPER
    Monitor(s) Displays
    ACER X34
    PSU
    CORSAIR RM 750X
    Cooling
    GENERIC TOWER
    Keyboard
    RAZER ORNATA CHROMA
    Mouse
    LOGITEC PRO WIRELESS
Back
Top Bottom