# Android Firefox trade off

**URL:** https://discuss.privacyguides.net/t/android-firefox-trade-off/13232
**Category:** General
**Created:** 2023-07-17T03:49:14Z
**Posts:** 14

## Post 1 by @Dkama — 2023-07-17T03:49:14Z

This isn’t meant to start the whole \*recommend FF" discussion again.

It’s a simple question: does having XSS protection and the ability to block 3rd party iframes (via NoScript and uBO) not (partially) make up for not having isolation?

I know proper site isolation is probably the most important thing in a browser, but it actually bugs me while using Brave/Vanadium that don’t have those two features.

---

## Post 2 by @anon63378630 — 2023-07-17T03:51:54Z

I document this here: [https://divestos.org/pages/browsers](https://divestos.org/pages/browsers)

---

## Post 3 by @ComplexSimplicity — 2023-07-17T05:36:28Z

I want to know this too. I have read alot of threads and also the DivestOS documentation but I still don’t get what would be the best for security and/or privacy, when browsing on Android.

My current setup is:  
VPN + NextDNS + Vanadium  
Is something in this setup redundant or missing?

My other setup:  
VPN + NextDNS + Mull + uBO  
Is something in this setup redundant or missing?

Which setup is preferred?

Is Brave still a browser to concider over Vanadium, even when one uses NextDNS?

---

## Post 4 by @anon28734771 — 2023-07-20T12:54:17Z

> [@ComplexSimplicity](#):
>
> Is Brave still a browser to concider over Vanadium, even when one uses NextDNS?

No. Unless Brave has something that Vanadium doesn’t and you really need it.

---

## Post 5 by @not_a_homosapien — 2023-07-22T14:21:16Z

> [@Dkama](#):
>
> does having XSS protection and the ability to block 3rd party iframes (via NoScript and uBO) not (partially) make up for not having isolation?

I would suggest reading [this](https://www.chromium.org/Home/chromium-security/site-isolation/) to know more about Site isolation. And no, blocking third-party iframes and enabling XSS protection cannot make up for not having site isolation.

---

## Post 6 by @jonah — 2023-07-22T16:41:24Z

> [@ComplexSimplicity](#):
>
> Is Brave still a browser to concider over Vanadium, even when one uses NextDNS?

Absolutely yes, and NextDNS doesn’t provide as complete coverage as an in-browser content blocker would. Context:

> [@Vanadium (GrapheneOS Web Browser)](https://discuss.privacyguides.net/t/vanadium-grapheneos-web-browser/12828/21):
>
> such as? I think we’re ignoring the elephant in the room here, which is that Vanadium is only available on a single operating system. Coupled with the fact that it is missing powerful privacy and content blocking features, I don’t really see where Vanadium fits in here, and I would argue that Brave on GrapheneOS still makes sense for most users. The only real advantage I see here is disabling JIT (even on a per-site basis, neat!), which is not actually relevant to most people for the same rea…

---

## Post 7 by @ComplexSimplicity — 2023-07-22T21:44:08Z

There seems to be a disagreement about Brave over Vanadium and vice versa. No clear suggestion here.

The most important question for me though, is if Mull+uBO all things considered, would be a suggested browser over Brave or Vanadium.

@anon63378630 seems to indicate otherwise, but I am yet to find a specific statement about these three browsers matching the different setups mentioned in my first comment.

---

## Post 8 by @woodruff — 2023-07-23T06:32:25Z

Since you can enable site isolation on Mull via about:config ([Introducing Site Isolation in Firefox - Mozilla Security Blog](https://blog.mozilla.org/security/2021/05/18/introducing-site-isolation-in-firefox/)) I would add this option to your question: is Mull+uBlock+Site Isolation as good as Vanadium or Brave?

---

## Post 9 by @anon63378630 — 2023-07-23T07:55:28Z

@woodruff  
please do not enable Fission on Fenix  
_it does not work yet_ and will break things in subtle ways  
it **cannot** be disabled once activated without clearing app data

---

## Post 10 by @woodruff — 2023-07-23T08:20:23Z

Thanks, don’t know that :slight_smile:

---

## Post 11 by @xe3 — 2023-07-23T18:57:11Z

> [@anon28734771](#):
>
> No. Unless Brave has something that Vanadium doesn’t and you really need it.

Probably the most obvious and desired thing that Brave has that Vanadium doesn’t that is relevant to average user would be content blocking (“adblocking”) in the browser. No content blocking is a dealbreaker for many people.

---

## Post 12 by @sha123 — 2023-07-28T15:03:50Z

> [@ComplexSimplicity](#):
>
> Which setup is preferred?

Use Vanadium plus DNS blocking. It has everything you need for a secure and private browsing experience and no unnecessary bloat. Don’t forget to clear cookies, cache and storage regularly. Brave is also fine.

---

## Post 13 by @Anonymous49 — 2023-07-29T14:59:43Z

If you use a VPN, then you need to use a third-party DNS. That’s why I cannot use DNS.

---

## Post 14 by @sha123 — 2023-07-29T20:15:54Z

With a VPN you can still use any DNS you want. Preferably a blocking one coming from your VPN provider to not deviate too much from other VPN users. Also DNS with ad/tracker blocking is not strictly necessary for a private browsing experience, as long as you know about the possible ways of tracking and how to mitigate them.

The main source of tracking is still via state (cookies, cache, storage,…). This can be mitigated through deleting it as often as possible and state partitioning, which most privacy browsers offer.
