IronFox (a new Mull fork)

I have a question if I enable add-ons and download LibRedirect and disable add-ons again would LibRedirect still get updates?

Yes, you’ll even get notification if the updated extension requests for new permissions.

Edit: Firefox desktop showed warning⚠️ for disabled video downloadhelper when it requested new permissions. So it might apply for android too.

@celenity maybe a silly question but what does enabling memory tagging support for IronFox actually entail? Is it modifying Firefox’s memory allocator to make it MTE-aware or maybe opting in to MTE/Advanced Protection when it is available? Is there any change if you were using IronFox on GrapheneOS and had not disabled “Memory Tagging”?

No, it is the same.

How good could IronFox be as a forgetful browser, like searching on the fly the name of a movie then delete all data on exit?

Just to note, trying the browser on coveryourtracks.eff says that, on default settings, gives off a unique fingerprint.

I deleted Iron Fox after noticing with Rethink DNS that it sends data in the background. Even when closing the browser with the “clear all on closing” feature enabled, the history still remains in the recently closed tab, which is very bad for forensics.

Anyone else???

Never used Mull as have only just started using the various privacy tools and being aware of them. I use Tor as a browser. Would Iron Fox offer anything different/better?

All of those connections are perfectly reasonable for my threat model… except for geolocation. Am I reading it right that unless you go out of your way to remove the beacondb URL from the geo.provider.network.url setting in about:config, and if location is disabled system wide, ironfox will basically override and provide geolocation data anyway? If so that should really be OPT IN not OPT OUT. Hopefully I’m just misunderstanding….

Edit: okay I think I jumped to an erroneous conclusion. That must be for if geolocation IS enabled systemwide and the default, for whatever reason, is unavailable. I have geolocation DISABLED system wide, and without changing anything in about:config, browser checks for geolocation are returning “denied by user” and such messages.

Is there any chance that we’ll be seeing an iOS/Windows version

The IronFox dev is also the creator of celenity/Phoenix: Phoenix is a suite of configurations & advanced modifications for Mozilla Firefox, designed to put the user first - with a focus on privacy, security, freedom, & usability. - Codeberg.org which IronFox also largely uses.

However personally I would prefer using Librewolf

Why?

It’s been a year now that IronFox has consistently delivered.

@celenity has among other things, removed a lot of Mozilla tracking that was still present in Mull and in Fennec.

They have also shown great care in having sane defaults and options. For example only proposing privacy-respecting search engines and DNS providers.

They also include uBlock Origin in the box. They removed uBlock Origin privileges to their own list for security reasons.

Should we add it ? Adding it around September this year would seem fine so everyone is satisfied and doesn’t think its too early.

Word of warning: IronFox does not properly protect the canvas. According to this test IronFox provides access to unaltered canvas, one of the main fingerprinting vectors.

Maximum respect for those who want to escape from Chromium and its derivatives. But if Firefox or Ironfox doesn’t offer any advantage in terms of privacy, because it can only protect you against naive scripts like Vanadium and Brave do, why recommend a less secure browser?

Also maximum respect for the developers of this project.

Because only Gecko based browsers support uBo on Android?

And does that make you block more trackers or something like that? What’s the use of that if they can still identify you despite Brave’s Shields, uBO, etc?

We allow first-party canvas data extraction, due to prompts unfortunately not being supported on Android (Third parties are still blocked from extracting canvas data, and canvas data is still randomized when extracted)

You do realize that using arkenfox would produce the same result.

Haven’t rechecked default FPP canvas for a while. You’re right, they’ve managed to break it completely now.

Since Arkenfox switched to FPP I’ve been always adding +CanvasImageExtractionPrompt, +CanvasExtractionFromThirdPartiesIsBlocked, +CanvasExtractionBeforeUserInputIsBlocked to my FPP overrides in desktop Firefox profiles to have RFP behavior for canvas.