Is secureblue really more secure if browsers have to be installed in flatpaks?

Mac is a decent option for privacy.

The right approach is making all users look the same while randomizing stuff. Brave has too many options, everyone’s config is different. An example metaphor: you can wear a mask in a crowd, and yes no one can see your face, but you’re the only one wearing a mask in a crowd. Firefox has the same issue.

They care about privacy. Privacy is built on top of security. if your device is compromised, privacy is nothing. Closed-source software can be private and secure.

Setting aside that the initial question is empty if you remove the incorrect assumptions and that there is too much misinfo in this thread to respond to piecemeal, the takeaways from this thread should be:

  • Do not use Flatpaked browsers of any kind until nested namespaces are supported and adopted (probably 2 ish years away) if you care about security
  • Do not use Firefox or any Firefox-based browser if you care about security
  • MV2 availability is a sign that a browser’s developers are not prioritizing security, since MV3 is a substantial security improvement
  • Anti-fingerprinting outside of Tor Browser is largely snakeoil and has nothing to do with privacy
  • If Trivalent isn’t for you, Trivalent developer RKNF404 has a browser hardening/selection guide Selecting a Browser - Chromium Hardening Guide, and yes, Google Chrome is a solid option.

don’t care about open source

Yup that’s why every secureblue project is FOSS
:joy_cat:

And just to add to that: ublock origin lite works perfectly fine in 99% of use cases. The whole “Google is going to end ublock origin lite too” thing is misinformation.

they seem a little too happy to clown on it.

I’m not “happy to clown” on any browser, except like one browser but that’s not Mullvad. If Mullvad were better and offered more, I wouldn’t “clown” on it.

One advantage is that you’re using VPN IPs instead of Tor exits which will have better IP reputation.

That’s not an advantage in a privacy sense. And there is a reason for the better reputation, not enough users, which proves my point of it being a downgrade from Tor.

Tor is going to add uBlock Origin, so it must be an acceptable compromise…

If you read the thread, which has been open since 2016 btw, you will see that they are explicitly trying to address some of the issues I mention in the Mullvad section prior to adding it to Tor. Namely filterlist updates and bundling filters at build-time. Mullvad doesn’t do that. So no, it is not an acceptable compromise. Even if Tor did it in the same way as Mullvad, it would be a bad decision.

Mullvad browser substitutes some anonymity with some convenience because more sites will accept you on VPN IPs than Tor IPs.

You misunderstand the criticism. The point is a lot of users won’t have Mullvad IPs, which reduces the crowd ratio of users that do use Mullvad and makes the userbase that doesn’t stand out a lot more. Also, slight correction, some a decent amount.

Actually there’s a feature that randomizes your serve

This was added after that section of the guide was written, I can update it. Would have been better as an issue in the guide’s repo so that I could more easily correct that, rather than a forum comment.

There was a comment in a thread that explained the downstreamness, but I can’t find it. This may be true, but the browser’s goal is more anonymity on the web

The point of that section is to say it doesn’t offer anonymity or security over Tor, it’s just regressions by comparison. That point still holds true.

I’ll just add a few things. @RKNF404, shouldn’t you add your affiliation to Secureblue to your PG account?

Also, if people want to use Tor with uBlock Origin, TailsOS already has it.

And the “Selecting a Browser - Chromium Hardening Guide” thing.. Is borderline lying about LibreWolf. I don’t think it’s fair to list Pale Moon and LibreWolf in the same boat like this.

  • LW isn’t as depended on Arkenfox as “The Guide” makes it sound. The Firefox hardening community isn’t just Thorin and Arkenfox.

  • LW also have added its own features like the WebGL permission.

  • LW have before backported security patches even before normal Firefox to my knowledge.

  • LW “uses ancient code” is a lie.

  • The slower update cycles aren’t true either. If we should go with this logic then Vanadium, Trivalent, Ironfox, Mullvad Browser, etc. Also have slow update cycles. :melting_face:

I can’t speak about Pale Moon I haven’t used it for 10+ years. :melting_face:

While I understand why this point keeps getting repeated, isn’t it ironic that, while providing a less secure desktop OS, which aims to improve the situation for those who prefer using Linux, you keep discounting the less secure browser option continuously and do not account for the same possibility in browsers?

If all Firefox‑based browsers are not to be used, shouldn’t all desktop Linux OSes be avoided too, including secureblue? Is it time to drop everything that is not the most ideal and let everything rely on a few set options?

How is everything outside of Tor Browser largely snake oil? Firefox with ETP set to Strict is capable of avoiding re‑identification by the only publicly testable commercial fingerprinting tool. Should this be disregarded too and should all efforts to improve privacy somewhat be stopped? Just because it doesn’t provide protections as strong as Tor Browser doesn’t mean it isn’t worth anything.

While I respect the work being done by RKNF404, the linked guide is full of misinformation when representing LibreWolf and not even a little bit of research was done, resulting in easily disprovable false statements as recently as three weeks ago.

While I really appreciate the work that is being done with secureblue, it is disappointing to see you take such stances.

which aims to improve the situation for those who prefer using Linux, you keep discounting the less secure browser option continuously and do not account for the same possibility in browsers?
If all Firefox‑based browsers are not to be used, shouldn’t all desktop Linux OSes be avoided too, including secureblue? Is it time to drop everything that is not the most ideal and let everything rely on a few set options?

You’re largely correct but I think you’re misconstruing the point I was making.

If someone’s top priority is security, they shouldn’t be using Firefox or anything Firefox-based. Similarly, if someone’s top priority is security, they shouldn’t be using desktop Linux including secureblue. That said, there are ways to “reduce the harm” in both cases. For example the point about avoiding flatpaked browsers until nested namespaces are available in flatpak-next applies to Firefox as well. So a similar type of phrasing applies to browsers and desktop linux:

  • If you’re insistent on using Firefox and not something Chromium-based, avoid the flatpaked version for now.
  • If you’re insistent on using desktop Linux and not MacOS or Windows, consider secureblue :slight_smile:

It should also go without saying that for the overwhelming majority of desktop users, the browser is going to be the most important application to secure, which is why we put so much effort into it and why we so consistently recommend against Firefox and derivatives.

Another important thing to note is that usually people are not choosing Windows over Linux because they think it’s “more private”. The same cannot be said for people choosing Firefox over Chromium and derivatives. That is to say, the type of person to insist on using Firefox is likely not doing so on Windows, so it’s not really a parallel. If someone cares about privacy, they’re probably not using Windows to begin with, so convincing them to avoid Firefox and derivatives is the next best thing given the criticality of the browser.

Should this be disregarded too and should all efforts to improve privacy somewhat be stopped?

It’s reasonable to view efforts to improve fingerprinting with skepticism, especially when they push users away from more secure alternatives, and for what? dubious, largely ineffective “anti-fingerprinting”. The article you linked even points out flaws in various “fingerprint checkers” like EFF’s cover your tracks. Does that mean those efforts should be stopped? No, but they shouldn’t be advertised or recommended until they’re actually effective.

Just because it doesn’t provide protections as strong as Tor Browser doesn’t mean it isn’t worth anything.

That’s the problem though, it does mean that. Insufficiently strong protections are equivalent to not being protected at all, as the article you linked demonstrates. Brave has fingerprinting protections, yet fingerprint.com can still identify it.

While I respect the work being done by RKNF404, the linked guide is full of misinformation when representing LibreWolf and not even a little bit of research was done, resulting in easily disprovable false statements as recently as three weeks ago.

I’m not following exactly but if there are inaccuracies then please open an issue on @RKNF404’s repo.

Unrelated, but did your community test the unofficial mullvad app installation for leaks? Is secureblue even compatible with sing-box/core based clients like Throne? Was there any IP, DNS leak evaluation done on any of the VPN installations?

I’m raising all of this since i know for a fact networkmanager has tricked a ton of people into believing their Wireguard config is leak safe. When i looked at Secureblue a year ago, ujust offered the same wireguard config that was prone to leaking.

When i looked at Secureblue a year ago, ujust offered the same wireguard config that was prone to leaking.

Our ujust install-vpn installs the official Mullvad client. Please direct general support and info to our Discord though, as PG is not the place for general secureblue support and info :slight_smile:

Which doesn’t officially support Silverblue and wasn’t tested and vetted by the developers to not leak. You should notify users about this fact, they shouldn’t blindly assume it’s safe to use their VPN clients on your OS.

This wasn’t a support ticket, i’m not going to become a Secureblue user.

The issue you linked is about packaging. Mullvad already provides an RPM repo, and Silverblue supports rpm repos. Silverblue and Fedora are running the same networking stack with the same packages and package versions from the same distro.

That said, your point is fair in that we already do warn VPN users when they’re using a VPN at the same time as our DNS Selector, since that is known to cause issues. VPN users should leave DNS settings on unmodified Fedora systemd-resolved defaults, as indicated by our tooling.

shouldn’t you add your affiliation to Secureblue to your PG account?

Probably? Idk haow to do that, I haven’t looked into it. Literally made the account a few days ago lol.

LW isn’t as depended on Arkenfox as “The Guide” makes it sound.

It is, that is where they get their main configuration. I dont believe LW claims otherwise lol.

The Firefox hardening community isn’t just Thorin and Arkenfox.

I never said it was, the guide literally mentions Pheonix.

LW have before backported security patches even before normal Firefox to my knowledge.

Could you link to this? This is major claim in LW’s favor.

LW “uses ancient code” is a lie.

Uh, I never said that… because it doesnt… it tries to keep ip with stable FF.

The slower update cycles aren’t true either.

They had a history of being very outdated, sometimes going out of date for months. That said, the update cadance does seem more consistent now, so that can be updated to reflect that. Honestly, the Librewolf mention could use a refresh.

If we should go with this logic then Vanadium, Trivalent, Ironfox, Mullvad Browser, etc. Also have slow update cycles.

Technically yes, But there needs to a decent enough benefit to actually use it. I don’t believe librewolf offers enough to be selected over Firefox.

@any1

the linked guide is full of misinformation when representing LibreWolf

I’m happy to correct anything you deem inaccurate.

resulting in easily disprovable false statements as recently as three weeks ago

Again, I would prefer you raise concerns about the way I present information in the guide in an issue. I would like to be as fair and objective as possible, that’s difficult if I am not aware that something is incorrect. Like, the update cadance point can be updated.

If all Firefox‑based browsers are not to be used, shouldn’t all desktop Linux OSes be avoided too, including secureblue?

This is kind of a false equivalence, operating system choices and browser choices are completely different.

Since they are already using an inferior option, desktop Linux in this case, wouldn’t it also be highly probably for them to possibly pick a different browser of choice, since they clearly put their personal preferences over security?

We do have a good chunk of windows users who have had LW installed for years.

Seeing that the only public demo for a commercial fingerprinter was “beaten” by the protections currently offered by Firefox, I would say it is effective. Since we can’t really know how widespread fingerprinters are or how sophisticated they are, this is the best real‑world insight we currently have.

Even if Firefox, Safari, and Brave were re‑identified by fingerprint.com, that wouldn’t directly mean the efforts are meaningless, since there are possibly many less‑sophisticated fingerprinters in use that would be fooled by the current mitigations.

We do not use arkenfox’s user.js

LW being based directly on arkenfox was true in the past, when one of the former maintainers talked directly to thorin for advice. But that hasn’t been the case for a while now, since that maintainer left the project years ago and we no longer use arkenfox as our base.

I would assume they mean having backported the STL hardening fixes from a future Firefox release instead of waiting until it reaches stable for Windows.

This was true before I got involved about half a year ago. I usually try to release builds within 24 hours of Firefox’s release and often have them out within 12 hours. The only outlier was the last release, which took a bit over a day due to networking issues with our build infrastructure.

Depends on what your threshold is for being considered sufficient. Since Firefox refuses to ship even simple options like -ftrivial-auto-var-init=zero or -fwrapv and it hasn’t enabled STL hardening on Linux yet because of a slight performance hit, I wouldn’t say the bar is high.

The biggest security benefit we achieve right now would be making WebGL a site‑permission that is blocked by default and placing DRM behind a permission as well. I also have some other hardening work that hasn’t been pushed yet, mainly CFI‑icall, since I’ve been focusing on improving our build system recently.

Although, I will talk about 2 desktop forks specifically, LibreWolf and Pale Moon. LibreWolf is just Firefox with defaults changed… nothing else. They don’t even maintain the defaults, they just use arkenfox-user.js. They may have some deviated changes but fundamentally it is just arkenfox built into Firefox with a slower update cycle. Because Arkenfox is going EoL soon, there is a dim future for Librewolf.

Considering the brief mention of LW is all wrong, I would say everything should be reconsidered with the points made above.

Also, don’t install browsers via flatpak (or at least firefox or mullvad browser). Flatpaks sandbox is, afaik, not as good as the default sandboxing provided, and installing it via flatpak disables it. You should install with rpm-ostree.

Yeah mb on that one. I read it worng, it’s about Pale Moon. :melting_face:

since they clearly put their personal preferences over security?

Sure but there are a lot of preferences that would push someone to desktop linux that aren’t “anti-fingerprinting”/“privacy”. For example someone with existing hardware who dislikes windows as an environment and for whom a hackintosh is not an option.

Even if Firefox, Safari, and Brave were re‑identified by fingerprint.com, that wouldn’t directly mean the efforts are meaningless, since there are possibly many less‑sophisticated fingerprinters in use that would be fooled by the current mitigations.

And this comes back to a question of priority. What does this actually get you? If for example someone is already blocking ads globally, what utility does anti-fingerprinting add?

My point about “they shouldn’t be advertised or recommended until they’re actually effective” was meant to probe what it means for anti-fingerprinting to be effective. Having a browser fingerprint that blends in isn’t an end in and of itself. It’s a means to some other end. Those ends as far as I can tell are generally one of two things:

  1. Avoiding advertiser tracking to prevent targeted ads
  2. Anonymity

If you’re already blocking ads globally, then #1 is unnecessary, and #2 is only accomplished by Tor Browser. So then what ends remain, especially given that the tradeoff generally involves substantial security sacrifices?

I can answer this question with two words: more privacy.

There are reasons besides wanting to not spend a big part of life watching ads (#1) and the life depending on anonymity (#2) for wanting to have privacy.

more privacy.

To what end though?

There are reasons

Any examples?

I wouldn’t want someone following me around town making a private database of my activities (when I go to the supermarket, what I buy, who I talk to, what I say), even if they aren’t able to show me ads.