# LibreWolf (Firefox-Based Browser)

**URL:** https://discuss.privacyguides.net/t/librewolf-firefox-based-browser/148
**Category:** Tool Suggestions
**Tags:** rejected
**Created:** 2022-10-01T12:55:04Z
**Posts:** 446

## Post 1 by @f0r_fr33d0m — 2022-10-01T12:55:05Z

I have tested it for a while. It is comparable (or even better, in my opinion) to a Firefox with Arkenfox. Its development is active, its results are quite good and, in general, it is a browser that I would personally recommend for any desktop user who wants a browser similar or based on Firefox, with good privacy, and without the difficulties that may arise from having to configure the program internally.

 ![Librewolf](//forum-uploads.privacyguidesusercontent.com/original/1X/3755cd6470ed66e0a874fe57b73bab1363379924.png)

[Website](https://librewolf.net/) & [Link of interest](https://privacytests.org/)

---

## Post 2 by @bayesian — 2022-10-01T13:02:52Z

I have concerns about long-term availability of librewolf. I’ve used in the past but I don’t see any extra benefits from a hardened Firefox (user.js arkenfox etc). Firefox has been around like decades. A much better long-term suggestion.

---

## Post 3 by @f0r_fr33d0m — 2022-10-01T13:21:55Z

In my opinion the benefits are more geared towards uninformed users looking for a quick fix, since hardening firefox correctly can require both a lot of prior knowledge and active time dedication. I understand that, for many users, these requirements will be short-lived, but I think we should try to make it as accessible and easy as possible to take the step towards a more private digital life, and I think Librewolf does that. About the long term maintenance, we can assume the same useful life as Firefox, because it is a fork of it, and the developers prevail in the task of maintaining and improving it. Best regards.

---

## Post 4 by @bayesian — 2022-10-01T15:05:30Z

> [@f0r_fr33d0m](#):
>
> and the developers prevail in the task of maintaining and improving it.

Until they don’t. At least Mozilla has a long record.

---

## Post 5 by @f0r_fr33d0m — 2022-10-01T15:20:31Z

Well, the same can happen with Arkenfox, in the sense that it becomes outdated because the day comes when it stops receiving updates, and while Firefox does receive updates, by default, it leaves a lot to be desired in terms of defending privacy. Librewolf has been active for over a year now, and there has not been a single moment where development has slacked off. I understand that it is a young project and that can generate suspicions, but I don’t think that argument is enough to not take it into account when recommending software for privacy.

---

## Post 6 by @anon74021444 — 2022-10-01T15:21:43Z

Use it for some time now and I like it. I have a Mullvad VPN and followed the guide to prevent DNS-leaks from it and made it fingerprinting proof. I have tested other privacy oriented browsers, but I prefer Librewolf for now.

---

## Post 7 by @anon82677111 — 2022-10-01T15:25:32Z

I’m against using LibreWolf for several reasons.

First off, LibreWolf does not add anything new from Firefox. Firefox users can disable telemetry in the settings and in about:config. I don’t believe LibreWolf improves Firefox security but actually worsens it because they install uBlock Origin by default, which [significantly increases attack surface](https://portswigger.net/research/ublock-i-exfiltrate-exploiting-ad-blockers-with-css) and uses Manifest V2 which is being deprecated as it’s a huge security risk, and they disable Google Safebrowsing which is a necessary security feature to protect users from malicious URLs and Mozilla’s implementation is privacy-respecting.

Second, because LibreWolf is a community fork of Firefox developed by a small team, it will always be behind Firefox in updates by a few days. This means users won’t receive security patches as quickly as Firefox users. While Chromium forks like Vanadium and Mulch also lag behind a day or two each release, it is not as easy to apply those security patches onto vanilla Chromium as you’d have to compile the browser yourself, so it’s worth the trade. Firefox users can just use Arkenfox to harden the browser, but most users will be fine using the recommended settings in about:preferences and leaving about:config alone.

Like bayesian said, LibreWolf hasn’t been around as long as Firefox and development for LibreWolf did come to a halt for a while a few years back.

In general, I think most people should avoid Firefox entirely and use a browser based on Chromium (Edge for Windows, Chrome or Brave for other operating systems).

---

## Post 8 by @anon74021444 — 2022-10-01T17:05:45Z

Well, there are thing to mention for one or the other. I stick with Librewolf for now. Like I said, I tried other privacy browsers and this ticks the most boxes for me.  
I can assure you however, that I will never ever use a browser made by Google or Microsoft.

---

## Post 9 by @bayesian — 2022-10-01T18:22:39Z

> [@anon82677111](#):
>
> Manifest V2 which is being deprecated as it’s a huge security risk

No security risk. Deprecated in Googleland only!

> [@anon82677111](#):
>
> In general, I think most people should avoid Firefox entirely and use a browser based on Chromium

I highly disagree! Firefox is one of the best (if not the best) browsers for you to use right now. Tor browser is built based on Firefox. I strong urge anyone to ditch Chromium-based browsers and adopt Firefox/Tor Browser. If you have 1-2h of your time you can learn how to hard it either by following a YouTube video or the Arkenfox/user.js README.

---

## Post 10 by @InconspicuousEntity — 2022-10-01T18:31:16Z

Watching YouTube videos doesn’t change the fact that Firefox is not as technically advanced as chromium, and doesn’t provide the level of protecting against attacks.

The idea that Chromium = Google = bad and Firefox != Google = good is just nonsense.

---

## Post 11 by @Jimmy — 2022-10-01T19:24:01Z

> No security risk. Deprecated in Googleland only!

While I understand the reasoning behind choosing Firefox over Chromium based browsers (more freedom, and supporting an open web), claiming that the current status quo with regards to adblockers (which have privileged access to the webpage) does not have any security risks is a bit disingenuous. As iOS Safari shows, good cosmetic filtering is still possible without giving up security, and hopefully Google will be moving in a similar direction.

---

## Post 12 by @anon82677111 — 2022-10-01T19:39:57Z

> [@bayesian](#):
>
> No security risk. Deprecated in Googleland only!

Extensions are highly privileged programs that have access to all your data on every website. Manifest V3 restricts what these extensions can do, but regardless, it’s a good idea not to install any browser extensions. Ideally, a browser would not support extensions at all and provide privacy by default. This would prevent any third-parties including Gorhill from spying on the user’s entire browsing history and everyone would be uniform.

> [@bayesian](#):
>
> I highly disagree! Firefox is one of the best (if not the best) browsers for you to use right now. Tor browser is built based on Firefox. I strong urge anyone to ditch Chromium-based browsers and adopt Firefox/Tor Browser. If you have 1-2h of your time you can learn how to hard it either by following a YouTube video or the Arkenfox/user.js README.

No. It’s not. Firefox is still behind Chromium in exploit mitigations and it’s sandboxing and site isolation is less mature than Chromium’s. That said, it’s still a better choice than most other browsers including ones that use even more insecure engines like QtWebEngine ([which uses an extremely old version of Chromium](https://wiki.qt.io/QtWebEngine/ChromiumVersions)), WebKit (no site isolation), Goanna, and NetSurf’s engine.

Tor Browser, while the only true way to browse anonymously, is seriously flawed due to being forked from Firefox instead of Chromium and not being as up-to-date as other Firefox and Chromium forks.

I think Google Chrome isn’t a bad browser for most people as it is the most secure (apart from Edge on Windows) and updated and users can disable most if not all telemetry in the settings. There should be a guide for this and Edge even if the browsers aren’t recommended since a lot of people must use those browsers or simply don’t want to switch.

---

## Post 13 by @samsepi0l — 2022-10-01T20:24:30Z

Just linking that [Add Librewolf · privacyguides · Discussion #206 · GitHub](https://github.com/orgs/privacyguides/discussions/206)

---

## Post 14 by @samsepi0l — 2022-10-01T21:17:50Z

Big tech conspiracy, it’s not a good argument.

Google and Microsoft are excellent in terms of security.

That’s why google pixel are recommended.

Firefox is a good browser in it’s own, but bear in mind that you need to use arkenfox to make it less shitty. Chromium-based browsers have no need for such things. And btw, after a long try with FF+AF and LW, I can tell you that just switching toggles in Firefox is enough, and for the arkenfox part, I use Tor Browser.

I will stop here as I don’t know much more about browsers. That being said, I used Firefox all my life, and I’m currently switching to Brave, as it gets better and better overall.

_P.S: I don’t want to tear down any project, just exposing some facts that I know. Don’t take my word for what I say as I don’t know much about browsers, I’m just exposing my experience. Thanks in advance._

---

## Post 15 by @anon82677111 — 2022-10-01T23:00:50Z

I agree. Google Chrome and Microsoft Edge have excellent security and should be considered over Firefox and LibreWolf. If one requires privacy, they can disable telemetry in the settings. A lot of people are worried about Google and Microsoft surveillance but a lot of it is just conspiracy theories and fearmongering, not saying that they don’t track their users because they do.

I believe that sometimes the best way to avoid Google surveillance is by using Google products as they provide security and there are ways to prevent tracking on Google products. For example, one can install GrapheneOS on a Google Pixel device. The “DeGoogle” movement is not a sane approach to privacy and security and I see no reason why anyone should completely avoid Google. Some telemetry is bad but being paranoid about telemetry is much worse.

---

## Post 16 by @anon74021444 — 2022-10-01T23:07:14Z

I think “big tech conspiracy” is a very good argument, sad to say. In terms of security Google is okay afaik (don’t know about MS in this regard). In terms of Privacy however, using software from these companies is very dangerous. To recommend any software from them is really a bad advise,  
Ah well, I also used Firefox for a long time and now have switched to Librewolf. It is good to have choices so anyone can choose what fits him best. In a world deprived of privacy there wouldn’t be choices.

---

## Post 17 by @f0r_fr33d0m — 2022-10-01T23:14:53Z

I will speak from my personal opinion: I use many browsers in my life, I always try to divide my online activity, but the browsers I use the most are Brave and Librewolf. My experience with Librewolf has always been pleasant, and it has always fulfilled its purpose.

I consider that it should be included because, as it is studied in the [link of interest](https://privacytests.org/) that nobody accessed, this browser beats Firefox in privacy and security. Another reason why, I insist, it should be included (or at least mentioned within the Firefox section) in PrivacyGuides is its simplicity: by default, unlike Firefox, it is already prepared internally to protect the user’s privacy and security, something that any potential ignorant user who intends to access privacy tools would appreciate and prefer rather than having to inform himself and spend a lot of time understanding and configuring the browser. Another thing that I think is not being taken into account is that the Librewolf development team [takes into account the Arkenfox user.js when configuring the browser internally](https://librewolf.net/license-disclaimers/).

I can understand a number of criticisms. It is clear that Chromium based browsers are more secure than Firefox based browsers, hence I usually recommend Brave over Librewolf. It is also true that for many it is much more interesting to configure your browser internally yourself, or rely on tools like Arkenfox, as they enjoy a reputation and in practice shows why they have it.  
There are also somewhat questionable criticisms, such as that it depends on Firefox… yes, and Tor too, and Brave also depends on Chromium, and we do not rule them out.

My main point, and what I want to imply, is that new PrivacyGuides users, above all, what they are looking for are privacy tools, and Librewolf, whether we like it more or less, meets all the necessary features to be perfectly considered a privacy-oriented browser, and therefore, in addition to the features already described, I think it should be included in the list and make it known to those users interested in protecting their privacy, which is essentially the reason why PrivacyGuides exists.

---

## Post 18 by @anon82677111 — 2022-10-02T00:41:54Z

> [@f0r_fr33d0m](#):
>
> My main point, and what I want to imply, is that new PrivacyGuides users, above all, what they are looking for are privacy tools, and Librewolf, whether we like it more or less, meets all the necessary features to be perfectly considered a privacy-oriented browser, and therefore, in addition to the features already described, I think it should be included in the list and make it known to those users interested in protecting their privacy, which is essentially the reason why PrivacyGuides exists.

The thing is, one cannot have privacy without security, and LibreWolf, being a fork of Firefox, is significantly less secure than Chromium browsers. For example, a browser that doesn’t send any telemetry or make any connections cannot be considered private if it doesn’t support site isolation or if it doesn’t have a sandbox at all. These security features are required for a private browsing experience as without site isolation, if I visited Privacy Guides and Google, Google could get information about my activities on Privacy Guides. Firefox-based browsers have site isolation now, but this feature is not black and white and Chromium does it better. This is why we don’t recommend minimalist browsers like Netsurf and Lynx, as they are much worse than Google Chrome due to their lack of security. But I digress.

Security should be one of the top priorities of PrivacyGuides along with privacy. Some support towards Firefox and LibreWolf is because it continues to support Manifest V2, which is bad for security, and because they don’t want Google dominating the web, they want to have a choice. This is just an excuse to promote insecure browsers and I believe sometimes you don’t have a choice. I get that people want freedom, but security is more important. It’s much saner to use Google Chrome (or Microsoft Edge if using Windows) and disable telemetry in chrome://settings.

The link of interest, Privacy Tests, only tests unmodified browsers. A hardened Firefox would likely perform just as well if not better than LibreWolf. Arkenfox isn’t even required to have basic privacy but it still improves the browser.

> [@f0r_fr33d0m](#):
>
> by default, unlike Firefox, it is already prepared internally to protect the user’s privacy and security, something that any potential ignorant user who intends to access privacy tools would appreciate and prefer rather than having to inform himself and spend a lot of time understanding and configuring the browser

They still have to install and update the browser. On Windows, **LibreWolf doesn’t automatically update nor does it notify users of new versions, which is a big red flag**. Linux users have this less bad as they can install LibreWolf and get updates depending on how they install it. I can’t speak for macOS. Changing a few settings in about:preferences (Firefox) or chrome://settings (for Chrome and Edge) is very easy and provides enough privacy for most people.

---

## Post 19 by @bluemonk — 2022-10-02T09:10:57Z

Its a great, all-around private browser by default, but im still an old school firefox user.

---

## Post 20 by @f0r_fr33d0m — 2022-10-02T09:11:52Z

> [@anon82677111](#):
>
> Security should be one of the top priorities of PrivacyGuides along with privacy. Some support towards Firefox and LibreWolf is because it continues to support Manifest V2, which is bad for security, and because they don’t want Google dominating the web, they want to have a choice. This is just an excuse to promote insecure browsers and I believe sometimes you don’t have a choice. I get that people want freedom, but security is more important. It’s much saner to use Google Chrome (or Microsoft Edge if using Windows) and disable telemetry in chrome://settings.

I partially disagree. It is true what you say, in the sense that Chromium browsers are better in security than those based on Firefox, I have not denied that at any time, but PrivacyGuides still recommends Firefox even if it is a more insecure browser than Chromium. It recommends to harden it, or put Arkenfox, but it is still Firefox, and **Librewolf IS a Firefox already hardened** , something that, I insist, those users who do not know how to harden it or do not want to spend much time would appreciate that it comes by default, and that is the goal of Librewolf.

> [@anon82677111](#):
>
> They still have to install and update the browser. On Windows, **LibreWolf doesn’t automatically update nor does it notify users of new versions, which is a big red flag**. Linux users have this less bad as they can install LibreWolf and get updates depending on how they install it. I can’t speak for macOS. Changing a few settings in about:preferences (Firefox) or chrome://settings (for Chrome and Edge) is very easy and provides enough privacy for most people.

Downloading and installing a browser is a simple task that I don’t know why you highlight. About the updates, I understand that it is a bad thing that does not receive updates automatically, but there are ways to fix it. The first one, if it were included in PrivacyGuides, would be to warn you with a red note, appealing to the user’s responsibility, but there is another much better solution: Recommend, together with Librewolf, the installation of [this extension](https://addons.mozilla.org/en-US/firefox/addon/librewolf-updater/) in it. I use this extension, and it helps a lot to keep your browser up to date, because it doesn’t automatically download the updates, but it does notify you. That may mean a couple of extra connections, but you gain in security.

I insist that I agree with you that a Chromium is preferable to a Firefox in terms of security, and it would be good if more projects like Brave or [Iridium](https://iridiumbrowser.de/) were born, that take a secure base and improve privacy, but I insist, Firefoxs are also browsers to consider, and if Firefox is recommended with some configurations, I do not see why Librewolf should not also be recommended with its corresponding configurations as well.

---

## Post 21 by @anon82677111 — 2022-10-02T14:59:32Z

There are ways to fix it, but a good browser would update automatically by default so users don’t have to fix it. On Linux, automatic updates for LibreWolf requires using the flatpak version (does it replace Firefox’s sandbox with Flatpak’s?) or your distro’s package manager (which may ship an outdated version). For this reason I don’t think LibreWolf should be recommended to newcomers.

This is like recommending Manjaro as a Linux distro for beginners because it might not have an update mechanism for installing new technologies like Wayland and Pipewire, but there are ways to fix that like manually installing that.

---

## Post 22 by @anon74021444 — 2022-10-02T15:41:06Z

Hey blacklymuss,  
Question, are you one of the admins or otherwise involved in the realization of this website and forum?

---

## Post 23 by @matchboxbananasynergy — 2022-10-02T15:45:45Z

Hi. I’m just going to quickly interject here to mention that Privacy Guides team members have a “Team Member” title next to their name (you’ll notice that I do). This is how you can tell if a forum member is part of the team or not.

---

## Post 24 by @anon74021444 — 2022-10-02T17:09:50Z

Ah, good to know.

If he was a member of your teams I would have immediately left this forum and would start a warning campaign against it I guess.  
The man has no clue about privacy and gives fierce-fully privacy-wise -very- dangerous advise. Very bad advise lots people will read on this Privacy forum.

Thanks for your reply. I will ignore his posts from now on. I can only hope you keep this forum a real privacy-minded forum.

---

## Post 25 by @jonah — 2022-10-02T17:33:24Z

> [@f0r_fr33d0m](#):
>
> Well, the same can happen with Arkenfox, in the sense that it becomes outdated because the day comes when it stops receiving updates

Since I don’t think anyone responded to this, I’ll chime in to point out that this isn’t actually true. **This is the entire reason we recommend Arkenfox+Firefox instead of Librewolf** : Arkenfox is a collection of modifications you make to your Firefox preferences, but _you’re still using Firefox_ and you’re getting updates (security patches, etc.) directly from Mozilla. With Librewolf you’re waiting for those updates from Mozilla to be merged into Librewolf’s code and released by the Librewolf devs.

For this reason, I agree with @bayesian in that I also don’t really see why Librewolf would be preferable to Arkenfox, which seems to do much the same stuff without forking the project. Maybe we should highlight Arkenfox more on the page?

---

## Post 26 by @f0r_fr33d0m — 2022-10-02T19:25:26Z

Hi Jonah. Thanks for your comment. I’m not entirely convinced by the argument, because at the end of the day, Firefox is releasing updates, and it is possible that over time new privacy/security features will emerge in the browser, and if Arkenfox does not update the user.js according to those new features, or if it stops supporting those settings, the counter-criticism falls by itself. On the other hand, as for the criticism about the time that occurs between Mozilla releases new versions of Firefox and the Librewolf team releases the corresponding version of your browser, at least on Windows and Linux, these times are always around 1~3 days, a really small time considering that the team has one developer per platform, although it will be long to meet your demands. The only criticism that I see relatively valid (although I personally always like to appeal to the individual responsibility of the user) is that the program does not update automatically on Windows. Anyway, and seeing that my proposal was rejected, I would like to thank you for the time you have dedicated to this thread. I will keep looking for tools and ideas to contribute to PrivacyGuides. Best regards.

---

## Post 27 by @samsepi0l — 2022-10-02T19:27:31Z

It’s ok to stay behind updates with Arkenfox, not with Firefox.

---

## Post 28 by @jonah — 2022-10-02T19:30:23Z

> [@f0r_fr33d0m](#):
>
> Firefox is releasing updates, and it is possible that over time new privacy/security features will emerge in the browser, and if Arkenfox does not update the user.js according to those new features, or if it stops supporting those settings, the counter-criticism falls by itself.

You’re correct in that future privacy settings will not be configured, however you are guaranteed to receive future privacy-related features and security updates provided by Mozilla immediately as they are released. On the other hand, Librewolf guarantees that all updates will have their privacy settings configured by default by Librewolf developers, however you are not guaranteed upstream features and security updates in a timely manner… 1-3 days is not usually significant, although it can be, and it’s never guaranteed to be that short of a turnaround. IIRC Librewolf fell behind on updates for longer than that at one point.

It is definitely a trade-off either way you go, I think our preference is just for the former over the latter.

---

## Post 30 by @f0r_fr33d0m — 2022-10-02T19:31:16Z

Well, I don’t agree. I feel more confident if I know that there is a team of developers actively updating and improving a browser than with a configuration file that may be out of date. But I guess it’s a matter of perceptions or preferences.

---

## Post 31 by @f0r_fr33d0m — 2022-10-02T19:33:55Z

I understand. Anyway, thanks for your time, and as I said:

> [@f0r_fr33d0m](#):
>
> I will keep looking for tools and ideas to contribute to PrivacyGuides.

Best regards.

---

## Post 32 by @anon20402919 — 2022-10-02T19:34:54Z

It’s not very healthy to never confront different points of view on the same subject and to be unable to do any questioning.  
You want to propose to delete the applications recommended on the site that have the same mentality?

Also, this is a very ironic speech on a topic that talks about “freedom”…

---

## Post 33 by @samsepi0l — 2022-10-02T19:35:26Z

I prefer to know there is a team of developers actively patching security on their own browsers than a team of developers actively trying to be update. (Don’t say what I haven’t said, Arkenfox and Librewolf are great projects, I just **personally** prefer having an up to date browser than a custom browser that I can forget to update imho)

---

## Post 34 by @f0r_fr33d0m — 2022-10-02T19:38:33Z

I’m sorry if I misunderstood your words, my English is terrible and I’m using a translator, so I can’t guarantee that I can understand or send messages 100% faithful to what they say or what I want to say. My apologies for that, and for the record I am not trying to say that Arkenfox is a bad project. It is simply a matter of preference, and above all, I defend freedom. Best regards.

---

## Post 35 by @samsepi0l — 2022-10-02T19:41:47Z

No problem mate, I was just insisting the fact that I’m no trying to be hateful about other projects.

At the end, it’s always the end user’s choice. We just need to guide people in the “right” direction.

---

## Post 36 by @vicky — 2022-10-03T03:48:17Z

So It is just a matter of preference to use Librewolf as compared to firefox with arkenfox?

---

## Post 37 by @f0r_fr33d0m — 2022-10-03T04:25:46Z

In essence, yes. Both have their advantages and disadvantages.

---

## Post 38 by @anon74021444 — 2022-10-03T17:29:21Z

You are right. I was just afraid the admins of this Privacy forum would advise the use of Google software and oppose against de-Googling. That was luckily not the case, so I am relieved.  
I was not ironic btw, I was shocked and I don’t want to delete anything.

---

## Post 40 by @starkle — 2022-10-03T23:39:09Z

It appears a decision has been made, but as a LibreWolf enjoyer I wanted to respond to the dialogue I’m seeing here. I’m also no expert so please correct me if I misspeak.

Firstly, please **stop comparing LibreWolf to Chromium based browsers**. If LibreWolf is too insecure to recommend simply because it’s not Chromium, then so is Firefox. And if Firefox is secure enough to recommend, then a fork like LibreWolf must make significant enough regressions to lose that status.

So then, what exactly are the downgrades LW makes from FF? Here’s the main points I see brought up here, and my response to each:

- it bundles uBlock Origin, which uses Manifest v2 and increases attack surface.

Ignoring the fact that the arkenfox project (which I see cited here as the alternative to using LW) profusely [recommends using uBO](https://github.com/arkenfox/user.js/wiki/4.1-Extensions), removing it is a simple 2-click process if you don’t want it. Many necessary security settings for FF, such as enabling HTTPS everywhere, are harder and more hidden than that. Also, after removing uBO, any Manifest v2 extensions must be added manually, so any risks around that apply to FF as well.

- [Insert setting here] isn’t set properly by default (Google Safebrowsing, etc).

By definition, this can be changed by the user. FF requires changing preferences as well – arguably far more extensively – so this criticism doesn’t hold up if FF is to be recommended.

- Being a software fork, it will be behind in updates, which is a security risk.

This is a valid concern, and the most we can ask for is a dev team that proves their ability to push timely updates. Projects like Brave or Vanadium have proven themselves, so we carefully recommend them.

That said, I’m tired of this FUD that LW can’t be trusted with updates. I sometimes see it suggested but never justified. My lazy searching found that the LW flatpak [was updated](https://gitlab.com/librewolf-community/browser/flatpak/-/commit/52fcefd85aab32770c9d24a927131d54c70ea946) within 1 day of the [current FF update](https://www.mozilla.org/en-US/firefox/105.0.1/releasenotes/), which seems reasonable to me. I’m not saying I’m certain that the LW devs have _never_ fallen behind on updates, I just asking the people who do say so to back up their claims.

- There are no automatic updates, which is a security risk.

This is a serious concern, and probably enough for LibreWolf to not be recommended by Privacy Guides.

However, I would suggest that it deserves something like an “honorable mention” slot. When automatic updates _are_ available, such as on Linux via flatpak, it matches or outclasses Firefox in every way; save for the slight delay in updates. Everything can be configured the same way as Firefox, but LibreWolf is far more convenient and minimal. People learning from this site deserve to know about LibreWolf and the conditions that make it viable.

---

## Post 41 by @f0r_fr33d0m — 2022-10-04T01:13:46Z

It is literally what I think, but with more information. My respects :place_of_worship:

---

## Post 42 by @vicky — 2022-10-04T03:48:31Z

Exactly What I feel. You have perfectly written what was on my mind!!

---

## Post 43 by @vicky — 2022-10-04T03:52:15Z

Its Easy. Librewolf stores all data in a firefox profile. You just import that profile into firefox.

---

## Post 44 by @matchboxbananasynergy — 2022-10-04T05:22:08Z

> There are no automatic updates, which is a security risk.

> This is a serious concern, and probably enough for LibreWolf to not be recommended by Privacy Guides.

I agree that this is the most important reasons why I’m wary about considering Librewolf for recommendation at this time.

Basic features such as easy (that includes automatic) updates are essential to keeping our readers secure. Firefox does that for them on Windows, macOS, and the Linux distributions we recommend are generally good about keeping Firefox up to date.

The moment updates become a manual thing, the person using that software has to start keeping track of things. We want to minimize this, as it is an important part to making privacy and basic security practices (keeping up-to-date) accessible and easy to accomplish.

> However, I would suggest that it deserves something like an “honorable mention” slot. When automatic updates are available, such as on Linux via flatpak, it matches or outclasses Firefox in every way; save for the slight delay in updates. Everything can be configured the same way as Firefox, but LibreWolf is far more convenient and minimal. People learning from this site deserve to know about LibreWolf and the conditions that make it viable.

I would not be comfortable with an “honorable mention”. Privacy Guides, in previously iterations, has historically had a “worth mentioning” section which was scrapped because it made no sense. Either we recommend something and can provide concrete reasons as to why, or we shouldn’t recommend it at all.

---

## Post 45 by @starkle — 2022-10-04T05:38:32Z

> [@matchboxbananasynergy](#):
>
> Privacy Guides, in previously iterations, has historically had a “worth mentioning” section which was scraped because it made no sense.

I must have been remembering such sections when I made the suggestion, but it makes sense that we would stop using them.

Perhaps we could format the browser pages as something more like the [Email Clients](https://www.privacyguides.org/email-clients/) page, where we give general as well as platform-specific recommendations all in one place. LibreWolf could be a recommendation for Linux, where automatic updates are possible.

Such a reformatting could even allow for combining the Desktop and Mobile Browser pages. It could also naturally allow for something like a Microsoft Edge recommendation for Windows, given its apparently desirable security features.

But I understand if that is too big a task :sweat_smile: just an idea

---

## Post 46 by @matchboxbananasynergy — 2022-10-04T06:00:33Z

The issue is not that it is too big a task, but that it is not really desirable.

For context, we used to have desktop and mobile browsers in the same page, as well as our Tor-related recommendations (which now have their own page in the Internet Browsing section).

There is thought being put into actually streamlining the email clients page as well.

> Perhaps we could format the browser pages as something more like the [Email Clients](https://www.privacyguides.org/email-clients/) page, where we give general as well as platform-specific recommendations all in one place. LibreWolf could be a recommendation for Linux, where automatic updates are possible.

My thought process is this:

If there is a cross-platform option that provides the same benefits, that is the option that we should opt for. So, if Thunderbird, for instance, doesn’t have any privacy or security disadvantages, I would argue that the Linux-specific options should be removed, and Thunderbird should become the primary email client recommendation.

This is getting a bit off-topic, so I’ll leave that there, but hopefully that provides a little bit more context from the perspective of how we want to evaluate recommendations and present them on the website.

---

## Post 49 by @samsepi0l — 2022-10-04T15:12:51Z

Librewolf is a little bit different, but it’s roughly the same.

---

## Post 50 by @samsepi0l — 2022-10-04T15:13:59Z

You can just use Firefox Sync, as it is e2ee. You enable it on LW

---

## Post 52 by @samsepi0l — 2022-10-04T15:17:37Z

I quite agree with you, but don’t forget that being behind updates for maxium 3 days (which is the case for LW) is OK most of the time, depending of your Threat Model obviously. IMHO, if you have basic threat model like mine (limiting data harvesting, tracking collection and basic virus/hackers/things). Using Firefox or Librewolf will just be a matter of preference.

---

## Post 53 by @anon82677111 — 2022-10-04T16:44:48Z

True, but most people are not going to use package managers or the LibreWolf updater. The fact that it does not automatically update **by default** makes it a questionable browser for newcomers.

---

## Post 54 by @poubellier — 2023-01-31T12:07:51Z

Is there something wrong with Librewolf?  
No mention of it on [https://www.privacyguides.org/desktop-browsers/](https://www.privacyguides.org/desktop-browsers/)

---

## Post 55 by @anon57307869 — 2023-01-31T12:35:42Z

Librewolf is basically just Firefox with arkenfox and uBlock Origin preinstalled. You can achieve all of this easily on regular Firefox and don’t have to trust another party (in that example: the Librewolf team) to release updates to the browser.

---

## Post 56 by @dngray — 2023-01-31T13:24:47Z

Previously discussed [Librewolf Browser (Firefox Fork)](https://discuss.privacyguides.net/t/librewolf-a-fork-of-firefox-focused-on-privacy-security-and-freedom/148)

and [Add Librewolf · privacyguides · Discussion #206 · GitHub](https://github.com/orgs/privacyguides/discussions/206)

---

## Post 57 by @ch3k — 2023-02-02T20:54:21Z

> [@starkle](#):
>
> it bundles uBlock Origin, which uses Manifest v2 and increases attack surface.
> 
> Ignoring the fact that the arkenfox project (which I see cited here as the alternative to using LW) profusely [recommends using uBO](https://github.com/arkenfox/user.js/wiki/4.1-Extensions)

that whole “ublock origin increases attack surface” argument is massively flawed, a lot of the time i see people backing it up with a theoretical (had never actually been exploited in the real world), article from portswigger where he managed to implement a keylogger via a filter list. However, that’s long been patched and whats important is that ublock origin reduces attack surface far more than it does increase it. Not having it on purpose for the claim of “better security” when in reality you’re harming it, and privacy, is just stupid.

---

## Post 59 by @Torsten — 2023-03-11T00:56:36Z

I tried to solve some Arkenfox issues with [my install, soften and automation script](https://github.com/trytomakeyouprivate/Arkenfox-softening) but its still more efford than Librewolf.

I think its the best browser for normal users. If normal means “wants to play online games on shady popup ad sites that even break on Vanilla FF with privacy settings hard” thats not a good experience at all.

On normal Firefox just create an insecure vanilla profile and your ready. I guess on Librewolf every profile will be hardened.

Also Librewolf disables FF sync, which I really like for non critical passwords. Its E2EE too… there is just one about:config to change.

But the first issue may be a problem.

I think such a setup script is nessecary, as the Arkenfox team will not remove features and systemd integration is important. Its only Linux at the moment, I would be happy about a Windows and mac version!

---

## Post 60 by @miku — 2023-05-08T05:38:24Z

Again, theoretical issue and future uncertainty is valued too high on PG, while current state of sotware is underlooked.

---

## Post 61 by @jonah — 2023-05-08T12:23:55Z

Saying “again” in your first post in a thread is certainly a bold choice. We recommend uBlock Origin on the site.

---

## Post 62 by @miku — 2023-05-08T13:12:29Z

This “again” here is for reflecting that common ideology holds by several forum members across posts, especially those with Firefox, Librewolf versus Brave, instead of restating anything previously said in this thread.

Meanwhile, originally as a reply to a thread, I acknowledged the recommendation of uBO as officially endorsed by PG but instead was replying to the opinion of “ublock origin increases attack surface”.

I apologise for lack of clarity in my precise statement.

---

## Post 63 by @Niek-de-Wilde — 2023-05-08T14:55:29Z

The issue with future uncertainty is that some reader will only visit our site when newly setting up their PC, not following the news, and blindly downloading the recommended software.

This way they may download software that ends up being abandoned after a few months, which leaves them without security updates.

This is why we want to only recommend software where the chance is very high that it will be around in a few years, whenever we have the luxury of choice.

---

## Post 64 by @anon43879818 — 2023-05-08T16:57:05Z

Btw I tried winget for the first time and it kinda solves the issue of librewolf not updating by itself.

Though there are still the other issues that you mentioned.

---

## Post 65 by @f0r_fr33d0m — 2023-06-12T10:08:16Z

“An attempt to make (automatic) updating of LibreWolf for Windows much easier ([mirror on GitHub](https://github.com/ltguillaume/librewolf-winupdater)). Can be used for installed and [portable instances](https://codeberg.org/ltguillaume/librewolf-portable).”

[Windows Installation – LibreWolf](https://librewolf.net/installation/windows/#installer)  
[ltguillaume/librewolf-winupdater](https://codeberg.org/ltguillaume/librewolf-winupdater)

As far as I have tested, it works, and it is already integrated into the LibreWolf installation. One less excuse to avoid putting in PrivacyGuides a browser that clearly [DESERVES](https://privacytests.org/) to be in this list. You should just clarify on the web, as you do with other browsers, the relevant settings that the browser requires to protect correctly or mostly the privacy of its users, in this case (perhaps among other things) that in the installation process they should activate the updater.

---

## Post 66 by @cocochoccy — 2023-07-10T01:51:38Z

I also think it should be recommended as well now, I think LibreWolf is still a great option and at least according to the site [PrivacyTests.org](https://privacytests.org/) it is neck to neck with Mullvad Browser, which is recommended, but without the awkward grey borders that drive me nuts lol.

---

## Post 67 by @dngray — 2023-07-10T08:42:01Z

> [@cocochoccy](#):
>
> but without the awkward grey borders

That is because of `privacy.resistFingerprinting.letterboxing`, [discussed here](https://fingerprint.com/blog/can-letterboxing-prevent-browser-fingerprinting/). This option is [on by default with arkenfox](https://github.com/arkenfox/user.js/issues/889), and provides more resistance to fingerprinting, although [it can be overriden](https://github.com/arkenfox/user.js/issues/1080). We don’t recommend doing so because it does provide better protection to leave it enabled. Librewolf just doesn’t [have it on by default](https://librewolf.net/docs/settings/#enable-letterboxing).

Personally, I just resize my window so that I don’t see it anyway.

Out of the Firefox forks, Librewolf is one of the better forks, especially how it has come along, in terms of documentation, auto updates etc. As the configuration changes are fairly minor, they haven’t been falling behind upstream on new releases as far as I can see.

---

## Post 68 by @privacyguides_users — 2023-07-10T10:31:42Z

In my use case, I not trust my self I have enough ability to maintenance hardening Firefox(Firefox + arkenfox userjs). I choose **Librewolf with Disabled Fingerprint settings** as my “dirty browser”(look like regular browser), Mullvad as my “clean browser”(Default Settings).

---

## Post 69 by @jonah — 2023-08-02T17:04:05Z

> [@LibreWolf Browser - 2023 Revisit](https://discuss.privacyguides.net/t/librewolf-browser-2023-revisit/13424/1):
>
> - LibreWolf is a mature FireFox fork with a mission to harden FireFox much in the same way as ArkenFox, but in a way that is approachable by non-technical users. In this sense, it has a similar relationship to FireFox as Brave has to Google Chrome (but without the controversy regarding paid ads).

I feel that this is not really the case, as far as I know LibreWolf only has a handful of contributors. I also don’t really feel it’s been demonstrated that Arkenfox is significantly worse to use.

> [@LibreWolf Browser - 2023 Revisit](https://discuss.privacyguides.net/t/librewolf-browser-2023-revisit/13424/1):
>
> - LibreWolf has uBlock Origin pre-installed, as recommended by Privacy Guides. If this is undesirable for any reason, it is easy to uninstall this plugin, but I personally feel that this is simply a time saver for people who are just going to install uBO anyways.
> - LibreWolf has multiple auto-update options on Windows and Linux. On Linux, it is distributed through the system package manager. On Windows, it is available on Chocolatey and the Windows Store, though the former is strongly preferred over the latter. Should one not wish to auto-update, manually downloading, verifying signatures, and installing updates manually from the website is an option, but I would not recommend it.

macOS? And on Windows I don’t think the existence of third-party package managers like Chocolatey excuse actual automatic update functionality.

> [@LibreWolf Browser - 2023 Revisit](https://discuss.privacyguides.net/t/librewolf-browser-2023-revisit/13424/1):
>
> All reasons for the browser’s initial rejection except for one have been rectified, and the one remaining reason (weaker sandboxing) did not stop FireFox from being added to Privacy Guides.

Have they though? The main reason (other than automatic updates which is perhaps still an even bigger issue) Librewolf was rejected is:

> [@jonah](#):
>
> Arkenfox is a collection of modifications you make to your Firefox preferences, but _you’re still using Firefox_ and you’re getting updates (security patches, etc.) directly from Mozilla. With Librewolf you’re waiting for those updates from Mozilla to be merged into Librewolf’s code and released by the Librewolf devs.

---

## Post 70 by @Foxtrek64 — 2023-08-02T20:38:57Z

> I also don’t really feel it’s been demonstrated that Arkenfox is significantly worse to use.

As someone who has never used Arkenfox before, I thought it’d be a good opportunity to go in blind as though I was setting it up for the first time. First thing I did was open up ddg and search for Arkenfox. This brings me to a github page, not a traditional website. As a software developer, it’s my personal experience that GitHub is not the most friendly to non-technical users. But let’s push on.

Second issue is a normal user will be looking for a download link. There doesn’t seem to be a “download” link anywhere on the page, but perhaps they get lucky and instead find “Releases.” Now they have a link to download a zip file called “source code.” Not quite what most users are looking for - they want an executable that’ll do everything for them.

Back on the main page, perhaps they get lucky and find a link to the wiki in the readme file. This takes them to [this page](https://github.com/arkenfox/user.js/wiki/2.1-User.js) discussing the user.js file, and immediately their eye gets drawn to the big code block showing how to write `user_pref()` declarations. This is arguably the worst place for non-technical users to end up, because many will either assume that if they even get this installed they will have to go through hours of lengthy customization work, maybe even in JavaScript, a language they may not read nor understand, or they think this is a guide for experts on how to create their own User.js file (which is sort of the case). Either way, it’s not where they want to be.

At this point the flow is mostly the same as though they had clicked WIKI at the top. They scroll through the page, find no “install” or “how to” link, give up, and install Chrome because it’s easy and doesn’t make their brain hurt.

People hate reading, and my example explores the journey of a user with a very generous amount of patience for a non-technical user trying to figure out technical things on their own. Many would not have made it this far.

Installing LibreWolf on the other hand is very easy for end users. Go to the website, click the big blue Installation button, click on their OS (probably Windows), and there’s a big blue Download button. No thinking involved and very minimal reading. At this point, a user will probably install the auto-updater too (especially if they click through the installer without reading anything), or perhaps they’ll opt to install the version from the Microsoft Store. Either way, they’re now using a browser comparable to FireFox + Arkenfox but in a way that’s much more user friendly, and one which will automatically update itself, even if it’s not in a way that we might call “ideal.”

> macOS?

Yes, MacOS is supported.

> And on Windows I don’t think the existence of third-party package managers like Chocolatey excuse actual automatic update functionality.

I just installed a fresh copy. It looks like there are now two options that do not require a third-party package manager:

1. Install [a plugin](https://addons.mozilla.org/en-US/firefox/addon/librewolf-updater/), mentioned previously, which will notify you when updates are available.
2. Install [librewolf-winupdate](https://addons.mozilla.org/en-US/firefox/addon/librewolf-updater/), which is officially recommended on their [Windows Installation page](https://librewolf.net/installation/windows/) and included in the Windows installer.

It seems they still lack a native auto-updater, and the root cause appears to be them trying to figure out how to get an update server to work using Mozilla’s documentation. In the mean time, even if we wouldn’t consider the available auto-update methods “ideal,” they do still work.

---

## Post 71 by @jonah — 2023-08-02T20:59:23Z

> [@Foxtrek64](#):
>
> the root cause appears to be them trying to figure out how to get an update server to work using Mozilla’s documentation.

Do you have a citation/link to where they say this or might be working on adding this feature?

---

## Post 72 by @Foxtrek64 — 2023-08-02T21:12:44Z

This claim is based off of a ten-month-old reddit post here. I have not taken any efforts to confirm Stanzabird’s place in the Librewolf project, just that they appear to be speaking from a position of authority on the matter:

> **[Reddit - The heart of the internet](https://www.reddit.com/r/LibreWolf/comments/y37qjq/autoupdate/isa5man/)**

Quote so people don’t have to go to reddit:

> Hi all, this is a good place to chime in and talk about the progress I’m making towards the auto-update stuff.
> 
> So why hasn’t it materialized yet?
> 
> First, other stuff was more urgent. I’ve only in the last few weeks been able to cross-compile the Windows version from Linux. This was a big goal because nobody wants to deal with the problems of compiling LW on Windows itself.
> 
> So I’m mostly done with figuring out how to set up the update server, as per [the mozilla guide for it](https://firefox-source-docs.mozilla.org/toolkit/mozapps/update/docs/SettingUpAnUpdateServer.html). The process of generating the .mar files is done in [this python script](https://gitlab.com/librewolf-community/browser/windows/-/blob/master/winbuild/mk.py#L14).
> 
> I would love to be able to make auto-updates possible on the Mac too, or at least write stuff in such a way that supporting it on macOS is not too different.
> 
> So how long will it take? I don’t know. There’s bugs I’ve not talked about. Once we’ve been able to update an experimental LW version on some throw-away update server, we’re mostly there.  
> – Stanzabird

Edit: they provide a dead link to the librewolf source. I cannot find a comparable `mk.py` file, but there does appear to be an [`update-version.py`](https://gitlab.com/librewolf-community/browser/source/-/blob/main/scripts/update-version.py?ref_type=heads) file that may be related.

---

## Post 74 by @starkle — 2023-08-03T01:39:26Z

While I have happily used LibreWolf for over a year, I’m content with it not being listed due to the lack of cross-platform automatic updates. However, the resistance I continue to see is perplexing.

> [@jonah](#):
>
> I feel that this is not really the case, as far as I know LibreWolf only has a handful of contributors. I also don’t really feel it’s been demonstrated that Arkenfox is significantly worse to use.

LibreWolf needs less contributors than Brave because the scope is way smaller. Brave builds a ton on top of Chromium while LibreWolf mostly changes existing Firefox options. I don’t see how having fewer contributors changes the LibreWolf’s description as a mature and user-friendly browser.

I am also surprised by the implication that arkenfox is _not_ significantly worse to use. The documentation literally has no installation instructions. I just re-read and confirmed the following steps are required and not explained in the documentation:

- Navigate to the Releases page
- Download and extract the Source code archive
- Navigate to `about:profiles` and open the current profile directory
- Move the `user.js` file to the root profile directory

Even if the documentation improves or someone makes it that far, there’s the ongoing maintenance work of manually editing prefs through text files, manually checking if there’s an update, then manually applying the update by running a shell script.

LibreWolf, by comparison, is installed as easily as any app, lets you set common overrides in the normal settings page, and doesn’t require any of the above maintenance. How is that not a significantly better experience?

> [@jonah](#):
>
> And on Windows I don’t think the existence of third-party package managers like Chocolatey excuse actual automatic update functionality.

The Windows Store is a first-party package manager, not a third-party one. Windows users no longer have to worry about LibreWolf updates. Don’t see why you’re singling out the Chocolatey option.

---

## Post 75 by @starkle — 2023-08-03T02:26:25Z

All in all, it seems the two reasons LibreWolf is not listed are still:

1. No automatic updates on all platforms
2. Potentially dangerous delay for updates

Since the discussion last year, the first point no longer applies to Windows. Thus the 75% of desktop users not using macOS or ChromeOS could reasonably be recommended LibreWolf.

The second point is overblown in my opinion. Anecdotally, LibreWolf reliably updates within 3 days of Firefox, usually less. I’m planning to make a chart showing LibreWolf’s update delay to settle this point one way or the other. Either way, that brief period of vulnerability seems only relevant to the more extreme threat models.

LibreWolf requires far less configuration than Firefox, for either private usage or DRM/WebGL/cookie riddled usage. It requires zero effort compared to arkenfox, for both installing and maintaining. It isn’t forced into Private mode compared to Mullvad browser, and is available in more Linux formats including Flatpak. The list could go on.

LibreWolf is simply the best option a lot of the time. Hopefully automatic updates on macOS aren’t too far down the road.

---

## Post 76 by @anon63378630 — 2023-08-03T02:43:48Z

> [@starkle](#):
>
> I’m planning to make a chart showing LibreWolf’s update delay to settle this point one way or the other

You can reuse the advisories and counts from my table: [https://divestos.org/misc/ffa-dates.txt](https://divestos.org/misc/ffa-dates.txt)  
But the dates there for Mozilla aren’t always the same as desktop edition.

---

## Post 77 by @Foxtrek64 — 2023-08-03T06:15:17Z

> 1. No automatic updates on all platforms.

To add to your point, I think it’s worth mentioning that if you’re on Linux, you are probably very used to installing applications using the terminal. As such, regularly updating all packages should be something on the back of your mind. Some distros include tooling to automate this process for you. For instance, RHEL has [dnf-automatic](https://dnf.readthedocs.io/en/latest/automatic.html). On systems with a desktop environment, it’s highly likely their package manager app is doing this for them already and will prompt the user to update any out of date packages. I’d be surprised if some don’t allow automatic updates (even if that’s a feature I hear Windows users complain about).

I have no idea what things look like on the MacOS side.

---

## Post 78 by @jd9834 — 2023-08-03T06:37:09Z

You can use homebrew in macos to install LibreWolf and somewhat automate the update process.

---

## Post 79 by @jd9834 — 2023-08-03T06:37:43Z

Still, despite my love for Librewolf, I do agree that the lack of actually automatic updates is an issue. When I first discovered Librewolf I had no idea it wasn’t auto-updating, I assumed it would notify me every time I needed to update like Firefox and Tor do. I kept browsing on an outdated version for weeks…

Now I know I need to look out for updates, but I wasn’t always aware of that. My point is that for a lambda user, chances are very high that they’ll do the same mistake I did because nowadays you just assume that programs take care of of the update process (especially browsers). It isn’t immediately obvious that Librewolf needs to be manually updated; if you did not understand that while downloading it, nothing will remind you of it afterwards.

---

## Post 80 by @Foxtrek64 — 2023-08-05T00:35:55Z

> It isn’t immediately obvious that Librewolf needs to be manually updated; if you did not understand that while downloading it, nothing will remind you of it afterwards.

This is no longer the case unless you go out of your way to make it so. Assuming you’re on Windows, the the installer bundles [librewolf-winupdate](https://addons.mozilla.org/en-US/firefox/addon/librewolf-updater/), as mentioned in a previous post of mine. You can choose to not install this, if you prefer, however there is no benefit to doing so.

That said, I’m not sure how this works in practice because I installed LW from Chocolatey.

---

## Post 81 by @jd9834 — 2023-08-05T06:16:13Z

> [@Foxtrek64](#):
>
> This is no longer the case unless you go out of your way to make it so. Assuming you’re on Windows

I was talking from a MacOS perspective. Apart from using homebrew (which I assume is similar to chocolatey), Librewolf does not auto-update nor make it clear that it won’t.

---

## Post 82 by @anon39565454 — 2023-08-22T10:29:14Z

but it _does_ make it clear [macOS Installation – LibreWolf](https://librewolf.net/installation/macos/)

> You can also install LibreWolf via a `.dmg`, but please note that this method requires to apply updates manually.

The first and recommended install method is using brew

---

## Post 83 by @anon10655404 — 2023-09-16T20:20:27Z

yes, it can auto-update with homebrew, but because of the LibreWolf team’s decision not to pay [Apple developer license](https://librewolf.net/docs/faq/#why-is-librewolf-marked-as-broken), you have to disable the MacOS [gatekeeper](https://support.apple.com/guide/security/gatekeeper-and-runtime-protection-sec5599b66df/web) for it. Which is another security risk to be taken. It also happened to me that I had to disable GK after updating LW again. I use rather Arkenfox or Brave.

---

## Post 84 by @anon39565454 — 2023-09-18T18:01:30Z

So it’s the typical apple fucking over everyone who doesn’t want to pay ~~security ransom~~ protection money, noted

---

## Post 85 by @anon10655404 — 2023-09-18T18:19:50Z

It’s their decision which has unfortunate consequences for user who has to deal with using SW with crippled protection which is not needed with other browsers.  
I completely understand why PG team don’t want to promote LW.

---

## Post 86 by @anon39565454 — 2023-09-18T18:50:41Z

To not recommend it to an apple user is understandable. But it’s still Apple’s fault for basically forcing apps that doesn’t even go through the mac app store to be signed. Which is $100USD/yr to Apple when they don’t even host the app.

And ofc it’s marked not as “potentially unsafe”, but “broken”. Quite a scummy move, Apple

---

## Post 88 by @You_will_own_nothing — 2023-10-19T12:04:47Z

> [@starkle](#):
>
> While I have happily used LibreWolf for over a year, I’m content with it not being listed due to the lack of cross-platform automatic updates. **However, the resistance I continue to see is perplexing**.

I (wrongly) though this place would be a good alternative to the Reddit’s privacy subreddit, but I guess I was wrong.

It easy to see that the team here has a decision made and they want everyone to follow their path, hence why it seems that everything is an excuse to avoid having LibreWolf on the guides. They will pick anything they can find just to backup their reason why the browser shouldn’t be listed.

If only LW had a search engine that sells data for AI training, or a VPN service being installed alongside it, it would probably made it into the list :wink:

_I’m not sad… just disappointed!_

---

## Post 89 by @anon63378630 — 2023-10-19T12:07:47Z

> [@You_will_own_nothing](#):
>
> , or a VPN service being installed alongside it,

Mullvad Browser does not come with Mullvad VPN in any way.  
And it is largely entirely maintained by Tor Project and based off of Base Browser which is the same base as Tor Browser.

---

## Post 90 by @Ganther — 2023-10-19T14:27:11Z

> [@You_will_own_nothing](#):
>
> I (wrongly) though this place would be a good alternative to the Reddit’s privacy subreddit, but I guess I was wrong.

What makes you say that?

I think not adding LibreWolf is pretty understandable when Mullvad Browser is essentially LibreWolf but better.

---

## Post 91 by @You_will_own_nothing — 2023-10-19T15:00:43Z

> [@Ganther](#):
>
> What makes you say that?
> 
> I think not adding LibreWolf is pretty understandable when Mullvad Browser is essentially LibreWolf but better.

I was hoping for some impartiality, but Im not seeing it.

Could we please stop with the Mullvad, its better preach? This is not a true fact. Whats the point of having the Mullvad Browser Extension enabled by default? Just to let me know that I don’t have the VPN connected? I dont need this kind of advertising.

This community adapts the music to suit its needs. I’ve seen a member of the team use an excuse like it’s easier for any user, when recommending Brave, but somehow he forgot that **Mullvad only supports 64bit** systems? **LibreWolf also supports 32bit alongside 64**. They are not the same!

In this case, LibreWolf would be the easier option, since a normal user would not even know the difference between x86 and x64.

---

## Post 92 by @Ganther — 2023-10-19T15:09:46Z

> [@You_will_own_nothing](#):
>
> Could we please stop with the Mullvad, its better preach? This is not a true fact.

It isn’t? In what ways do you find LibreWolf to be better?

> [@You_will_own_nothing](#):
>
> Whats the point of having the Mullvad Browser Extension enabled by default?

Who cares? It’s a 637 kB addon. I’ve never once even noticed it’s running. If you want to judge them for something, judge them for not inviting PrivateVPN and co to the proxy party.

> [@You_will_own_nothing](#):
>
> but somehow he forgot that **Mullvad only supports 64bit** systems? **LibreWolf also supports 32bit alongside 64**. They are not the same!

32-bit users are a dip in the ocean today. Do you really think 32-bit support in the year 2023 should be an advantage worth taking into consideration?

> [@You_will_own_nothing](#):
>
> In this case, LibreWolf would be the easier option, since a normal user would not even know the difference between x86 and x64.

You seem to be trolling at this point. In what world is LibreWolf the easier option? Mullvad Browser has an automatic updater by default. LibreWolf doesn’t. It’s really not harder than that.

I can see a future with LibreWolf in it, if it wasn’t an “everything is deleted on shutdown” browser it would definitely fill a hole as a more privacy conscious Firefox, but as it is now it’s a lesser Mullvad Browser.

That’s how I’m using LibreWolf, personally. I’m writing from it at this very moment, in fact.

---

## Post 93 by @You_will_own_nothing — 2023-10-19T15:24:24Z

> [@Ganther](#):
>
> It isn’t? In what ways do you find LibreWolf to be better?

I don’t think so… I think they are identical. I don’t see one better than the other one.

> [@Ganther](#):
>
> You seem to be trolling at this point.

Honestly, I’m not going to waste any more time with you or your comments (aside from this one), because you’re insinuating that I’m trolling just because you don’t like my opinion.

> [@Ganther](#):
>
> Who cares? It’s a 637 kB addon. I’ve never once even noticed it’s running.

Is that your argument? So now the size of the add-on matters? Was not okay if it was 1024Kb?  
And you never noticed it? It was the first thing I notice after installing it.  
That’s very ironic when you think I’m the one trolling.

> [@Ganther](#):
>
> 32-bit users are a dip in the ocean today. Do you really think 32-bit support in the year 2023 should be an advantage worth taking into consideration?

I know that 32-bit users are almost extinct. **But** , if you have two equal products, and one of them supports a function that the other one doesn’t (even if it’s meaningless) shouldn’t it be considered an advantage? So what is it? How does having backwards compatibility supports harms you?!

> [@Ganther](#):
>
> In what world is LibreWolf the easier option? Mullvad Browser has an automatic updater by default. LibreWolf doesn’t. It’s really not harder than that.

Automatic updater by _default_ is indeed an advantage. But, it seems to me that it’s the only relevant option, and you guys grab into it like if it was the holy grail.

---

## Post 94 by @anon63378630 — 2023-10-19T15:32:05Z

> [@You_will_own_nothing](#):
>
> shouldn’t it be considered an advantage

fwiw, 32-bit programs are directly less secure than 64-bit programs, as numerous security features/mitigations cannot be used due to the smaller address space and fewer available registers.

also I have a handful of laptops from 2007, every single one is 64-bit

---

## Post 95 by @Ganther — 2023-10-19T15:32:47Z

> [@You_will_own_nothing](#):
>
> I don’t think so… I think they are identical. I don’t see one better than the other one.

If LibreWolf is 99% the same as MB then MB is 1% better.

> [@You_will_own_nothing](#):
>
> Honestly, I’m not going to waste any more time with you or your comments (aside from this one), because you’re insinuating that I’m trolling just because you don’t like my opinion.

I’m insinuating that you’re trolling because your so called “opinions” come off as shilling and strawmanning. Normally, a person can write something more convincing than “32-bit support and a 637 kB addon is BAD” when asked for reasons why LW is better than MB.

> [@You_will_own_nothing](#):
>
> I know that 32-bit users are almost extinct. **But** , if you have two equal products, and one of them supports a function that the other one doesn’t (even if it’s meaningless) shouldn’t it be considered an advantage? So what is it? How does having backwards compatibility supports harms you?!

It doesn’t. It’s just that 32-bit support just isn’t as appealing as the superior update speed of MB, for example. If you want a privacy-oriented browser then you presumably want it to be secure as well.

> [@You_will_own_nothing](#):
>
> Automatic updater by _default_ is indeed an advantage. But, it seems to me that it’s the only relevant option, and you guys grab into it like if it was the holy grail.

PrivacyGuides exists to give normal users easy options.

The average user isn’t going to set up an automatic updater. It’s not happening.

---

## Post 96 by @You_will_own_nothing — 2023-10-19T19:34:03Z

> [@anon63378630](#):
>
> fwiw, 32-bit programs are directly less secure than 64-bit programs, as numerous security features/mitigations cannot be used due to the smaller address space and fewer available registers.
> 
> also I have a handful of laptops from 2007, every single one is 64-bit

I know some of the advantages of x64 systems, since I started using them with Win XP 64-bit Edition.  
I’m not surprised you have laptops that support x64, I also do. But you would be surprised by how many apps you use, that still use x86 libraries or executables, especially on Windows (given that Apple killed x86 support with Catalina).

I’ve heard that argument before, but I’ve never seen any evidence of that claim (I’m not saying they don’t exist). The only thing I found was an ancient article from [Ars Technica](https://arstechnica.com/information-technology/2012/11/64-bit-firefox-for-windows-should-be-prioritized-not-suspended/), and that’s it.

But if you have further information about that, please share it (I’m not being sarcastic/ironic, btw).

---

## Post 97 by @anon63378630 — 2023-10-19T20:00:16Z

> [@You_will_own_nothing](#):
>
> But you would be surprised by how many apps you use, that still use x86 libraries or executables

I don’t have a single 32-bit package on any of my servers or workstations (`rpm -qa | grep -i 686`).

> [@You_will_own_nothing](#):
>
> I’ve heard that argument before, but I’ve never seen any evidence of that claim

Here is an old but relevant real world study which covers how easy it is to break ASLR under 32-bit: [https://www.blackhat.com/docs/asia-16/materials/asia-16-Marco-Gisbert-Exploiting-Linux-And-PaX-ASLRS-Weaknesses-On-32-And-64-Bit-Systems-wp.pdf](https://www.blackhat.com/docs/asia-16/materials/asia-16-Marco-Gisbert-Exploiting-Linux-And-PaX-ASLRS-Weaknesses-On-32-And-64-Bit-Systems-wp.pdf)

It is also quite common for CVEs to be much worse under 32-bit.  
eg. under 32-bit this was a full KASLR bypass: [oss-security - CVE-2021-34693: Infoleak in CAN BCM protocol in Linux kernel](https://www.openwall.com/lists/oss-security/2021/06/15/1)

And some other notes: [https://security.stackexchange.com/questions/255210/security-considerations-of-x86-vs-x64](https://security.stackexchange.com/questions/255210/security-considerations-of-x86-vs-x64)

---

## Post 99 by @Ganther — 2023-10-19T20:59:30Z

> [@Voilable](#):
>
> basically a spyware

If there was a better option for normies I’d be standing in line to replace Brave with that.

There isn’t though.

---

## Post 100 by @You_will_own_nothing — 2023-10-19T21:07:13Z

> [@anon63378630](#):
>
> Here is an old but relevant real world study which covers how easy it is to break ASLR under 32-bit: [https://www.blackhat.com/docs/asia-16/materials/asia-16-Marco-Gisbert-Exploiting-Linux-And-PaX-ASLRS-Weaknesses-On-32-And-64-Bit-Systems-wp.pdf](https://www.blackhat.com/docs/asia-16/materials/asia-16-Marco-Gisbert-Exploiting-Linux-And-PaX-ASLRS-Weaknesses-On-32-And-64-Bit-Systems-wp.pdf)
> 
> It is also quite common for CVEs to be much worse under 32-bit.  
> eg. under 32-bit this was a full KASLR bypass: [oss-security - CVE-2021-34693: Infoleak in CAN BCM protocol in Linux kernel](https://www.openwall.com/lists/oss-security/2021/06/15/1)
> 
> And some other notes: [https://security.stackexchange.com/questions/255210/security-considerations-of-x86-vs-x64](https://security.stackexchange.com/questions/255210/security-considerations-of-x86-vs-x64)

Much appreciated. That was insightful. I’ll read the first PDF with more detail.

Correct me if I am wrong, but it appears that those weaknesses are more vulnerable on a non-x64 kernel. Isn’t it different from executing an x86 app on a x64 kernel?

> [@anon63378630](#):
>
> I don’t have a single 32-bit package on any of my servers or workstations (`rpm -qa | grep -i 686`).

I ran `dpkg-query -l | awk '$4 != "amd64" {print $0}'` and I have many apps that they aren’t 64bit only, they have the flag all. AFAIK, they include all kinds of architectures, including x86 ones. I consider these also 32bit apps (alongside x64). I think you might also have those in yours.

---

## Post 101 by @anon63378630 — 2023-10-19T22:01:35Z

> [@You_will_own_nothing](#):
>
> Isn’t it different from executing an x86 app on a x64 kernel?

No.  
Running a 32-bit program on x86\_64 has the same issues.

> [@You_will_own_nothing](#):
>
> AFAIK, they include all kinds of architectures, including x86 ones. I consider these also 32bit apps (alongside x64). I think you might also have those in yours.

I don’t know why you think i686 is mandatory in 2023:

```
rpm -qa | grep -v -e x86_64 -e noarch 
gpg-pubkey-eb10b464-6202d9c6
gpg-pubkey-d651ff2e-5dadbbc1
gpg-pubkey-dbf5b694-5fcb6b87
gpg-pubkey-18b8e74c-62f2920f
```

all/noarch means that it isn’t machine specific code, it is either JITed/python/java/js/etc or it is non-executable like config files or assets.

Most distros don’t even support installation on 32-bit systems.

edit:  
just to be clear  
i386 is from 1985  
i686 is from 1995  
x86\_64 is from 1999

---

## Post 102 by @ph00lt0 — 2023-10-20T22:54:15Z

This is interesting. Bit off topic i think but thank you for sharing these links. I didn’t know about those. Now I have even more arguments to make people use x64

---

## Post 103 by @You_will_own_nothing — 2023-10-24T19:02:03Z

So, today Mozilla released a new Firefox version (119), and out of curiosity I decided to check on how does Librewolf took the last time to update it, and I compared it to Mullvad Browser, since there are a few people here that seem to have an erection when they talk about that browser.

Mozilla released FF [118.0.2](https://www.mozilla.org/en-US/firefox/118.0.2/releasenotes/) and [ESR 115.3.1](https://www.mozilla.org/en-US/firefox/115.3.1/releasenotes/) on the 10th of October.  
Librewolf which is **based on the non-esr version** , got [updated](https://gitlab.com/librewolf-community/browser/bsys6/-/releases/118.0.2-1) on the 12th of October (so, two days after).  
Mullvad Browser 13, which seems to be **based on the ESR version of FF** (this by itself makes them a bit different, but okay), was [updated](https://github.com/mullvad/mullvad-browser/releases/tag/13.0) on the 13th of October (so, three days after).

I guess that the [speed of the updates](https://discuss.privacyguides.net/t/brave-browser-installing-vpn-services-on-windows/14450/8) is not so relevant in this case, right? :wink:

---

## Post 104 by @jonah — 2023-10-24T19:15:47Z

Mullvad Browser is based on Tor Browser and not Firefox ESR, so that’s not really the comparison you’d have to make.

The distinction is important even though Tor Browser is built on the same codebase as Firefox ESR, because Tor Browser receives privacy & security features _ahead_ of Firefox in some cases (which is why the Tor uplift project exists at Firefox), and Tor has their own auditing process for new browser features in addition to Mozilla’s work anyways, which means that new browser features from Mozilla don’t even get enabled in Tor (WebAuthn, for example) until they go through a separate review process on Tor’s end.

All of this is covered in our extensive Mullvad Browser discussions :slight_smile:

---

## Post 105 by @anon28734771 — 2023-10-24T19:21:09Z

Mullvad Browser is basically Tor Browser, but it doesn’t route traffic through Tor. You can choose to just use it as it is or use a VPN to try to blend in with other people that use that same VPN with Mullvad Browser.

Librewolf is basically a worse version of Mullvad Browser, and there is no reason to recommend it, especially when it doesn’t even have automatic updates.

Unless someone will explain to us the benefits of Librewolf over other options, which can even outweigh the lack of automatic updates, Librewolf will not be recommended.

---

## Post 106 by @anon63378630 — 2023-10-24T19:39:26Z

You also can’t directly compare regular ESR to Base/Tor/Mullvad Browser ESR, as they regularly backport fixes from newer Firefox versions.

---

## Post 107 by @You_will_own_nothing — 2023-10-24T20:27:20Z

> [@jonah](#):
>
> Mullvad Browser is based on Tor Browser and not Firefox ESR, so that’s not really the comparison you’d have to make.

Okay, fair enough!

> [@anon28734771](#):
>
> Librewolf is basically a worse version of Mullvad Browser, and there is no reason to recommend it, especially **when it doesn’t even have automatic updates.**

It doesn’t out-of-the-box.  
You can save the _Uno Update card_, since you know perfectly well that there are options to deal with that: updater tool, chocolatey, Windows Store (yeah this sucks).

> [@anon28734771](#):
>
> **Unless someone will explain to us the benefits of Librewolf over other options** , which can even outweigh the lack of automatic updates, **Librewolf will not be recommended.**

The question is not if there are benefits (probably there are), it’s more of: if we find them, will you accept them?

I have a feeling that you won’t (I might be wrong), but it will be a matter of time until we find the answer for that.  
It’s not a matter if Librewolf deserves to be on the list or not, it’s if the team has the user’s best interests in mind or their own. This is the answer we all should be looking for :vulcan_salute:

---

## Post 108 by @jonah — 2023-10-24T20:39:16Z

Quote from another thread which is relevant:

> [@Kagi (Search Engine)](https://discuss.privacyguides.net/t/kagi-search-engine/14172/16):
>
> reminder that just because we don’t include something on the website doesn’t mean we’re recommending _against_ it, it just means that we have no official opinion one way or the other.

* * *

Also here’s the other thing with automatic updates, they’re not an impossible challenge for LW. You know how I know this? Because literally every other browser we recommend can do it. IMO, LW simply just isn’t taking the time to do things properly, which is their prerogative, but it doesn’t mean we have to like it (and clearly most people here don’t like it).

> [@You_will_own_nothing](#):
>
> will you accept them?

It doesn’t come down to any one person’s thoughts.

TBH, we make these decisions largely based on whether the community as a whole feels that we should add a recommendation, and like it or not you’re simply in the minority here, so yes if you want to change the community opinion of LW you’re going to have your work cut out for you.

---

## Post 109 by @xe3 — 2023-10-25T01:57:05Z

> [@anon28734771](#):
>
> Librewolf is basically a worse version of Mullvad Browser, and there is no reason to recommend it.

I don’t agree with this characterization or comparison. Mullvad Browser–like Tor Browser–has a very specific use case it is intended for, it serves that purpose well but it is not intended to be used the way that the vast majority of people use their web browser.

For this reason, in my eyes it is not the right browser to be comparing to Librewolf which is designed for a different and broader scope of use. If you want to argue Librewolf shouldn’t be listed (an argument that I am sympathetic to, but not 100% onboard with), I think you should be comparing it to PG’s other recommendations (Firefox + Arkenfox, or Brave) which have a much more similar scope of use to librewolf than Mullvad Browser does in my opinion.

> [@anon28734771](#):
>
> especially when it doesn’t even have automatic updates.

\*For users of a certain proprietary operating system.

If you use any of the OSes recommended by privacy guides (or any Linux distro for that matter) it receives automatic updates like any other flatpak does.

---

## Post 110 by @jonah — 2023-10-25T04:39:22Z

> [@xe3](#):
>
> Firefox + Arkenfox

For the record, this is what _most_ of the discussion in this thread has been comparing LW to, and we believe FF+AF is better too, not just Mullvad Browser.

> [@Librewolf Browser (Firefox Fork)](https://discuss.privacyguides.net/t/librewolf-browser-firefox-fork/148/25):
>
> Since I don’t think anyone responded to this, I’ll chime in to point out that this isn’t actually true. This is the entire reason we recommend Arkenfox+Firefox instead of Librewolf: Arkenfox is a collection of modifications you make to your Firefox preferences, but you’re still using Firefox and you’re getting updates (security patches, etc.) directly from Mozilla. With Librewolf you’re waiting for those updates from Mozilla to be merged into Librewolf’s code and released by the Librewolf devs. …

> [@Librewolf Browser (Firefox Fork)](https://discuss.privacyguides.net/t/librewolf-browser-firefox-fork/148/27):
>
> It’s ok to stay behind updates with Arkenfox, not with Firefox.

---

## Post 111 by @f0r_fr33d0m — 2023-12-07T02:18:42Z

Wow, one year without logging into the forum and the Librewolf issue is still being discussed… I am honored to have created one of the most discussed threads on privacyguides hahahahahaha.

By the way, hello everyone again. I’m not going to appear here much, the truth is that I’m very busy with my computer science degree, and on top of that I’ve become obsessed with philosophy, so I don’t have much time left during the day to stay updated on the forum, but even with that I try to check the forum and the web updates from time to time.  
I will try, as far as I can, to be more active in the forum and propose/discuss more things.

(PS: In general terms, nowadays I still prefer to use Librewolf in Linux as default browser that I almost never use, something like what happens with Vanadium in Graphene, that although I use more frequently Brave or Firefox, I leave Vanadium as default so I don’t mix up the fingerprints when opening links from the rest of the applications.)

---

## Post 113 by @Average_Joe — 2023-12-31T20:15:06Z

Welcome back!

I just came across this and there’s a tonne of useful information here: [Reddit - The heart of the internet](https://www.reddit.com/recap/LibreWolf/)

---

## Post 114 by @GreenNebula — 2024-04-13T15:51:35Z

LibreWolf is one of the best privacy browsers out of the box. It also does have automatic updates now.

> **[Which browsers are best for privacy?](https://privacytests.org/)**
>
> An open-source privacy audit of popular web browsers.

---

## Post 115 by @xe3 — 2024-04-13T18:33:54Z

> [@GreenNebula](#):
>
> It also does have automatic updates now.

Good news.

> LibreWolf is one of the best privacy browsers out of the box.

I agree. I think LW serves much the same niche as Brave (easy privacy without much of a learning curve)

**My _personal_ perspective:**

**Librewolf doesn’t provide anything that can’t already be achieved with Firefox** (in fact virtually every privacy protection Librewolf enables was built by Firefox (and Tor) contributors and is present in Firefox.

**But that doesn’t mean there is no value to Librewolf**. Librewolf serves a particular type of user quite well, more or less a similar demographic to Brave Browser, those who desire privacy, but lack either the knowledge, time, interest, or confidence to harden their browser themselves. For this sizeable group of users, I think Librewolf is a very reasonable choice.

**Regardless of whether you start with Firefox and harden it yourself, use a template like Arkenfox, or want a turnkey solution like Librewolf, you can achieve more or less the same configuration**. It just depends on how you want to get there, and the degree to which factors like reliance on an additional smaller 3rd party matter to you.

In terms of the Firefox family of browsers I think all of these options have a place and a comparative advantage in at least one specific area:

1. Firefox mildly hardened (etp strict, https only, gpc, uBO, and a couple other tweaks)
2. Librewolf
3. Firefox w/ Arkenfox (“hardened” Firefox)
4. Mullvad Browser
5. Tor Browser

> **relevant, but personal frustration**
>
> A mild frustration of mine, is that because Librewolf has been debranded/rebranded, and because there is a bit of bias/distrust of larger projects in this space, less informed users often misattribute Firefox features present in Librewolf as being Librewolf features, and misconstrue Librewolf as “fixing Firefox” when in reality it is leveraging features built into Firefox, and is much closer to a pre-configured Firefox profile, than an alternative to it (LW’s configuration is largely based on Arkenfox’s user.js template). This is not a criticism of Librewolf as a project, just a frustration.

edit: IIRC the (valid in my eyes) reason LW isn’t recommended officially by PG (apart from automatic updates) is that compared to just using Firefox itself, it introduces potential vulnerabilities (trusting a smaller project/additional 3rd party, potential for delayed updates, etc), while not solving any additional privacy/security problems that can’t be solved with a well configured Firefox or another recommended option (Brave, Mullvad, Tor). But remember, something not being recommended by PG, just means its not a recommendation, It doesn’t mean it is an _anti-recommendation._

---

## Post 116 by @Sprout3425 — 2024-04-14T02:53:04Z

> [@xe3](#):
>
> it introduces potential vulnerabilities (trusting a smaller project/additional 3rd party, potential for delayed updates, etc)

Just asking out of curiosity, does this not apply to Arkenfox as well?

---

## Post 117 by @xe3 — 2024-04-14T03:46:18Z

> [@Sprout3425](#):
>
> Just asking out of curiosity, does this not apply to Arkenfox as well?

Not really. I think this is one of the strengths of the Arkenfox approach. Arkenfox is just a template, (the user.js file in combination with your own useroverrides.js file which are a set of changes to Firefox’s default preferences).

When you use Arkenfox, you are still using Firefox, Arkenfox isn’t software, it doesn’t modify the Firefox browser, doesn’t affect Firefox updates (which still come directly from Firefox). So you are not dependent on the maintainer of Arkenfox in the same ways you are dependent on a software developer

And equally importantly because Arkenfox is a semi-DIY process, you are expected to read the wiki, encouraged to understand the changes being made and the process, and expected to customize it to fit your needs. You are necessarily much more involved in the process and informed if you follow the [wiki](https://github.com/arkenfox/user.js/wiki), review the pretty well commented [user.js](https://github.com/arkenfox/user.js/blob/33a84b608c8a1f871c6ce9c4d2b932dc57078fae/user.js) or [webui](https://arkenfox.github.io/gui/). So the trust relationship is a bit different in the case of Arkenfox.

With that said, you are still putting some trust in the maintainer of Arkenfox to choose good defaults, and/or trust in yourself to recognize when they make a choice you disagree with and override it yourself (this is how the project is intended to be used, it isn’t a one-size-fits-all solution).

---

## Post 118 by @eqrlzo8t — 2024-04-14T05:44:21Z

Sorry I can’t buy the additional 3rd party potential vulnerabilities argument. It just sounds so unfair to Librewolf team.

Who would assure that arkenfox won’t change `security.certerrors.mitm.priming.endpoint` from `https://mitmdetection.services.mozilla.com/` to their own server, or change DoH to their own DNS server in an update?

Who would assure that the next [31/71 virus detection of Mullvad](https://discuss.privacyguides.net/t/mullvad-browser-trojan-script-wacatac-b-ml/17753) won’t be false positive any more?

You are exposing to the codes of 2 entities (Chromium and Brave) with Brave and 3 entities (Firefox, Tor and Mullvad) with Mullvad. It’s not different to Librewolf’s. The only difference is the “bigger” organizations of the others. If PG’s criteria for browsers include “Must come from a big team” then I would 100% agree of rejecting Librewolf because of that criterion.

Currently the only valid reason to reject Librewolf is the update criteria. All of other reasons are just bias nitpicking and ignoring the same things with other browsers, and not in the criteria at all.

---

## Post 119 by @jonah — 2024-04-14T05:51:45Z

> [@eqrlzo8t](#):
>
> You are exposing to the codes of 2 entities (Chromium and Brave) with Brave and 3 entities (Firefox, Tor and Mullvad) with Mullvad. It’s not different to Librewolf’s.

The difference is that Brave and TB/Mullvad are **ahead** of their upstream projects. Features originally developed by the Tor Project are regularly added to Firefox as well as vice-versa. Brave has features which are unavailable in any other Chromium browser, Tor private windows and native IPFS support just to name two examples.

I don’t think Librewolf adds anything to Firefox that Firefox can’t already do, it just takes things that Mozilla’s released and enables them by default. Arkenfox does the same thing, except to stock Firefox. Correct me if I’m wrong :eyes:

* * *

**Personally** I’m kind of neutral on Librewolf at this point, but I think the update situation in particular is still a big deal to other team members, so it likely still won’t be added.

---

## Post 120 by @eqrlzo8t — 2024-04-14T07:44:29Z

I was talking about the concern of “potential vulnerabilities” due to Librewolf being a 3rd-party or a smaller project, it’s an unfair reason if it’s used to reject the proposal. I didn’t talk about its features comparing to the upstream, it’s about the same vulnerabilities existing in other configurations/browsers that are not from chromium or firefox team themselves as well.

I did say if there’s a reason to reject this based on the criteria, it’s just about the updates. (And yes, if you count “bringing something different” as a hidden criterion for recommendations, I would agree too, since I also see this in some other topics, and I don’t have further opinions about this criterion).

---

## Post 121 by @GreenNebula — 2024-04-14T15:23:20Z

> I don’t think Librewolf adds anything to Firefox that Firefox can’t already do

Honestly, you might be right, but not 100% sure this is true, but even so, I think privacy by default is very valuable to the common user especially if they are not so tech savvy (majority of users). There is a trade off for privacy at slight expense of security via relatively slower updates, but this is a privacy guide after all. There are several projects on Privacy Guides that are as small as Librewolf, yet still recommended.

Just find it somewhat odd that almost every other privacy community outside of Privacy Guides recommends Librewolf as a default out-of-the-box privacy browser.

Maybe add it as a sub-recommendation below firefox for those user without the capability or will to harden firefox with a small disclaimer on the trade-off?

---

## Post 122 by @overdrawn98901 — 2024-04-14T15:43:15Z

> [@eqrlzo8t](#):
>
> Sorry I can’t buy the additional 3rd party potential vulnerabilities argument. It just sounds so unfair to Librewolf team.

Hmmm, I do not think it’s just that it’s a 3rd party. Technically Mullvad Browser, Tor Browser, etc, are also 3rd party and therefore a non zero risk introduced. I think the differences are the following points:

- Mullvad Browser and Tor Browser have substantially larger resources dedicated to development
- The above two browsers offer entirely unique use cases as to why you’d want to choose them over vanilla Firefox

The point seems to be that it seems to be fork with less resources and doesn’t seem to do anything majorly different than a configured Firefox, or Firefox with Arkenfox.

With that, if there are automatic updates, and there is a clear comparison between the other choices about why it is better than an alternative, then I think it makes for a good recommendation. But if the other choices offer the same benefits with less risk, seems to be at best a footnote that it was considered but excluded due to XYZ.

---

## Post 123 by @xe3 — 2024-04-14T18:55:13Z

On the topic of Librewolf:

> [@eqrlzo8t](#):
>
> I was talking about the concern of “potential vulnerabilities” due to Librewolf being a 3rd-party or a smaller project, it’s an unfair reason if it’s used to reject the proposal

I think part of the issue here is differing impressions of what PG recommendations mean, and what role the criteria play.

My imperfect understanding is that PG recommendations are meant to highlight the best in class software and services (in the context of Privacy and Security). It is a curated selection, not an exhaustive list of every tool that exceeds minimum criteria. Meeting the criteria is the minimum, not a guaranteed way to get a product listed. And just because something is not listed as a recommendation doesn’t mean you personally can’t or shouldn’t use it, and doesn’t mean it is an anti-recommendation.

> Sorry I can’t buy the additional 3rd party potential vulnerabilities argument. It just sounds so unfair to Librewolf team.

I think you don’t buy it because you’ve only considered half of the equation: the issue is that you are extending reliance to a 3rd party _AND_ not gaining anything not already possible with mainline FF or the other recommendations on the list. It is a cost/benefit thing, you can’t just look at half the equation.

Brave offers clear improvements over upstream Chromium, Mullvad and Tor Browser serve _specific use-cases_ better than any other browser, including upstream Firefox. A downstream derivative that has some unique clear comparative advantage will be weighted differently than a downstream derivative that isn’t providing something unique.

(with that said, I’m sympathetic to the argument that the comparative advantage LW provides is ‘easy-button-privacy’–although Brave serves that niche as well)

I also think you may have misinterpreted what I meant by vulnerabilities. I was not referring specifically to malicious code. Maybe additional “potential points of failure” would be a clearer way to express what I mean. You are counting on an additional 3rd party to:

1. Consistently and promptly provide updates. (this has historically been a common issue with smaller derivative browsers)
2. Write decent code / be competent
3. Stay committed / not lose focus or interest in the project. (this is historically a big issue in FOSS, so many projects get a flurry of attention/development in the first few years and then slowly (or quickly) fade into being under or un-mantained.
4. Not do something dumb or immature (see Thorium)
5. Have decent security practices

That doesn’t mean downstream derivatives are bad or should never be used (I think they are good in the bigger picture, and I’ve repeatedly [defended](https://discuss.privacyguides.net/t/librewolf-browser-firefox-fork/148/109) and acknowledged the [value](https://discuss.privacyguides.net/t/librewolf-browser-firefox-fork/148/115) of Librewolf throughout this thread). These are just somewhat minor points to consider when choosing the browser that is best for you. Personally I am fairly neutral on whether LW should or should not be listed, I don’t really think there is a wrong choice here, but I think I understand the reasons why LW is currently not listed as well as the reasons many people are attracted to Librewolf.

* * *

On the topic of Arkenfox:

> [@eqrlzo8t](#):
>
> Who would assure that arkenfox won’t change `security.certerrors.mitm.priming.endpoint` from `https://mitmdetection.services.mozilla.com/` to their own server, or change DoH to their own DNS server in an update?

Ideally _you would and should_. And it’s made easy to do. the ability to see the changes an update will apply is built into the updater script which you run manually. Arkenfox is just a human readable file, it cannot and does not update itself on its own.

Also, changelogs and changes are posted and discussed publicly and all modified settings can be reviewed [here](https://arkenfox.github.io/gui/). And because it is just a user.js file, changes tend to be somewhat infrequent and very ‘bite sized’ (small). Because updates are small and infrequent (often just a few flipped preferences) and because the userbase is pretty experienced and engaged, it is pretty unlikely a malicious or negligent setting would slip by unnoticed, even if you are not personally checking every update (which you are encouraged to do).

But again, I do not think we need to be focusing on the less likely risk of either LW or AF being outright malicious. That was not something I intended to imply. But if that were to occur the potential consequences are much more limited in the case of AF (as it is just a list of changes to about ~100 Firefox preferences)

---

## Post 124 by @eqrlzo8t — 2024-04-15T00:30:01Z

Security risks have their own standards and assessments. It’s not something to ignore just because the software brings something different of privacy to the upstream. GrapheneOS rejects Gecko-browsers because of their security risks although forks like Mull bring a lot of improvements in privacy (and actually security with JIT-disabled) comparing to chromium.

I did not just compare with AF alone.

> Who would assure that the next [31/71 virus detection of Mullvad](https://discuss.privacyguides.net/t/mullvad-browser-trojan-script-wacatac-b-ml/17753) won’t be false positive any more?

Why is only Librewolf’s security is a concern while Mullvad showed the same security concern with that? I know about Mullvad’s response. My point here is if you bring security as an aspect to reject, please back it up with valid evidence because it’s a serious topic.

(And actually the non-autoupdateable of AF brings a contradiction to PG’s update criterion, and a “difference” of LW with FF+AF, but ok if no one wants to discuss between LW and AF, I won’t discuss it further).

* * *

Again, as I said above, if we count “bringing something different” as a hidden criterion, I won’t oppose it and there would be none of this discussion. But if you bring security concern as another half of equation, please back up that half clearly with security-based evidence, not via “its privacy trade-off aspect” because it’s a whole other serious field with plenty of resources and can easily raise many other people’s eyebrows.

---

## Post 125 by @xe3 — 2024-04-15T02:01:01Z

> [@eqrlzo8t](#):
>
> And actually the non-autoupdateable of AF brings a contradiction to PG’s update criterion

I think you’re still fundamentally misunderstanding what Arkenfox is.

Arkenfox is _not a browser._ There is no Arkenfox Browser to autoupdate, no security patches to apply, etc.

Arkenfox “users” are simply Firefox users, using the Firefox Browser (not a fork, not modded version, _just Firefox_).

Updates come directly from Firefox, exactly as quickly as mainline Firefox (because _it is_ mainline Firefox). In terms of update speed, In terms of update speed, FF+AF exceeds all of the recommended desktop browsers except for Firefox (which it ties with) on the update criteria:

> - Supports automatic updates. _[Firefox does, and by extension Arkenfox does]_
> - Receives engine updates in 0-1 days from upstream release. _[Firefox has no upstream, FF (including FF+AF) users receive updates as soon as they are ready]_

I think that you are confusing updating _the browser_ (this is the PG criteria) with updating your personal settings which are fundamentally very different things. An unpatched browser is a big deal, a Firefox setting being left in its default state is not (and that is the only consequence of not updating your user.js file).

What you are interpreting as a flaw of Arkenfox is actually one of its strengths.

---

## Post 126 by @eqrlzo8t — 2024-04-15T02:54:44Z

FF + AF is recommended as a bundle in one of the recommendations. Yes, outdated preference can still lead to some security risks because under the hood, it changes the relevant codes inside too. This is integrated to the browser core even deeper than changing CSS on the website’s interface and CSS is not immune to security risks either. There’s not much sense to keep your browser updated and your forced preferences outdated for years.

And that is just a small part about the security assessments in my previous comments. I’m using FF+AF with RSS feed notified about the commits before updating, and the only reason I assess it to be safe is because it’s still active, discussed and updated with FF’s updates. I’m also using both Librewolf and Mullvad, depending on the situation, and security-wise everytime I deemed myself that “this browser is more secure”, I have to ask myself the opposite question “what is the risk of the other browser”. That’s when things are boiled down to these 3 bullets (which are applied to all 3 options I’m using above)

- Is it updated? How many days is it late to upstream’s updates? Do I accept that delay?
- Who is the team behind the project?
- How much different is it comparing to the upstream?

Only the 1st one is valid based on PG’s criteria. The other 2, if we agree as hidden criteria, I agree too. But none of that is just because they are done by 3rd-party team, it needs more details than that.

---

## Post 127 by @pinkandwhite — 2024-04-15T09:13:50Z

I’m not sure where you’re getting the idea that outdated user.js “changes relevant codes inside” because if the preference the user.js is changing gets deprecated or removed or even just renamed, _there is no setting in the ff code for that user.js preference to change_ and ff will just ignore it when parsing the prefs.js generated from the user.js. It’s pretty clear what user.js does [as per the Arkenfox wiki](https://github.com/arkenfox/user.js/wiki/2.1-User.js)

---

## Post 128 by @eqrlzo8t — 2024-04-15T09:48:08Z

I don’t really mean outdated here as Firefox removes it completely at an update. In many cases, Firefox hid the option out of `about:config` and put the plan to deprecate it over time (and of course it would still run during this time until they remove it completely). It’s not uncommon practice. And yeah, “change” is not really a correct term here, I should say that they run another code path depending on the value of the preferences.

---

## Post 129 by @plonkeyt — 2024-05-28T21:35:15Z

I can understand why PG may have a preference for Firefox/Arkenfox in its recommendation, considering LibreWolf’s delay in security updates. But I do not understand why they cannot both be recommended, with the caveat included for readers to decide for themselves.

Personally I find the modification of Firefox too daunting, and find the Mozilla big-tech affiliations off-putting. The LibreWolf developers takes care of both of these concerns, by doing the modifications for me, and by providing an independent check of Mozilla updates just in case Mozilla were to tamper with anything privacy related.

Which is why I am opting for LibreWolf. But I think it would be of benefit to all if the PG desktop browser recommendation page included LibreWolf, and more generally had a more clear and comprehensive synopsis in the opening paragraph.

For example:

Tor is the only browser which can come close to ensuring full anonymity. However, websites are often blocked through Tor, and connection speeds are slow, which is why we also recommend Mullvad, Firefox, and Brave, all of which provide good privacy in conjunction with a VPN.

Mullvad out-of-the-box provides strong privacy protections, which are greatly weakened if extensions are used or settings modified. Firefox is capable of providing the same anti-fingerprinting protection, but requires much modification (with Arkenfox) which some may find inconvenient. LibreWolf is a preconfigured Firefox suitable for those who are intimidated by the modification required to harden Firefox, though comes with the security risk of having its updates released a couple of days later than the mainline Firefox browser.

Some websites may not work properly on Mullvad and Firefox, which is why we also recommend Brave, which is based on Chromium and therefore has minimal compatibility issues. Brave does not provide the same level of privacy protection, however it remains good option for those who value privacy, relative to Google Chrome and other mainstream browsers.

---

## Post 130 by @Dkama — 2024-06-06T17:51:53Z

Apparently LW doesn’t disable JIT (not sure it’s an issue in ARM Linux, though).  
MB does so (in an Apple silicon Mac).

---

## Post 131 by @anon66791365 — 2024-06-07T13:54:10Z

Mullvad browser just seems superior in every way honestly I’m not sure what LW brings to the table. No point in listing a million Firefox forks, just keep Firefox itself and tor browser/mullvad browser.

---

## Post 132 by @Dkama — 2024-06-07T14:53:20Z

Well, TB/MB don’t have builds for aarch64 Linux, so LW can be a shortcut for FF+AF in Linux VMs in a Mac. Just so we don’t say it brings absolutely nothing to the table lol.

---

## Post 133 by @Regime6045 — 2024-06-07T15:21:42Z

If you disable telemetry, Pocket and WebGL and enable “Strict” Enhanced Tracking Protection and `resistfingerprinting` and change a few of the normal settings like the search engines in vanilla Firefox - what even is the difference to Librewolf then?

The only one I’m aware of that’s an actual improvement rather than just more private default settings is that Librewolf enables the JPEG XL feature which Firefox only has in the Nightly version. (Though it’s still behind a flag in about:config and has nothing to do with privacy or security.)

---

## Post 134 by @Tech-Trooper — 2024-06-07T16:48:16Z

No. Mullvad and LW have two different purposes. You can’t keep logins in MB unlike LW.

---

## Post 135 by @anon66791365 — 2024-06-07T17:50:28Z

What’s wrong with regular Firefox for that purpose.

---

## Post 136 by @Dkama — 2024-06-07T18:30:42Z

Of course you can. Just add an exception in “Delete cookies and site data when Mullvad Browser is closed”. You can even disable that option altogether if that’s what you want.

---

## Post 137 by @bee — 2024-06-08T07:02:21Z

This entirely defeats the purpose of MB per my understanding. Mullvad browser relies on a “crowd” for users to blend in and take advantage of some claims for better privacy. The second you make an adjustment to the settings, you no longer fit within that crowd, and all anti-fingerprinting benefits are lost.

At that point, there’s no major benefit to using it over LibreWolf. Personally, the logo alone is enough to make the choice between the two from there.

In all seriousness though, I think Librewolf has merit over Mullvad. It’s less misleading to recommend it than Mullvad where you won’t be taking advantage of the purpose it was engineered for.

I don’t see why Librewolf shouldn’t be added, at least as a small card near the Arkenfox section where it’s explained as an option. I think it could very well be the best choice for many people.

---

## Post 138 by @Juicy — 2024-06-08T12:50:52Z

This is nonsense: you can change pretty much everything not under site settings while not increasing your fingerprint. Clearing history upon close is not a flag that’s forward facing, i.e. it’s not revealed to other parties (local and offline). Using Librewolf on the other hand is about the worst you can possibly do when it comes to fingerprinting with Firefox.

Besides Mullvad already having Tor’s anti-fingerprinting & Arkenfox’s hardening, the maintainers have an incomparably better track record. In other words, there is zero point to using Librewolf!

---

## Post 139 by @benm — 2024-06-08T15:01:47Z

Given that PG begins the whole Knowledge Base with a description of threat modeling, I take for granted that different users will have different needs and thus it makes sense to recommend tools that are not suitable for everyone. Its not necessary for Librewolf to be superior to Firefox + Arkenfox if it fits a different threat model or use case.

Most linux users for example will be using package managers, rendering the auto-update concern a moot point, and that is the strongest argument against Librewolf.

One of the most obvious advantages to Librewolf is that it insulates you from user error. Rather than needing to stay on top of whatever Firefox settings need to be changed, remembering what settings I have changed manually vs. defaults, keeping track of which of my computers have the settings implemented, and so on, I can just install one package. If Firefox updates in the future in a way that requires a new mitigation, I can assume that keeping Librewolf updated will take care of it, rather than needing to check and keep track of it manually.

Given that there are Auto Updaters for Librewolf, it seems like this could easily be mitigated with a strongly worded note.

In my use case, I have Librewolf as an alternate browser, for situations where my primary browser has problems (i.e. certain websites are broken).

---

## Post 140 by @jonah — 2024-06-08T16:27:41Z

> [@benm](#):
>
> Given that PG begins the whole Knowledge Base with a description of threat modeling, I take for granted that different users will have different needs and thus it makes sense to recommend tools that are not suitable for everyone. Its not necessary for Librewolf to be superior to Firefox + Arkenfox if it fits a different threat model or use case.

I mean, yes and no. Tools are not going to be recommended on Privacy Guides simply because a threat model they’d apply to conceivably could exist. All threat models are _valid_… **but** some threat models are out of scope for our coverage. Like we’re not going to recommend Microsoft Edge simply because _someone_ might not care about Microsoft spyware for whatever reason, for example. I recently talked more about this here:

> [@Implement Threat Model Labels](https://discuss.privacyguides.net/t/implement-threat-model-labels/18659/2):
>
> No, things can be objectively not private. If a tool doesn’t give you the option to use it privately, then we do not consider it to be a privacy-respecting tool. You can certainly exercise your right to use tools which aren’t privacy-respecting, if you don’t care about that loss of your right in that specific context, but such tools still have no place in our recommendations. Identifying the threats that tools defend against best is probably a good idea, and was the original intent yes. I hav…

That being said, I agree it probably _could_ be valid to list Librewolf. The use-case over hardening Firefox is still not entirely clear to me, is it just: people who don’t feel like reading the Arkenfox wiki and learning about how their browser works? :man_shrugging:

---

## Post 141 by @Tech-Trooper — 2024-06-08T16:31:06Z

> [@anon66791365](#):
>
> What’s wrong with regular Firefox for that purpose.

I am not saying it’s bad or good, but stating that they cater to different needs.

> [@Dkama](#):
>
> You can even disable that option altogether if that’s what you want.

I don’t use MB for logins, but that was one of the complaints I saw on Reddit. I am not sure if it’s possible to make MB to keep logins completely. Where is that option in the settings?

---

## Post 142 by @Dkama — 2024-06-08T17:11:51Z

It’s exactly what I said: “Delete cookies and site data when Mullvad Browser is closed”. Just uncheck it and it should keep all logins. It should be under” privacy and security" I think.

I wouldn’t do it, though. There’s a “manage exceptions” button next to it. Just open it and add individual sites you want to keep logged in. All the others will forget you, which is what you want anyway.

I just wish they would copy Brave’s mechanism though. Instead of settings \> privacy \> manage exceptions you just click on the Brave button and click on a toggle.

---

## Post 143 by @bee — 2024-06-08T17:42:33Z

Hmm I see, I didn’t realize that wasn’t a forward facing flag. In that case there’s nothing wrong with it I suppose.

Still, saying Librewolf is the worst for firefox fingerprinting is an exaggeration. A regular firefox install + arkenfox configured by the user would likely have far more variance in the settings people change, whereas in Librewolf one would generally only change some of the major settings made accessible in the UI by lw. Even if Librewolf has a smaller user base, I think it would even out. Besides, without serious effort put into fingerprinting protection like MB or Tor Browser, fingerprint protections are naïve at best. This is outlined clearly in the arkenfox wiki as well. I don’t think it’s worth being overly concerned with if you’re using something like vanilla FF or Librewolf to begin with.

I think the place to recommend Librewolf then is to users who don’t want to deal with the defaults of Mullvad as they aren’t as concerned with fingerprinting, which would require a little more work to disable, such as the window resizing to be similar accross all devices, restriction of fonts, etc. Stuff some people may find overly restrictive.

Otherwise I understand the points being made that MB is the best option here. I think mentioning Lw would be solely to provide an in between for people who wouldn’t put up with MB, or aren’t savvy enough or willing to configure arkenfox for vanilla FF.

---

## Post 144 by @benm — 2024-06-08T17:46:49Z

> [@jonah](#):
>
> That being said, I agree it probably _could_ be valid to list Librewolf. The use-case over hardening Firefox is still not entirely clear to me, is it just: people who don’t feel like reading the Arkenfox wiki and learning about how their browser works? :man_shrugging:

That would be a valid group. Its the same reason one might not recommend Arch Linux to a general audience just because it could hypothetically be hardened more carefully than something else which is more hardened by default. Another example is someone who is managing a fleet of, say, 30+ computers who would not want to have to manually undergo the process of commissioning Firefox with custom configurations and keeping them up to date.

Plenty of users would also lack the confidence that they did the configurations correctly, since if you did it incorrectly it might be invisible to you as a user.

---

## Post 145 by @xe3 — 2024-06-08T19:27:09Z

> [@benm](#):
>
> I take for granted that different users will have different needs and thus it makes sense to recommend tools that are not suitable for everyone.

This is true.

> Its not necessary for Librewolf to be superior to Firefox + Arkenfox if it fits a different threat model or use case.

This is true also. But the question is what threat model does it cater to that isn’t already well served by one of the existing recommendations?

My perspective is somewhat inline with @jonah’s, I don’t dislike Librewolf, I have it installed on my system, but I don’t really see a common threat model or use-case served by Librewolf that isn’t already served by at least one of the current recommendations.

Playing devil’s advocate (to what I just wrote above) If I were to make the case for Librewolf’s inclusion it would probably be that:

There are some cracks between the current offerings that Librewolf could potentiallly fill.

1. There are probably at least some users who don’t want to contribute to the Chromium monoculture (which would rule out Brave Browser) or just don’t want to use Brave specifically.
2. And also, are intimidated by or uninterested in the moderate learning curve and _teach-a-(hu)man-to-fish_ approach of Arkenfox.
3. And also don’t need (or aren’t willing to deal with) the strong anti-fingerprinting stance of Mullvad Browser and/or Tor Browser.

For this imagined users preferences, that leaves 2 remaining options in the current recommendations (#1) Firefox lightly hardened per PG guidelines (#2) Mullvad Browser (used “the wrong way”).

#2 is something PG probably shouldn’t recommend, even if there may be nothing fundamentally wrong with doing that in the right context, I think it would be hard to communicate in a way that didn’t cause confusion or give users a false sense of security/put less knowledgeable users near a slippery slope. But there is still option #1, lightly hardened Firefox, which is not intimidating to setup, provides moderately strong privacy, and promotes a bit more learning and knowledge compared to a pre-configured setup.

So that leaves just a little bit of daylight for Librewolf to potentially fill, for the sub-sub-sub niche of users who require simplicity out of the box, won’t consider Brave/Chromium, and want _marginally_ more privacy than lightly hardened Firefox but marginally less rigid protection than Mullvad Browser.

But I’m skeptical that there are many users who really fall into that sub-niche. It seems the main attraction to Librewolf in practice is ‘Arkenfox but easy’ which is a totally valid _personal preference_ but it isn’t really a _threat model_ or _use case_.

---

## Post 146 by @xe3 — 2024-06-08T19:47:55Z

> [@benm](#):
>
> Another example is someone who is managing a fleet of, say, 30+ computers who would not want to have to manually undergo the process of commissioning Firefox with custom configurations and keeping them up to date.

This is actually part of the value that I see in the Arkenfox approach of using a config file (user.js) to define a custom configuration. The learning curve is a one time thing, once you understand how things work, its really pretty simple, and having a single pair of config files makes configurations really portable and reproducible. IIRC Firefox actually has purpose built functionality already built-in for the use-case you describe (a system administrator deploying a custom Firefox configuration across many systems), in fact I strongly suspect that is probably the mechanism that Librewolf uses to manage their own custom configuration. This piqued my curiosity so I’m going to look into that.

> That would be a valid group. Its the same reason one might not recommend Arch Linux to a general audience just because it could hypothetically be hardened more carefully than something else which is more hardened by default.

The difference between AF and Arch, is that with AF you _start out_ with a very hardened template. If you change nothing, you have very strong privacy and security by default. The customization of Arkenfox usually entails _relaxing_ some settings to suit your preference, not _hardening_ further. With Arch it is the opposite, learning how to secure your system is your own responsibility, and you are not starting from a place of strong security defaults.

> Plenty of users would also lack the confidence

This is very valid and something I can empathize with, as I’ve been in that position many times. For those users I think lightly hardened Brave, lightly hardened Firefox, Mullvad Browser, and Librewolf are all valid options.

---

## Post 147 by @Zombie.Turtle — 2024-06-14T05:35:24Z

I’ve found Mullvad to be a lot more problematic than Librewolf. Limiting my options to watch videos through the browser is a huge thumbs-down. :-1:

I haven’t tried Arkenfox yet.

---

## Post 148 by @Zombie.Turtle — 2024-06-14T06:40:55Z

I was watching Techlore’s “[The Ultimate Guide to Firefox Hardening!](https://www.youtube.com/watch?v=F7-bW2y6lcI)” and came across “[Why I Stopped Hardening Firefox.](https://www.youtube.com/watch?v=N67kJLaWtoA)”.

Librewolf seems to be positively received and in the comments too.

---

## Post 149 by @Zombie.Turtle — 2024-06-26T15:10:52Z

What are the current thoughts on the regulars and privacy experts here as of this date on Librewolf?

---

## Post 150 by @anon48875053 — 2024-06-26T17:33:41Z

Just use Tor Browser, Mullvad Browser, Firefox, and Brave.

---

## Post 151 by @asanyan — 2024-07-16T22:29:19Z

This should be seriously considered again, as it looks like Mozilla will just continue to add garbage to their browser with every release and most people can’t be bothered to manually check for updates and update arkenfox every time FF updates, and If you’re outside of Linux and have autoupdates enabled then you can’t even check for things before they shove it down your throat. Librewolf at least always ensures that the garbage is disabled.

---

## Post 152 by @xe3 — 2024-07-17T02:20:51Z

While I disagree with your characterization ([here’s why](https://andrewmoore.ca/blog/post/mozilla-ppa/)) I think what you are advocating has some validity, particularly for the subset of people who (1) want Firefox, but (2) don’t want to actively manage their browser / keep up with changes (3) choose to trust the people behind Librewolf more than (and in addition to) Firefox and (4) aren’t willing to use Mullvad Browser for whatever personal reasons.

But why recommend Librewolf in addition to Mullvad Browser, considering that Mullvad Browser is planning to implement a [‘Persistent Mode’.](https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/issues/300) In light of that, is there a compelling reason to recommend Librewolf and not just stick with the current recommendations, and wait for that feature to land in MB?

_(edit: not trying to be dismissive of the proposal btw, the question at the end of the last paragraph is earnest and open, not rhetorical)_

---

## Post 153 by @woodruff — 2024-07-17T11:28:08Z

I quite approve of what I read but I think everyone has “a few different reasons” for preferring LibreWolf to Mullvad. For example I care almost nothing about “Persistent Mode” but I miss two things for which I prefer LibreWolf:

- The ability to install extensions such as Proton Pass.
- the ability to enable Firefox Sync

Best alternative would be Brave but I prefer to use a non-Chromium engine.

---

## Post 154 by @asanyan — 2024-07-17T16:15:51Z

While it’s a good browser, MB shares many of the usability drawbacks as the Tor Browser. It’s also important to have a browser that you can stay logged in on stuff that requires your identity, as logging to your bank or Google account through MB renders its privacy benefits moot because all your tabs share the same IP address. It’s also based on ESR so it doesn’t have all of the security fixes backported.

---

## Post 155 by @anon63378630 — 2024-07-17T16:58:49Z

> [@asanyan](#):
>
> It’s also based on ESR so it doesn’t have all of the security fixes backported.

Tor Project gets access to all the security issues from Mozilla while they are embargoed and backports them as necessary.

> [@asanyan](#):
>
> through MB renders its privacy benefits moot

no it does not.  
It still prevents them from learning exactly what hardware you have or various other information.

---

## Post 156 by @asanyan — 2024-07-17T17:16:16Z

> Tor Project gets access to all the security issues from Mozilla while they are embargoed and backports them as necessary.

Thanks for the info

> no it does not.  
> It still prevents them from learning exactly what hardware you have or various other information.

True, maybe it’s not completely moot then, but your activities can still be correlated and to prevent this you need another web browser.

---

## Post 157 by @xe3 — 2024-07-17T18:23:16Z

> [@asanyan](#):
>
> it’s also important to have a browser that you can stay logged in on stuff that requires your identity, as logging to your bank or Google account

I think that is what adding a “persistent mode” is intended to address.

> MB renders its privacy benefits moot because all your tabs share the same IP address

I don’t agree that it ‘renders its privacy benefits moot’ but even if it did, that wouldn’t be any less true with Librewolf, FIrefox, or Brave and a VPN.

Also, you should know, if you use Mullvad VPN extension (with any Firefox based browser) you can set per site VPN connections, so in cases where you do want different websites to see different IP’s you can do this. It was one of my favorite features of the Mullvad browser extension when I used it.

> [@woodruff](#):
>
> but I miss two things

Fair points. Not installing extensions is indeed a limiting factor. Though technically nothing stops you. You risk making yourself stand out, but then that would be the case with LW or other browsers also, its just talked about more with MB because MB is going for a higher standard of anti-FP protection than LW, Firefox, etc.

This gets at a question I’ve been mulling over for some time. Obviously it is best, and recommended to use Mullvad Browser _the right way,_ (no extensions, no changes, etc), but is using Mullvad Brower _the wrong way_ (e.g. installing an extension or two, maybe using a custom list in uBO) still as good or better, than using a lesser browser like LIbrewolf, FF+AF, or Brave? Using MB “the wrong way” undermines the strong anti-FP, but then LW and AF, and Brave, don’t really achieve strong anti-FP to start with, so idk. Thoughts?

---

## Post 158 by @asanyan — 2024-07-17T20:21:47Z

> I don’t agree that it ‘renders its privacy benefits moot’ but even if it did, that wouldn’t be any less true with Librewolf, FIrefox, or Brave and a VPN.

Yeah, but this is why you need more than one browser to properly isolate your activities.

> you can set per site VPN connections, so in cases where you do want different websites to see different IP’s you can do this.

How..? I use their browser with their VPN, and I have the plugin.. It does have a proxying feature, but it says that it’s for all sites, so not domain specific like what Tor Browser does

---

## Post 159 by @woodruff — 2024-07-17T20:27:54Z

> [@xe3](#):
>
> This gets at a question I’ve been mulling over for some time. Obviously it is best, and recommended to use Mullvad Browser _the right way,_ (no extensions, no changes, etc), but is using Mullvad Brower _the wrong way_ (e.g. installing an extension or two, maybe using a custom list in uBO) still as good or better, than using a lesser browser like LIbrewolf, FF+AF, or Brave? Using MB “the wrong way” undermines the strong anti-FP, but then LW and AF, and Brave, don’t really achieve strong anti-FP to start with, so idk. Thoughts?

I have been thinking about this. My thought is that using extensions or something else on Mullvad Browser is worse both because of the audience of users who use Mullvad (who will likely not use any extensions) and the fact that Mullvad Browser uses Firefox ESR.

I figured that using Firefox ESR with Mullvad Browser settings and one or more extensions is like having a beacon pointed at you :grin:

In the end, Mullvad Browser and LibreWolf do not differ that much in my opinion to justify this “effort.” I refer for example to this table: [https://privacytests.org/](https://privacytests.org/) where they are almost identical.

But if someone more experienced can answer this better than I can I look forward to other opinions!

---

## Post 160 by @jonah — 2024-07-17T20:59:15Z

I am tempted to re-evaluate Librewolf. Wonder if @dngray thinks it’s worth it?

> [@xe3](#):
>
> but is using Mullvad Brower _the wrong way_ (e.g. installing an extension or two, maybe using a custom list in uBO) still as good or better, than using a lesser browser like LIbrewolf, FF+AF, or Brave?

I’m not aware of a reason it’d be _worse_, outside of being on ESR.

---

## Post 161 by @redoomed1 — 2024-07-17T21:23:19Z

> [@jonah](#):
>
> re-evaluate Librewolf

Just a quick FYI, Librewolf doesn’t currently fulfill [the following minimum requirement](https://www.privacyguides.org/en/desktop-browsers/#minimum-requirements) on the Desktop Browsers page:

> - Must receive engine updates in 0-1 days from upstream release.

The first [version 128 release for Librewolf](https://codeberg.org/librewolf/source/releases/tag/128.0-1) was released on July 12th, **3 days** after [Firefox 128.0](https://www.mozilla.org/en-US/firefox/128.0/releasenotes/) was released.

---

## Post 162 by @xe3 — 2024-07-17T21:33:40Z

> [@redoomed1](#):
>
> The first [version 128 release for Librewolf](https://codeberg.org/librewolf/source/releases/tag/128.0-1) was released on July 12th, **3 days** after [Firefox 128.0](https://www.mozilla.org/en-US/firefox/128.0/releasenotes/) was released.

This may or may not be a symptom of some of the concerns expressed [here](https://github.com/arkenfox/user.js/issues/1809#issuecomment-1949635343) (informally and a little abrasively)

---

## Post 163 by @anon48875053 — 2024-07-17T21:41:07Z

> [@jonah](#):
>
> I am tempted to re-evaluate Librewolf. Wonder if @dngray thinks it’s worth it?

Why? Why not just recommend the best of the best, which is currently the case for desktop browsers?

---

## Post 164 by @anon63378630 — 2024-07-17T22:28:52Z

There is little benefit of Librewolf in comparison to the already recommended Mullvad Browser.

---

## Post 165 by @jonah — 2024-07-18T03:47:42Z

Yeah, I’ve spent some time tonight looking at Librewolf and it is (still) not good. Seeing a lot of other bad experiences from people on Mastodon who are switching because of Mozilla news too.

I don’t think they do any testing for their builds either, as far as I can tell. So, nothing has changed :innocent:

---

## Post 166 by @jonah — 2024-07-18T18:07:47Z

4 posts were split to a new topic: [Why can my operating system be detected with Mullvad/Tor Browser?](/t/why-can-my-operating-system-be-detected-with-mullvad-tor-browser/19537)

---

## Post 168 by @jonah — 2026-03-11T19:47:25Z

14 posts were split to a new topic: [LibreWolf: A Secure, Privacy-Focused Firefox Alternative](/t/librewolf-a-secure-privacy-focused-firefox-alternative/36219)

---

## Post 182 by @f0r_fr33d0m — 2024-10-30T07:18:54Z

Hello everyone, I’m back.

I want to say two things:

First, that after two years of disappearing from this forum, I can’t believe my pride when I see that even today this thread I created is still being discussed and commented.

And second, that after two years of using and monitoring the Librewolf project, I do not change my mind that, at least, it should be mentioned in some way in PrivacyGuides.  
What can I say: I enter PrivacyGuides, in the browsers section, and instead of finding Librewolf, a project that has demonstrated over the years not to vary in its eagerness to fight for the privacy of its users; I find Firefox, a project with many years behind it and that has demonstrated more than enough that its interest in the privacy of its users is pure propaganda. I do not deny that Firefox _can be_ private. I am simply stating a fact: _By itself, it is not_.  
Librewolf does everything Firefox should do, by default, as do Mullvad, Brave and Tor. Today Librewolf meets practically all the minimum (and many of the “Best Case”) criteria PG sets for recommending a browser.

Anyway, glad to be back on this forum and, @jonah, please reconsider even a small mention of Librewolf.

Best regards to all.

---

## Post 183 by @xe3 — 2024-10-30T16:46:53Z

> [@f0r_fr33d0m](#):
>
> has demonstrated more than enough that its interest in the privacy of its users is pure propaganda.

If this were actually true (it isn’t), then Librewolf would be a horrible choice for privacy (considering that every single Privacy feature Librewolf has comes directly from upstream Firefox).

If every Firefox Privacy feature was “pure propaganda” then Librewolf would be without privacy features.

The time money and work developing and implementing the privacy features you seem to like in Librewolf happens upstream at Firefox (and some cases Tor Project), and Librewolf gets to freely benefit as well.

---

## Post 184 by @f0r_fr33d0m — 2024-10-30T21:46:38Z

> [@xe3](#):
>
> If this were actually true (it isn’t), then Librewolf would be a horrible choice for privacy (considering that every single Privacy feature Librewolf has comes directly from upstream Firefox).

So I understand that, based on your reasoning, Brave should not be recommended because it is based on a browser that does not pretend to protect the privacy of its users, right? Let’s not commit logical fallacies, please (Fallacy of the consequent).

I repeat what I have already said: It is not a question of how private Firefox can become thanks to the features they have developed for the browser, but how much it IS by itself, by default. I am not questioning its capabilities, but its standards.

You won’t find any serious privacy enhancement scripting projects for Brave, Mullvad or Tor on the internet, because they don’t need it, because by default they have their various privacy features enabled and/or accessible. For Firefox, they had to create Arkenfox. If the privacy standards in Firefox were as great as Mozilla claims, there would be no need for non-Mozilla projects based on Firefox like Arkenfox or Librewolf to exist. That’s what I’m saying, and nothing else.

Is it so hard to recognize that the average user should be given things chewed and prepared from the beginning? That not everyone, not even the majority, are “privacy geeks” like us, please, that Privacy _Guides_ exist for a reason. I just propose to add alternative mentions for those users seriously concerned about their privacy who, in turn, have difficulties or find it too complex to thoroughly configure the programs they use.

Best regards.

---

## Post 186 by @xe3 — 2024-10-30T23:54:39Z

> [@f0r_fr33d0m](#):
>
> So I understand that, based on your reasoning, Brave should not be recommended because it is based on a browser

No. You clearly have not understood my reasoning (which has nothing to do with whether a browser is based on another or not). Let me see if I can be a bit more clear.

My reasoning is simple:

- _Every single privacy feature present in Librewolf, comes directly from upstream Firefox_. Firefox devotes considerable time, money, and resources to the privacy features we enjoy in Firefox or in Librewolf. Librewolf just flips some switches that Firefox makes available to them (and us). The same is not true of Brave which begins from a not-very-private base, and meaningfully improves upon it.

- _Brave’s privacy features are in many cases their own_, not inherited from Chromium or Chrome. Brave substantially improves upon Chrome(ium), whereas Librewolf just enables upstream things already present in Firefox.

- (put another way, Brave meaningfully improves privacy in many cases _in spite of its upstream_ whereas Librewolf’s privacy _is only possible because of it’s upstream_)

If Firefox’s commitment to privacy were “pure propaganda” Librewolf (which relies 100% on Firefox for all of it’s privacy protections, and Arkenfox (a Firefox community project for its defaults) could not be any better since they don’t introduce any features of their own.

If you prefer Librewolf’s defaults out of the box, by all means, use Librewolf. But don’t pretend it brings anything new or different to the table beyond a set of defaults, and don’t erase/devalue the hard work done upstream to allow me (via Arkenfox or Mullvad) or you (via Librewolf) to have the level of privacy we desire. There are serious, committed, passionate real people devoting a lot of time, thought, and effort to building these privacy features that you, I, and small derivatives like Librewolf rely on.

---

## Post 187 by @lurkeroy99245 — 2024-10-31T00:11:25Z

Brave browser in my opinion is mid. I don’t care for all the crypto stuff. And I haven’t used Brave in a while so maybe they aren’t doing that anymore idk. Also though, and more importantly, being built on Chrome I’m sure manifest 3 integration will become mandatory at some point, which means uBlock will no longer work. Even if you side load it.

I think Mullvad browser is hard to beat. It basically comes with the same fingerprinting resistance that Tor browser comes with, and uBlock Origin is installed by default. You can even use Mullvad’s DNS if you aren’t already encrypting it another way. It basically checks all the boxes for a privacy respecting clearnet browser. If you need anything extra you might as well use Tor. In addition to clearnet, since some anonymity networks like i2p and hyphanet don’t have dedicated browsers, I think Mullvad browser would be an excellent browser to proxy their connections through.

---

## Post 188 by @f0r_fr33d0m — 2024-10-31T07:07:13Z

> [@xe3](#):
>
> But don’t pretend it brings anything new or different to the table beyond a set of defaults, and don’t erase/devalue the hard work done upstream to allow me (via Arkenfox or Mullvad) or you (via Librewolf) to have the level of privacy we desire.

“I have created the Ferrari Enzo of privacy, and I will beat my chest for my achievements, and I will sing to the four winds my successes, but when it is time to sell it to customers, I will leave it configured to give the performance of a Fiat Punto, and if they want it to perform at the level of the Ferrari Enzo, they can reconfigure it themselves or go to a mechanic to have it configured”… That’s propaganda. It doesn’t matter that Mozilla spends time, effort, sweat, tears, BLOOD… if in practice it delivers that great work with half of it not connected. Equivalent to buying a flat screen, that when you install it, only half of the LEDs light up, that you have to go to the configuration to activate the other half, and that we have nothing to complain to the seller of the screen for selling it with half of the screen turned off. I insist, your defense of Firefox seems to me quite poor.

Yes, everything Librewolf is inherited from Firefox. Now choose: Recommend the Ferrari that works like a Ferrari, or the Ferrari that works like a Fiat. Recommend the screen that by default only has half of the LEDs lit, or the screen that by default has all the LEDs lit. Recommend a finished job, or one with what you are looking for without activation.

To each one with what he decides from there, but please, let’s not deny the reality.  
And let’s not deny what the other says either, because I remind you that what I have said from the beginning is this:

> [@f0r_fr33d0m](#):
>
> I do not deny that Firefox _can be_ private. I am simply stating a fact: _By itself, it is not_.

> [@f0r_fr33d0m](#):
>
> I repeat what I have already said: It is not a question of how private Firefox can become thanks to the features they have developed for the browser, but how much it IS by itself, by default. I am not questioning its capabilities, but its standards.

Best regards.

---

## Post 189 by @anon48875053 — 2024-10-31T09:46:36Z

Configuring Firefox is very easy if you actually want to do it. Recommending Librewolf doesn’t make sense for all the reasons discussed above.

All you have to do to have the best privacy and security for Firefox is to:

1. Go to about:profiles.
2. Make a profile called arkenfox or give it whatever name you want.
3. Close Firefox.
4. Download three files from GitHub and copy/move them to your created profile directory.
5. Open Firefox.

Making a new profile is optional, you could just reuse the same one if you want.

---

## Post 190 by @anon48875053 — 2024-10-31T10:10:02Z

> [@f0r_fr33d0m](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/f0r_fr33d0m/48/211_2.png) f0r\_fr33d0m:
> 
> > I do not deny that Firefox _can be_ private. I am simply stating a fact: _By itself, it is not_.
> 
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/f0r_fr33d0m/48/211_2.png) f0r\_fr33d0m:
> 
> > I repeat what I have already said: It is not a question of how private Firefox can become thanks to the features they have developed for the browser, but how much it IS by itself, by default. I am not questioning its capabilities, but its standards.

You do realize that Firefox is a competitor to Chrome and Chromium as a whole? If you want to become a widely used browser and not just stay a niche browser that is used by a few people, then you need to give the best experience for as many people as possible.

Imagine if someone who isn’t tech savvy at all decides to try Firefox and experiences breakage or things not working just because it’s configured to be as private and secure as you think it should be. That person would never touch Firefox again.

When you do things like setting up arkenfox or changing settings to more extreme ones, then you probably know what you’re doing, why you’re changing them, and what the possible consequences are.

For people like you who want the best privacy and security, there is Mullvad Browser, which is a million times better than Librewolf.

You want the best defaults? Mullvad Browser.  
You want a browser that can be configured and used to your liking? Firefox.  
Need or want Chromium? Brave.  
It just doesn’t make sense to recommend Librewolf.

---

## Post 191 by @Privacy_Goblin — 2024-10-31T12:13:31Z

> [@anon48875053](#):
>
> You want the best defaults? Mullvad Browser.  
> You want a browser that can be configured and used to your liking? Firefox.  
> Need or want Chromium? Brave.  
> It just doesn’t make sense to recommend Librewolf.

I am curious, what makes it not worthy of a recommendation (or a mention under Firefox) on Privacy Guides?

---

## Post 193 by @Privacy_Goblin — 2024-10-31T21:59:22Z

I know this is not how Privacy Guides operate, but I would personally like to see the recommendations be a little more… approachable?!  
Instead of the “our way or the highway” approach that I feel the recommendations currently is, I think that listing out other browser options - even inferior ones - and what you can do to make them more private, while also educating people on the actual differences between those browsers and their shortcomings, could help people start their privacy journey with what they already use. Or by choosing an easy second browser option, close to what they already use.

I have tried to get my nephews on board with some of this, but jumping through too many hoops at once just makes them feel overwhelmed. I have a feeling they are not the only ones who feel like that. Having another simple Firefox option with Librewolf does not seem like an “opinionated power user” option to me, but an easy way for someone to try something different out.

I am of course not saying to get rid of the “objectively best” recommendations that it currently provides, since that is useful, but I just wish the recommendations could be a little bit more than just a top tier list. No offense to the Privacy Guides team, of course. I would not be here otherwise. :slightly_smiling_face:

---

## Post 194 by @Astatine — 2024-10-31T23:21:09Z

> [@f0r_fr33d0m](#):
>
> Is it so hard to recognize that the average user should be given things chewed and prepared from the beginning? That not everyone, not even the majority, are “privacy geeks” like us, please, that Privacy _Guides_ exist for a reason.

Honestly, that’s why I recommend Brave to friends, family members, and other acquaintances who are not tech-savvy like myself; it’s a literal upgrade from Microsoft Edge’s bloatware and crap, which is just unparalleled.

---

## Post 195 by @Astatine — 2024-10-31T23:34:56Z

> [@Anon47486929](#):
>
> The only niche I can see Librewolf filling is:  
> A user who doesn’t want to use chromium based browsers (or they’d use Brave), and doesn’t want to use arkenfoxjs (or they’d use Firefox), but also doesn’t want settings locked out for fingerprinting protection as they still want to fiddle (or they’d use Mullvad browser).

> **Off-topic(ish)**
>
> I used to have that mentality, but forced myself to use Arkenfox. Even to this day, I have **never** looked back.

---

## Post 196 by @asanyan — 2024-11-01T00:10:08Z

> [@Anon47486929](#):
>
> A user who doesn’t want to use chromium based browsers (or they’d use Brave), and doesn’t want to use arkenfoxjs (or they’d use Firefox), but also doesn’t want settings locked out for fingerprinting protection as they still want to fiddle (or they’d use Mullvad browser).

LW competes with Firefox+Arkenfox which is meant for the user to tweak, not with MB (which you shouldn’t touch). I’d argue that it’s a bigger niche than you’d think. Many people have a problem with Mozilla and its direction with regards to user privacy and data collection. LW seems to be pretty committed at shipping good defaults that can be configured to match each users’ needs.

> [@Astatine](#):
>
> I used to have that mentality, but forced myself to use Arkenfox. Even to this day, I have **never** looked back.

I have a browser installed in which I use arkenfox too, but remembering to update AF, merging changes etc. is a PITA, so I just pretty much never update (AF not the browser). Also, if Mozilla happens to implement a bad feature, said bad feature will be shipped to me and may be enabled straight away. Not ideal.

An ideal setup for me right now is: TB, MB with the proxy feature for ephemeral searches/browsing, and multiple instances of librewolf, with extra extensions for more convenient browsing, and one extra instance with split tunnelling for services that need to know my identity. In practice however I use a different browser (floorp+arkenfox, might switch to Zen sometime) for the latter, because keeping multiple instances of the same browser is a pain and is very likely to lead to a mistake (e.g. performing a search that I didn’t intend to, in the browser not connected to the VPN).

---

## Post 197 by @Astatine — 2024-11-01T00:20:39Z

> [@asanyan](#):
>
> I have a browser installed in which I use arkenfox too, but remembering to update AF, merging changes etc. is a PITA, so I just pretty much never update (AF not the browser).

~~In your use case, I would use Brave browser.~~ With updating Arkenfox, it was initially annoying, but naturally became easier as I did it.

To add, Librewolf is neither a disaster nor a [great option](https://github.com/arkenfox/user.js/issues/1809#issuecomment-1949635343), when thinking in _long term_ mindset.

---

## Post 198 by @asanyan — 2024-11-01T00:35:10Z

> [@Astatine](#):
>
> ~~In your use case, I would use Brave browser.~~

xD I think that of people who have a problem with Mozilla, pretty much 100% also have a problem with Brave. Plus, it’s chromium.

> [@Astatine](#):
>
> naturally became easier as I did it.

do you have a RSS for releases, or do you just randomly check the github to see if there’s an update every now and then?

> [@Astatine](#):
>
> To add, Librewolf is neither a disaster nor a [great option](https://github.com/arkenfox/user.js/issues/1809#issuecomment-1949635343), when thinking in _long term_ mindset.

It’s unfortunate but when it comes to long term, other than MB/TB things aren’t exactly looking up in my opinion. As far as I’m aware LW is still the better choice, but maybe Zen Browser will turn out good? I suppose we wait and see.

---

## Post 199 by @Astatine — 2024-11-01T00:38:54Z

> [@asanyan](#):
>
> do you have a RSS for releases, or do you just randomly check the github to see if there’s an update every now and then?

I run the [updater](https://github.com/arkenfox/user.js/wiki/3.4-Apply-&-Update-&-Maintain#-update) after a new Firefox release or some of my modifications, which pulls the latest user.js from Github. Then, I get prompted to run the [prefsCleaner](https://github.com/arkenfox/user.js/wiki/3.5-prefsCleaner).

Did you read the entire wiki?

---

## Post 200 by @asanyan — 2024-11-01T01:23:43Z

Oops, somehow I missed that. Thanks, I’ll try it out!

---

## Post 201 by @xe3 — 2024-11-01T01:51:43Z

> [@asanyan](#):
>
> but remembering to update AF, merging changes etc. is a PITA

Arkenfox isn’t for everyone, and especially isn’t for people who prefer a hands-off relationship towards tech. But calling it a _“PITA”_ to update is a very big exaggeration in my opinion.

(I just timed how long it took me to update and it took _ **19 seconds** in total_. And it would be even quicker via the terminal.

Considering that on average Arkenfox has an update every 2 or 3 months, 19 seconds to update doesn’t seem especially burdensome (but if it is, checking for updates could just be automated).

---

## Post 202 by @redoomed1 — 2024-11-01T04:01:14Z

> [@Astatine](#):
>
> Librewolf is neither a disaster

About that…

a timely [update](https://github.com/arkenfox/user.js/issues/1906#issuecomment-2443323664):

> Hey all, I’m on the LibreWolf team, and it’s true that since the departure of [@fxbrit](https://github.com/fxbrit) the project has taken a total nosedive when it comes to keeping up to date with Arkenfox and settings in general. We’re still making releases, but settings did not get updated.  
> There are also a bunch of useful tickets that also take my time, I’ve not been able to take the LW settings to the last AF release.

---

## Post 204 by @asanyan — 2024-11-01T16:52:36Z

> [@Anon47486929](#):
>
> Maybe, but LW is based on arkenfox, and Thorin has repeatedly claimed arkenfox will lead to Mullvad Browser, with the user js approach being retired. So I’m not sure if they are entirely separate competitors.

But the approaches are different. If Arkenfox dies then I guess there will be no good options left if you want to customize.. LW seems to be in a worse state than I thought but maybe it will improve.

> [@Anon47486929](#):
>
> If it was a competition though, LW would lag behind Firefox and arkenfox combo, since they can’t ship update, their lead dev seems afk (as redoomed pointed out below), and tbf LW has been a bit of a messy project with some interesting choices.

That’s true. I thought that I could trust LW to check for new stuff and disable any telemetry, data collection etc. before they ship the update but if they can’t even do that then there really isn’t a point.

> [@Anon47486929](#):
>
> Then developing something non-Mozilla is the way not LW. Being very practical, LW is nowhere near offering an alternative to Mozilla Firefox at all, and at best can fiddle with the toggles Mozilla gives them. LW can’t and won’t be able to develop an alternate browser, just a fork.

Trusting Mozilla with security is one thing, and trusting them for best practices when it comes to user privacy/data collection is something else. I’d prefer to have at least a middle man that could “clean up” the browser a little before it’s shipped to me.

---

## Post 205 by @Average_Joe — 2024-11-04T11:38:07Z

> [@f0r_fr33d0m](#):
>
> Hello everyone, I’m back.

Welcome back For\_Freedom! You doing okay?

I think your thread is still active after such a long time is because web browser choice is definitely one of the most important security/privacy choices.

This topic will probably be discussed as long as this community is focused on user privacy! :innocent:

---

## Post 206 by @anon48875053 — 2024-11-04T11:45:25Z

The answer has never been simpler:

Tor browser for anonymity.  
Mullvad Browser for regular browsing.  
Brave or Firefox with arkenfox for staying logged into sites.

---

## Post 207 by @jonah — 2026-03-11T19:42:49Z

2 posts were split to a new topic: [Why use another browser for staying logged in to sites?](/t/why-use-another-browser-for-staying-logged-in-to-sites/36218)

---

## Post 208 by @Average_Joe — 2024-11-11T12:13:52Z

> [@anon48875053](#):
>
> The answer has never been simpler:
> 
> Tor browser for anonymity.  
> Mullvad Browser for regular browsing.  
> Brave or Firefox with arkenfox for staying logged into sites.

I appreciate your reply!

I wasn’t talking about the current day but in 6 months and beyond.

EDIT:  
Nevermind… Firefox is definitely struggling.

---

## Post 210 by @Anvil — 2025-03-06T16:31:13Z

Just wanted to share that I’ve been looking for a similarly easy to use alternative to Brave’s [forgetful browsing](https://brave.com/privacy-updates/25-forgetful-browsing/) feature. If you click the lock button by the search bar on LibreWolf, it gives you the option to always store cookies/site data for specific websites, while by default, website cookies will be cleared on exit. Very nice.

---

## Post 211 by @jonah — 2026-03-11T19:36:33Z

6 posts were merged into an existing topic: [Librewolf thoughts](/t/librewolf-thoughts/26104/5)

---

## Post 217 by @jonah — 2026-03-11T19:34:27Z

7 posts were split to a new topic: [How should I install LibreWolf?](/t/how-should-i-install-librewolf/36217)

---

## Post 224 by @win11.shading291 — 2025-11-03T02:33:11Z

The slow on updates thing is apparently outdated.

Librewolf update regularly within 1-3 days.

There was another concern about auto-updates which have also been resolved now. When you install it, you have the option to install a helper file that takes care of the update automatically.

There isn’t much against Librewolf left. You can always try it, and if you encounter lots of website breakage or don’t like it, then switch to another browser.

---

## Post 225 by @jonah — 2026-03-11T19:32:03Z

18 posts were split to a new topic: [Why use LibreWolf over Mullvad Browser?](/t/why-use-librewolf-over-mullvad-browser/36216)

---

## Post 242 by @Libre_Software_Enjoyer — 2025-11-12T20:46:55Z

> [@What are the concerns with Librewolf?](https://discuss.privacyguides.net/t/what-are-the-concerns-with-librewolf/30864/3):
>
> Unless you flag specific websites as exempt… but that defeats the purpose of Librewolf.

No because the strong privacy will still aplly to all other sites, especially does in different containers.

> [@What are the concerns with Librewolf?](https://discuss.privacyguides.net/t/what-are-the-concerns-with-librewolf/30864/3):
>
> I’d say it’s best suited for someone who needs extreme privacy or for niche web needs.

Librewolf is advanced privacy.  
Extreme privacy would be Tor inside Whonix who itself is inside QubesOS or Secure Blue

---

## Post 243 by @SYST3M_D3STR0YER — 2025-11-15T21:09:15Z

After reviewing the arguments against LibreWolf in the discussion and spending many hours in research, I have come to the conclusion that LibreWolf should be included in the browser recommendations. In the following, I will address the objections that have been raised against LibreWolf and explain why they don’t apply in my opinion.

This are the objections I will address:

- LibreWolf receives security fixes slower than FireFox.
- LibreWolf doesn’t offer anything that FireFox can’t do.
- LibreWolf doesn’t offer anything that MullvadBrowser can’t do / MullvadBrowser is LibreWolf, just better.
- LibreWolf doesn’t have automatic updates.
- LibreWolf has no use case, in either way you wouldn’t use LibreWolf.

#### LibreWolf receives security fixes slower than FireFox.

This is the most commonly used and according to those who don’t want LibreWolf in the PG recommendations, probably the best:

> [@jonah](#):
>
> **This is the entire reason we recommend Arkenfox+Firefox instead of Librewolf** : Arkenfox is a collection of modifications you make to your Firefox preferences, but _you’re still using Firefox_ and you’re getting updates (security patches, etc.) directly from Mozilla. With Librewolf you’re waiting for those updates from Mozilla to be merged into Librewolf’s code and released by the Librewolf devs.

So I did some research and found out that if we take the last twenty security fix delays, we get an average security fix delay of 1.7 days. Here’s the whole Comparison of Firefox and LibreWolf Release Dates:

[LibreWolf vs FireFox Release QUickness.txt](/uploads/short-url/faKM5wHqEUUkobjXKYqn7rdrIF0.txt) (2.4 KB)

And because I was really very interested, how much the security fix delay of other, on Privacy Guides recommended forks is, I did the same research with the MullvadBrowser, which is the first recommended Browser on the Privacy Guides Browser Recommendations. It had an average security fix delay of 1.3 days. Here’s the whole Comparison of Firefox and MullvadBrowser Release Dates:

[MullvadBrowser vs FireFox Release QUickness.txt](/uploads/short-url/QrHkph3w5LivTXVUW6sXRmytpi.txt) (3.2 KB)

If 1.3 days of security fix delay is not so relevant that a browser is not included in the Privacy Guides recommendations, then it would probably be ridiculous to argue that 1.7 days would be too much to be included in the Privacy Guides browser recommendations.

#### LibreWolf doesn’t offer anything that Firefox can’t do.

That’s not correct. First, the most frequently mentioned and probably also most important point: you don’t have to configure and maintain (= checking each time whether ArkenFox has been updated and maybe updating it. You have to do that, otherwise there’s a risk that protection against a possible existing new tracking techniques isn‘t activated) FireFox with ArkenFox. Second, there’s an extra category under the settings that gives GUI access to settings that are only accessible in Firefox through about:config. Third, it’s significantly easier in LibreWolf to set/remove exceptions for cookie and website data deletion on close. You simply click on the lock in the URL bar and activate/deactivate the toggle “LibreWolf: Always store cookies/data for this site”. This toggle doesn’t exist in Firefox with “Delete cookies and site data when Firefox is closed” turned on (or off). Instead, you have to:

1. Option: Lock in the URL bar ➝ “Connection secure” ➝ “More information” ➝ “Permissions” ➝ Deactivate “Set Cookies Use Default” ➝ “Allow”

2. Option: Menu ➝ “Settings” ➝ “Privacy & Security” ➝ Scroll to “Cookies and Site Data” ➝ “Manage exceptions” ➝ Enter/paste URL ➝ Click Enter ➝ “Save Changes”.

#### LibreWolf doesn’t offer anything that MullvadBrowser can’t do / MullvadBrowser is LibreWolf, just better.

That’s not true. You can use MullvadBrowser for Browsing if you don’t want to log in into sites. But if you want to log in into websites,… you can’t. There’s [an issue that’s present for two years, were disabling “Always use private browsing mode“ and adding a website to the whitelist doesn’t keep cookies and websitedata reliable](https://github.com/mullvad/mullvad-browser/issues/29). And since the 1.7 day security fix update delay doesn’t seem so relevant not to include it in the Privacy Guides Recommendations (see above), and LibreWolf is _much_ more user-friendly (because of the mentioned three reasons, see above) than FireFox and ArkenFox, LibreWolf should be included in the Privacy Guides Browser Recommendations.

Privacy Guides should recommend LibreWolf at very least until the above mentioned issue is fixed (I would argue that it should still be recommended afterwards).

#### LibreWolf doesn’t have automatic updates.

This argument is out of date, it has now automatic updates for all supported platforms.

#### LibreWolf has no use case, in either way you wouldn’t use LibreWolf.

This objection was actually refuted by the refutation of the 2nd and 3rd arguments.

---

## Post 245 by @win11.shading291 — 2025-11-15T23:59:30Z

Great analysis and research! Couldn’t agree more!

I would also add that Librewolf saves time and is much easier to recommend to non-privacy folks.

---

## Post 246 by @any1 — 2025-11-16T13:28:41Z

> [@SYST3M_D3STR0YER](#):
>
> So I did some research and found out that if we take the last twenty security fix delays, we get an average security fix delay of 1.7 days. Here’s the whole Comparison of Firefox and LibreWolf Release Dates:

Wanna know something funny?

Firefox 145 released on [November 11, 2025.](https://www.firefox.com/en-US/firefox/145.0/releasenotes/) This release has security fixes for **9 High CVEs.**

LibreWolf bumped the Firefox version to 145 on [November 12, 2025](https://codeberg.org/librewolf/source/commit/6d03858c009acfcbca7a9405f70444c2651efd29). But guess what, their build has been [failing since then](https://gitlab.com/librewolf-community/browser/source/-/pipelines/2153939167/failures) and users have been using an **outdated Firefox version for 5 days now** and there have not been any commits to the repo trying to fix it.

> [@SYST3M_D3STR0YER](#):
>
> You have to do that, otherwise there’s a risk that privacy-relevant settings won’t be activated/deactivated, which means you have different settings than everyone else who has updated ArkenFox, which enables fingerprinting

This is nonsense. There is [no crowd](https://github.com/arkenfox/user.js/wiki/3.3-Overrides-%5BTo-RFP-or-Not%5D#-summary) for arkenfox. arkenfox is a template with sensible defaults anyway, you are supposed to change things to your liking if you want. What you are talking about would only impact Tor/Mullvad browser.

> [@SYST3M_D3STR0YER](#):
>
> That’s not true. You can use MullvadBrowser for Browsing if you don’t want to log in into sites. But if you want to log in into websites,… you can’t. There’s [an issue that’s present for two years, were disabling “Always use private browsing mode“ and adding a website to the whitelist doesn’t keep cookies and websitedata reliable](https://github.com/mullvad/mullvad-browser/issues/29)

See my post from [here](https://discuss.privacyguides.net/t/mullvad-browser-is-working-on-persistent-mode/32569), this is being worked on.

---

## Post 247 by @SYST3M_D3STR0YER — 2025-11-16T14:23:24Z

> [@any1](#):
>
> Firefox 145 released on [November 11, 2025.](https://www.firefox.com/en-US/firefox/145.0/releasenotes/) This release has security fixes for **9 High CVEs.**
> 
> LibreWolf bumped the Firefox version to 145 on [November 12, 2025](https://codeberg.org/librewolf/source/commit/6d03858c009acfcbca7a9405f70444c2651efd29). But guess what, their build has been [failing since then](https://gitlab.com/librewolf-community/browser/source/-/pipelines/2153939167/failures) and users have been using an **outdated Firefox version for 5 days now** and there have not been any commits to the repo trying to fix it.

Seems to be the same with MullvadBrowser. If you look at the [official MullvadBrowser Releases Page](https://github.com/mullvad/mullvad-browser/releases), the last Release is 15.0, released on 29. Oct., so before the

> [@any1](#):
>
> security fixes for **9 High CVEs**

and Privacy Guides recommends MullvadBrowser.

> [@any1](#):
>
> This is nonsense. There is [no crowd](https://github.com/arkenfox/user.js/wiki/3.3-Overrides-%5BTo-RFP-or-Not%5D#-summary) for arkenfox. arkenfox is a template with sensible defaults anyway, you are supposed to change things to your liking if you want. What you are talking about would only impact Tor/Mullvad browser.

So you could just ignore every ArkenFox-UpDate or what do you mean by that?

> [@any1](#):
>
> See my post from [here](https://discuss.privacyguides.net/t/mullvad-browser-is-working-on-persistent-mode/32569), this is being worked on.

See my reply to that here:

> [@SYST3M_D3STR0YER](#):
>
> Privacy Guides should recommend LibreWolf at very least until the above mentioned issue is fixed (I would argue that it should still be recommended afterwards).

---

## Post 248 by @any1 — 2025-11-16T15:16:40Z

> [@SYST3M_D3STR0YER](#):
>
> Seems to be the same with MullvadBrowser. If you look at the [official MullvadBrowser Releases Page](https://github.com/mullvad/mullvad-browser/releases), the last Release is 15.0, released on 29. Oct., so before the

Good catch. No idea why the releases are not being made considering [Mullvad Browser 15.0.1](https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/issues/41611) has been finished. I opened an [issue on github](https://github.com/mullvad/mullvad-browser/issues/513). @ruihildt

Edit: It is [tagged](https://github.com/mullvad/mullvad-browser/releases/tag/15.0.1) but no proper release has been made and no downstream packagers have updated.

> [@SYST3M_D3STR0YER](#):
>
> So you could just ignore every ArkenFox-UpDate or what do you mean by that?

I didn’t say that. If you are late to update, you aren’t going to immediately stick out since you are already unique. Yes, you should update, but it isn’t going to make a huge difference since the changes arkenfox makes in each version are getting smaller over time anyway.

> [@SYST3M_D3STR0YER](#):
>
> See my reply to that here:

Until LibreWolf manages to have consistent updates, it shouldn’t be recommended; until then, Persistent mode is probably already released anyway, making the recommendation even more useless.

---

## Post 249 by @win11.shading291 — 2025-11-16T18:11:55Z

> [@any1](#):
>
> Until LibreWolf manages to have consistent updates, it shouldn’t be recommended; until then, Persistent mode is probably already released anyway, making the recommendation even more useless.

It does have consistent updates though.

---

## Post 250 by @any1 — 2025-11-16T18:14:32Z

Did you not read my other post? It still hasn’t been updated to release 145.

---

## Post 251 by @win11.shading291 — 2025-11-16T18:24:57Z

Yes, but are you suggesting Mullvad Browser shouldn’t be recommended either?

---

## Post 252 by @any1 — 2025-11-16T18:27:22Z

No? Mullvad Browser already has been updated and has a working build. For some reason there hasn’t been made a release yet.

LibreWolf has no working build for 145 and currently nothing has been done to make one.

---

## Post 253 by @SYST3M_D3STR0YER — 2025-11-16T18:30:02Z

Neither does Mullvadbrowser! And really, 5 days is worrying, but the MullvadBrowser had this issue in the past already: If you look at my [table](https://forum-uploads.privacyguidesusercontent.com/original/2X/0/05edb82bceb605e790ac86cc273ceed7e6d9b804.txt), you see that the security vulnerabities fixed in FireFox 139.0, among others one „critical“-security fix (which is even much higher than a „high“-security fix) and seven „moderate“-security fixes, were fixed in MullvadBrowser **six days** after firefox!

---

## Post 254 by @any1 — 2025-11-16T18:51:51Z

I still don’t understand why you keep trying to justify LibreWolf being five days behind on updates by pointing to Mullvad Browser’s six-day gap.

LibreWolf should be recommended as a Firefox + arkenfox replacement, not a Mullvad Browser alternative.

I’m not saying Mullvad being behind is good — I’m saying that for LibreWolf to be recommended as a Firefox + arkenfox replacement, it must add value compared to that setup, and being behind on updates does not add value, especially as it’s often recommended to less technically knowledgeable users who would rely more on faster security fixes not less.

---

## Post 255 by @SYST3M_D3STR0YER — 2025-11-16T19:22:45Z

> [@any1](#):
>
> I still don’t understand why you keep trying to justify LibreWolf being five days behind on updates by pointing to Mullvad Browser’s six-day gap.

Because of the fact that MullvadBrowser is recommended and LibreWolf isn‘t! When you say, LibreWolf shouldn‘t be added to the browser recommendations because of a five day security fix delay, you should consequently also say, that MullvadBrowser shouldn‘t be recommended because it had also such a delay! But that‘s not the case:

> [@any1](#):
>
> No

EDIT: And I am not saying this only because of the missing 15.0.1/15.1 Release, but also because of the 6day security fix delay which happened in the past I already mentioned above

---

## Post 256 by @any1 — 2025-11-16T19:34:47Z

Mullvad Browser is almost always worse in terms of security than regular Firefox because it uses the ESR version and relies on CVE backports from the normal releases, which has its own problems.

Mullvad Browser **adds immense value** compared to what you can achieve with normal Firefox; that’s why **it is recommended**. It isn’t recommended for being the most secure.

LibreWolf would have to add value compared to Firefox + arkenfox to be considered, but being behind on updates does not add value. You can have the fastest updates and privacy benefits by sticking with Firefox + arkenfox without relying on a third party for updates.

If LibreWolf had a longer track record of pushing updates quickly—which it almost had until now—then maybe it could be up for discussion, but considering its history in the past few years I doubt it.

---

## Post 257 by @anonymous477 — 2025-11-16T19:43:21Z

> [@SYST3M_D3STR0YER](#):
>
> When you say, LibreWolf shouldn‘t be added to the browser recommendations because of a five day security fix delay, you should consequently also say, that MullvadBrowser shouldn‘t be recommended because it had also such a delay!

Note: I haven’t read the whole thread for this specific argument, so excuse me if I misunderstand some things.

The symmetry is between Mullvad Browser and Librewolf’s delay is not well founded. Mullvad Browser is recommended because it serves a particular purpose very well that the other browsers do not: it provides Tor-like fingerprinting protections but without its downsides, like lack of speed and website blocks. The fact that there is a delay _is_ a concern, but it still provides the best service for that particular purpose discussed above. There are no alternatives to it.

The purpose that Librewolf serves is not the same as Mullvad Browser. It aims to serve the same purpose as that of Brave and Firefox. Therefore, we are comparing Librewolf to those two. What @any1 probably meant is that Librewolf has no additional value when compared to those two browsers. Comparing it to Mullvad Browser is ill-founded because it serves a different purpose.

---

## Post 258 by @any1 — 2025-11-16T19:52:19Z

> [@anonymous477](#):
>
> What @any1 probably meant is that Librewolf has no additional value when compared to those two browsers. Comparing it to Mullvad Browser is ill-founded because it serves a different purpose.

Not probably, I said it multiple times :grin:

---

## Post 259 by @SYST3M_D3STR0YER — 2025-11-16T19:53:45Z

I agree, and I don‘t want(ed) to compare MullvadBrowser with LibreWolf in terms of the way you mentioned. I just wanted to compare it in terms of security fix delay to see which delay isn‘t so bad that it wouldn‘t be added to the browser recommendations. (I hope this sentence is understandable :sweat_smile:)

---

## Post 260 by @anonymous477 — 2025-11-16T19:54:06Z

> [@any1](#):
>
> Not probably, I said it multiple times :grin:

Didn’t want to put words in your mouth, especially because I just skimmed through the arguments and didn’t read them in-depth.

> [@anonymous477](#):
>
> Note: I haven’t read the whole thread for this specific argument, so excuse me if I misunderstand some things.

---

## Post 261 by @any1 — 2025-11-16T19:54:45Z

> [@anonymous477](#):
>
> Didn’t want to put words in your mouth, especially because I just skimmed through the arguments and didn’t read them in-depth.

It wasn’t meant in a negative way. Thats why I put the :grin:

---

## Post 262 by @anonymous477 — 2025-11-16T19:59:14Z

Oh I see. I did not interpret it in a negative way, I just wanted to clarify. I also cannot react with emojis since I am an anonymous account, so I felt the need to reply.

---

## Post 263 by @jonah — 2026-03-11T19:24:04Z

2 posts were split to a new topic: [Why do things like canvas-randomization need to exist if your fingerprint is already unique?](/t/why-do-things-like-canvas-randomization-need-to-exist-if-your-fingerprint-is-already-unique/36215)

---

## Post 265 by @SYST3M_D3STR0YER — 2025-11-16T20:35:27Z

> [@any1](#):
>
> LibreWolf would have to add value compared to Firefox + arkenfox to be considered

I think it does. I‘ve revised my reply to this objection. I’ve generalized the crucial part:

> [@SYST3M_D3STR0YER](#):
>
> #### LibreWolf doesn’t offer anything that Firefox can’t do.
> 
> That’s not correct. First, the most frequently mentioned and probably also most important point: you don’t have to configure and maintain (= checking each time whether ArkenFox has been updated and maybe updating it. You have to do that, otherwise there’s a risk that protection against a possible existing new tracking techniques isn‘t activated) FireFox with ArkenFox. Second, there’s an extra category under the settings that gives GUI access to settings that are only accessible in Firefox through about:config. Third, it’s significantly easier in LibreWolf to set/remove exceptions for cookie and website data deletion on close. You simply click on the lock in the URL bar and activate/deactivate the toggle “LibreWolf: Always store cookies/data for this site”. This toggle doesn’t exist in Firefox with “Delete cookies and site data when Firefox is closed” turned on (or off). Instead, you have to:
> 
> 1. Option: Lock in the URL bar ➝ “Connection secure” ➝ “More information” ➝ “Permissions” ➝ Deactivate “Set Cookies Use Default” ➝ “Allow”
> 2. Option: Menu ➝ “Settings” ➝ “Privacy & Security” ➝ Scroll to “Cookies and Site Data” ➝ “Manage exceptions” ➝ Enter/paste URL ➝ Click Enter ➝ “Save Changes”.

---

## Post 266 by @win11.shading291 — 2025-11-16T20:41:54Z

I’m glad there seem to be a consensus where delay in updates should not alone be a disqualifying factor, as it was clearly indicated earlier in this thread.

And as @SYST3M_D3STR0YER said, there is clearly huge benefits to Librewolf as compared to Firefox + Arkenfox.

I would also add that is saves a lot of time, which essential to have non tech people switch to privacy focused alternatives to the big giants.

---

## Post 267 by @eylin — 2025-11-16T21:34:56Z

When evaluating LibreWolf, it’s important to consider the perspective of someone who is new to privacy-related configurations.

For instance, after installing Firefox, simply instructing a user to install Arkenfox may not be straightforward for them. To us, it might seem as simple as downloading a file and placing it in the right directory, but to others, that process can feel overly complex or even burdensome. Additionally, Firefox doesn’t include an ad blocker by default, which means users must install one separately. While these steps may be second nature to many of us, there are plenty of people who prefer not to deal with such tasks. Another consideration is the need to regularly check the Arkenfox updates page to ensure the configuration remains current. LibreWolf handles these updates automatically.

LibreWolf also offers a more intuitive interface for enabling or disabling key privacy settings, making it easier for users to customize their experience without diving into complex configurations. For example, enabling and disabling resist fingerprinting, letterboxing, WebGL, etc. is very simple to do in case you run into issues. Going through about:config for Arkenfox is not as friendly (but yes, significantly more powerful).

As far as I know, the Mullvad Browser still clears all browsing history once a session ends. This is ideal for users accustomed to a Tor-like level of privacy, but it can be frustrating for those who want to retain access to their browsing history. While you could advise such users to adjust this setting manually, the reality is that many people aren’t willing to make these kinds of adjustments themselves.

@any1 I fully agree with your assessment that both the Mullvad Browser and Arkenfox offer superior privacy solutions; however, this is only true provided the user is willing and able to continually configure and maintain them.

From the standpoint of someone who doesn’t want to tinker with settings but still desires a reasonably secure, ready-to-use browser for everyday tasks, LibreWolf makes the most sense. The Mullvad Browser isn’t initially configured for daily driving, and combining Firefox with Arkenfox involves too much effort for many users. To offer an anecdote, if a relative who is not tech-savvy asked me which browser to choose if he were to switch away from Chrome, I know it would be much easier to install LibreWolf versus applying an Arkenfox configuration. He’d likely have no trouble installing LibreWolf on his own, but might struggle significantly with the latter option and give up and go back to something they are more comfortable with.

---

## Post 268 by @ImTooPhaT — 2025-11-17T10:13:48Z

If the end user requires minimal configuration, we also recommend Brave. It has better ootb settings than Firefox, better website compatibility, built-in ad blocker and fingerprint randomization, can daily drive and probably easier for most people to switch since most people are using Chrome. For privacy, ephemeral browsers like Mullvad and Tor is better than Librewolf.

---

## Post 269 by @any1 — 2025-11-17T11:33:23Z

> [@eylin](#):
>
> From the standpoint of someone who doesn’t want to tinker with settings but still desires a reasonably secure, ready-to-use browser for everyday tasks, LibreWolf makes the most sense.

I still don’t understand the use case people are presenting for when LibreWolf should be recommended.

On one hand, it’s supposed to be the “easier” alternative for less technical users who want privacy comparable to arkenfox without having to install or update it themselves. But looking at what LibreWolf actually provides, that suggestion becomes less convincing.

LibreWolf enables RFP by default (which breaks sites), disables WebGL (also breaks functionality for some sites), disables Safe Browsing (combined with the slower updates, terrible for less techncal users) and deletes cookies and site data on close, meaning no persistent logins.

It feels like LibreWolf has an identity crisis: it’s caught between being too disruptive for less-technical users who want privacy without constant breakage, and unnecessary for users experienced enough to run arkenfox themselves.

For less-technical users I recommend Brave: it “just works,” offers privacy benefits, fast updates, and being Chromium-based better web compatibility and security (Similar to what @ImTooPhaT says). At this point, the default arkenfox user.js (which uses FPP instead of RFP) is more user-friendly than LibreWolf because it causes less breakage.

If LibreWolf were simply arkenfox plus uBlock Origin on top of Firefox with custom branding and fast updates, it would be worth recommending, but it isn’t. In its current “Schrödinger’s Firefox” state I don’t feel comfortable recommending it, because for the use cases people describe there are better alternatives.

Edit: For anyone following this thread, Mullvad Browser 15.0.1 has been [released now](https://github.com/mullvad/mullvad-browser/issues/513#issuecomment-3541117985)

---

## Post 270 by @SYST3M_D3STR0YER — 2025-11-17T14:42:18Z

I agree with the basis of your argument (identitfy crisis etc.), and I want to add two things:  
First, I also wouldn’t recommend LibreWolf to people who are bad at tech. I would recommend it to people who are intermediate or anything above technical, because those people can deal with broken websites. I don’t think, LibreWolf is for less technical users, I think much more that it is for convenient intermediate and anything above technical users.

Second, your argument is the reason why I don’t had any kind of argument in my arguments for adding LibreWolf to the Privacy Guides Browser Recommendations that says “LibreWolf should be recommended because it’s easy to use for less technical users“. I don’t think, LibreWolf is easy to use for less technical users and should be recommend for less technical users, but LibreWolf is definetely more convenient than FireFox and ArkenFox, and since the security fix delay seems not to be relevant (that’s the decision of the Privacy Guides-Team, and not mine) - and please note, it’s about the average time of security fix delay, not about that one example that @any1 mentioned several times - it should be recommended.

---

## Post 271 by @any1 — 2025-11-17T15:07:40Z

> [@SYST3M_D3STR0YER](#):
>
> First, I also wouldn’t recommend LibreWolf to people who are bad at tech. I would recommend it to people who are intermediate or anything above technical, because those people deal with broken websites. I don’t think, LibreWolf is for less technical users, I think much more that it is for convenient intermediate and anything above technical users.

Does this target audience even exist, people who can diagnose website breakage caused by LibreWolf and end up reading the LibreWolf wiki to work around it but cannot read the arkenfox wiki to install arkenfox themselves?

---

## Post 272 by @SYST3M_D3STR0YER — 2025-11-17T15:40:14Z

It’s not that they _can’t_ install ArkenFox, it’s that

> [@SYST3M_D3STR0YER](#):
>
> LibreWolf is definetely more convenient than FireFox and ArkenFox, and since the security fix delay seems not to be relevant (that’s the decision of the Privacy Guides-Team, and not mine) - and please note, it’s about the average time of security fix delay, not about that one example that @any1 mentioned several times - it should be recommended.

---

## Post 273 by @any1 — 2025-11-17T15:54:37Z

arkenfox has a handful of releases a year, and if including a third‑party is worth it, if you can’t be bothered to update, then be my guest.

---

## Post 274 by @anonymous477 — 2025-11-17T18:19:04Z

Why don’t we all touch base to see where exactly we are now at, taking into account the past few discussions. It’s been a very messy thread. (I wish I could make this a wiki reply so that others can edit it accordingly. I may unfortunately get some things wrong.) I will use [this reply](https://discuss.privacyguides.net/t/librewolf-firefox-based-browser/148/243) from @SYST3M_D3STR0YER as a starting point. Here are the original objections they highlighted in that reply, which I will now characterize as discussion points taking into account what was previously discussed as best I can:

1. “LibreWolf receives security fixes slower than FireFox”
  - Discussion:
    - We’ve established earlier that comparing the rate of security fixes to that of Mullvad Browser’s was not well founded: Mullvad Browser being late on security fixes _is_ an issue, but it serves a wholly different purpose from Librewolf and the value it brings to browsing (namely Tor-like fingerprinting protections but with better website compatibility) outweighs it
    - Librewolf, on the other hand, must be compared to Firefox and/or Brave, if anything; comparisons to Mullvad Browser are therefore off the agenda
    - The slow rate of security fixes that Librewolf has must be weighed with the value it brings compared to Firefox/Brave
    - **If you want to discuss this point** , you must explain why the late security patches are not an issue _without_ appealing to that of Mullvad Browser’s
      - (Side note: @SYST3M_D3STR0YER said, “[[T]he security fix delay seems not to be relevant (that’s the decision of the Privacy Guides-Team, and not mine](https://discuss.privacyguides.net/t/librewolf-firefox-based-browser/148/270)”)
        - Can we link the reply/source to where the team says? I haven’t seen it.

2. “LibreWolf doesn’t offer anything that FireFox can’t do”
  - Discussion:
    - This is directly related to the discussion above: the value that Librewolf brings compared to Firefox/Brave is relevant _precisely because_ it is necessary to outweigh the slow rate of security fixes Librewolf has
    - **If you want to discuss this point** , you therefore need to explain _not just_ what Librewolf offers that Firefox/Brave does not, _but also_ how their offerings _directly outweigh_ their slow security updates

3. ~~“LibreWolf doesn’t offer anything that MullvadBrowser can’t do / MullvadBrowser is LibreWolf, just better”~~
  - No longer on the discussion agenda:
    - Librewolf must be compared to Firefox and/or Brave, not Mullvad Browser

4. ~~“LibreWolf doesn’t have automatic updates”~~
  - No longer on the discussion agenda:
    - There are now automatic updates

5. “LibreWolf has no use case, in either way you wouldn’t use LibreWolf”
  - Discussion:
    - This discussion point will be written differently from the 1 and 2, since it is still being discussed currently; I will therefore highlight the relevant points of that current discussion below:
      - **Claim** : @eylin says that Librewolf is more user-friendly and requires less technical know-how than Arkenfox. The intended audience for Librewolf is “less-technical” people.
        - **Response** : @ImTooPhaT and @any1 says that if being user-friendly is a factor, then Brave is the solution. It serves the same intended audience. Additionally, it is more user-friendly than Librewolf.

      - **Claim** : @SYST3M_D3STR0YER says that the intended audience is actually “technical” people who want convenience instead of maintaining Arkenfox.
        - **Response** : @any1 says that if the audience is for “technical” people, then that audience _can and should_ go to Arkenfox. Convenience should not be a factor.

---

## Post 275 by @any1 — 2025-11-17T19:02:01Z

> [@anonymous477](#):
>
> Can we link the reply/source to where the team says? I haven’t seen it.

This was never said. This is just what @SYST3M_D3STR0YER went with because of Mullvad Browser being recommended.

Very good summary!:+1:

---

## Post 276 by @SYST3M_D3STR0YER — 2025-11-17T19:10:47Z

I’ve concluded that because there isn’t even a tiny note at [Privacy Respecting Web Browsers for PC and Mac - Privacy Guides](https://www.privacyguides.org/en/desktop-browsers/#mullvad-browser) that says MullvadBrowser has a security fix delay of ca. 1,5 days.

---

## Post 277 by @xe3 — 2025-11-17T19:13:40Z

> [@anonymous477](#):
>
> **Claim** : @SYST3M_D3STR0YER says that the intended audience is actually “technical” people who want convenience instead of maintaining Arkenfox.
> 
> - **Response** : @any1 says that if the audience is for “technical” people, then that audience _can and should_ go to Arkenfox. Convenience should not be a factor.

I’d strongly agree with @any1 and others on this point. There just isn’t much space left between _just moderately_ technical users (who are more than capable of using any of PG’s current recommendations) and less technical users (who would be better served by Firefox or Brave, or if their threat model calls for it Mullvad Browser or Tor Browser). The defaults aren’t ideal for casual users, but the (perceived) convenience benefit is pretty much only relevant to casual users (for advanced users, the user.js approach can be a very convenient way to manage settins)

Admitteld this is probably be a bit reductive, but every time the case is made for the Librewolf, it always comes back to essentially “but I like the mild convenience of not configuring anything” (which can be a valid _personal priority_ but isn’t a valid basis for a PG recommendation)

I get people having a personal preference for Librewolf, but it just doesn’t really have any compelling comparative advantages relative to the _full set_ of current recommendations.

Particularly when Librewolf’s _own_ remaining volunteer maintainers have described the state of the project as being _‘basically in maintenance mode’_ and lacking the time and manpower to keep up with upstream changes (upstream being both Firefox and indirectly Arkenfox) as well as a lack of expertise in browser security and anti-fingerprinting.

As an aside, there are 526,000 minutes in year, I’d estimate I devote maybe 5 to 10 of those minutes to Arkenfox, it’s not nearly as burdensome as some imagine it to be (excluding an intial learning curve)

---

## Post 278 by @fria — 2025-11-17T19:16:59Z

I think we’re losing the plot here a bit. The pitch for Mullvad Browser is its Tor browser without Tor. You can use a VPN, preferably Mullvad, and blend in with a crowd and get all the nice anti fingerprinting of Tor browser without dealing with the slow and unreliable Tor network. The pitch for Librewolf is Firefox without some tweaks OOTB. It’s not just Firefox with Arkenfox by the way, they have their own separate stuff. It’s my opinion that’s not enough of a benefit to list it. Essentially if Arkenfox is too hard then you can just stick to tweaking the user-facing settings of Firefox, so imo Firefox itself already fulfills that niche while not having to trust an extra party and getting an update delay however slight.

---

## Post 279 by @SYST3M_D3STR0YER — 2025-11-17T19:17:02Z

> [@xe3](#):
>
> Particularly when Librewolf’s _own_ remaining volunteer maintainers have described the state of the project as being _‘basically in maintenance mode’_

Could you please give a source to that?

---

## Post 280 by @any1 — 2025-11-17T19:19:27Z

> Hey all, I’m on the LibreWolf team, and it’s true that since the departure of **[@fxbrit](https://github.com/fxbrit)** the project has taken a total nosedive when it comes to keeping up to date with Arkenfox and settings in general. We’re still making releases, but settings did not get updated.  
> There are also a bunch of useful tickets that also take my time, I’ve not been able to take the LW settings to the last AF release.
> 
> I’m mostly a c/rust/vulkan hobby person, not at all good with Browser Security. My first impression is that it’s a total mine field :slight_smile:

> <https://github.com/arkenfox/user.js/issues/1906#issuecomment-2443323664>
>
> normies don't use arkenfox. they don't even use firefox. and they certainly do n…ot read wiki. there is zero reason firefox sync, firefox pocket, firefox labs, firefox lockwise (or built-in password manager), more from mozilla, ~~google~~ e-corp safe browsing needs to be enabled by default. at least provide a separate user.js for users with hardened privacy demands who are now having to monitor and flip arkenfox settings every release or migrate to forks like librewolf to preserve the privacy they signed up for when downloading arkenfox.

---

## Post 281 by @xe3 — 2025-11-17T20:01:23Z

> [@SYST3M_D3STR0YER](#):
>
> Could you please give a source to that?

Sure, I would’ve cited a [source](https://github.com/arkenfox/user.js/issues/1906#issuecomment-2453043327), but I thought I’d already shared those quotes earlier in this (very long) thread. Here are a couple of the statements I was referring to:

> [Threadpanic] Hey all, I’m on the LibreWolf team, and it’s true that since the departure of _fxbrit_ the project has taken a total nosedive when it comes to keeping up to date with Arkenfox and settings in general.

> [Threadpanic] I’m mostly a c/rust/vulkan hobby person, not at all good with Browser Security. My first impression is that it’s a total mine field

> [Malte] As [threadpanic](https://github.com/threadpanic) said, since fxbrit left we have been in a kind of “maintenance” mode in terms of settings. Mainly because we are really only three people left, who all only have varying time to put into the project

* * *

One thing I want to make clear is I’m not bringing up these quotes here as a criticism of the LW volunteer maintainers. They are volunteers who are very admirably devoting their free time to a privacy project people find value in. That deserves respect. They are simply stretched thin, and overworked (and possibly lacking in expertise, but that’s not for me to judge).

I respect these people and their contributions to the privacy space and I appreciate their transparency and openness, it shows maturity. _But_ these quotes do highlight a comparative advantage in the simple design model of Arkenfox and disadvantage of small community browser forks like Librewolf. Because Arkenfox is essentially just a ‘list of settings’ that you apply to Firefox using a built in feature of Firefox, the maintenance burden for the maintainer is much lower and simpler.

On a more positive note, Malte also said this in that same discussion:

> [Malte] But we have had some discussion in our build chat the last days, and decided on new and more clear responsibilities. I will now take care of maintaining the settings, and will generally put in a bit more time, hopefully doing a similarly good job at some point as fxbrit once did

I personally have no knowledge as to whether Librewolf continued to backslide, stabilized, or has begun to improve in the ~year that has passed since this discussion happened.

---

## Post 282 by @SYST3M_D3STR0YER — 2025-11-17T21:09:24Z

I want to sincerely thank you all for taking the time to explain me why my arguments for including LibreWolf in the browser recommendations was mistaken. After reading your points carefully, I realized that I was wrong and that my reasoning was too simplistic.

I truly appreciate the effort you put into this discussion—it helped me understand the deeper considerations I had overlooked. I’ve learned a lot from this thread and I want to correct my position. I was wrong.

Best regards, SYST3M\_D3STR0YER

---

## Post 283 by @eylin — 2025-11-17T22:58:53Z

I’d like to offer one more viewpoint as a last pitch

I agree that Brave would be the ideal choice for someone who wants a “just works” setup. However, I have also talked with and heard perspectives from others about why they want to avoid Brave.

To preface, I personally use Brave, but I can see several reasons why someone would avoid wanting to support them. Many people refuse to support Google and the Chromium monopoly. Firefox as an alternative may not be the greatest choice, but choosing to use FF for this reason comes from a place of wanting to enable the lesser evil. Brave works well on Chromium, but several people simply cannot see themselves using it due to being against Google as a whole.

There is also the conversation about Eich’s comments and donations against a group of people. To play devil’s advocate—one could argue that these comments and donations were made a long time ago and no longer affect the day-to-day operations of the browser today. But hearing the voices of the LGBT community makes me think about it more. It makes it extremely hard for anyone or others close to them to want to support someone who could do something as awful as Eich has done. Eich has also never publicly apologized for the comments or donations he made. From their perspective alone, why should they support and use a browser of a man who doesn’t want them to exist and has failed to even give them the courtesy of an apology? I do not want to dive too much into this or condemn people who use the browser every day, but it is something to think about.

I also see that there are several people who want a “just works setup”, but without the bloatware included in Brave. Out of the box, Brave comes with Brave Rewards, Brave Talk, Brave Sync, Brave News, Brave Leo (AI), ads on their initial homepage, and it by default allows web3 connections to be made. I have installed Brave multiple times and it’s about a 5-minute process to turn all of this off. I have even told them that it is easy to turn off, but from the perspective of an individual who literally could care less about any of this, it can be extremely annoying.

If we take a look at LibreWolf, it is very bare-bones when you start. You have a clean homepage and essentially just a search bar. No advertising or anything. It performs the design philosophy of KISS very well. One of the more recent LibreWolf changes automatically disabled Firefox’s AI too (something that you would need to manually update had one used Arkenfox). It is incredibly nice to have sensible defaults without needing to tinker with it out of the box. Brave has some nice additions that I use, but it is much more anxiety-inducing out of the box compared to the very fresh and simple presentation of LW.

I’d also like to add that even as an experienced user who can install Arkenfox with ease or configure Brave in the shortest amount of time—if I open a VM, LibreWolf is the first browser I will install. It is one of the browsers I need to worry about configuring the least. I do not need to worry about disabling unnecessary features, or take time to install the Arkenfox config.

> LibreWolf enables RFP by default (which breaks sites), disables WebGL (also breaks functionality for some sites), disables Safe Browsing (combined with the slower updates, terrible for less technical users) and deletes cookies and site data on close, meaning no persistent logins.

Yes, but the difference between this and Arkenfox is that it is much more intuitive to enable and disable in settings. You will also have many who blindly install Arkenfox without reading the docs, and get stuck when a site breaks. Here the settings that may cause breakages in LW are readily available and easy to access.

Resist fingerprinting does indeed lead to breakages, but if we attempt to compare the defaults on LibreWolf versus that of Mullvad Browser, a user would face far more breakages since it’s essentially using Tor’s extremely strong defaults. Even if users enable history, cookies, etc., it will not be as pleasant of an experience to use in contrast to LibreWolf (I personally think letterboxing degrades my browsing experience). On that note about cookies, I believe Brave clears cookies on exit (or they call it forgetful browsing mode—not sure if it works differently) by default too, although I’d agree it is more intuitive to turn on and off.

In conclusion, the way I look at LibreWolf is that it is trying to cater to a variety of people. Those who are fed up with Mozilla, but cannot bring themselves to use a Chromium alternative, and those who still like the idea of Firefox but do not want to waste loads of time on tinkering it to be better. There are many who are also fed up with the amount of bloatware and unneeded things in their browser (even Mullvad has their VPN extension there even if you don’t need it, ~~and it is advised not to remove it because of the potential for increased fingerprinting~~ which feels odd for those who do not care about their vpn). There are also several people who do not like Brave’s reputation/integration with crypto or ever want to use a product of Eich.

I think these are compelling enough reasons that justify recommending LibreWolf for many people who fit into this criteria.

---

## Post 284 by @moonwriting — 2025-11-17T23:28:04Z

> [@eylin](#):
>
> Mullvad has their VPN extension there even if you don’t need it, and it is advised not to remove it because of the potential for increased fingerprinting

Small correction, but you can actually remove it if you want since the extension [doesn’t affect fingerprinting](https://www.privacyguides.org/en/desktop-browsers/#anti-fingerprinting).

---

## Post 285 by @eylin — 2025-11-18T05:27:10Z

Thank you for the correction :slightly_smiling_face:

---

## Post 286 by @jonah — 2026-03-11T19:20:16Z

16 posts were split to a new topic: [What is the difference between Mullvad Browser and LibreWolf?](/t/what-is-the-difference-between-mullvad-browser-and-librewolf/36214)

---

## Post 291 by @win11.shading291 — 2025-11-19T04:07:57Z

> [@anonymous477](#):
>
> Librewolf, on the other hand, must be compared to Firefox and/or Brave, if anything; comparisons to Mullvad Browser are therefore off the agenda

Why? Mullvad Browser does serve an entirely different purpose being fingerprinting protection. But Librewolf also serve an entire different purpose being a turnkey product. They don’t share the same purpose at all.

At one point in this thread, the **main reason** for disqualifying Librewolf was untimely update.

It ultimately boils down to:

**Pro to Arkenfox (con Librewolf):** live Firefox updates.

**Cons to Arkenfox (pro Librewolf):** You have to read through a wiki that is IMO not ELI5 at all. Going through [this](https://arkenfox.github.io/gui), is as painful as going through the Windows 11 Group Policies and takes a lot of time.

> [@xe3](#):
>
> Admitteld this is probably be a bit reductive, but every time the case is made for the Librewolf, it always comes back to essentially “but I like the mild convenience of not configuring anything” (which can be a valid _personal priority_ but isn’t a valid basis for a PG recommendation)

This is not a mild convenience though. Especially when you think about most people having trouble switching app that takes literally 30 seconds (say, signal for instance), I feel like this is a big miss in this community where the time component seem to be absent in all the recommendations. To me and to many, this is critical. Convenience should absolutely be a factor when the choice is there.

There are also many other Librewolf pros as described by @eylin.

> [@xe3](#):
>
> As an aside, there are 526,000 minutes in year, I’d estimate I devote maybe 5 to 10 of those minutes to Arkenfox, it’s not nearly as burdensome as some imagine it to be (excluding an intial learning curve)

With that logic, PG should only recommend products that are self-hostable. Maintenance of a NAS is really nothing much after the initial learning curve.

> [@eylin](#):
>
> LibreWolf enables RFP by default (which breaks sites), disables WebGL (also breaks functionality for some sites), disables Safe Browsing (combined with the slower updates, terrible for less technical users) and deletes cookies and site data on close, meaning no persistent logins.

I’ve also been daily driving Librewolf for more then a month and have yet to encounter any sort of site breakages.

And as again eylin said:

> [@eylin](#):
>
> You will also have many who blindly install Arkenfox without reading the docs, and get stuck when a site breaks. Here the settings that may cause breakages in LW are readily available and easy to access.

So I would 100% recommend Librewolf to anyone looking to switch from Chrome.

And I’m not even fedup with Mozilla as some are. Librewolf just is more private and maybe even more secure ,albeit the 1-3 days update delay, then plain Mozilla without Arkenfox.

---

## Post 293 by @No_Name — 2025-11-19T09:48:15Z

> [@any1](#):
>
> Does this target audience even exist, people who can diagnose website breakage caused by LibreWolf and end up reading the LibreWolf wiki to work around it but cannot read the arkenfox wiki to install arkenfox themselves?

Yes, actually it does exist, as I myself fit into that category. I’ve tried to install ArkenFox and do not understand it. I eventually gave up and went back to Librewolf. Luckily, I’ve known about Librewolf for a long time and find it easy to use. If I hadn’t known about it already and were looking on Privacy Guides for the first time trying to make a good privacy decision for myself, I would

1. Just give up on Firefox since I couldn’t figure out how to use arkenfox
2. Might use Mullvad for a particular use case, but can’t use it as an everyday browser because it breaks things more than Librewolf
3. Maybe use Brave, but I wanted to get away from Chromium browsers because of all the stuff I’ve read elsewhere on the internet and don’t like all of the crypto stuff attached with the browser.
4. In the end, just deciding to go back with good ole Chrome because it seems being private is just too complicated.

---

## Post 294 by @ImTooPhaT — 2025-11-19T10:36:35Z

Reading the Librewolf wiki negates the argument that Librewolf is more convenient. I don’t understand why you would read the Librewolf wiki, but not Arkenfox wiki when most people won’t read either wiki.

---

## Post 295 by @ImTooPhaT — 2025-11-19T10:41:34Z

> [@win11.shading291](#):
>
> With that logic, PG should only recommend products that are self-hostable. Maintenance of a NAS is really nothing much after the initial learning curve.

I have a Synology NAS that I use for self-hosting. Troubleshooting is the biggest headache.

Also, PG recommends using a service provider if you can’t self-host \*CORRECTLY

---

## Post 297 by @No_Name — 2025-11-19T11:46:50Z

I never needed the Librewolf wiki because I’ve never had trouble using the browser. I’ve read the Arkekfox wiki, but still wasn’t able to install and use Arkenfox. To be fair, I haven’t read it in a while, so maybe they’ve updated it by now with easier to understand instructions (I don’t know). I may give it another shot and see how it goes. Librewolf has everything needed available in the settings so I just haven’t had the need to read their wiki.

---

## Post 304 by @any1 — 2025-11-19T17:35:20Z

Since nobody seemed to be working on porting the failing patches to release 145, I went ahead and [did it](https://codeberg.org/librewolf/source/pulls/104).

I have no idea if it’s working correctly since I don’t use LibreWolf, but they should just ship it and not wait even longer.

---

## Post 305 by @Anvil — 2025-11-19T20:22:12Z

> [@any1](#):
>
> Since nobody seemed to be working on porting the failing patches to release 145, I went ahead and [did it](https://codeberg.org/librewolf/source/pulls/104).

Thank you for putting the work in. That’s really too bad, I was under the impression that they’ve been pretty good about putting in timely updates. Maybe it’s time to give Trivalent another spin…

---

## Post 308 by @any1 — 2025-11-20T09:43:27Z

Update: My pull request has been merged and is building now [without failing](https://gitlab.com/librewolf-community/browser/source/-/jobs/12149151228). Once it has been tested there should be a new release soon.

---

## Post 310 by @jonah — 2026-03-11T19:14:15Z

10 posts were split to a new topic: [What sites are broken by RFP/LibreWolf?](/t/what-sites-are-broken-by-rfp-librewolf/36213)

---

## Post 312 by @win11.shading291 — 2025-11-20T15:52:47Z

Yes, before going back to uBO hard mode, I wanted to test if Librewolf would actually break sites on its own.

---

## Post 321 by @Bumbashirovich — 2025-11-21T02:11:23Z

I don’t want LibreWolf to be added to the recommendations because it will attract the attention of the NSA and talking heads in the EU who (to protect children) will want to insert a backdoor. Let LibreWolf remain in the shadows.

---

## Post 322 by @SYST3M_D3STR0YER — 2025-12-01T21:11:27Z

anonymous477:

> We’ve established earlier that comparing the rate of security fixes to that of Mullvad Browser’s was not well founded: Mullvad Browser being late on security fixes is an issue, but it serves a wholly different purpose from Librewolf and the value it brings to browsing (namely Tor-like fingerprinting protections but with better website compatibility) outweighs itLibrewolf, on the other hand, must be compared to Firefox and/or Brave, if anything; comparisons to Mullvad Browser are therefore off the agendaThe slow rate of security fixes that Librewolf has must be weighed with the value it brings compared to Firefox/BraveIf you want to discuss this point, you must explain why the late security patches are not an issue without appealing to that of Mullvad Browser’s

Well, I disagree. You could just use the lastest version of FireFox (so no security fix delay ➞ in that terms better than MullvadBrowser), configure it with [MullvadBrowser’s configs](https://github.com/mullvad/mullvad-browser/blob/fd37a7308534573827b027101c0e6ce03052cd53/browser/app/profile/001-base-profile.js) before the first startup of FireFox, install uBlock Origin and configure it the exact same way MullvadBrowser does, don’t log in anywhere, don’t change any setting, use it with MullvadVPN and don’t install any extension more than uBlock Origin and you would look in the web exactly like any other MullvadBrowser user, wouldn’t you?

So where’s the difference? Why can’t you compare LibreWolf and MullvadBrowser? You can make FireFox nearly the same as MullvadBrowser and you can make FireFox nearly the same as LibreWolf.

anonymous477:

> @any1 says that if the audience is for “technical” people, then that audience can and should go to Arkenfox. Convenience should not be a factor.

This argument looks kinda silly to me (now).

Why don’t use QubesOS with Whonix every single day? “But then surfing is slow and I can’t visit several websites and“ - “Convenience shouldn’t be a factor.”

I know you meant it only for the narrow limits of configuring, maintaining and learning ArkenFox instead of using LibreWolf. I just want to point out that **in every way, you are making Privacy/Security/Convenience trade-offs** , so the _only question should be:_

Outweighs the convenience and additional privacy features (yes, there are some, I will get into that later) of LibreWolf compared to FireFox & ArkenFox the security fix delay of LibreWolf?

So, here‘s what I think:

**You just can‘t say objectively if some convenience features outweighs security disadvantages, _so the User should choose._** That’s why I think we should mention LibreWolf.

Also, I found a few more things in LibreWolf that can‘t be achieved in FireFox except the three things already named. Here‘s the List:

1. FireFox is hosting its source code on GitHub, which itself is closed-source and owned by MicroSoft. I and many other people don‘t want to support closed-source projects and we certainly don‘t want to support MicroSoft. But LibreWolf uses Codeberg, which is a 100% Open-Source Non-Profit-Organisation.

2. ArkenFox is hosting its source code on GitHub, which itself is closed-source and owned by MicroSoft. I and many other people don‘t want to support closed-source projects and we certainly don‘t want to support MicroSoft. But LibreWolf uses Codeberg, which is a 100% Open-Source Non-Profit-Organisation.

3. Even if you disable any telemetry before the first startup, FireFox will send a one-time ping to Mozilla which says that telemetry was disabled.

4. With new UpDates, there‘s more and more Crap in FireFox. Very disturbing Sync, Adverts for Mozilla‘s VPN, a „More from Mozilla“-Category in the Settings, [AI-Features which partially activates themselves after disabling](https://support.mozilla.org/bm/questions/1497223) and much more.

5. And since ArkenFox don‘t disables this Crap, you have to disable all these things again and again after every single ArkenFox-UpDate.

6. Some things like “Set FireFox as the default browser” or the whole telemetry part are firmly anchored in the settings and cannot be removed. If you want to change something, you also have to scroll through these departments, which costs unnecessary time. Of course, this is only relevant - if at all - for perfectionists, but it should be mentioned here for the sake of attempted completeness.

7. It is not possible to set a really clean HomePage. There are only three options: 1., Set it to “FireFox-HomePage (Default)”, where you then have to deactivate the sponsored links and all the news. Then it looks like there is only the search bar on the settings page for the HomePage; however, when you open a new tab, the FireFox LoGo is emblazoned above the search bar and “Firefox” next to it in bold letters. You can’t remove that, and I and many others hate this kind of advertising, “self-advertising”. 2., You set it to “Blank” (which is ArkenFox’s default), but then the HomePage really looks too naked. And 3rd, the last option, “Custom WebPage”, is of course not practical either, because you really don’t want to wait for every new tab until a website has finished loading. LibreWolf goes a perfect way in my opinion: The HomePage is just a very light grey background which isn‘t too intense but also not to nacked with a SearchBar in the upper center.

8. There is the potential for mistakes (placing ArkenFox in the wrong directory, downloading an old ArkenFox, forgetting to unpack ArkenFox), as you have to reconfigure ArkenFox every time there is an ArkenFox update.

9. FireFox is licensed under the MPL, which allows it to be incorporated into a proprietary product (weak copyleft). I and many other people don’t want to support something like that.

10. ArkenFox is licensed under the MIT license, which allows it to be incorporated into a proprietary product (no copyleft). I and many other people don’t want to support something like that.

In know that Privacy Guides is also licensed under the MIT-License and the code is hosted on GitHub, but since that‘s more or less the only bad thing about Privacy Guides, I use it anyway.

---

## Post 323 by @win11.shading291 — 2025-12-01T22:24:54Z

GREAT points!!

At this point, I doubt the PG team will change their mind. It seems when a decision is taken, if the topic is slightly controversial, it’s pretty hard to reverse that decision, whatever the arguments thrown in are, even if it makes sense for a lot of people.

That being said, all these arguments are still be in this thread and people will be able to make their own decisions.

I could be wrong though!

---

## Post 324 by @Cyber-Typhoon — 2025-12-01T22:55:55Z

Very good points!

> [@SYST3M_D3STR0YER](#):
>
> FireFox is hosting its source code on GitHub, which itself is closed-source and owned by MicroSoft. I and many other people don‘t want to support closed-source projects and we certainly don‘t want to support MicroSoft. But LibreWolf uses Codeberg, which is a 100% Open-Source Non-Profit-Organisation.

Not challenging this opinion but in fact curios if some more “traditional” purist open source Linux distros would have similar take. So far a lot of repos and installations that I’m aware, normally have Firefox instead of Librewolf.

Checking the installation instructions it seems that for Arch is AUR not pacman, .deb and .rpm have to add third party Librewolf repo, the other Linux distros seems to be with the Flatpak option.

> [@SYST3M_D3STR0YER](#):
>
> FireFox is licensed under the MPL, which allows it to be incorporated into a proprietary product (weak copyleft). I and many other people don’t want to support something like that.

Perhaps, in this line of thinking one could say that Librewolf has installations available for Windows and MacOS and therefore are incorporated in closed source platforms that many people don’t want to support.

I see the difference on what you said but still that I have a little bit of trouble to separate the proprietary use of an application in closed source environment when the project creator also promotes it.

---

## Post 325 by @anon59300808 — 2025-12-01T23:48:21Z

> [@SYST3M_D3STR0YER](#):
>
> Why can’t you compare LibreWolf and MullvadBrowser?

This was compared long ago, and you were shown all of it. Have you read it, or do you prefer writing?  
The difference between Firefox, Mullvad, and LibreWolf isn’t just in the config file. They have different patches. How do you plan to integrate Tor patches into regular Firefox?  
And LibreWolf has some questionable patches, for example, JXL enabled by default. What security can there be in this case?

---

## Post 326 by @win11.shading291 — 2025-12-02T00:08:23Z

What’s wrong with JXL?

---

## Post 327 by @anon12918199 — 2025-12-02T00:12:33Z

I believe its irresponsible to recommend LibreWolf to anyone because their team is no longer able to keep up with the maintenance of the project after loosing their main maintainer as [suggested last year](https://github.com/arkenfox/user.js/issues/1906#issuecomment-2443323664).

This is further evident by the fact that the latest 145 release only came out when it did thanks to a member of this community who’s not even a LibreWolf user: [#104 - Fix failing patches for version 145 - librewolf/source - Codeberg.org](https://codeberg.org/librewolf/source/pulls/104)

---

## Post 328 by @win11.shading291 — 2025-12-02T00:18:22Z

You’re just repeating debunked argument. This is FUD at this point.

This is exactly what happened with Mullvad.

If Librewolf can’t be recommended because if this, then don’t recommend Mullvad either.

> [@SYST3M_D3STR0YER](#):
>
> Neither does Mullvadbrowser! And really, 5 days is worrying, but the MullvadBrowser had this issue in the past already: If you look at my [table](https://forum-uploads.privacyguidesusercontent.com/original/2X/0/05edb82bceb605e790ac86cc273ceed7e6d9b804.txt), you see that the security vulnerabities fixed in FireFox 139.0, among others one „critical“-security fix (which is even much higher than a „high“-security fix) and seven „moderate“-security fixes, were fixed in MullvadBrowser **six days** after firefox!

---

## Post 329 by @anon59300808 — 2025-12-02T00:29:30Z

> [@win11.shading291](#):
>
> What’s wrong with JXL?

Adding another C++ decoder, what could possibly go wrong? Who is responsible for the new vulnerabilities? Mozilla or someone from who knows where?

> [@win11.shading291](#):
>
> If Librewolf can’t be recommended because if this, then don’t recommend Mullvad either.

Yes, and Tor too, everyone should use Google Chrome. Great suggestion. Do people forget they’re on PrivacyGuides, not SecurityGuides?

---

## Post 330 by @win11.shading291 — 2025-12-02T00:36:21Z

> [@anon59300808](#):
>
> Yes, and Tor too, everyone should use Google Chrome. Great suggestion.

Strawmen.

I’m not advocating for the removal of Mullvad at all. I’m advocating for adding Librewolf.

> [@anon59300808](#):
>
> Do people forget they’re on PrivacyGuides, not SecurityGuides?

Thank you, my thoughts exactly.

---

## Post 331 by @SYST3M_D3STR0YER — 2025-12-02T07:19:16Z

> [@Cyber-Typhoon](#):
>
> Not challenging this opinion but in fact curios if some more “traditional” purist open source Linux distros would have similar take. So far a lot of repos and installations that I’m aware, normally have Firefox instead of Librewolf.
> 
> Checking the installation instructions it seems that for Arch is AUR not pacman, .deb and .rpm have to add third party Librewolf repo, the other Linux distros seems to be with the Flatpak option.

Sorry, but I didn‘t understand that point.

> [@Cyber-Typhoon](#):
>
> Perhaps, in this line of thinking one could say that Librewolf has installations available for Windows and MacOS and therefore are incorporated in closed source platforms that many people don’t want to support.
> 
> I see the difference on what you said but still that I have a little bit of trouble to separate the proprietary use of an application in closed source environment when the project creator also promotes it.

Great point and I also thought about that, and after research, I found out that LibreWolf was first only available for Open-Source OS‘s - so it was initially designed only for Open-Source Projects. Proprietary OS support came later due to big demand.

> [@anon59300808](#):
>
> How do you plan to integrate Tor patches into regular Firefox?​

The TOR uplift project ports TOR privacy patches to Firefox. Well, you could argue that there‘s a delay, but often, there‘s also a delay for the TOR browser to port firefox‘ new privacy features to the TOR browser - for example, Letterboxing was almost half a year available in firefox before it was available in the TOR browser, so this argument from you isn‘t valid.​

> [@anon59300808](#):
>
> Adding another C++ decoder, what could possibly go wrong? Who is responsible for the new vulnerabilities? Mozilla or someone from who knows where?

Actually, since it‘s a feature also available in FireFox, Mozilla. Additionally, @starkle has responded to this at the beginning of this discussion very good:

> [@starkle](#):
>
> By definition, this can be changed by the user. FF requires changing preferences as well – arguably far more extensively – so this criticism doesn’t hold up if FF is to be recommended.

---

## Post 332 by @any1 — 2025-12-02T08:00:40Z

> [@SYST3M_D3STR0YER](#):
>
> Well, I disagree. You could just use the lastest version of FireFox (so no security fix delay ➞ in that terms better than MullvadBrowser), configure it with [MullvadBrowser’s configs](https://github.com/mullvad/mullvad-browser/blob/fd37a7308534573827b027101c0e6ce03052cd53/browser/app/profile/001-base-profile.js) before the first startup of FireFox, install uBlock Origin and configure it the exact same way MullvadBrowser does, don’t log in anywhere, don’t change any setting, use it with MullvadVPN and don’t install any extension more than uBlock Origin and you would look in the web exactly like any other MullvadBrowser user, wouldn’t you?

This is not possible. Latest release of Firefox is not what Mullvad/Tor use. They don’t even use the latest ESR release directly but rebase their changes onto it instead. If you just slap the Mullvad config onto the latest release you will not be a part of the crowd.

---

## Post 333 by @any1 — 2025-12-02T08:05:14Z

> [@anon59300808](#):
>
> Adding another C++ decoder, what could possibly go wrong? Who is responsible for the new vulnerabilities? Mozilla or someone from who knows where?

I also don’t like the idea of having JXL in the browser using [libjxl](https://github.com/libjxl/libjxl) and would rather wait for the promised Rust implementation that Google said they [would provide](https://github.com/mozilla/standards-positions/pull/1064) for Firefox.

---

## Post 334 by @anon51983832 — 2025-12-02T08:08:34Z

> [@SYST3M_D3STR0YER](#):
>
> Why can’t you compare LibreWolf and MullvadBrowser? You can make FireFox nearly the same as MullvadBrowser and you can make FireFox nearly the same as LibreWolf.

I don’t understand why you keep going on about the same thing when it’s been proven to you that what CAN be achieved with Mullvad/Tor CANNOT be achieved with AF/LW/Firefox, and you yourself have acknowledged it:

> [@SYST3M_D3STR0YER](#):
>
> I want to sincerely thank you all for taking the time to explain me why my arguments for including LibreWolf in the browser recommendations was mistaken. After reading your points carefully, I realized that I was wrong and that my reasoning was too simplistic.

---

## Post 335 by @any1 — 2025-12-02T08:10:28Z

> [@anon12918199](#):
>
> I believe its irresponsible to recommend LibreWolf to anyone because their team is no longer able to keep up with the maintenance of the project after loosing their main maintainer as [suggested last year](https://github.com/arkenfox/user.js/issues/1906#issuecomment-2443323664).
> 
> This is further evident by the fact that the latest 145 release only came out when it did thanks to a member of this community who’s not even a LibreWolf user: [#104 - Fix failing patches for version 145 - librewolf/source - Codeberg.org](https://codeberg.org/librewolf/source/pulls/104)

I am already testing the patches against the release candidate for 146, so the next release should be much faster.

---

## Post 336 by @SYST3M_D3STR0YER — 2025-12-02T14:37:06Z

> [@any1](#):
>
> If you just slap the Mullvad config onto the latest release you will not be a part of the crowd.

1. Well then, can you just name a few concrete fingerprinting-relevant values which distinguish a user with that theoretical setup (lastest [ESR/Non-ESR] version of FireFox, configured with [MullvadBrowser’s configs](https://github.com/mullvad/mullvad-browser/blob/fd37a7308534573827b027101c0e6ce03052cd53/browser/app/profile/001-base-profile.js) before the first startup of FireFox, installed uBlock Origin and configured with the exact same way MullvadBrowser does, don’t logged-in anywhere, don’t changed any setting, used with MullvadVPN and don’t installed any extension more than uBlock Origin) to a MullvadBrowser+MullvadVPN user?

2. If that is true and you can’t compare MullvadBrowser with LibreWolf (which might be the case!), then my main argument still persists:

And also, none of the 13 in FF non-achievable advantages of LibreWolf has been yet refuted (except maybe one that Cyber-Typhoon mentioned).

---

## Post 337 by @any1 — 2025-12-02T16:20:50Z

> [@SYST3M_D3STR0YER](#):
>
> Well then, can you just name a few concrete fingerprinting-relevant values which distinguish a user with that theoretical setup (lastest [ESR/Non-ESR] version of FireFox, configured with [MullvadBrowser’s configs](https://github.com/mullvad/mullvad-browser/blob/fd37a7308534573827b027101c0e6ce03052cd53/browser/app/profile/001-base-profile.js) before the first startup of FireFox, installed uBlock Origin and configured with the exact same way MullvadBrowser does, don’t logged-in anywhere, don’t changed any setting, used with MullvadVPN and don’t installed any extension more than uBlock Origin) to a MullvadBrowser+MullvadVPN user?

Are you even aware of what you’re asking? You are asking whether there is a change in fingerprinting that, by the end of the lifecycle, represents almost a year’s worth of changes, not including Tor/Mullvad rebases that are missing compared to regular Firefox releases.

If you’re so convinced, then go ahead and make your frankenbrowser and compare it to Mullvad Browser with [TZP](https://arkenfox.github.io/TZP/tzp.html).

---

## Post 338 by @anon12918199 — 2025-12-02T18:05:11Z

I don’t understand your intentions. I see that you just signed up to codeberg and you’ve stated that you don’t even use LibreWolf, but you decided that you want to be its batman anyways and start working on new release? Why?

Anyways, I used to use LibreWolf for roughly a year before I found this community. I wanted to share why I’m never going back again. To me it’s a lack of community and past dev fuck ups that completely eroded my trust in the project.

1. Maybe half a year ago LibreWolf rolled out a new release then rolled it back after about a day. Everyone that updated to the new release had their profiles updated for the new version. After that new release got rolled back, LibreWolf refused to use my old “new” profile and it required some manual intervention. To me this was catastrophic to temporarily “lose” my profile and it was ~15 minutes of panic googling to fix the issue. I’m a dev, so I can’t imagine how non-technical users managed.
2. I’m on arch now and use AUR for third party packages. Unlike firefox, which is a first class citizen and lives in a more “trusted” repository, LibreWolf is managed by a single volunteer. Some malicious AUR user has been spamming packages with incorrect “out-of-date” flags that the maintainer wasn’t clearing promptly. The end user would see these warnings every time when running any installs/updates and this was going on for roughly a month, but I see that he was stopped now.
3. The AUR maintainer also didn’t specify the correct version of ffmpeg (firefox-based browsers only run on v4.4 and can’t work with any other versions) as a dependency. One day, when I switched from VLC to mpv, most of my browser videos started failing with dubious errors. I’m a bit of a home assistant, IoT enthusiast so this was another catastrophe for me that I had to dedicated over an hour to solve. To be fair this ffmpeg4.4 dependency fuck up affected all the other volunteer-run AUR forks like zen and mullvad. I went on a personal crusade to get all the other maintainers to fix their shit too now.

I have since switched to Brave based on PG’s recommendation and its been working great for me. I do believe that PG could be much better at prompting their more technical users on how to deshitify Brave with “organizational override config” to remove all the AI/web3/other crap from Brave, but that’s a completely separate story.

---

## Post 339 by @Blackbird — 2025-12-02T18:29:49Z

It only takes five minutes to do all the adjustments, so there’s no need.

---

## Post 340 by @any1 — 2025-12-02T18:42:58Z

> [@anon12918199](#):
>
> I don’t understand your intentions. I see that you just signed up to codeberg and you’ve stated that you don’t even use LibreWolf, but you decided that you want to be its batman anyways and start working on new release? Why?

Why not? It’s something interesting to work on, and it might benefit some people down the line. Maybe LibreWolf will turn into something worth using, but that depends on how much resistance I face with my planned changes.

---

## Post 341 by @anon12918199 — 2025-12-02T20:01:11Z

That’s not true. Local organizational policies do more than just check checkboxes which is what the PG guide suggests. They actually remove the enshitified parts from the Brave UI which leaves a vastly cleaner browser experience. In particular I removed: _AI Chat, News, Rewards, Speedreader, VPN, Wallet_ so there’s no reference to them in my Brave anywhere.  
I’m not going to talk about my Brave configs or anything like that further here to not derail this thread further.

---

## Post 342 by @anon59300808 — 2025-12-02T21:27:16Z

> [@SYST3M_D3STR0YER](#):
>
> Actually, since it‘s a feature also available in FireFox, Mozilla. Additionally, @starkle has responded to this at the beginning of this discussion very good:

Actually, JXL only available in the Firefox Nightly. In LibreWolf, this is the default and it is enabled.

> [@SYST3M_D3STR0YER](#):
>
> The TOR uplift project ports TOR privacy patches to Firefox. Well, you could argue that there‘s a delay, but often, there‘s also a delay for the TOR browser to port firefox‘ new privacy features to the TOR browser - for example, Letterboxing was almost half a year available in firefox before it was available in the TOR browser, so this argument from you isn‘t valid.​

So what? Are all the Tor patches now fully added to Firefox?

> You could just use the lastest version of FireFox (so no security fix delay ➞ in that terms better than MullvadBrowser), configure it with [MullvadBrowser’s configs](https://github.com/mullvad/mullvad-browser/blob/fd37a7308534573827b027101c0e6ce03052cd53/browser/app/profile/001-base-profile.js) before the first startup of FireFox, install uBlock Origin and configure it the exact same way MullvadBrowser does, don’t log in anywhere, don’t change any setting, use it with MullvadVPN and don’t install any extension more than uBlock Origin and you would look in the web exactly like any other MullvadBrowser user, wouldn’t you?

Did you even try to test this nonsense yourself? Even the link to your config is already outdated. When using this config, or an updated one, in Firefox, some fingerprints are not hidden, but that’s for later. First, you’ll need to edit this config because Firefox doesn’t know which fonts to use and everything appears as squares. So, Firefox most likely doesn’t have all the Tor patches, right?

I think you need to start personally testing things and showing the results. Right now it looks like you’re not even sure of your own words. Personally, I haven’t seen a single reason to mention it in recommendations, except for far-fetched personal preferences.

---

## Post 343 by @win11.shading291 — 2025-12-03T04:36:27Z

> [@any1](#):
>
> I am already testing the patches against the release candidate for 146, so the next release should be much faster.

Thanks for that!

> [@anon59300808](#):
>
> Personally, I haven’t seen a single reason to mention it in recommendations, except for far-fetched personal preferences.

You clearly haven’t read the thread then.

---

## Post 344 by @SYST3M_D3STR0YER — 2025-12-03T05:30:49Z

> [@anon12918199](#):
>
> Maybe half a year ago LibreWolf rolled out a new release then rolled it back after about a day. Everyone that updated to the new release had their profiles updated for the new version. After that new release got rolled back, LibreWolf refused to use my old “new” profile and it required some manual intervention. To me this was catastrophic to temporarily “lose” my profile and it was ~15 minutes of panic googling to fix the issue. I’m a dev, so I can’t imagine how non-technical users managed.

Non-technical people don‘t use Arch :+1:

I am pretty sure that that was a problem only with Arch/AUR since I didn‘t had that problem and I‘m using LibreWolf over half an year. I use the AppImage

> [@anon12918199](#):
>
> LibreWolf is managed by a single volunteer

You should problably take a look [here](https://codeberg.org/librewolf/source/activity/contributors)

> [@anon59300808](#):
>
> Actually, JXL only available in the Firefox Nightly. In LibreWolf, this is the default and it is enabled.

So FireFox Nightly is not FireFox? :rofl: And FireFox ESR is probably also not FireFox, right? :joy:

> [@anon59300808](#):
>
> So what? Are all the Tor patches now fully added to Firefox?

Didn‘t said that. I just wanted to point out that the way isn‘t always TOR-Project adds a Feature - Mozilla ports it into ForeFox, but also often Mozilla adds a privacy feature - TOR-Project ports it into the TOR-Browser, so arguing just one way around doesn‘t makes sense.

---

## Post 345 by @anon12918199 — 2025-12-03T06:05:29Z

> I am pretty sure that that was a problem only with Arch/AUR since I didn‘t had that problem and I‘m using LibreWolf over half an year. I use the AppImage

My mistake. The catastrophic LibreWolf dev mess up I was referring to actually happened exactly a year ago with the 132\< -– \>133 upgrades. I was on Windows then and it affected all platforms. Read more about it here if you want: [Reddit - The heart of the internet](https://www.reddit.com/r/LibreWolf/comments/1h3sbbg/after_updating_to_version_132021_the_old_profiles/)

---

## Post 346 by @any1 — 2025-12-03T19:39:24Z

> [@SYST3M_D3STR0YER](#):
>
> And also, none of the 13 in FF non-achievable advantages of LibreWolf has been yet refuted (except maybe one that Cyber-Typhoon mentioned).

Here is a reason to avoid using it: a patch [added nine months ago](https://codeberg.org/librewolf/source/commit/abab298054c67844f8fd3cd5097f177c035efbac) turned the remote settings into a whitelist. Not much was added to this whitelist.

Take a look at my [PR](https://codeberg.org/librewolf/settings/pulls/96) and see what is missing that is actively making LibreWolf have worse security compared to just using Firefox. You are actively missing protections against add-ons that are insecure or malicious, and this is just one of the missing remotes.

This is just from quickly looking at what is being blocked, there probably are more that need to be added.

---

## Post 347 by @SYST3M_D3STR0YER — 2025-12-04T12:00:37Z

> [@any1](#):
>
> You are actively missing protections against add-ons that are insecure or malicious

I don‘t think this particular argument is valid since [LibreWolf encourages strongly against installing more AddOns](https://librewolf.net/docs/addons/#other-addons).

> [@anon12918199](#):
>
> My mistake. The catastrophic LibreWolf dev mess up I was referring to actually happened exactly a year ago with the 132\< -– \>133 upgrades. I was on Windows then and it affected all platforms. Read more about it here if you want: [Reddit - The heart of the internet](https://www.reddit.com/r/LibreWolf/comments/1h3sbbg/after_updating_to_version_132021_the_old_profiles/)

I also don‘t think this argument is valid. Time to time, there‘s always big mess ups in browsers. (FireFox also had those things ([example](https://www.reddit.com/r/firefox/comments/1j04omx/i_lost_my_firefox_profile_data_because_of_an/)) and it is still recommended.)

---

## Post 348 by @any1 — 2025-12-04T12:07:17Z

> [@SYST3M_D3STR0YER](#):
>
> I don‘t think this particular argument is valid since [LibreWolf encourages strongly against installing more AddOns](https://librewolf.net/docs/addons/#other-addons).

Just because they don’t recommend installing more add-ons doesn’t mean that users will listen, and does not justify not having these protections.

What about these that are missing?

- main/hijack-blocklists — Supplies remote blocklists used to detect and block known malicious or hijacking domains and protect against address/URL hijacking.
- main/addons-data-leak-blocker-domains — Remote list of domains where extensions are prevented from accessing or exfiltrating data to stop known data-leak destinations.
- blocklists/gfx — Remote blocklist of graphics/driver-related entries used to disable or alter graphics features for problematic GPUs/drivers to improve stability.

---

## Post 349 by @anon39279085 — 2025-12-04T13:23:28Z

Not mentioning a password manager and/or alias manager like qwacky

---

## Post 350 by @win11.shading291 — 2025-12-05T03:32:28Z

You can always find stuff on ALL browsers that happened that weren’t optimal. You can basically nitpick on anything.

For example, when I initially read [this](https://discuss.privacyguides.net/t/why-does-brave-browser-get-a-free-pass/32124) reddit post on Brave, I was shocked Brave was recommended.

When you dig a little, you can dismiss most of those as honest mistakes, or not that big of a deal.

Brave is recommended. Librewolf is not.

It still doesn’t make sense to me.

---

## Post 351 by @bodin — 2026-02-10T22:49:39Z

@any1 Are you working on Librewolf now? Is it something you feel comfortable recommending now? Is it better now? Better (more private and secure) than FF with PG’s recommended settings and UBO?

I remember you (I think) saying something akin to…the project seems held together with duct tape or is running on a wing and prayer or something like that anyway, and that scared me away from using it. I moved to MB then back to FF now. I just scrolled through the thread and could not find the exact quote though.

---

## Post 352 by @any1 — 2026-02-11T13:19:25Z

> [@bodin](#):
>
> Are you working on Librewolf now?

Yes

> [@bodin](#):
>
> Is it something you feel comfortable recommending now? Is it better now? Better (more private and secure) than FF with PG’s recommended settings and UBO?

If you rely on FPP (what the PG guide recommends and what arkenfox now defaults to), you’ll get better protection by using FPP with the default RFPTargets in LibreWolf. Security would currently be about the same as what you get with Firefox + arkenfox.

> [@bodin](#):
>
> held together with duct tape or is running on a wing and prayer or something like

I think working on a fast-moving, large codebase such as Firefox as a fork will always involve things constantly breaking and requiring hacky workarounds. All you can really do is test the next release early enough to fix issues so you don’t have to delay the release when something breaks.

In general I would say the situation has vastly improved

- Releases are made within a day after Firefox makes a release, often within a few hours.
- We moved the CI/releases from GitLab to Codeberg.
- We test against the beta of the next release so we can fix regressions earlier and avoid delaying new releases.
- We are the only fork, AFAIK, that supports the new XDG functionality.
- We fixed a regression in the FPP canvas protections.
- I have open PRs to move to MOZILLA\_OFFICIAL.
- I finished a WebGL per-site permission, which will be included soon after some testing.
- Moving from RFP to FPP is currently in progress.
- The settings have been cleaned up.
- A lot of other small fixes.

I would suggest installing it alongside Firefox to see how you like it and whether you have any usability concerns. Other than getting MOZILLA\_OFFICIAL merged (which should happen soon), I don’t see anything that would prevent me from recommending it.

---

## Post 353 by @jonah — 2026-03-11T19:55:44Z

4 posts were split to a new topic: [Should LibreWolf be used with its default settings?](/t/should-librewolf-be-used-with-its-default-settings/36220)

---

## Post 357 by @win11.shading291 — 2026-02-12T03:09:10Z

> [@any1](#):
>
> We

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/4/f/4f9da4ce0ea574e3b8eddb318732c68c20769344.jpeg)

---

## Post 358 by @SYST3M_D3STR0YER — 2026-02-14T10:19:14Z

Obviously, the following isn’t that relevant anymore as the more or less only argument, the bad security, is now fixed. But, to end the discussion…

* * *

> [@any1](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/syst3m_d3str0yer/48/15679_2.png) SYST3M\_D3STR0YER:
> 
> > Well then, can you just name a few concrete fingerprinting-relevant values which distinguish a user with that theoretical setup (lastest [ESR/Non-ESR] version of FireFox, configured with [MullvadBrowser’s configs](https://github.com/mullvad/mullvad-browser/blob/fd37a7308534573827b027101c0e6ce03052cd53/browser/app/profile/001-base-profile.js) before the first startup of FireFox, installed uBlock Origin and configured with the exact same way MullvadBrowser does, don’t logged-in anywhere, don’t changed any setting, used with MullvadVPN and don’t installed any extension more than uBlock Origin) to a MullvadBrowser+MullvadVPN user?
> 
> Are you even aware of what you’re asking? You are asking whether there is a change in fingerprinting that, by the end of the lifecycle, represents almost a year’s worth of changes, not including Tor/Mullvad rebases that are missing compared to regular Firefox releases.

> [@anon59300808](#):
>
> Did you even try to test this nonsense yourself? Even the link to your config is already outdated. When using this config, or an updated one, in Firefox, some fingerprints are not hidden, but that’s for later. First, you’ll need to edit this config because Firefox doesn’t know which fonts to use and everything appears as squares. So, Firefox most likely doesn’t have all the Tor patches, right?
> 
> I think you need to start personally testing things and showing the results. Right now it looks like you’re not even sure of your own words.

> [@anon51983832](#):
>
> I don’t understand why you keep going on about the same thing when it’s been proven to you that what CAN be achieved with Mullvad/Tor CANNOT be achieved with AF/LW/Firefox, and you yourself have acknowledged it

Yes, I was wrong in that point; this misunderstanding from me was based on an [unaccuracy](https://discuss.privacyguides.net/t/firefox-arkenfox-instead-of-mullvadbrowser/33024/6) that [Privacy Guides wrote itself](https://discuss.privacyguides.net/t/firefox-arkenfox-instead-of-mullvadbrowser/33024) (so no, not bad research, or being dumb [at least not that time :sweat_smile:] or something like that which @anon59300808 was heavily implying).

* * *

# An attempted summary of the discussion (+ new arguments)

Please note that “ProLW” or “ConLW” (Pro LibreWolf / Contra LibreWolf) isn’t always something on which all Pro- or ConLW “Team members” agree. Sometimes when I write a ProLW bullet point, I’m even myself unsure whether it’s valid.

_Whenever there are numbers in the reply (1., 2. etc.) it means that these are completely separate arguments which are valid even if you refute one of them. If you want to challenge that LibreWolf should not be recommended, you would have to refute every point separately, otherwise LibreWolf should **still** be recommended_.

## Against LibreWolf

### Security fix delay

- **ConLW:** LibreWolf has a dangerous security fix delay which makes it insecure.

- **ProLW:** MullvadBrowser has a just very slightly differing security fix delay; recommending LibreWolf not because it has an average security fix delay approximately 0.4 days longer than MullvadBrowser (which is recommended) is ridiculous.

- **ConLW:** LibreWolf had a 9 days security fix delay which could have been even longer if @any1 didn’t went ahead and fix it. Until LibreWolf manages to have consistent updates, it shouldn’t be recommended; until then, persistent mode is probably already released anyway.

- **ProLW** (partially NEW) **:** MullvadBrowser was not that much faster there; 6 days is also very worrying. And we don’t know what would’ve happened if @any1 didn’t fix it; maybe someone else new to the LibreWolf project or ohfp (LibreWolf project admin) would’ve done it.

- **ConLW:** You can’t compare MullvadBrowser and LibreWolf because they are completely different and serve different purposes; MullvadBrowser adds the TOR browser patches and LibreWolf does not and that can’t be achieved with FireFox. LibreWolf can only be compared to FireFox or Brave.

- (Here is one dumb argument (mine) and its reply missing; see for that beginning of this post)

- **ProLW** (partially NEW) **:** 1. With @any1 being a new maintainer of LibreWolf, the updates are now confirmed to be within one day. 2. If “consistent updates” is enough as one single criteria to throw something out of “even possible to recommend”, then MullvadBrowser shouldn’t be recommended as through your own logic. However, it would be logical if you’d say “Until LibreWolf manages to have consistent updates or to add real privacy, security or usability improvements compared to FireFox or Brave, it shouldn’t be recommended; until then, persistent mode is probably already released anyway.” But then I could say: _Yes, it does add real privacy and usability improvements,_ see the next section of „Against LibreWolf“. 3. **In every way, you are making Privacy-, Security- and Convenience trade-offs** , so the _only question should be:_  
Outweighs the convenience and additional privacy features of LibreWolf compared to FireFox & ArkenFox the security fix delay of LibreWolf?  
**You can‘t say objectively if all the additional features of LibreWolf compared to FireFox outweighs this one security disadvantage, _so the User should choose for himself._** That’s why we should mention LibreWolf.

### Offering additional value compared to FireFox / Brave

- **ConLW:** LibreWolf doesn’t add any value compared to FireFox or Brave.

- **ProLW:** This is not true, you don’t have to configure and maintain ArkenFox; checking & eventually adopting new changes from a potential new ArkenFox release, which is necessary to disable fingerprinting. For many settings, you don’t have to use about:config but can use the convenient GUI extra settings category. Making per-site cookie deleting exceptions is _much_ faster and easier.

- **ConLW:** You don’t necessarily have to, in your definition, “maintain” ArkenFox because there is no crowd for ArkenFox users - ArkenFox can only, if anything, fool naive fingerprinting scripts.

- **ProLW:** You should still update ArkenFox to avoid being tracked by a potentially new tracking method.

- **ConLW:** Liking not configuring anything is a valid personal preference, but not a valid basis for a Privacy Guides recommendation.

- **ProLW:** 1. This is _absolutely not true,_ usability is a big criteria when recommending something, otherwise only the TOR browser would be recommended as it is the most private one. **In every way, you are making Privacy-, Security- and Convenience trade-offs** , so the _only question should be:_  
Outweighs the convenience and additional privacy features of LibreWolf compared to FireFox & ArkenFox the security fix delay of LibreWolf?  
**You can‘t say objectively if all the additional features of LibreWolf compared to FireFox outweighs this one security disadvantage, _so the User should choose for himself._** That’s why we should mention LibreWolf. 2. I found 10 things more which can’t be achieved with FireFox, but can be achieved / are implemented in LibreWolf (reply [322](https://discuss.privacyguides.net/t/librewolf-firefox-based-browser/148/322)) – so in total there are _13 things which can’t be achieved with FireFox, but can be achieved with LibreWolf_.

### Target audience

- **ConLW:** For not technical users, LibreWolf is not recommendable because they can’t diagnose and especially don’t fix site breakage. For intermediate and technical users, including a - in case of LibreWolf, _(in the past)_ unreliable - third party is not worth configuring the handful releases ArkenFox does every year which only takes 5 of the 526,000 minutes every year, except on the initial learning curve.

- **ProLW:** 1. Now, the updates are fast and consistent (thanks to @any1), so it is at least at this point already recommendable for intermediate and technical users. 2. (Further argument that it’s recommendable for intermediate and technical users) **In every way, you are making Privacy-, Security- and Convenience trade-offs** , so the _only question should be:_  
Outweighs the convenience and additional privacy features of LibreWolf compared to FireFox & ArkenFox the security fix delay of LibreWolf?  
**You can‘t say objectively if all the additional features of LibreWolf compared to FireFox outweighs this one security disadvantage, _so the User should choose for himself._** That’s why we should mention LibreWolf. 3. LibreWolf _is_ recommendable for not technical users, but see for that „Beginner friendliness“ in the section „For LibreWolf“.

### JXL

- **ConLW:** LibreWolf enables JXL by default which is another C++ decoder with „who knows who‘s responsible for it“ state and therefore a security risk.

- **ProLW:** 1. JXL is also available in FireFox. 2. FireFox is recommended which requires changing far more preferences than LibreWolf.

- **ConLW:** JXL is only available in FireFox Nightly.

- **ProLW:** 1. FireFox Nightly is still FireFox and Mozilla is for both (regular FireFox and FireFox Nightly) responsible. JXL is maintained by Mozilla. 2. The second point from the previous response is still unanswered.

### Missing blocklists

- **ConLW:** In LibreWolf, you have worse security compared to FireFox as there are blocklists missing; you are actively missing protections against add-ons that are insecure or malicious, and this is just one of the missing remotes.

- **ProLW:** This is fixed now, the three mentioned missing blocklists are now added to LibreWolf (LibreWolf‘s about:config librewolf.services.settings.allowedCollections value).

## For LibreWolf

### Trade-Offs on Privacy, Security and Convenience

- **ProLW: In every way, you are making Privacy-, Security- and Convenience trade-offs** , so the _only question should be:_  
Outweighs the convenience and additional privacy features of LibreWolf compared to FireFox & ArkenFox the security fix delay of LibreWolf?  
**You can‘t say objectively if all the additional features of LibreWolf compared to FireFox outweighs this one security disadvantage, _so the User should choose for himself._** That’s why we should mention LibreWolf.

### Beginner friendliness

- **ProLW:** LibreWolf is more user-friendly and easy to use; beginners and less-technical people can benefit from this. You also have to read the entire ArkenFox wiki (at least it says so) which takes lots of time and can be hard to understand.

- **ConLW:** LibreWolf has settings and disables much things which breaks functionality of many sites; LibreWolf is therefore not recommendable for beginners or less technical users. If you are comfortable not reading the LibreWolf docs, you can be even more comfortable not reading the ArkenFox wiki as you will encounter less breakage with ArkenFox compared to LibreWolf.

- **ProLW:** Some are skeptical due to personal experience that LibreWolf breaks sites.

- **ConLW:** LibreWolf uses RFP currently as default (this will probably be [soon changed](https://codeberg.org/librewolf/issues/issues/2121)) and ArkenFox FPP which breaks much lesser sites; therefore, our argument stands and LibreWolf is not recommendable to less technical people because they can‘t fix site breakage (this would apply also when LibreWolf switches to FPP).

- **ProLW** (NEW) **:** According to the ArkenFox wiki, [99 % of site breakage can be fixed with setting a temporarily or permanent Canvas exception](https://github.com/arkenfox/user.js/wiki/3.3-Overrides-%5BTo-RFP-or-Not%5D#-rfp). Doing so is very easy; just click on the image icon at the URL bar and select if you want to allow it once or every time. This could be said with an easy information if we recommend LibreWolf.

---

## Post 359 by @win11.shading291 — 2026-02-14T16:50:51Z

Well this reply is the nails in the coffin as we say. :face_with_tongue:

AMAZING job @SYST3M_D3STR0YER

Also, just to add to this

> [@SYST3M_D3STR0YER](#):
>
> Some are skeptical due to personal experience that LibreWolf breaks sites.

I have yet to encounter any website breakages 6 months in.

---

## Post 360 by @any1 — 2026-02-14T17:56:32Z

> [@SYST3M_D3STR0YER](#):
>
> ### JXL
> 
> - **ConLW:** LibreWolf enables JXL by default which is another C++ decoder with „who knows who‘s responsible for it“ state and therefore a security risk.
> - **ProLW:** 1. JXL is also available in FireFox. 2. FireFox is recommended which requires changing far more preferences than LibreWolf.
> - **ConLW:** JXL is only available in FireFox Nightly.
> - **ProLW:** 1. FireFox Nightly is still FireFox and Mozilla is for both (regular FireFox and FireFox Nightly) responsible. JXL is maintained by Mozilla. 2. The second point from the previous response is still unanswered.

JXL used to be enabled by default, but it seems this was changed some time ago (before I got involved). Now the build only includes JXL support, and it needs to be enabled manually in about:config. As far as I can tell, no JXL-related code is reachable when the pref to use it is off.

---

## Post 361 by @jonah — 2026-03-11T19:07:48Z

9 posts were split to a new topic: [Does LibreWolf have a changelog?](/t/does-librewolf-have-a-changelog/36212)

---

## Post 371 by @Sword.of.light — 2026-02-25T01:12:36Z

I’ll just leave this here: [#1779 - Feature Request: Radio Silence by Default for Browser Startup and Background Connections aka "Disable Phone Home" - librewolf/issues - Codeberg.org](https://codeberg.org/librewolf/issues/issues/1779)

Every time the user opens up their librewolf browser it phones home that :index_pointing_at_the_viewer:, started using the browser to servers like mozzila, github, global sign and other.

Leading to creating patterns based on your behavior. IP, TIME, GEOlocation. each time you are about to browse and open up the browser, it phones **user just open up their browser**

The feature **LibreWolf IJWY or (I Just Want You To Shut Up)** was completely removed a couple of years ago; a feature its predecessor librefox and old librewolf had, basically **don’t phone home each time you start the browser giving out unnecessary metadata**

[Last time this issue was brought up to some devs they dismissed it](https://github.com/arkenfox/user.js/issues/1807)

[Here’s how they can use this information against you](https://mullvad.net/en/why-privacy-matters/collected-data-cant-be-kept-anonymous)

---

## Post 372 by @jonah — 2026-03-11T19:06:04Z

6 posts were split to a new topic: [Why was IJWY removed from LibreWolf?](/t/why-was-ijwy-removed-from-librewolf/36210)

---

## Post 378 by @jonah — 2026-03-11T19:06:48Z

2 posts were split to a new topic: [Does LibreWolf attempt to look like Tor / use Tor’s anti-fingerprinting?](/t/does-librewolf-attempt-to-look-like-tor-use-tors-anti-fingerprinting/36211)

---

## Post 380 by @any1 — 2026-03-08T16:27:24Z

[https://discuss.privacyguides.net/t/lost-topics/35995/5](https://discuss.privacyguides.net/t/lost-topics/35995/5)

With regard to the linked post, what would be the approach for this thread since it was rejected years ago? Does the discussion continue here, or would a new thread be the recommended approach? @jonah

---

## Post 381 by @jonah — 2026-03-11T19:04:01Z

8 posts were split to a new topic: [When will Librewolf be moving to using FPP?](/t/when-will-librewolf-be-moving-to-using-fpp/36209)

---

## Post 389 by @win11.shading291 — 2026-03-10T16:12:54Z

It’s important to understand that the browsers have different use case. Mullvad is made to avoid fingerprinting completely.

The other browsers like Librewolf have fingerprinting protection, but it’s not the entire purpose of it.

---

## Post 390 by @byte — 2026-03-11T19:00:44Z

I have very mixed feelings about this…

As i think, LibreWolf should be recommended, even if there is downside like another dev to trust.

LibreWolf already come hardened (like Arkenfox, but native), already includes UBlockOrigin.

This is mostly all what you need for comfortable usage.

LibreWolf also non-comercial (they even don’t have donations!).

Also mullvad browser is _commercial_ produc that can be used _only_ with mullvad VPN (i cannot for example put there selfhosted VPN). It also haves another dev to trust.

So i think LibreWolf should be listed anyways. It is far more comfortable just to install LibreWolf without learning Arkenfox wiki (ideal for newcomers) and get pure experience without shitty AI in browser or extremely long config manuals…

---

## Post 391 by @Blackbird — 2026-03-11T19:11:58Z

Put a VPN on your router, and you can use Mullvad with any VPN.

---

## Post 392 by @jonah — 2026-03-11T19:59:34Z

> [@any1](#):
>
> Does the discussion continue here

Yes.

---

## Post 393 by @jonah — 2026-03-11T20:04:20Z

So I have read everything again and I have more thoughts, but right out of the gate, one of our minimum requirements is:

> Must be available on Linux, macOS, and Windows.

I would argue that [this…](https://librewolf.net/docs/faq/#why-is-librewolf-marked-as-broken)

> This happens because we do not notarize the macOS version of the browser: we don’t have a paid Apple Developer license and we don’t want to support this signing mechanism

…means Librewolf does not meet this criteria, which has been an [issue noted by the community](https://discuss.privacyguides.net/t/librewolf-firefox-based-browser/148/79) here since 2023.

I note that LibreWolf _does_ sign packages on Windows, and even distributes via the Microsoft App Store, making the argument against supporting Apple’s distribution methods even less convincing. Do we know if there are any plans to change this?

---

## Post 394 by @SYST3M_D3STR0YER — 2026-03-11T20:08:44Z

> [@jonah](#):
>
> So I have read everything again and I have more thoughts, but right out of the gate, one of our minimum requirements is:
> 
> > Must be available on Linux, macOS, and Windows.
> 
> I would argue that [this…](https://librewolf.net/docs/faq/#why-is-librewolf-marked-as-broken)
> 
> > This happens because we do not notarize the macOS version of the browser: we don’t have a paid Apple Developer license and we don’t want to support this signing mechanism
> 
> …means Librewolf does not meet this criteria, which has been an [issue noted by the community](https://discuss.privacyguides.net/t/librewolf-firefox-based-browser/148/79) here since 2023.

It is _available_ on macOS, just not through the more official sources when you install something on macOS.

> [@jonah](#):
>
> I note that LibreWolf _does_ sign packages on Windows, and even distributes via the Microsoft App Store, making the argument against supporting Apple’s distribution methods even less convincing.

Because you don‘t have to _pay_ the evil big corporation for distributing your app in the MicroSlop store, whereas you have to do it for CrApple.

---

## Post 395 by @any1 — 2026-03-11T20:13:46Z

> [@jonah](#):
>
> I note that LibreWolf _does_ sign packages on Windows, and even distributes via the Microsoft App Store, making the argument against supporting Apple’s distribution methods even less convincing. Do we know if there are any plans to change this?

> **[macOS signing](https://codeberg.org/librewolf/issues/issues/2902#issuecomment-11289487)**
>
> This issue tracks the progress of signing the macOS release. Split off from #2664 | This issue tracks the progress of signing the macOS release.
> Split off from https://codeberg.org/librewolf/issues/issues/2664

TL;DR: [https://ossign.org/](https://ossign.org/), which has provided us the Windows cert, will soon also provide the required macOS signing certificate.

---

## Post 396 by @jonah — 2026-03-11T20:13:53Z

I believe LibreWolf happens to get code signing for free via OSSign, which makes this not a principled stance against any paid certificates, but merely a matter of expense LW doesn’t want to pay. If OSSign provided free macOS signing as well, would LW take advantage of it?

I’d prefer to get answers from someone who knows _why LibreWolf specifically_ made this decision (from @any1 I would presume), not just a reason why codesigning on Apple is bad in general.

edit: so I think that last reply answers my question, and the answer is **yes** , right?

---

## Post 397 by @any1 — 2026-03-11T20:16:49Z

> [@jonah](#):
>
> edit: so I think that last reply answers my question, and the answer is **yes** , right?

Yes. Once they add the ability to sign for macOS, we will start signing for macOS as well.

---

## Post 398 by @jonah — 2026-03-11T20:22:52Z

My second question is: Why do auto-updates remain so challenging for LibreWolf?

Other Firefox forks are seemingly able to do this trivially, namely Zen Browser (which doesn’t have the support from Mozilla that I’d expect Tor/Mullvad Browser do, so it signifies in my mind that this is not an insurmountable problem outside of Mozilla).

---

## Post 399 by @any1 — 2026-03-11T20:41:19Z

There was some work to support the MAR updates a few years back, but I am not sure why it was never finished.

My guess is that, since we already had the bundled Windows updater (which was supposed to be a temporary solution), it wasn’t seen as a priority.

I looked at how Mullvad/Tor Browser handles MAR updates a few days ago, and it should be doable and is something that I have planned on supporting.

---

## Post 400 by @jonah — 2026-03-11T20:45:58Z

I think both of these things are probably the only reasons I personally would block LW from being added at this time.

Can’t speak for the rest of the team here though, unfortunately, I believe a lot of them mainly lend stock to the idea that there is a community consensus against forks in general. I’d love to eventually kick Firefox out, on the other hand, given how often we are negatively reporting on them.

---

## Post 401 by @win11.shading291 — 2026-03-11T20:52:15Z

This is not a requirement though as per the criteria.

It would bug me if I didn’t received updates automatically from LW, but I do.

The macOS thing I can understand, but as for ProtonVPN, maybe PG should have some sort of notes that says “recommended only for OS XYZ.” Or have it on the recommendation page, but put a flag that says it’s not recommended on macOS and state the reason why.

---

## Post 402 by @any1 — 2026-03-11T21:00:44Z

> [@jonah](#):
>
> I’d love to eventually kick Firefox out, on the other hand, given how often we are negatively reporting on them.

Yeah, Mozilla has been making very disappointing decisions compared to its former self.

Instead of trying to make an actually usable alternative to Chromium, they peddle this weird stance about being some kind of resistance against Big Tech and portray themselves as saviors while letting their most important project fall behind and struggle to keep up with Chromium (especially regarding security, which has many open Bugzilla issues that have been dormant for years). Their biggest mistake, in my opinion, was not following through with Servo and disbanding the team that was working on it.

It is sad to see how Firefox has fallen.

---

## Post 403 by @jonah — 2026-03-11T21:09:17Z

I quoted the minimum criteria where it is a requirement, and in addition automatic updates are also a long-standing requirement.

---

## Post 404 by @any1 — 2026-03-11T21:11:58Z

> [@jonah](#):
>
> I believe a lot of them mainly lend stock to the idea that there is a community consensus against forks in general.

~~Firefox has gone beyond what projects like [arkenfox can achieve with configs alone](https://github.com/arkenfox/user.js/issues/1813#issuecomment-3704600797). LibreWolf and IronFox have had a FPP Canvas regression fixed for weeks and restored a protection that had been removed because it broke Google Meet, of all things.~~

[Comment from thorin](https://github.com/arkenfox/user.js/issues/1813#issuecomment-4044255479)

If LibreWolf won’t be added because the team disfavors forks, at least put Firefox out of its misery, since the current guide doesn’t help much when the base it builds on is broken.

---

## Post 405 by @win11.shading291 — 2026-03-11T21:13:06Z

> [@jonah](#):
>
> and in addition automatic updates are also a long-standing requirement.

I’m not sure to understand. LW has automatic updates.

---

## Post 406 by @any1 — 2026-03-11T21:16:22Z

> [@win11.shading291](#):
>
> I’m not sure to understand. LW has automatic updates.

Technically we have automatic updates for all supported platforms. We just don’t currently support the MAR updates that Mozilla uses.

---

## Post 407 by @win11.shading291 — 2026-03-11T21:20:13Z

Ok, why does this matter? Even if you did support MAR updates, the updates wouldn’t be instant as you would still need to apply LW configs and own updates, no?

Just curious to understand, thanks.

---

## Post 408 by @any1 — 2026-03-11T21:22:46Z

> [@win11.shading291](#):
>
> Even if you did support MAR updates, the updates wouldn’t be instant as you would still need to apply LW configs and own updates, no?

[MAR files, short for Mozilla ARchive files](https://firefox-source-docs.mozilla.org/toolkit/mozapps/update/docs/MarFiles.html)

We don’t repackage a built Firefox, we build our own from source with our changes.

MAR updates is just another way we could deliver these updates instead of using our custom Windows updater or using rpm for example.

---

## Post 409 by @win11.shading291 — 2026-03-11T21:26:11Z

Thanks for the explanation.

I just wanted to clarify LW does have automatic update and respect that PG criteria. I don’t think the way you do it matters.

So I believe the only valid remaining point would be this:

> [@any1](#):
>
> TL;DR: [https://ossign.org/](https://ossign.org/), which has provided us the Windows cert, will soon also provide the required macOS signing certificate.

---

## Post 410 by @byte — 2026-03-11T22:31:01Z

> [@jonah](#):
>
> Must be available on Linux, macOS, and Windows.

Ahem…

Maybe we can create a poll to cancel this? This looks like “commercial guides” not about privacy.

> [@SYST3M_D3STR0YER](#):
>
> It is _available_ on macOS, just not through the more official sources when you install something on macOS.

This is even more right, that i wanted to explain.

* * *

PG should focus on what we do best: privacy!

Not distribution. Not cross-platform. This can be noted in guide separately.

If tool is good, users who want _privacy_ will find and install it themselves.

This requirement is ridiculous. Most of devs of best projects are non-profit hobby ones, so they don’t have money to pay evil corps.

And if Mac requirement is partially explainable, microslop? Seriously?

When shitdows ever was about privacy? Telemetry is privacy? Or maybe AI shit and ads is privacy?

* * *

P.S: LibreWolf devs, many thanks for your hard work! Best browser ever!

---

## Post 411 by @jonah — 2026-03-11T23:57:32Z

> [@byte](#):
>
> Maybe we can create a poll to cancel this?

Not the place. This is a LibreWolf discussion. Start a new #Site Development thread.

---

## Post 412 by @dada_goose — 2026-03-12T07:53:24Z

@any1

I’d always understood that LibreWolf was basically the same as Firefox with Arkenfox, have I got that wrong? Are there privacy or security benefits (other than ease of setup) from using LibreWolf over the Firefox and Arkenfox setup?

---

## Post 413 by @dngray — 2026-03-12T08:29:30Z

They do differ, I believe arkenfox is a little more strict in some ways though I forget which.

---

## Post 414 by @any1 — 2026-03-12T10:05:14Z

> [@dada_goose](#):
>
> I’d always understood that LibreWolf was basically the same as Firefox with Arkenfox, have I got that wrong?

It used to be similar to arkenfox but not sure how close we are at this point since I add things I stumble upon or when talking with Celenity.

> [@dada_goose](#):
>
> Are there privacy or security benefits (other than ease of setup) from using LibreWolf over the Firefox and Arkenfox setup?

You get some security benefits compared to Firefox, since they refuse to ship some mitigations because of performance loss or because some things become dormant and nobody has looked at them in years.

I backported some build-system changes from release 150 (we are currently on 148), so we can ship STL hardening early for all platforms, compared to Firefox, which currently has it only for macOS and has it planned for Windows in release 150 but nothing yet for Linux.

Also, the recently added per-site WebGL toggle can help reduce the attack surface compared to having to decide between having it on globally or off.

> [@dngray](#):
>
> They do differ, I believe arkenfox is a little more strict in some ways though I forget which.

I would have to look, but just by us currently still being on RFP, compared to arkenfox with the default broken FPP RFPTargets, we are more strict.

---

## Post 415 by @dada_goose — 2026-03-12T10:11:49Z

Thanks so much for the reply, really helpful.

---

## Post 416 by @dada_goose — 2026-03-12T11:01:03Z

Could I ask one further question…. The only thing that has prevented me from using LW regularly in the past is the way the 1Password extension behaves on MacOS. It logs me out everytime I close the browser and doesn’t seem to play nicely with the desktop app. Is this a know issue and is there a way around it?

---

## Post 417 by @privacy.slouchy — 2026-03-12T11:20:38Z

> **off topic: mulvad browser**
>
> > [@byte](#):
> >
> > mullvad browser is _commercial_ produc that can be used _only_ with mullvad VPN
> 
> This is incorrect. Mulvad Browser is FOSS; it is licensed under Mozilla Public License V2 & code is available on Github (though Im not sure if builds are reproducible). The browser does not require MulvadVPN; it can be used with a different VPN, or no VPN at all

---

## Post 418 by @any1 — 2026-03-12T11:25:50Z

Not sure what the issue was/is but it could be related to the macOS release not being signed. Could also be related to [Frequently Asked Questions – LibreWolf](https://librewolf.net/docs/faq/#how-do-i-get-native-messaging-to-work-1)

---

## Post 419 by @dada_goose — 2026-03-12T12:04:59Z

I tried adding the symbolic link but still can’t get it working, guess it must be to do with the not being signed. Thanks for the help.

---

## Post 420 by @byte — 2026-03-14T04:34:56Z

Also, i always wondered, why aren’t you packaged into official repos of Debian/Ubuntu and using extrepo?

I am not against this, but it is a little hard to explain newbies how to use terminal, since they just got used to GUI and app managers…

---

## Post 421 by @any1 — 2026-03-14T14:56:48Z

Since we already have our own repo, which allows us to ship updates much faster, there isn’t much need for it. It would also add additional maintenance we’d have to do. I wouldn’t be against having LibreWolf be packaged in the repos for Debian or Ubuntu, but it would have to be maintained by someone else.

---

## Post 422 by @bodin — 2026-03-14T19:51:29Z

@any1 Are containers redundant/not really necessary in Librewolf?

---

## Post 423 by @any1 — 2026-03-14T21:11:49Z

They serve the same role as they would in Firefox. I personally have never used them, though. You could use them to have multiple separated logins for the same site, for example.

---

## Post 424 by @bodin — 2026-03-14T21:17:41Z

I should have added more context.

The Librewolf FAQ/docs say this:

> ”Please also notice that dFPI makes containers and containers extensions redundant, unless you want to protect your privacy when visiting the same website multiple times, during the same browsing sessions.”

Is this still the case?

I usually put YouTube in a container. I have no idea if that is useful or helpful or useless but it is one of the more privacy invasive sites I use (don’t use Facebook or Twitter or TikTok etc) so I thought I should put it in a container (thinking it is like an isolated tab jail).

I do often have multiple YouTube tabs open.

Is using containers in this context redundant and unnecessary?

---

## Post 425 by @any1 — 2026-03-15T09:01:54Z

Are you logged into youtube and have it set to keep cookies?

---

## Post 426 by @bodin — 2026-03-15T13:04:32Z

No I am not logged in (I refuse to have a Google account), and have not made any cookie exceptions for YouTube.

---

## Post 427 by @any1 — 2026-03-15T14:31:56Z

Then you don’t really need it.

---

## Post 428 by @bodin — 2026-03-15T16:55:35Z

Thanks!

Is this something specific to Librewolf and how it deals with containers and tabs or would this also be true if I was using Firefox?

Is it Total Cookie Protection that makes using containers in this situation unnecessary? I am assuming TCP isolates cookies to a single tab.

Pretty impressive that this thread has ~43 _thousand_ views eh!?!

---

## Post 429 by @any1 — 2026-03-15T17:48:55Z

> [@bodin](#):
>
> Is this something specific to Librewolf and how it deals with containers and tabs or would this also be true if I was using Firefox?

Firefox behaves the same with Total Cookie Protection.

> [@bodin](#):
>
> Is it Total Cookie Protection that makes using containers in this situation unnecessary? I am assuming TCP isolates cookies to a single tab.

Not per tab but rather per top-level site you visit. [Firefox Rolls Out Total Cookie Protection By Default](https://blog.mozilla.org/en/mozilla/firefox-rolls-out-total-cookie-protection-by-default-to-all-users-worldwide/)

---

## Post 430 by @Blackbird — 2026-03-16T06:36:27Z

> [@any1](#):
>
> Firefox Rolls Out Total Cookie Protection By Default

“making Firefox the most private and secure major browser” :grinning_face_with_smiling_eyes:

---

## Post 431 by @bodin — 2026-03-25T22:52:43Z

Just wanted to add to this Librewolf monster thread…

To counter the narrative that Librewolf is slow to add upstream updates…at least on my system with Firefox 149, Librewolf beat Fedora (packages) with their update!

Librewolf just updated to 149 for me and Firefox is still 148.x.x.

Maybe it is a one off, maybe it is something about my system or how I have them both installed but I do not think so but I could be wrong.

Nice work @any1 and team!

Excited to see Firefox is adding an RPM format/version, that we will be able to get directly from them via their repo as far as I understand it.

---

## Post 432 by @DucksLive — 2026-03-25T23:01:53Z

Confirmed same on my Fedora Atomic Cosmic. Great work LW Team!

---

## Post 433 by @any1 — 2026-05-21T20:44:33Z

> [@Brave funded by Peter Thiel's VC firm](https://discuss.privacyguides.net/t/brave-funded-by-peter-thiels-vc-firm/37722/31):
>
> The rejection thread already goes through those concerns in detail. I’d rather point people there than restart the same debate here.

Would be interested in hearing why and not just pointing to this three year old topic.

---

## Post 434 by @dixon — 2026-06-21T18:12:32Z

Well, now I am considering switching from native Mozilla to Mullvad or LibreWolf. I think LibreWolf is more suitable for me, but I am new to this, never used it and have sensitive online accounts (banks + crypto)

Is LibreWolf trustworthy for this? As I see it is FOSS, which is actually good, but `sudo apt install librewolf` not working, no such package , which made me confused. If it is not available in repos, than there is some catch, right? Or I am being overparanoid?

Also, if I switch, what to do with [FROST attack](https://discuss.privacyguides.net/t/ars-technica-websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity/38171)? Now (in native Firefox) I am using [this workaround](https://discuss.privacyguides.net/t/ars-technica-websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity/38171/6)…

---

## Post 435 by @any1 — 2026-06-21T19:12:14Z

> [@dixon](#):
>
> Is LibreWolf trustworthy for this? As I see it is FOSS, which is actually good, but `sudo apt install librewolf` not working, no such package , which made me confused. If it is not available in repos, than there is some catch, right? Or I am being overparanoid?

> **[LibreWolf Browser](https://librewolf.net/installation/debian/)**
>
> A custom version of Firefox, focused on privacy, security and freedom.

You have to enable the extrepo first

> [@dixon](#):
>
> Also, if I switch, what to do with [FROST attack](https://discuss.privacyguides.net/t/ars-technica-websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity/38171)? Now (in native Firefox) I am using [this workaround](https://discuss.privacyguides.net/t/ars-technica-websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity/38171/6)…

I honestly wouldn’t worry about this and [toggling that preference causes breakage](https://codeberg.org/celenity/Phoenix/commit/6c959a74e5ada71a237d9f57452c2badce7776c2)

---

## Post 436 by @dixon — 2026-06-21T19:58:58Z

> [@any1](#):
>
> extrepo

This worked! Tnx! But now it is unsigned .deb? Or I am misunderstanding something?

> [@any1](#):
>
> [toggling that preference causes breakage](https://codeberg.org/celenity/Phoenix/commit/6c959a74e5ada71a237d9f57452c2badce7776c2)

Strange. I didn’t notice any issues

> [@any1](#):
>
> wouldn’t worry about this

Why? I think malicious website can just kill SSD on purpose with so huge writes

P.S: Wait a second… Are you a DEV?! :star_struck:

---

## Post 437 by @any1 — 2026-06-21T20:35:18Z

> [@dixon](#):
>
> This worked! Tnx! But now it is unsigned .deb? Or I am misunderstanding something?

No, it still checks the signature with the GPG key from the extrepo.

> [@dixon](#):
>
> Why? I think malicious website can just kill SSD on purpose with so huge writes

I meant in terms of fingerprinting, not a site just abusing the API.

> [@dixon](#):
>
> P.S: Wait a second… Are you a DEV?! :star_struck:

Yes, one of the people working on it

---

## Post 438 by @dixon — 2026-06-22T20:29:25Z

Today I finally switched to LibreWolf fully (it took some time, because I had to rewrite various bash scripts that was tied to vanilla firefox)

And it is awesome! Now I understand why everyone recommended me exactly LibreWolf.

Separate like for included UBlockOrigin.

Settings seems a little less rich than in vanilla firefox (for example lack of toggle to enfore private (aka “incognito”) window mode only, but I toggled with about:config)

Finally! No AI, no telemetry, no google shit (safe browsing). Added following lists to UBlockOrigin to slightly compensate my decision not to enable google safe browsing: Dandelion Sprout’s Anti-Malware, Online Malicious URL Blocklist, Phishing URL Blocklist

Good luck, teem! Put my vote to add it too!

---

## Post 439 by @any1 — 2026-06-22T20:36:52Z

> [@dixon](#):
>
> Settings seems a little less rich than in vanilla firefox (for example lack of toggle to enfore private (aka “incognito”) window mode only, but I toggled with about:config)

This was purposefully removed due to it being potentially fingerprintable and having other various issues associated with it. [Frequently Asked Questions – LibreWolf](https://librewolf.net/docs/faq/#why-cant-i-use-always-on-private-browsing)

---

## Post 440 by @Borgin — 2026-06-27T14:36:06Z

Hello everyone. LibreWolf really appeals to me, but so far I’ve been held back by the fact that it’s not in the official repositories of Linux distributions. Isn’t it possible to reach an agreement to get LW included? Thank you very much

---

## Post 441 by @any1 — 2026-06-27T18:00:46Z

> [@Borgin](#):
>
> Isn’t it possible to reach an agreement to get LW included?

There is nothing preventing LW from being included from Linux distributions other than someone going ahead and investing the time to do it.

---

## Post 442 by @Borgin — 2026-06-27T18:54:03Z

Hi Any. Shouldn’t LW be the most vested party in having this browser available in official Linux distribution repositories? Thanks so much!

---

## Post 443 by @any1 — 2026-06-27T19:16:15Z

> [@Borgin](#):
>
> Shouldn’t LW be the most vested party in having this browser available in official Linux distribution repositories?

Not really, considering we already provide our own repo for rpm/deb installs. The only benefit would be that no external repo would have to be added when installing LibreWolf.

Like I said, I would not be against someone else taking the initiative and getting it into the various distro repositories, but I currently lack the time. Considering that there are now planned weekly Firefox releases + unplanned ones too, I simply lack the time to also manage even more installation methods.

---

## Post 444 by @Borgin — 2026-06-27T20:02:01Z

Hi Any. I try to avoid adding third-party repositories to my Linux distributions. I’ll wait until that moment comes to install LW. But regardless of that, I really appreciate your work, dedication, and contributions. Thank you so much and good luck

---

## Post 445 by @any1 — 2026-06-27T20:22:28Z

> [@Borgin](#):
>
> I try to avoid adding third-party repositories to my Linux distributions. I’ll wait until that moment comes to install LW.

I assume that you won’t change your mind, but I will still argue against that stance for anyone else who might come across this in the future.

You are not gaining anything by refusing to use our or, in general, a third‑party repository directly from the developers, since you are already trusting them to provide the software.

Instead, you are adding another maintainer who will possibly provide questionable builds of the software and in most cases, slower updates.

---

## Post 446 by @Borgin — 2026-06-27T20:54:31Z

Hi Any. I understand your stance, however, by sticking to official distribution repositories I also ensure that the software is 100% compatible with the operating system, that it’s free of malware, since packages in official repos are reviewed before being made available and that I have centralized management and better control over the OS and its updates.

I hope you can see where I’m coming from and understand the benefits this brings.

That said, I’m always glad to hear other perspectives, and I really appreciate you taking the time to talk with me and explain your position.
