Vanadium (GrapheneOS Web Browser)

IronFox isn’t even recommended?

Look at what the lack of recommending Vanadium is already doing to people!

Safari is (rightfully) recommended on iOS, it makes sense for Vanadium to be recommended for Graphmeme users @fria

I don’t like when people saying “the best” because what may be best for me, may not be best for you.

But I kinda agree. I think they should keep the cross-platform criteria for the main browser page recommendations for catch-all the non-forum addicts but add an “honorable mentions” style page with more OS-specific recommendations like Vanadium on GOS, Trivalent on Fedora based distros. Maybe it is to much work idk.

They should also replace Firefox with LibreWolf on the main page.

Offtopic meme

iOS is lille different all browsers on iOS are based on WebKit anyways, so I think it makes sense why Safari recommended.

Safari isn’t recommended for Mac because I guess Mac support other browser engines. I’m just going with criteria logic.

If safari is only recommended for iOS, and Vanadium is only available for GrapheneOS, perhaps it would be better to just get rid of the mobile browser page altogether, and instead state on each respective OS overview page to just stick with the default browser. I don’t see the value in having a dedicated mobile browser page if every recommendation on there is going to be exclusive to just one mobile OS.

I thought Mull was replaced with an IronFox recommendation. My bad.

If we’re talking about privacy and security (which is what this forum is mainly about), then Vanadium is pretty much unmatched if you’re on GrapheneOS.

Of course, if you want things like E2EE sync, then Brave is the way to go.

Afaik Brave has the edge on fingerprinting protections over Vanadium, though Vanadium has substantially better security.

Resisting fingerprinting usually is done one of two ways: randomization and unified crowd blending. Randomizing is the most common and simple technique, basically it adds noise or fake data to existing metrics to make them different across visits and sessions. Ideally, this fully evades fingerprinting, since you will look different to every site. Typically it is generated per-load, meaning if you visit a webpage, then reload the webpage, the fingerprint will be slightly different. Brave offers a slightly different approach by offering a per-site per-session fingerprint, this is done by binding the randomized metrics to a site’s randomized session key. This will cause each site to have one static fingerprint for the session, but each site will have a different random fingerprint.

The other approach is unified crowd blending (unofficial term I’m using for convenience). This is often done in tandem with randomization to mask metrics that may be unique (such as Canvas rendering). Basically, the goal is to get all users to look as similar as possible. The most popular approach would be Apple’s Safari. Since Apple has good control over their hardware production, and Safari basically only runs on their hardware, then most of the metrics that depend on unique hardware combinations are basically identical. This gives the impression that most Safari users are potentially the same user. To my knowledge, Safari doesn’t really use randomization and it doesn’t really need to.

The issue with most anti-fingerprinting attempts is they rarely achieve either of these approaches very effectively. Firefox is often cited as a more privacy-friendly choice over Chrome, partly due to some fingerprinting resistance. The resistance Firefox offers is actually very weak, even when configured to be as strong as possible. Firefox does not really unify its userbase’s metrics, and the randomization it does offer is limited to basically just Canvas when Resist FingerPrinting or FingerPrinting Protections are on. There is also another major issue with toggling on these protections, the number of users doing the same.

This is one of the biggest issues with fingerprinting protection configurations of common browsers, they often create small userbases that look somewhat-similar to each other but are drastically different from 99% of the browser userbase. An example metaphor: you can wear a mask in a crowd, and yes no one can see your face, but you’re the only one wearing a mask in a crowd. There is a similar problem for more comprehensive solutions, like Brave and Mullvad Browser. They do offer a somewhat decent anti-fingerprinting solutions out of the box, but they also encourage customization (Mullvad via extensions, and Brave through Shields, flags, or the various bloat and crypto features), which in turn makes you unique.