Commit Graph
100 Commits
Author SHA1 Message Date
Thorin-OakenpantsandGitHub 4f3f789f28 Add files via upload 2022-02-25 23:15:01 +13:00
Thorin-OakenpantsandGitHub 6b6ed86b6c Update troubleshooting-help.md 2022-02-24 00:26:15 +00:00
Thorin-OakenpantsandGitHub 382b9181df Add files via upload 2022-02-20 19:00:32 +13:00
Thorin-OakenpantsandGitHub ba052105de Add files via upload 2022-02-14 05:38:13 +13:00
Thorin-OakenpantsandGitHub 4bd17611df Update troubleshooting-help.md 2022-02-13 13:11:55 +00:00
Thorin-OakenpantsandGitHub 41468d0d0b Update troubleshooting-help.md 2022-02-13 13:11:26 +00:00
Thorin-OakenpantsandGitHub a98b73c64e v97 (#1346) 2022-02-13 11:15:00 +00:00
Thorin-OakenpantsandGitHub 58e2618b9d dom.securecontext.whitelist_onions
replaced by dom.securecontext.allowlist_onions - https://bugzilla.mozilla.org/1744006
2022-02-09 20:00:43 +00:00
Thorin-OakenpantsandGitHub d61da93aad Update troubleshooting-help.md 2022-02-06 15:30:25 +00:00
Thorin-OakenpantsandGitHub 562127be87 Update troubleshooting-help.md 2022-02-06 15:27:50 +00:00
Thorin-OakenpantsandGitHub 89bee0e361 Add files via upload 2022-01-31 03:08:22 +13:00
Thorin-OakenpantsandGitHub 4c74f1bffb Update README.md 2022-01-30 08:53:08 +00:00
Thorin-OakenpantsandGitHub 0d9de9174a Update README.md 2022-01-30 03:23:06 +00:00
Thorin-OakenpantsandGitHub 45043537d8 Update README.md 2022-01-30 03:20:59 +00:00
Thorin-OakenpantsandGitHub cc7ca9d0fa cleanup dead images (#1353) 2022-01-29 05:24:41 +00:00
Thorin-OakenpantsandGitHub ac0820a5dc add last bits about ETP Strict/dFPI, closes #1337 2022-01-21 03:48:06 +00:00
Thorin-OakenpantsandGitHub 83b6d64e67 security.insecure_connection_text.enabled
AF has been using HTTPS-Only mode since v84, the interstitial is more than ample, padlock is still marked as insecure
2022-01-16 02:36:08 +00:00
Thorin-OakenpantsandGitHub b5bf2ee017 oophs, add removed item from last commit to 6050 2022-01-16 02:34:21 +00:00
Thorin-OakenpantsandGitHub 09d62d2302 remove 1273: "not Secure" text on insecure sites
AF has been using HTTPS-Only mode since v84, the interstitial is more than ample, padlock is still marked as insecure
2022-01-16 02:31:57 +00:00
Thorin-OakenpantsandGitHub 7a4676fe2d make 1601 setup tag more explicit, closes #1326 2022-01-15 05:25:11 +00:00
Thorin-OakenpantsandGitHub bc2aba3829 move last update pref to personal 2022-01-12 05:25:31 +00:00
Thorin-OakenpantsandGitHub 926a2d4ac8 v96 deprecated, #1325
also tidy the description to reflect that the setting is hidden
2022-01-12 05:09:17 +00:00
Thorin-OakenpantsandGitHub ab7380c93b HoM: tweak background request info 2022-01-11 09:21:37 +00:00
Thorin-OakenpantsandGitHub 06b8d8bfa3 move 0362 to don't touch 2022-01-07 17:29:26 +00:00
Thorin-OakenpantsandGitHub 7016c2050d move TLS 1.0/1.1 downgrades to don't bother
https://bugzilla.mozilla.org/show_bug.cgi?id=1745678
2021-12-30 03:15:56 +00:00
Thorin-OakenpantsandGitHub 2787da7f90 Update README.md 2021-12-24 06:04:38 +00:00
Thorin-OakenpantsandGitHub 7e18f8b473 tweak 2011
- FF85+ switched to using application regional locale
   - go to about:support > Internationalization & Localization (almost at the very end)
   - look at Application > Regional Preferences
- add test
2021-12-24 06:01:41 +00:00
Thorin-OakenpantsandGitHub d2510b014d move updates to personal
updating (app, extensions, ext cache) is not a privacy issue
- if you're willing to use Firefox but not trust updating, then I have two bricks to sell you: users who wish to disable it (to check changes first etc) and update in a timely manner, then that is on them - including any prompt fatigue
- same goes for extensions: the end-user installed them (and arkenfox only recommends a very select few) - the onus is on the end-user

The remaining ones I will deal with later
2021-12-23 23:42:28 +00:00
Thorin-OakenpantsandGitHub 87bd8683fa 2022: add browser.eme.ui.enabled
for those who want to remove DRM prompts and have no intention of enabling it
2021-12-23 21:22:41 +00:00
Thorin-OakenpantsandGitHub d48d3ad29a remove browser.eme.ui.enabled 2021-12-23 21:20:28 +00:00
Thorin-OakenpantsandGitHub 6675225ec4 make 0301 inactive
auto-updating is not a security nor a privacy risk, by default it should be enabled and it's on end-users if they want to disable it - does not affect windows users
2021-12-23 06:36:39 +00:00
Thorin-OakenpantsandGitHub bb56056a68 explain 0-RTT 2021-12-15 19:23:03 +00:00
Thorin-OakenpantsandGitHub 93f0ff89c8 move web notifcations to don't bother 2021-12-15 00:05:03 +00:00
Thorin-OakenpantsandGitHub 7811e912f4 make push notifications inactive
- they require SWers which are already blocked by virtue of permissions being session only
- also remove "dom.push.userAgentID" as this means prefsCleaner resets it and would wipe user's subscriptions
   - not adding "dom.push.userAgentID" to the cleanup script for the same reason
2021-12-14 13:25:46 +00:00
Thorin-OakenpantsandGitHub 238f1545f4 fixup thanks #fxbrit have a 🍥 fish cake 2021-12-13 14:15:25 +00:00
Thorin-OakenpantsandGitHub c269ac9f7d remove duplicate 2021-12-13 03:49:42 +00:00
Thorin-OakenpantsandGitHub 78297132b4 fix syntax 2021-12-12 15:44:39 +00:00
Thorin-OakenpantsandGitHub 8de87de050 update 0704: GIO, closes #1050 (#1300)
https://bugzilla.mozilla.org/show_bug.cgi?id=1666725
2021-12-12 15:41:55 +00:00
Thorin-OakenpantsandGitHub 8bc25b552d expand 0650 to include any removed item
this should reduce any dependency on the scratchpad script
2021-12-12 15:30:53 +00:00
Thorin-OakenpantsandGitHub c8c86262d7 enforce SmartBlock shims 2021-12-12 13:51:25 +00:00
Thorin-OakenpantsandGitHub f836e55363 tidy ETP stuff 2021-12-12 13:31:01 +00:00
Thorin-OakenpantsandGitHub 8cdb30cc08 make cookie pref active
@SkewedZeppelin ... https://github.com/arkenfox/user.js/issues/1051#issuecomment-991806497
2021-12-12 00:26:12 +00:00
Thorin-OakenpantsandGitHub 54810e333f typo 2021-12-11 19:17:43 +00:00
Thorin-OakenpantsandGitHub 7ec13c0323 sharedWorkers tweak
tested in FF91+. Seems as if sharedWorkers no longer requires an explicit `Allow`
2021-12-11 12:22:00 +00:00
Thorin-OakenpantsandGitHub af109d4696 tweak 7016 2021-12-11 11:15:34 +00:00
Thorin-OakenpantsandGitHub 460951df9e tidy, add instructions 2021-12-11 09:37:45 +00:00
Thorin-OakenpantsandGitHub 93874bda43 rename 2021-12-11 09:14:59 +00:00
Thorin-OakenpantsandGitHub 4ebabbb569 Delete arkenfox-clear-deprecated.js 2021-12-11 09:13:51 +00:00
Thorin-OakenpantsandGitHub 1f0dc1853d merge scratchpads into one 2021-12-11 09:13:09 +00:00
Thorin-OakenpantsandGitHub 13e5fe17b1 remove rfpalts (#1288) 2021-12-11 06:56:43 +00:00
Thorin-OakenpantsandGitHub ec7cb6a491 2702: partition service workers 2021-12-09 17:17:52 +00:00
Thorin-OakenpantsandGitHub d9f49bdf1f make 7017 clearer 2021-12-09 16:17:53 +00:00
Thorin-OakenpantsandGitHub d5bc6715cd remove web workers section
farewell parrot
2021-12-09 16:14:36 +00:00
Thorin-OakenpantsandGitHub 8860c90abf make service workers inactive
currently 3rd party service workers are blocked in FF95 when dFPI is enabled (which this version has should anyone update to 96-alpha)
   - but I get an error even on first party - https://arkenfox.github.io/TZP/tzp.html#storage
   - I get : service worker | test : enabled | failed: SecurityError
in FF96+ service workers they are covered by dFPI
  - see https://bugzilla.mozilla.org/show_bug.cgi?id=1731999
2021-12-09 14:31:41 +00:00
Thorin-OakenpantsandGitHub 4d5abd6cc3 tweak 8000 title
lets not encourage non-RFP users to see this as a sign to use them
2021-12-09 14:18:25 +00:00
Thorin-OakenpantsandGitHub de28689e76 flip from FPI to dFPI
I will tidy and expand 2700 entries later
2021-12-09 14:13:39 +00:00
Thorin-OakenpantsandGitHub 5d508e4242 move LSNG to don't touch 2021-12-09 14:05:47 +00:00
Thorin-OakenpantsandGitHub 1fc43574d6 move "cookie" permission info into 2801 2021-12-09 14:00:21 +00:00
Thorin-OakenpantsandGitHub 83602baa38 misc site storage/data prefs
been inactive since jesus was a baby
2021-12-09 13:47:57 +00:00
Thorin-OakenpantsandGitHub 0634a568ef remove redundant site data prefs
we've never used these
- service workers are disabled (or soon to be covered by dFPI when enabled) and sanitizing is already done (or will be done via enhanced cookie cleaning)
- storage API, storage access API: we sanitize on close, and sites are isolated by eTLD+1
2021-12-09 13:45:46 +00:00
Thorin-OakenpantsandGitHub 97322d6e8b various inactive FPI prefs 2021-12-09 12:31:38 +00:00
Thorin-OakenpantsandGitHub f7bba92c71 cleanout FPI section
farewell parrot
2021-12-09 12:28:45 +00:00
Thorin-OakenpantsandGitHub fe75baa79f move DNT to DON'T BOTHER 2021-12-09 11:44:51 +00:00
Thorin-OakenpantsandGitHub 72cc4d176e 0706: network.proxy.allow_bypass, closes #1292 2021-12-09 11:41:18 +00:00
Thorin-OakenpantsandGitHub 7e1b92567c 95 final 2021-12-08 12:13:47 +00:00
Thorin-OakenpantsandGitHub fec5168203 95 deprecated 2021-12-08 04:28:47 +00:00
Thorin-OakenpantsandGitHub b60a888da3 update WebRTC, closes #1282 2021-12-06 14:45:47 +00:00
Thorin-OakenpantsandGitHub ec595c3b95 fixup duplicate line 2021-12-05 19:59:33 +00:00
Thorin-OakenpantsandGitHub 9d61992c8c don't clear offlineApps on shutdown, #1291
- in v94 we switched to cookies lifetime as session, so users could use site exceptions to retain selected cookies (to stay logged in one assumes)
- that mean not deleting all cookies on shutdown
- but some login methods/types require more than cookies and also need the "site data" part of "cookies + site data" - that's the offlineApps part
- note: all site data (and cookies) is still cleared on close except site exceptions
2021-12-05 19:49:32 +00:00
Thorin-OakenpantsandGitHub fd860e6c69 flip RFP newwin max values, closes #1286 2021-12-04 10:23:59 +00:00
Thorin-OakenpantsandGitHub d1d20b897a wiki cleanup (#1289) 2021-12-04 09:36:09 +00:00
Thorin-OakenpantsandGitHub cf0102f71e fixup: from being flogged to death by overseers
thanks @dngray, also save some precious bytes .. polar bears know about scarce resources
2021-12-02 09:34:34 +00:00
Thorin-OakenpantsandGitHub 4dc5372257 0603: network.predictor.enable-prefetch
make active for Nighty users - see https://bugzilla.mozilla.org/show_bug.cgi?id=1506194
2021-11-30 13:29:19 +00:00
Thorin-OakenpantsandGitHub c2ddfd60bf tidy 79-91 removed items 2021-11-28 13:22:46 +00:00
Thorin-OakenpantsandGitHub 47de4f520b tidy 5505 2021-11-28 09:01:39 +00:00
Thorin-OakenpantsandGitHub 27977a16ad 2652: browser.download.alwaysOpenPanel
FYI: https://bugzilla.mozilla.org/1738372

There is a small privacy issue with shoulder surfers, but in reality, this just needs to happen IMO
- we already prompt where to save, but even if we didn't, we also know we clicked or initiated a download
   - unless it's a drive by or user-gesture trickery - which is why we prompt
- the download icon is shown (if hidden) and the throbber/accent color go to work
- users can always click the icon to show entries (and open folder etc)
- this maintains the current behavior in FF94
2021-11-25 06:49:38 +00:00
Thorin-OakenpantsandGitHub 4b393b9b12 start 95-alpha 2021-11-24 01:09:10 +00:00
Thorin-OakenpantsandGitHub 6027aaa45d fixup warnOnQuitShortcut 2021-11-23 12:02:50 +00:00
Thorin-OakenpantsandGitHub cbfb8abf15 94 final 2021-11-23 07:11:43 +00:00
Thorin-OakenpantsandGitHub 58d0161b67 add warnOnQuitShortcut, closes #1270 2021-11-23 07:05:01 +00:00
Thorin-OakenpantsandGitHub 6b351a9458 fixup trade-offs
anti-fingerprinting doesn't fit here: it's not a major component or priority of this user.js, and only a few prefs outside RFP (as a robust built-in browser solution that defeats naive scripts) have anything to do with it
2021-11-22 18:15:53 +00:00
Thorin-OakenpantsandGitHub c9e4cac618 tweak webRTC
webRTC will be overhauled... but not today... in the meantime
- remove dead link before @dngray has a hernia
- correctly refer to the type of IP leak
2021-11-22 18:08:07 +00:00
Thorin-OakenpantsandGitHub 34bd3c5a04 consolidate/simplify sanitizing, fixes #1256
move all sanitizing on exit prefs into 2800

switch to cookie lifetime as session
- now users can utilize exceptions (as allow)
- session cookies still block service workers (which we disable anyway)
- we still block 3rd party cookies (until we move to dFPI)
- we still have defense in depth for 3rd party cookies with 2803
- we still bulk sanitize offlineApps on exit: localStorage, service worker cache, QuotaManager (IndexedDB, asm-cache)
   - i.e you get to keep the cookies only IF you add an exception

add `privacy.clearsitedata.cache.enabled`
2021-11-22 05:40:49 +00:00
Thorin-OakenpantsandGitHub 2f88ca2e40 misc
- move DoH so it has room to grow
- tidy privacy.clearOnShutdown, privacy.cpd
2021-11-18 01:28:21 +00:00
Thorin-OakenpantsandGitHub e2e7f9c647 font vis changes (#1275) 2021-11-16 11:56:20 +00:00
Thorin-OakenpantsandGitHub f8932dced1 remove ambiguous line
The point was that google have said (stated in policy, but fuck knows where that is located these days) that it is anonymized and not used for tracking. It's an API used by **_4 billion devices_** - the API has privacy policies for use. If a whistleblower or someone else found out that google was using this to enhance their user profiling, then all hell would break loose. And they don't even need this to fuel their ad revenue. It is provided, gratis, to the web to help ensure security - they wouldn't dare taint it and get it caught up in a privacy scandal involving **+4 billion devices_**. And in all this time (since 2007), there has been no such whistleblower or proof it is used to track or announcements by google of changes to the contrary.

Anyway, a quick search brings up
- Here is their policy - https://www.google.com/intl/en_us/privacy/browsing.html - it's empty and points to
- https://www.google.com/intl/en/chrome/privacy/
   - and if you scroll down to "Safe Browsing practices" it doesn't say anything about privacy policies for the API itself (or the owner of the API) - it just spells out what happens in chrome
- I'm not going to bother to look any further and find a history of policy changes

Anyway, this is Firefox and hashes are part hashes bundled with other real hashes - and we turned off real time binary checks. So this line can fuck the fuck off. It was meant to reassure those who want the security of real-time binary checks, that privacy "shouldn't" be an issue, but I'm not going to expand on it
2021-11-07 06:48:45 +00:00
Thorin-OakenpantsandGitHub 17beb468f1 tweak 1510 default info 2021-11-04 22:44:23 +00:00
Thorin-OakenpantsandGitHub bd59131d3e default changes, missed one 2021-11-04 22:38:16 +00:00
Thorin-OakenpantsandGitHub 0f8217ad60 cleanup sanitizing-on-close prefs 2021-11-04 16:18:35 +00:00
Thorin-OakenpantsandGitHub 1515897449 default changes 2021-11-02 16:07:42 +00:00
Thorin-OakenpantsandGitHub ba92918d38 don't disable system addon updates, closes #1251 2021-10-26 10:16:42 +00:00
Thorin-OakenpantsandGitHub 094356e073 0706: add reference 2021-10-25 20:56:18 +00:00
Thorin-OakenpantsandGitHub 7d68a32971 start 94-alpha
- and remove obsolete ESR78 notations
- note: we leave the deprecated ESR78.x section and item 6050 until v95 so users upgrading to ESR91 can easily reset those prefs with prefsCleaner
2021-10-25 17:41:16 +00:00
Thorin-OakenpantsandGitHub 85438d00e4 v93 deprecated 2021-10-12 08:23:46 +00:00
Thorin-OakenpantsandGitHub a764149520 v92 2021-10-11 13:56:38 +00:00
Thorin-OakenpantsandGitHub 535346df87 Delete arkenfox-clear-RFP-alternatives.js 2021-10-10 23:55:39 +00:00
Thorin-OakenpantsandGitHub 412c8f9f94 0807 urlbar contextual suggestions, #1257 2021-10-09 07:14:20 +00:00
Thorin-OakenpantsandGitHub 380a88ee57 oophs 2021-10-05 11:14:16 +00:00
Thorin-OakenpantsandGitHub 8404e8a59c tidy, closes #1260 2021-10-05 03:04:14 +00:00
Thorin-OakenpantsandGitHub b37df0bcfe embiggen 4500, #1218 2021-09-25 02:32:48 +00:00