You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/browsers.en.md
+72-42Lines changed: 72 additions & 42 deletions
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: "Web Browsers"
3
3
icon: octicons/browser-16
4
4
---
5
-
These are our current web browser recommendations and settings. We recommend keeping extensions to a minimum: they have privileged access within your browser, require you to trust the developer, can make you [stand out](https://en.wikipedia.org/wiki/Device_fingerprint#Browser_fingerprint), and [weaken](https://groups.google.com/a/chromium.org/g/chromium-extensions/c/0ei-UCHNm34/m/lDaXwQhzBAAJ) site isolation.
5
+
These are our currently recommended web browsers and configurations. In general, we recommend keeping extensions to a minimum: they have privileged access within your browser, require you to trust the developer, can make you [stand out](https://en.wikipedia.org/wiki/Device_fingerprint#Browser_fingerprint), and [weaken](https://groups.google.com/a/chromium.org/g/chromium-extensions/c/0ei-UCHNm34/m/lDaXwQhzBAAJ) site isolation.
6
6
7
7
## General Recommendations
8
8
@@ -12,7 +12,7 @@ These are our current web browser recommendations and settings. We recommend kee
**Tor Browser** is the choice if you need anonymity. This browser provides you with access to the Tor Bridges and [Tor Network](https://en.wikipedia.org/wiki/Tor_(network)), along with extensions that can be automatically configured to fit its three security levels - *Standard*, *Safer* and *Safest*. We recommend that you do not change any of Tor Browser's default configurations outside of the standard security levels.
15
+
**Tor Browser** is the choice if you need anonymity. This browser provides you with access to the Tor Bridges and [Tor Network](https://en.wikipedia.org/wiki/Tor_(network)), along with extensions that can be automatically configured to fit its three security levels: *Standard*, *Safer* and *Safest*. We recommend that you do not change any of Tor Browser's default configurations outside of the standard security levels.
You should **never** install any additional extensions on Tor Browser, including the ones we suggest for Firefox. Browser extensions make you stand out from other people on the Tor network, and make your browser easier to [fingerprint](https://support.torproject.org/glossary/browser-fingerprinting).
30
+
You should **never** install any additional extensions on Tor Browser, including the ones we suggest for Firefox. Browser extensions make you stand out from others on the Tor network, thus making your browser easier to [fingerprint](https://support.torproject.org/glossary/browser-fingerprinting).
31
31
32
-
## Desktop Browser Recommendations
32
+
## Desktop Recommendations
33
33
34
34
### Firefox
35
35
@@ -54,7 +54,7 @@ These are our current web browser recommendations and settings. We recommend kee
54
54
55
55
#### Recommended Configuration
56
56
57
-
Tor Browser is the only way to truly browse the internet anonymously. When you use Firefox we recommend changing the following settings to protect your privacy from certain parties, but all browsers other than Tor will be traceable by *somebody* in some regard or another.
57
+
Tor Browser is the only way to truly browse the internet anonymously. When you use Firefox we recommend changing the following settings to protect your privacy from certain parties, but all browsers other than [Tor Browser](#tor-browser) will be traceable by *somebody* in some regard or another.
58
58
59
59
These options can be found in :material-menu: → **Settings** → **Privacy & Security**.
60
60
@@ -114,72 +114,101 @@ The [Arkenfox project](https://github.com/arkenfox/user.js) provides a set of ca
**Brave** is built upon the Chromium browser, featuring a built in ad blocker and some [privacy features](https://brave.com/privacy-features/) enabled by default.
117
+
**Brave Browser** includes a built in content blocker and [privacy features](https://brave.com/privacy-features/), many of which are enabled by default.
118
118
119
-
We only recommend Brave as a desktop browser. There are better [alternatives](#mobile-browser-recommendations) on mobile platforms.
119
+
Brave is built upon the Chromium web browser project, so it should feel familiar and have minimal website compatibility issues.
1. We advise against using the Flatpak version of Brave as it is believed to feature a weaker sandboxing system. As well, the package is **not** maintained by Brave Software, Inc.
130
133
131
134
#### Recommended Configuration
132
135
136
+
Tor Browser is the only way to truly browse the internet anonymously. When you use Brave we recommend changing the following settings to protect your privacy from certain parties, but all browsers other than the [Tor Browser](#tor-browser) will be traceable by *somebody* in some regard or another.
137
+
138
+
These options can be found in :material-menu: → **Settings**.
139
+
133
140
##### Shields
134
141
135
-
Brave has privacy options such as ad and tracker blocking. It also includes some antifingerprinting features in the[Shields](https://support.brave.com/hc/en-us/articles/360022973471-What-is-Shields-)component. We suggest configuring these options [globally](https://support.brave.com/hc/en-us/articles/360023646212-How-do-I-configure-global-and-site-specific-Shields-settings-) across all pages that you visit.
142
+
Brave includes some anti-fingerprinting measures in its[Shields](https://support.brave.com/hc/en-us/articles/360022973471-What-is-Shields-)feature. We suggest configuring these options [globally](https://support.brave.com/hc/en-us/articles/360023646212-How-do-I-configure-global-and-site-specific-Shields-settings-) across all pages that you visit.
136
143
137
-
We recommend setting *Aggressive* which can be found in :material-menu: **Settings** → **Shields** → **Trackers & ads blocking**.
144
+
Shields' options can be downgraded on a per-site basis as needed, but by default we recommend setting the following:
138
145
139
-
We also suggest changing the fingerprinting blocker to *Strict* in :material-menu: **Settings** → **Shields** → **Fingerprint blocking**. You can always downgrade it if you need to on a per-site basis.
146
+
<divclass="annotate"markdown>
140
147
141
-
!!! danger "Do not use brave://adblock!"
142
-
143
-
Brave allows users to select additional adblock filters by visiting brave://adblock. We recommend that you do not use this feature and stick to the default settings provided by the Brave Shield to not stand out from other braves users and to not increase your attack surface. If there is a vulnerability in the Shield, third party filters can provide malicious rules to exploit it.
148
+
-[x] Select **Aggressive** under Trackers & ads blocking
149
+
150
+
??? warning "Use default filter lists"
151
+
Brave allows you to select additional content filters within the internal `brave://adblock` page. We advise against using this feature; instead, keep the default filter lists. Using extra lists will make you stand out from other Brave users and may also increase attack surface if there is an exploit in Brave and a malicious rule is added to one of the lists you use.
152
+
153
+
-[x] (Optional) Select **Block Scripts** (1)
154
+
-[x] Select **Strict, may break sites** under Block fingerprinting
155
+
156
+
</div>
157
+
158
+
1. This option provides functionality similar to uBlock Origin's advanced [blocking modes](https://github.com/gorhill/uBlock/wiki/Blocking-mode) or the [NoScript](https://noscript.net/) extension.
144
159
145
160
##### Social media blocking
146
161
147
-
Disable social media components in :material-menu: **Settings** → **Social media blocking**.
162
+
-[ ] Uncheck all social media components
148
163
149
164
##### Privacy and Security
150
165
151
-
There are a few options in here you may want to change:
152
-
153
-
- Set the [*WebRTC IP Handling Policy*](https://support.brave.com/hc/en-us/articles/360017989132-How-do-I-change-my-Privacy-Settings-#webrtc) to *Disable Non-Proxied UDP* in :material-menu: **Settings** → **Privacy and Security**.
166
+
-[ ] Select **Disable Non-Proxied UDP** under [WebRTC IP Handling Policy](https://support.brave.com/hc/en-us/articles/360017989132-How-do-I-change-my-Privacy-Settings-#webrtc)
167
+
-[ ] Uncheck **Use Google services for push messaging**
-[ ] Uncheck **Automatically send daily usage ping to Brave**
156
-
-Enable *Always use secure connections* in :material-menu:**Settings** → **Privacy and Security**→ **Security**.
170
+
-[x] Select **Always use secure connections** in the**Security**menu
157
171
158
-
##### Sanitizing on close
172
+
!!! important "Sanitizing on Close"
173
+
- [x] Select **Clear cookies and site data when you close all windows** in the *Cookies and other site data* menu
159
174
160
-
Select all items in *Clear browsing data* except for *Site and Shields Settings*in :material-menu: **Settings** → **Privacy and Security** → **Clear browsing data** → **On exit**.
175
+
If you wish to stay logged in to a particular site you visit often, you can set exceptions on a per-site basis under the *Customized behaviors* section.
161
176
162
177
##### Extensions
163
178
164
-
Disable the extensions you do not use in :material-menu: **Settings** → **Extensions**
179
+
Disable the extensions you do not use in **Extensions**
180
+
181
+
<divclass="annotate"markdown>
165
182
166
183
-[ ] Uncheck **Hangouts**
167
-
-[ ] Uncheck **Private window with Tor**
184
+
-[ ] Uncheck **Private window with Tor** (1)
168
185
-[ ] Uncheck **WebTorrent**
169
186
170
-
Brave is **not** as resistant to fingerprinting as the Tor Browser and far fewer people use Brave with Tor, so you will stand out. Where [strong anonymity is required](https://support.brave.com/hc/en-us/articles/360018121491-What-is-a-Private-Window-with-Tor-Connectivity-) use the [Tor Browser](#tor-browser).
187
+
</div>
188
+
189
+
1. Brave is **not** as resistant to fingerprinting as the Tor Browser and far fewer people use Brave with Tor, so you will stand out. Where [strong anonymity is required](https://support.brave.com/hc/en-us/articles/360018121491-What-is-a-Private-Window-with-Tor-Connectivity-) use the [Tor Browser](#tor-browser).
171
190
172
191
##### IPFS
173
192
174
-
InterPlanetary File System (IPFS) is a decentralized peer-to-peer network for storing and sharing data in a distributed filesystem. Unless you use it set *Method to resolve IPFS resources* to *Disabled* in :material-menu: **Settings** → **IPFS**.
193
+
InterPlanetary File System (IPFS) is a decentralized, peer-to-peer network for storing and sharing data in a distributed filesystem. Unless you use the feature, disable it.
194
+
195
+
-[ ] Select **Disabled** on Method to resolve IPFS resources
196
+
197
+
##### Additional settings
198
+
199
+
Under the system *System* menu
175
200
176
-
##### Background apps
201
+
<divclass="annotate"markdown>
177
202
178
-
Disable background apps in :material-menu: **Settings** → **Additional settings** → **System** → **Continue running apps when Brave is closed**.
203
+
-[ ] Uncheck **Continue running apps when Brave is closed** to disable background apps (1)
179
204
180
-
## Mobile Browser Recommendations
205
+
</div>
181
206
182
-
Firefox on Android is still less secure than Chromium-based alternatives: Mozilla's engine, [GeckoView](https://mozilla.github.io/geckoview/), has yet to support [site isolation](https://hacks.mozilla.org/2021/05/introducing-firefox-new-site-isolation-security-architecture) or enable [isolatedProcess](https://bugzilla.mozilla.org/show_bug.cgi?id=1565196).
207
+
1. This option is not present on all platforms.
208
+
209
+
## Mobile Recommendations
210
+
211
+
On Android, Firefox is still less secure than Chromium-based alternatives: Mozilla's engine, [GeckoView](https://mozilla.github.io/geckoview/), has yet to support [site isolation](https://hacks.mozilla.org/2021/05/introducing-firefox-new-site-isolation-security-architecture) or enable [isolatedProcess](https://bugzilla.mozilla.org/show_bug.cgi?id=1565196).
183
212
184
213
On iOS, any app that can browse the web is [restricted](https://developer.apple.com/app-store/review/guidelines) to using an Apple-provided [WebKit framework](https://developer.apple.com/documentation/webkit), so there is little reason to use a third-party web browser.
185
214
@@ -193,10 +222,11 @@ On iOS, any app that can browse the web is [restricted](https://developer.apple.
- [:pg-f-droid: F-Droid](https://www.bromite.org/fdroid) ([Neo Store](/android/#neo-store) users can enable the *Bromite repository* in :material-dots-vertical: → **Repositories**)
Additional filter lists do slow things down and may increase your attack surface, so only apply what you need. If there is a vulnerability in uBlock Origin, third party filters can provide malicious rules to exploit it.
329
+
!!! warning "Use default filter lists"
330
+
331
+
Additional filter lists can impact performance may increase attack surface. Only apply what you need. If there is a [vulnerability in uBlock Origin](https://portswigger.net/research/ublock-i-exfiltrate-exploiting-ad-blockers-with-css) a third party filter could add malicious rules that can potentially steal user data.
**AdGuard for Safari** is a free and open-source content-blocking extension for Safari that uses the native [Content Blocker API](https://developer.apple.com/documentation/safariservices/creating_a_content_blocker).
339
+
**AdGuard for Safari** is a free and open-source content-blocking extension for Safari that uses the native [Content Blocker API](https://developer.apple.com/documentation/safariservices/creating_a_content_blocker).
310
340
311
341
We suggest enabling the filters labled *#recommended* under the "Ad Blocking" and "Privacy" [content blockers](https://kb.adguard.com/en/safari/overview#content-blockers). The *#recommended* filters can also be enabled for the "Social Widgets" and "Annoyances" content blockers, but they may break some social media functions.
312
342
@@ -345,7 +375,7 @@ Running a Snowflake proxy is low-risk, even moreso than running a Tor relay or b
345
375
346
376
**Terms of Service; Didn't Read** grades websites based on their terms of service agreements and privacy policies. It also gives short summaries of those agreements. The analyses and ratings are published transparently by a community of reviewers.
0 commit comments