2024-01-31 12:43:10 +01:00
|
|
|
# Chromium policies
|
|
|
|
|
2024-02-12 16:10:51 +01:00
|
|
|
- https://chromeenterprise.google/policies/
|
|
|
|
|
2024-01-31 12:43:10 +01:00
|
|
|
<!-- editorconfig-checker-disable -->
|
|
|
|
<!-- prettier-ignore-start -->
|
|
|
|
|
|
|
|
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
|
|
|
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
|
|
|
|
|
|
|
- [`aminda-extensions.json`](#aminda-extensionsjson)
|
2024-02-07 16:07:54 +01:00
|
|
|
- [Silk - Privacy Pass Client for the browser](#silk---privacy-pass-client-for-the-browser)
|
2024-05-11 15:46:20 +02:00
|
|
|
- [uBlock Origin](#ublock-origin)
|
2024-02-07 09:38:15 +01:00
|
|
|
- [Fedora User Agent](#fedora-user-agent)
|
2024-04-21 08:58:30 +02:00
|
|
|
- [IPvFooBar](#ipvfoobar)
|
2024-02-28 19:04:08 +01:00
|
|
|
- [AdNauseam](#adnauseam)
|
2024-05-11 15:46:20 +02:00
|
|
|
- [uBlock Origin](#ublock-origin-1)
|
2024-02-07 09:38:15 +01:00
|
|
|
- [Bitwarden](#bitwarden)
|
|
|
|
- [Privacy Badger](#privacy-badger)
|
2024-04-27 09:08:43 +02:00
|
|
|
- [`black-theme-colour.json`](#black-theme-colourjson)
|
2024-04-16 06:15:30 +02:00
|
|
|
- [`brave-shields-disabled.json`](#brave-shields-disabledjson)
|
2024-04-16 06:11:55 +02:00
|
|
|
- [`disable-brave-rewards-wallet.json`](#disable-brave-rewards-walletjson)
|
|
|
|
- [`disable-brave-tor.json`](#disable-brave-torjson)
|
2024-04-10 09:53:37 +02:00
|
|
|
- [`disable-brave-vpn.json`](#disable-brave-vpnjson)
|
2024-02-07 09:46:57 +01:00
|
|
|
- [`disable-floc.json`](#disable-flocjson)
|
2024-04-25 13:01:54 +02:00
|
|
|
- [`disable-incognito.json.badidea`](#disable-incognitojsonbadidea)
|
2024-04-19 07:24:29 +02:00
|
|
|
- [`doh-cloudflare-secure.json`](#doh-cloudflare-securejson)
|
2024-04-21 13:00:39 +02:00
|
|
|
- [`doh-unlocked-unset.json`](#doh-unlocked-unsetjson)
|
2024-02-07 09:51:12 +01:00
|
|
|
- [`doh-dns0.json`](#doh-dns0json)
|
2024-03-23 11:15:21 +01:00
|
|
|
- [`doh-mullvad-base.json`](#doh-mullvad-basejson)
|
2024-04-10 09:53:37 +02:00
|
|
|
- [`doh-quad9-ecs.json`](#doh-quad9-ecsjson)
|
2024-04-25 13:01:54 +02:00
|
|
|
- [`doh-quad9-insecure-ecs.json.badidea`](#doh-quad9-insecure-ecsjsonbadidea)
|
|
|
|
- [`doh-quad9-insecure.json.badidea`](#doh-quad9-insecurejsonbadidea)
|
2024-04-21 10:35:28 +02:00
|
|
|
- [`doh-quad9.json`](#doh-quad9json)
|
2024-02-07 09:46:57 +01:00
|
|
|
- [`enable-ech-ocsp.json`](#enable-ech-ocspjson)
|
2024-04-16 06:15:30 +02:00
|
|
|
- [`enable-labs.json`](#enable-labsjson)
|
2024-03-28 17:57:29 +01:00
|
|
|
- [`fix-edge-search.json`](#fix-edge-searchjson)
|
2024-04-25 13:01:54 +02:00
|
|
|
- [`force-incognito.json.badidea`](#force-incognitojsonbadidea)
|
2024-01-31 13:12:21 +01:00
|
|
|
- [`https-everywhere.json`](#https-everywherejson)
|
2024-03-23 11:15:21 +01:00
|
|
|
- [`README.md`](#readmemd)
|
2024-01-31 12:43:10 +01:00
|
|
|
|
|
|
|
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
|
|
|
|
|
|
|
<!-- prettier-ignore-end -->
|
|
|
|
<!-- editorconfig-checker-enable -->
|
|
|
|
|
|
|
|
## `aminda-extensions.json`
|
|
|
|
|
|
|
|
As I cannot separate the keys to multiple files I am forced to keep them in
|
|
|
|
one and separate by what the file does, `aminda-extensions.json` is unlikely
|
|
|
|
to overlap with someone else.
|
|
|
|
|
|
|
|
Changing `normal_installed` to `force_installed` would also prevent
|
|
|
|
uninstallation.
|
|
|
|
|
2024-04-21 08:58:30 +02:00
|
|
|
This does contain some bloat or something not necessary in all situations or
|
|
|
|
even overlapping extensions, but there is an important side goal of _teaching
|
|
|
|
users to disable extraneous extensions they don't need_ (unless I decide they
|
|
|
|
do need something and thus it's `force_installed`.
|
|
|
|
|
2024-02-17 17:25:37 +01:00
|
|
|
### [Silk - Privacy Pass Client for the browser](https://chrome.google.com/webstore/detail/ajhmfdgkijocedmfjonnpjfojldioehi)
|
2024-02-07 16:07:54 +01:00
|
|
|
|
|
|
|
- `ajhmfdgkijocedmfjonnpjfojldioehi`
|
|
|
|
|
|
|
|
Silk or Privacy Pass has a chance of decreasing the amount of captchas
|
|
|
|
especially from Cloudflare when "suspicious" traffic is detected.
|
|
|
|
|
2024-02-11 12:13:13 +01:00
|
|
|
To intentionally trigger it and what should be allowed in NoScript:
|
|
|
|
|
|
|
|
- https://captcha.website
|
|
|
|
- https://issuance.privacypass.cloudflare.com
|
|
|
|
|
2024-05-11 15:46:20 +02:00
|
|
|
### uBlock Origin
|
2024-02-11 12:11:37 +01:00
|
|
|
|
2024-05-11 15:46:20 +02:00
|
|
|
- `cjpalhdlnbpafiamejdnhcphjbkeiagm`
|
2024-02-11 12:11:37 +01:00
|
|
|
|
2024-05-11 15:46:20 +02:00
|
|
|
Blocked for Ad Nauseam
|
2024-02-26 11:20:47 +01:00
|
|
|
|
2024-02-17 17:25:37 +01:00
|
|
|
### [Fedora User Agent](https://chrome.google.com/webstore/detail/hojggiaghnldpcknpbciehjcaoafceil)
|
2024-01-31 12:43:10 +01:00
|
|
|
|
2024-02-07 09:46:57 +01:00
|
|
|
- `hojggiaghnldpcknpbciehjcaoafceil`
|
|
|
|
|
2024-01-31 12:43:10 +01:00
|
|
|
Communicates websites that Ubuntu isn't the only Linux distribution and makes
|
|
|
|
some offer rpm packages directly.
|
|
|
|
|
2024-04-21 08:58:30 +02:00
|
|
|
### [IPvFooBar](https://chromewebstore.google.com/detail/ipvfoobar/iimpkhokkfekbpmoamlmcndclohnehhk)
|
|
|
|
|
|
|
|
- `iimpkhokkfekbpmoamlmcndclohnehhk`
|
|
|
|
|
2024-02-28 19:04:08 +01:00
|
|
|
### [AdNauseam](https://microsoftedge.microsoft.com/addons/detail/adnauseam/mlojlfildnehdpnlmpkeiiglhhkofhpb)
|
|
|
|
|
|
|
|
- `mlojlfildnehdpnlmpkeiiglhhkofhpb`
|
|
|
|
|
|
|
|
Complementing PrivacyBadger with an adblocker so first profile runs have at
|
|
|
|
least something to block Malvertising now that I no longer enable NoScript out
|
|
|
|
of the box.
|
|
|
|
|
2024-05-11 15:46:20 +02:00
|
|
|
### uBlock Origin
|
2024-04-10 10:03:19 +02:00
|
|
|
|
2024-05-11 15:46:20 +02:00
|
|
|
- `odfafepnkmbhccpbejgmiehpchacaeak`
|
2024-04-10 10:03:19 +02:00
|
|
|
|
2024-05-11 15:46:20 +02:00
|
|
|
yes, it's the second time ,one is edge, one is chrome
|
2024-04-10 10:03:19 +02:00
|
|
|
|
2024-02-17 17:25:37 +01:00
|
|
|
### [Bitwarden](https://chrome.google.com/webstore/detail/nngceckbapebfimnlniiiahkandclblb)
|
2024-02-07 09:34:43 +01:00
|
|
|
|
2024-02-07 09:38:15 +01:00
|
|
|
- `nngceckbapebfimnlniiiahkandclblb`
|
2024-02-07 09:34:43 +01:00
|
|
|
|
2024-02-07 09:38:15 +01:00
|
|
|
The password manager of my choice.
|
|
|
|
|
2024-02-17 17:25:37 +01:00
|
|
|
### [Privacy Badger](https://chrome.google.com/webstore/detail/pkehgijcmpdhfbdbbnkijodmdjhbjlgp)
|
2024-02-07 09:38:15 +01:00
|
|
|
|
|
|
|
- `pkehgijcmpdhfbdbbnkijodmdjhbjlgp`
|
|
|
|
|
|
|
|
Configured to learn locally and also in incognito as opposed to only relying
|
|
|
|
on vendor list. Also not display the "Welcome to Privacy Badger screen".
|
|
|
|
|
|
|
|
See also:
|
|
|
|
|
|
|
|
- https://github.com/EFForg/privacybadger/blob/master/doc/admin-deployment.md
|
|
|
|
- https://github.com/EFForg/privacybadger/blob/master/src/data/schema.json
|
2024-02-07 09:34:43 +01:00
|
|
|
|
2024-04-27 09:08:43 +02:00
|
|
|
## `black-theme-colour.json`
|
|
|
|
|
|
|
|
Sets the theme colour as black. This is managed instead of recommended,
|
|
|
|
because even the recommended policy seems to block theme changing.
|
|
|
|
|
2024-04-16 06:15:30 +02:00
|
|
|
## `brave-shields-disabled.json`
|
|
|
|
|
|
|
|
Allowlist for sites where I think Brave Shields may be breaking things. Similar is also in
|
|
|
|
`aminda-extensions.json` for Privacy Badger.
|
|
|
|
|
2024-04-16 06:11:55 +02:00
|
|
|
## `disable-brave-rewards-wallet.json`
|
|
|
|
|
2024-04-16 06:15:30 +02:00
|
|
|
Disables Brave rewards and wallet.
|
2024-04-16 06:11:55 +02:00
|
|
|
|
|
|
|
## `disable-brave-tor.json`
|
|
|
|
|
2024-04-16 06:15:30 +02:00
|
|
|
Disables Tor in Brave as I recommend using Tor Browser instead.
|
2024-04-16 06:11:55 +02:00
|
|
|
|
2024-04-10 09:53:37 +02:00
|
|
|
## `disable-brave-vpn.json`
|
|
|
|
|
|
|
|
Disables Brave VPN, which is the most annoying feature that has group policy
|
|
|
|
that I can see.
|
|
|
|
|
2024-02-07 09:46:57 +01:00
|
|
|
## `disable-floc.json`
|
|
|
|
|
|
|
|
Disables floc or ad topics that are against privacy.
|
|
|
|
|
|
|
|
- https://start.duckduckgo.com/?q=google+floc+privacy+topics
|
|
|
|
|
2024-04-25 13:01:54 +02:00
|
|
|
## `disable-incognito.json.badidea`
|
2024-02-07 09:46:57 +01:00
|
|
|
|
|
|
|
Disables incognito mode. I don't recommend this.
|
|
|
|
|
2024-04-19 07:24:29 +02:00
|
|
|
## `doh-cloudflare-secure.json`
|
|
|
|
|
2024-04-21 13:00:39 +02:00
|
|
|
Sets Cloudflare with malware protection as the forced DNS-over-HTTPS server.
|
2024-04-19 07:24:29 +02:00
|
|
|
|
2024-04-21 13:00:39 +02:00
|
|
|
## `doh-unlocked-unset.json`
|
2024-02-07 09:51:12 +01:00
|
|
|
|
2024-04-21 13:00:39 +02:00
|
|
|
If no DNS over HTTPS policy is used, this unlocks the setting. Enabling managed policies disable it by default.
|
2024-02-07 09:51:12 +01:00
|
|
|
|
2024-04-25 10:00:40 +02:00
|
|
|
My other `doh-*.json` set this as well, because `secure` doesn't allow
|
|
|
|
downgrade to system resolver and Chromium seems somewhat unreliable with it often reporting
|
|
|
|
`DNS_PROBE_POSSIBLE` and while this occassionally disables ECH, it works and
|
|
|
|
my system resolvers are encrypted. I hope they will implement ECH with system
|
|
|
|
resolver soon to fix this.
|
2024-04-19 07:24:29 +02:00
|
|
|
|
2024-02-07 09:51:12 +01:00
|
|
|
## `doh-dns0.json`
|
2024-01-31 12:43:10 +01:00
|
|
|
|
2024-04-21 13:00:39 +02:00
|
|
|
Simply forces DNS-over-HTTPS with DNS0.eu.
|
2024-04-19 07:24:29 +02:00
|
|
|
|
2024-03-23 11:15:21 +01:00
|
|
|
## `doh-mullvad-base.json`
|
|
|
|
|
2024-04-21 13:00:39 +02:00
|
|
|
Forces DNS-over-HTTPS with Mullvad Base, which features ad, malware & tracker blocking.
|
2024-03-23 11:15:21 +01:00
|
|
|
|
|
|
|
- https://mullvad.net/en/help/dns-over-https-and-dns-over-tls#specifications
|
|
|
|
|
2024-04-10 09:53:37 +02:00
|
|
|
## `doh-quad9-ecs.json`
|
|
|
|
|
2024-04-21 13:00:39 +02:00
|
|
|
Forces DNS over HTTPS with Quad9 ECS enabled threat-blocking server and also contains
|
2024-04-21 10:35:28 +02:00
|
|
|
their alternative port.
|
|
|
|
|
2024-04-25 13:01:54 +02:00
|
|
|
## `doh-quad9-insecure-ecs.json.badidea`
|
2024-04-21 10:35:28 +02:00
|
|
|
|
2024-04-21 13:00:39 +02:00
|
|
|
Forces DNS over HTTPS with Quad9 ECS enabled unfiltered server and also contains
|
2024-04-21 10:35:28 +02:00
|
|
|
their alternative port. **No DNSSEC either.**
|
|
|
|
|
2024-04-25 13:01:54 +02:00
|
|
|
## `doh-quad9-insecure.json.badidea`
|
2024-04-21 10:35:28 +02:00
|
|
|
|
2024-04-21 13:00:39 +02:00
|
|
|
Forces DNS over HTTPS with Quad9 unfiltered server and also contains
|
2024-04-21 10:35:28 +02:00
|
|
|
their alternative port. **No DNSSEC either.**
|
|
|
|
|
|
|
|
## `doh-quad9.json`
|
|
|
|
|
2024-04-21 13:00:39 +02:00
|
|
|
Forces DNS over HTTPS with Quad9 threat-blocking server and also contains
|
2024-04-21 10:35:28 +02:00
|
|
|
their alternative port.
|
2024-04-10 09:53:37 +02:00
|
|
|
|
2024-02-07 09:46:57 +01:00
|
|
|
## `enable-ech-ocsp.json`
|
|
|
|
|
2024-04-26 10:27:11 +02:00
|
|
|
Enables encrypted client hello (ECH) and Online Certificate Status Protocol
|
|
|
|
(OCSP)/Certificate Revocation List (CRL) checks.
|
2024-04-21 13:00:39 +02:00
|
|
|
|
2024-04-25 10:00:40 +02:00
|
|
|
However ECH requires `"DnsOverHttpsMode": "secure"` which will break things
|
|
|
|
(and thus my files don't enable it),
|
|
|
|
or it will occassionally get disabled (I hope they implement it with system
|
|
|
|
resolver soon).
|
2024-02-07 09:46:57 +01:00
|
|
|
|
2024-04-16 06:15:30 +02:00
|
|
|
## `enable-labs.json`
|
|
|
|
|
|
|
|
Enables the beaker button "Experiments" for easier management than `about:flags`.
|
|
|
|
|
2024-03-28 17:57:29 +01:00
|
|
|
## `fix-edge-search.json`
|
|
|
|
|
|
|
|
Tells Microsoft Edge to redirect queries from new tab search box to URL bar
|
|
|
|
effectively forcing it to respect user configured search engine instead of
|
|
|
|
stealthily sending those queries to Bing.
|
|
|
|
|
2024-04-25 13:01:54 +02:00
|
|
|
## `force-incognito.json.badidea`
|
2024-02-07 09:46:57 +01:00
|
|
|
|
|
|
|
Forces incognito mode. I don't recommend this.
|
|
|
|
|
2024-01-31 13:12:21 +01:00
|
|
|
## `https-everywhere.json`
|
|
|
|
|
|
|
|
Enforces https and attempts to upgrade http to https.
|
2024-03-23 11:15:21 +01:00
|
|
|
|
|
|
|
## `README.md`
|
|
|
|
|
|
|
|
You are reading this file, are you not?
|