Commit Graph

175 Commits

Author SHA1 Message Date
Aminda Suomalainen 81d1a2a0fb
privacy.userContext.extension is extra forbidden! 2024-05-19 20:32:14 +03:00
Aminda Suomalainen e066a99481
Does Mozilla have a point in not allowing me to customize fonts through policy? No comment. 2024-05-19 20:19:35 +03:00
Aminda Suomalainen fc8efef261
pre-commit: return & run pretty-format-json as I like its sorting 2024-05-19 19:49:46 +03:00
Aminda Suomalainen 1585a6daae
firefox: or maybe I don't trust my family that much 2024-05-19 19:46:13 +03:00
Aminda Suomalainen 8b050a2bab
firefox: force enable phishing & malware protection
Although they can still be disabled through about:config, I am trusting my family to not start doing that
2024-05-19 19:31:14 +03:00
Aminda Suomalainen ee83db4ddc
firefox: comment fingerprinting protections for now 2024-05-19 19:01:38 +03:00
Aminda Suomalainen 294bcb4049
policies.json: comment what is unclear and I understand, clear what I don't understand 2024-05-19 18:40:16 +03:00
Aminda Suomalainen 3ec414c933
firefox: disable extension recommendations & default sending crashreports 2024-05-19 18:28:15 +03:00
Aminda Suomalainen c8e85859c3
{firefox,chromium}: accept regional languages as well to not fallback to Russian? 2024-05-19 18:22:21 +03:00
Aminda Suomalainen 0e5b94c867
firefox: allow disabling peertube-companion, remove forgotten blocked_message & opendyslexic 2024-05-19 18:05:07 +03:00
Aminda Suomalainen 6c3382683b
firefox: install facebook container 2024-05-19 18:02:54 +03:00
Aminda Suomalainen 4d11897918
{firefox,chromium}#ubo: add antipaywall.txt which apparently helps with Quora login prompt as well 2024-05-19 15:04:52 +03:00
Aminda Suomalainen 6ece6f5e75
{firefox,chromium}#ubo: add lists I can imagine triggering in near future 2024-05-19 14:47:06 +03:00
Aminda Suomalainen 17a189396b
initial commit of firefox-forbidden-policies.js (autoconfig take#2) 2024-05-19 14:05:04 +03:00
Aminda Suomalainen 6293ce0a14
run prettier on json files (4) 2024-05-19 13:10:20 +03:00
Aminda Suomalainen 79411a0932
{firefox,brave}: add forgotten integrated protection excemptions 2024-05-19 11:59:50 +03:00
Aminda Suomalainen 162912dd82
{firefox,chromium}#PrivacyBadger: just trust cloudflare.com directly
I remembered that the analytics domain is cloudflareinsigts.com and I use cloudflare's esni testing etc. too often
2024-05-19 11:54:58 +03:00
Aminda Suomalainen 79a7e38d93
{firefox,chromium}: actually cut PrivacyBadger's list a lot 2024-05-19 11:41:20 +03:00
Aminda Suomalainen 1f0ac5a0e9
{firefox,chromium}: simplify allowlist configuration
PrivacyBadger continues having stricter rules and I am trusting it to catch what I let through
2024-05-19 11:38:18 +03:00
Aminda Suomalainen b4e1f7fd0e
{firefox,chromium}: allow challenges.cloudflare.com just in case 2024-05-19 11:04:09 +03:00
Aminda Suomalainen 77e2e37362
{firefox,chromium}: add cookie lists to uBlock Origin
I was staring at them too much while testing policies
2024-05-19 09:53:16 +03:00
Aminda Suomalainen e8a3ecff0c
firefox: stop offering to translate English [and Finnish] by default
Otherwise it's not intelligent enough to understand that accepted language en also means en-US
2024-05-19 09:27:32 +03:00
Aminda Suomalainen 9fff2bb17d
firefox: don't install Dark Reader by default
I cannot deploy it, so I have to configure it anyway and this means only Bitwarden throws a welcome page at me
2024-05-19 09:07:51 +03:00
Aminda Suomalainen ea5db5a670
firefox: install Ecosia extension by default for non-{ESR,nightly} 2024-05-19 09:03:51 +03:00
Aminda Suomalainen a4f3943073
{firefox,chromium}: add small hints of possibly being connected to Russia
https://krebsonsecurity.com/2021/05/try-this-one-weird-trick-russian-hackers-hate/
2024-05-19 08:32:00 +03:00
Aminda Suomalainen 9b348b16cc
{firefox,chromium}: switch from AdNauseam to uBlock Origin
I love AdNauseam, but it's a tool for protests and it shows constantly, while uBlock Origin is more sysadmin-friendly deploying silently and not complaining about browser protection or PrivacyBadger etc.
2024-05-19 07:37:33 +03:00
Aminda Suomalainen 6a9798c61b
firefox: restore prefetching
I accidentally tried it and it's just too significant performance improvement for me to keep disabled. Additionally AdNauseam is making clicks to ads anyway and I think I am still safer than someone who has no tracking protections at all.
2024-05-18 18:44:39 +03:00
Aminda Suomalainen 2ff416d880
{firefox,chromium}: also enable curben-phishing 2024-05-18 14:04:43 +03:00
Aminda Suomalainen 20679e705d
{firefox,chromium}: enable AdNauseam ublock-annoyances & adguard-mobile-app-banners 2024-05-18 13:55:18 +03:00
Aminda Suomalainen c68e3f66ab
firefox: attempt to enable http for esr 2024-05-18 10:21:44 +03:00
Aminda Suomalainen 5a88836d59
firefox: Comment/clear network.dns.native_https_query_win10 2024-05-18 09:44:25 +03:00
Aminda Suomalainen 5995ef8f32
firefox/policies.json: attempt to autoconfig, but again not allowed 2024-05-18 09:24:25 +03:00
Aminda Suomalainen 1290db73f5
firefox/policies.json: import more disallowed things from autoconfig, comment disallowed ones, clear location provider 2024-05-18 09:15:10 +03:00
Aminda Suomalainen df1458af1f
firefox: use system DNS for ECH (and prefer IPv6 and try image.animation.mode)
The last is not allowed for stability reasons apparently.
2024-05-18 07:33:10 +03:00
Aminda Suomalainen fb57ae0ea5
firefox & chromium: accidentally silence DuckDuckGo post-install 2024-05-17 14:28:33 +03:00
Aminda Suomalainen c92ded3ad3
firefox & chromium: add Ruffle.rs 2024-05-17 11:05:31 +03:00
Aminda Suomalainen 05a3cb6c08
firefox: allow private ECS 2024-05-16 19:48:39 +03:00
Aminda Suomalainen 38710540f2
firefox & chromium: add missing favicons for DDG & Brave 2024-05-16 19:12:10 +03:00
Aminda Suomalainen 729013c3c1
firefox: install user-agent-string-switcher automatically so I don't have to worry about that for Microsoft Teams
TODO: proper automagic deployment
2024-05-16 15:37:59 +03:00
Aminda Suomalainen e6f4bd72ba
firefox: explicitly enable FirefoxAccounts & Screenshots
I have a feeling I might sometime have a situation where I want to disable at least accounts
2024-05-16 15:16:25 +03:00
Aminda Suomalainen b36f37196f
firefox: lock DoH again since I don't want to worry about multiple places where to edit it when I inevitably do 2024-05-16 15:13:11 +03:00
Aminda Suomalainen 34799d0776
firefox & curl: default to dns0.eu, but have comment on unfiltered.adguard-dns.con available as well 2024-05-16 15:12:12 +03:00
Aminda Suomalainen 23803ad433
firefox: restore privacy.userContext
Reverts: 4b7eff36b2
2024-05-16 15:06:04 +03:00
Aminda Suomalainen 5158b52da4
firefox: apparently HTTPS Only mode can be set here contrary to the documentation
Also generic hardening(?)
2024-05-16 15:03:01 +03:00
Aminda Suomalainen 4b7eff36b2
firefox: remove privacy.userContext policies for stability reasons (Firefox ESR is upset by them) 2024-05-14 15:40:37 +03:00
Aminda Suomalainen 8d3609f171
firefox: lock ecs to disabled 2024-05-14 15:01:14 +03:00
Aminda Suomalainen fb6a44d264
firefox: on second thoughts, let the user have some control 2024-05-14 11:51:22 +03:00
Aminda Suomalainen ae0e3beb9a
firefox: fix pdf dark mode 2024-05-14 11:49:17 +03:00
Aminda Suomalainen b60bc9f1b8
firefox: switch to AMO version of Privacy Badger 2024-05-14 11:18:26 +03:00
Aminda Suomalainen 5d46d529bb
firefox: new tab page crashes? No problem, we can disable it. 2024-05-14 11:01:28 +03:00
Aminda Suomalainen c23e857c91
firefox: confusing user and default means I can use dark theme here 2024-05-14 10:44:14 +03:00
Aminda Suomalainen 7b22530eb9
policies.json: seems like I confused default and user 2024-05-14 10:38:39 +03:00
Aminda Suomalainen 372a032a18
firefox: actually trr.mode 3 may be nice for the ECH 2024-05-14 10:10:50 +03:00
Aminda Suomalainen 583cc6a8a3
firefox: please do warn if TRR isn't working 2024-05-14 10:08:19 +03:00
Aminda Suomalainen 7c867e1329
firefox: explicitly allow about:{addons,config,profiles,support} 2024-05-14 09:57:52 +03:00
Aminda Suomalainen fb73f8e5d3
firefox: maybe be done with preferences? 2024-05-14 09:55:24 +03:00
Aminda Suomalainen 5cc2e5d720
firefox: the end of preferences additions is approaching 2024-05-14 09:43:17 +03:00
Aminda Suomalainen 89dd05c882
firefox: set user policies of hiding Mozilla ads 2024-05-14 09:38:12 +03:00
Aminda Suomalainen cb5c844e1c
firefox: TRR IPv6 preference & reading /etc/hosts 2024-05-14 09:34:01 +03:00
Aminda Suomalainen 82bcaa0d80
firefox: disable prediction/prefetching
Interestingly the policy didn't seem to touch the two preferences
2024-05-14 09:25:17 +03:00
Aminda Suomalainen 88c391fd04
firefox: don't protect any domains from extensions
OK, so this simultaneously hurts security as extensions could modify the page,
but it may improve privacy by blocking analytics and it can improve
accessibility for any accessibility extensions.
2024-05-14 09:18:26 +03:00
Aminda Suomalainen fd22af5142
firefox: move DoH excluded domains here 2024-05-14 09:12:21 +03:00
Aminda Suomalainen beee380a30
firefox: begin adding security preferences 2024-05-14 09:04:56 +03:00
Aminda Suomalainen 7a68117198
firefox policies: go wild 2024-05-13 21:54:05 +03:00
Aminda Suomalainen 95d59857eb
policies.json: lock DoH provider so I only have to configure it at one place 2024-05-13 18:07:22 +03:00
Aminda Suomalainen 9b4cc804e5
browsers: expose to Ecosia that we are using gpo (or policies), remove extraneous PostData from Firefox
The logic here is hope that it will stop offering the addon if I am following their instructions and sending them the information. Oh and I added icons
2024-05-13 17:56:41 +03:00
Aminda Suomalainen d93b8eb3d5
firefox policy: disable bookmarks toolbar, default browser checking & add tracking protection exceptions 2024-05-13 06:29:17 +03:00
Aminda Suomalainen 575332b4ce
firefox: return to Quad9 ECS, disable Pocket (I don't actually use it), fix search engine typo 2024-05-12 21:43:33 +03:00
Aminda Suomalainen e5fc9bfbaf
{firefox,chromium}: add Plasma Integration mainly for family 2024-05-12 15:49:12 +03:00
Aminda Suomalainen d6aae8fb9a
browsers: add OISD (big) to AdNauseam 2024-05-11 18:01:05 +03:00
Aminda Suomalainen 7430dd9e99
{firefox,chromium}: add HTTP Indicator 2024-05-11 17:35:37 +03:00
Aminda Suomalainen 28542ca06a
firefox policy: clean-up attempt 2024-05-11 17:28:29 +03:00
Aminda Suomalainen ba4fb50c76
firefox: set DoH to Quad9 DNS as a more international option, Ecosia Search Engine 2024-05-11 17:26:33 +03:00
Aminda Suomalainen fef359500f
firefox: add AdNauseam configuration 2024-05-11 17:24:44 +03:00
Aminda Suomalainen 9a974e7bca
{firefox,chromium,edge}: add Ecosia 2024-05-11 16:16:12 +03:00
Aminda Suomalainen 18a04b1351
{firefox,chromium}: disable protections for one.one.one.one
For some reason they make connection to 1.1.1.1 appear as no or unreachable.
2024-04-28 09:21:29 +03:00
Aminda Suomalainen 2113b593e7
Chromium & Firefox: force Bitwarden (for passkeys) 2024-04-27 08:32:39 +03:00
Aminda Suomalainen da85d0d9c7
firefox & chromium: allow PrivacyPass attestor & Keyoxide.org 2024-04-27 08:31:05 +03:00
Aminda Suomalainen e64e4e7fd0
firefox: DisableEncryptedClientHello: false
I am not sure if this does anything, I just saw a message in logs and it didn't trigger an error
2024-04-21 10:13:29 +03:00
Aminda Suomalainen 6a97040386
firefox: add IPvFoo* 2024-04-21 10:08:43 +03:00
Aminda Suomalainen 422ab0de4e
libreawoo, unbound & resolved: uncomment Quad9 default, comment ECS 2024-04-20 17:50:12 +03:00
Aminda Suomalainen 47e51ee38b
firefox policy: use Quad9 ECS as TRR 2024-04-19 08:48:57 +03:00
Aminda Suomalainen ac922aea86
{firefox,chromium}: add Floccus bookmarks sync so I will remember its existence 2024-04-14 14:10:39 +03:00
Aminda Suomalainen bf1fdc4cff
{firefox,chromium} policy: PB exclude Disroot Mvim, Microsoft {Teams,Learn} 2024-04-12 14:24:31 +03:00
Aminda Suomalainen 149cadfa41
firefox & chromium: add IPFS Companion 2024-04-10 11:03:19 +03:00
Aminda Suomalainen c034e016e8
firefox policy: add search engine suggestion urls 2024-04-05 14:04:14 +03:00
Aminda Suomalainen 99c63d25fe
{firefox,chromium} policy: add OpenDyslexic 2024-04-04 14:27:43 +03:00
Aminda Suomalainen 08ae59ed99
firefox policy: configure Homepage 2024-03-31 08:46:12 +03:00
Aminda Suomalainen 323dde1545
{firefox, chromium}: force install privacy pass
This is in hopes of reducing family member frustation with captchas should they happen
2024-03-29 08:32:44 +02:00
Aminda Suomalainen e823810723
firefox: add search engine aliases 2024-03-24 08:16:20 +02:00
Aminda Suomalainen 4bab0cbb6a
firefox: default to Brave Search 2024-03-24 08:15:43 +02:00
Aminda Suomalainen 405d407c2a
firefox: add Brave Search Goggles 2024-03-21 17:21:30 +02:00
Aminda Suomalainen 3e56346be0
firefox: add Brave Search 2024-03-20 18:53:18 +02:00
Aminda Suomalainen cc6dbceaff
{firefox,chromium} policy: add UpdateSWH 2024-03-14 20:25:06 +02:00
Aminda Suomalainen 39b0f1d19a
{firefox,chromium} policy: disable PrivacyBadger on Element Web instances 2024-03-13 11:45:19 +02:00
Aminda Suomalainen 5c1dce8d36
{firefox,chromium} policy: explicitly configure PrivacyBadger
I think all of these default to true anyway, but explicit is better than implicit is what they say
2024-03-12 10:15:15 +02:00
Aminda Suomalainen e35c477a71
firefox policy: block uBlock & uMatrix to avoid conflict with force_install AdNauseam 2024-03-09 15:45:02 +02:00
Aminda Suomalainen 685b14c2f6
firefox policy: block wayback machine 2024-03-09 15:41:39 +02:00
Aminda Suomalainen 5149b23598
browser policies: add wayback machine 2024-03-08 08:41:41 +02:00
Aminda Suomalainen 16d6a3df09
browser policies: install Bias Finder 2024-03-08 08:29:54 +02:00