[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y ] [Home]
4chanarchives logo
/g/ security general
Images are sometimes not shown due to bandwidth/network limitations. Refreshing the page usually helps.

You are currently reading a thread in /g/ - Technology

Thread replies: 45
Thread images: 5
File: Android-password-management-5.jpg (129 KB, 1200x795) Image search: [Google]
Android-password-management-5.jpg
129 KB, 1200x795
>Browser Fingerprint
https://www.privacytools.io
Anything you missed that this told you about?
How did you do?

>WebRTC IP Leak Test
https://www.privacytools.io/webrtc.html
You leaking?

>Questions
What OS?
What Browser?
What mobile OS?
One thing you use that you know is insecure but use anyway?

Give this a go. I didn't rank to well, but I don't really give a shit. The more you try to hide, they more likely they are to notice you.
>>
File: Git Gud.png (43 KB, 992x604) Image search: [Google]
Git Gud.png
43 KB, 992x604
:^)
>>
>>53809327
Use whitelist blocking with noscibbidibidoo
>>
Reminder to use either Firefox developer edition or better yet GNU IceCat, and use this list of addons:


(Cross-)Site Request, Anti-XSS, Trackers, Referer, User-Agent and Cookies: uMatrix (https://addons.mozilla.org/en-US/firefox/addon/umatrix/).

Security Settings: Privacy Settings (https://addons.mozilla.org/en-US/firefox/addon/privacy-settings/).

SSL (strict HTTPS): HTTPS by default (https://addons.mozilla.org/en-US/firefox/addon/https-by-default/).

URL Deobfuscator: Pure URL (https://addons.mozilla.org/en-US/firefox/addon/pure-url/).

Plugin And Mimetype Enumeration: Disable Plugin & Mimetype Enumeration (https://addons.mozilla.org/en-US/firefox/addon/happy-bonobo-plugins-mimety/). CURRENTLY NOT AVAILABLE.

Passwords: KeePassX "autocomplete" (https://www.keepassx.org/)

Browsing History Cleaner: Bleachbit.

LSO Cookies: BetterPrivacy (https://addons.mozilla.org/en-US/firefox/addon/betterprivacy/).
>>
File: 1459392654988.jpg (42 KB, 306x344) Image search: [Google]
1459392654988.jpg
42 KB, 306x344
>>53810767
>no ublock origin
>>
>>53810767
Explain why you would use firefox over chrome or chromium
>>
>>53809327

I want to have a password manager that stores its shit in my owncloud instillation.

I use it in my network and externally through a vpn right now. In this way the password manager can just use the pre existing protection to share its data.

Would like something I can trust to be secure. Open source is of course preferable.
>>
Why is nobody anonymous? Is this an April fools joke? Sorry, been away at work all day.
>>
File: 1459271786581.jpg (50 KB, 736x724) Image search: [Google]
1459271786581.jpg
50 KB, 736x724
>>53810872
I'd like too know that too.
New version of firefox is pretty bad and there's worse to come.
>>
>>53810767

firefox is really slow lately

I have started looking at chromium plus self hosting my own sync data.

There are some (supposedly) even more secure versions of chromium.
>>
>>53810937
Okay so does it remember that I'm Nettie? I like my new name.
>>
>>53810872
>>53810945
>>53810948

Its fucking dying.
>>
>>53810963
Fuck. Guess I'm not really Nettie.
>>
>>53810980
At least you are not anthony burch.
>>
>>53810948
I was using Chrome today on an i3, 4GB memory. It was slow as fuck and freezing a lot. No it was not using virtual memory, I checked.

If you're using Firefox and it's slow, it's probably because you forgot to enable e10s (multiprocess)
>>
>>53811008

4chan has been terrible on firefox lately basically anything big. Dont know why what is this e10 activation.
>>
>>53810975
If anything is dying it's firefox.

I'd love to hear from a security perspective why firefox is better than chrome though.
>>
>>53811008
Is e10s more stable now?
Last time I tried it crashed every hour.
>>
>>53811026

Thats what I meant. Im working this weekend on figuring out how to get chromium to sync to my freenas server.

Anyone know how safe chrome is? That built in flash is nice.
>>
>>53810824
You know uMatrix is made by the same developer? I guess you could stay with uBlock Origin, but it has less features.

>>53810872
>>53810945
>>53810948
Expanded security via addons and less privacy invasion can be achieved in firefox, but only if you follow the precise steps. That's why using GNU IceCat is even better.

Otherwise, I don't exactly recommend this to total strangers but you could use dwb if you can handle the interface.
>>
>>53811040
>Anyone know how safe chrome is? That built in flash is nice
This is hilarious.
Using flash player is arguably the worst thing you can do in terms of safety/security.
>>
>>53811040
Probably the safest browser, a few years ago firefox + noscript was without a doubt the best way to go but now it's almost impossible to browse the internet without scripting.

Chrome + ublock + java/flash configured for click to play is probably the safest way to browse now.

There are privacy issues with chrome though.
>>
File: 1456419103602.png (7 KB, 268x341) Image search: [Google]
1456419103602.png
7 KB, 268x341
>>53811040
Some thing's I've seen is that firefox manages most things by itself (mime linking etc.) while chrome uses the OS linking files.

Also the security pause on download prompts while chrome just downloads it.
>>
>>53810948
Explain me why use Chromium when Iridium is available?
>>
>>53811058
Thanks, I will look into uMatrix and dwb.
>>
>>53811058
Everything you have said can be done in chrome.

Firefox security is very questionable, is it even sandboxed?

http://www.eweek.com/security/pwn2own-hacking-contest-returns-as-joint-hpe-trend-micro-effort.html
>One change in the 2016 event is that the Mozilla Firefox Web browser is no longer part of the contest.
>"We wanted to focus on the browsers that have made serious security improvements in the last year," Gorenc said.

It's a dying browser imo and google have an incredible focus on security.
>>
>>53811026
Its not. Recently George Hotz (geohotz) have a talk and made it very clear that ff is shit and you should use chrome for security.
>>
>>53811184
>Everything you have said can be done in chrome.
Questionably, as the main developer is Google and it made chrome to be meld into the "services" the company provides.

>>53811191
Maybe, but then again the addons save you from the changes. And is not that the several forks out there don't cover that.

Overall, just check again my posts.
>>
>>53811159
One word, dwb is a browser you can only have in Linux. You been warned.
>>
>>53811253
I'm a linux user there shouldn't be any problems.
>>
>>53811234
>Maybe, but then again the addons save you from the changes.

How does some addons that force https and deobfuscate urls prevent you from getting owned by a browser exploit?
The issue is security here not privacy.
>>
>>53811325
Force SSL/TLS is not only about privacy.
Look at mitm proxies for example. Changing a file while you download it or redirect your browser to landing pages.
>>
>>53811325
Do you even checked about the uMatrix capability to avoid XSS?
Maybe is not you type, maybe you need something like NoScript, or better yet Policeman.
>>
>>53810767
>Bleachbit
should I use this or ccleaner
>>
>>53811431
why even use ccleaner?
>>
>>53811431
I trust more Bleachbit, but be careful not to erase something you want back, when the file is gone is gone.
>>
Firefox is the browser to use, and frankly the only major one these days that actually cares about your security and privacy. Sure, there are technical security issues with every browser and they all are frequently improved. However, Chrome /ium is built by Google FOR Google's aims, which include enriching Google by data mining and ensuring their revenue generation services work as intended. Firefox however is made by Mozilla, which is a non-profit that is dedicated to privacy and an open web, designed for the user. Never forget that Chrome/ium ad blocking addons was originally only allowed to visually hide, but still load the content, and that uBlock Origin has features that don't work on Chrome/ium because it won't "let" them by design.

Firefox isn't perfect, there are things I'd like to see them do better, but overall its the only major browser that has user freedom and privacy in mind. All the others are pseudo-open when it suits them, or not at all and that's a problem. Note that every one of you who leave for Chrome etc...is hurting Firefox, and if they go down we all suffer for it.
>>
>>53811624
truth has spoken
>>
>>53811624

and here's an assortment of worthwhile addons for said Firefox. Yes, a few of them have Chrome/ium versions too. Note that the privacytools.io and prism-break.org lists are pretty decent as well. Most listed here are open source under one license or another.

Better Privacy - Eats up LSO "aka Flash Cookies" that other things don't usually delete.
Decentraleyes - Avoids loading stuff from content delivery networks, but instead either has a local generic version that can't be tracked or loads the asset directly.
Disconnect - An excellent tracker blocker, the Firefox Private Browsing Mode is based on a slimmed down version of this addon. It helpfully shows where you're getting requests to load content and categorizes them (ie this is an ad network, that is social media, lastly this is probably actual content). Note, they have a private VPN service, but the addon is called "Disconnect Private Browsing". Scroll to the bottom of disconnect.me
Disconnect Private Search - Want to search Google and whatnot without being tracked? Disconnect Private Search lets you do so, proxies the searches so they can't be IDed as coming from you.
HTTPS Everywhere - From the EFF comes a great addon that automatically loads HTTPS versions of sites if available.
Lightbeam - Want to see a visual map of your browsing/tracks? Here's an addon that makes a visual web. A nice little tool.
NoScript - This basically allows you to white or blacklist any domains and the content they load. **Warning: Requires user knowledge**. Pages will "break" until you enable/save things for them, but after awhile its not so bad, gives major javascript blocking security benefit.
Private Tab - Allows you to load private mode tabs, not just windows
Random Agent Spoofer - Allows you to specify any useragent you wish from a huge list, write your own, or have it automatically rotate between any or all of them! Excellent example of its type

Oops out of space... more to come..
>>
>>53811624
>However, Chrome /ium is built by Google FOR Google's aims, which include enriching Google by data mining and ensuring their revenue generation services work as intended.

That's why I can't comprehend why anybody trust Google over Mozilla.
http://www.businessinsider.com/google-microsoft-amazon-taboola-pay-adblock-plus-to-stop-blocking-their-ads-2015-2
>>
>>53811911

Self Destructing Cookies - Excellent cookie addon, allowing granular permissions per page. By default, it deletes all cookies the moment you browse away from the page! However, you can set a particular one to stay until you close the tab/browser, or even forever if you wish. Great addon.
uBlock Origin - Move over AdBlock Plus / AdBlock Edge, this is probably one of the best ad and tracker blockers around! Read up on it though, as though it has a great set of defaults there's a lot of functionality here that may be a little more in depth if you choose to enable it. Could in theory be your only ad/tracker blocker, or you can run it along with Disconnect. Remember regular "uBlock" is crap, you want "uBlock Origin"
uMatrix - What uBlock Origin is to ad blockers, uMatrix is to NoScript. It can block a ton of content, but requires some work just like NoScript. Note that you still want uBlock Origin alongside uMatrix, generally.
Privacy Badger - Made by the EFF, this is a tracker blocker similar to Disconnect, but Iv'e found it tends to break more sites and has some other differences. It has been in the earlier stages of development so maybe it will be refined, but its still a worthy project and some may like it.

Oh here are a few addosn that aren't directly security/privacy related but are worthwhile...

Cryptocat - Encrypted chat.
Download Manager (S3) - Upgrade of the now defunct "Download Statusbar" app. Shows all your downloads on a little bar (hideable etc..) at the bottom of your browser, which each download as a "block" on it. Also has a lot of other download features.
FlashGot - while we're speaking of downloads, FlashGot is another download addon that is made to work with any and all internal or external download managers (ie jDownloader etc) . It can also rip/save all web videos (including flash, html5), so its nice to have dual functionality in this regard especially when sites don't want you to download

Out of space again..
>>
>>53812316

Greasemonkey - Userscript enabling addon, neeeded for running such scripts, including those for 4chan if you wish!
Password Exporter - Using a password manager like Keepass, KeepassX, PasswordSafe, or Encryptr, but already saved your Firefox Passwords? Password Exporter allows you to easily export them as .csv or xml files, makes your life easier.
KeeFox - Want to substitute KeePass as your Firefox password database entirely? Then use Keefox! It will save firefox capured uname/pass to Keepass, and use Keepass databases passwords etc.. in Firefox through autotype! May take some setup.
Stylish - What Greasemonkey does for userscripts, Stylish does for userstyles! Makes webpages pretty and more usable. Want Google to always be a dark theme instead of white? Well, just load a userstyle for it etc.
The Addon Bar (restored) - Firefox unfortunately removed the separate addon bar awhile back, but this addon brings it back with some upgrades! Useful if you have lots of addons/icons!
Status-4-Evar - Brings back a lot of old Firefox features, including a status bar, loading icons etc.. personally I use The Addon Bar Restored instead but some may prefer this.
>>
>>53811911
>>53812316
>>53812418

Just mention the addons you retard, everyone can see their description on the spot when they search them.
>>
Firefox 45.0.1 with some hardening applied does not seem to leak.
>>
>>53809327
>>53810767
Thanks anons, good posts


Also, change DNS if necessary
Thread replies: 45
Thread images: 5

banner
banner
[Boards: 3 / a / aco / adv / an / asp / b / biz / c / cgl / ck / cm / co / d / diy / e / fa / fit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mu / n / news / o / out / p / po / pol / qa / r / r9k / s / s4s / sci / soc / sp / t / tg / toy / trash / trv / tv / u / v / vg / vp / vr / w / wg / wsg / wsr / x / y] [Home]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
If a post contains personal/copyrighted/illegal content you can contact me at [email protected] with that post and thread number and it will be removed as soon as possible.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com, send takedown notices to them.
This is a 4chan archive - all of the content originated from them. If you need IP information for a Poster - you need to contact them. This website shows only archived content.