{"id":8615,"date":"2018-09-26T09:30:24","date_gmt":"2018-09-26T16:30:24","guid":{"rendered":"https:\/\/www.privateinternetaccess.com\/blog\/?p=8615"},"modified":"2020-07-05T07:22:00","modified_gmt":"2020-07-05T07:22:00","slug":"firefox-hardening-guide","status":"publish","type":"post","link":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/","title":{"rendered":"Firefox Hardening Guide 2018"},"content":{"rendered":"<p>Purpose:<\/p>\n<p>This guide shows a user in an easy-to-follow way how to improve the privacy and security settings of Firefox, which, when combined with a privacy VPN, gives a user a strong framework for protecting their information.<\/p>\n<p><b>This guide is broken down into sections, each addressing different areas of security and privacy settings within Firefox. It should also be noted that these settings will break some websites, especially the components that block scripts. These problems will improve over time as the sites that you routinely visit will be fixed by your settings changes in the recommended plugins. <\/b><b>Some websites are enemies of privacy and will not be usable securely or privately due to security flaws that break functionality or intentional blocking by the websites that cannot track you.<\/b><\/p>\n<p><strong>Also, when Firefox installs updates, it is common for some of these settings to revert back to their defaults. When Firefox notifies you that it has updated, it is a good idea to review this guide again and make sure that no settings have changed. This page will also be routinely updated with the latest information, so it is good to check this page for updates.<\/strong><\/p>\n<p>Update: Nov 14th 2018 \u2013 Mitigation for the <a href=\"https:\/\/www.privateinternetaccess.com\/blog\/supercookey-a-supercookie-built-into-tls-1-2-and-1-3\/\">SuperCooKeys privacy flaw in TLS 1.2 and TLS 1.3<\/a> added.<\/p>\n<h2 id=\"navigationX\">2018 Firefox Hardening Guide Navigation<\/h2>\n<ul>\n<li><a title=\"Firefox Security Guide Part 1: Privacy Add-ons and Extensions for Firefox Quantum\" href=\"#section1\">Section 1: Privacy Add-ons\/Extensions for Firefox Quantum<\/a><\/li>\n<li><a title=\"Firefox Security Guide Part 2: Options in Firefox Quantum to Improve Security and Privacy\" href=\"#section2\">Section 2: Options in Firefox Quantum to Improve Security and Privacy<\/a><\/li>\n<li><a title=\"Firefox Security Guide Part 3: Advanced privacy and security improvements with about:config settings changes\" href=\"#section3\">Section 3: Advanced privacy and security improvements with about:config settings changes<\/a><\/li>\n<li><a title=\"Firefox Security Guide Part 4: Editing Trusted Certificate Authorities\" href=\"#section4\">Section 4: Editing Trusted Certificate Authorities<\/a><\/li>\n<\/ul>\n<h2 id=\"section1\">Section 1: Privacy Add-ons\/Extensions for Firefox Quantum<\/h2>\n<p><b>Block ads with uBlock Origin<\/b> \u2013 Not to be confused with uBlock, <a href=\"https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/ublock-origin\/\">uBlock Origin<\/a> is a powerful ad-blocking tool that prevents most types of ads from appearing in your browsing or streaming. Unlike Adblock Plus and other alternatives, uBlock Origin does not have a whitelist and universally blocks all of the ads that it can. It is crucial to block ads because it is a common vector for both surveillance and malware.<\/p>\n<p><b>Block much more with uMatrix<\/b> \u2013 <a href=\"https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/umatrix\/?src=search\">uMatrix<\/a> is a powerful and script, cookie, and cross-site request blocker. It can recognize and block tracking through media and image files, and gives you granular control over what you allow and what you disallow on a per-site basis. It is important to block scripts and XHR requests as they are the most common attack vectors for malware and intrusion. <a href=\"https:\/\/www.privateinternetaccess.com\/blog\/umatrix-a-powerful-firefox-extension-to-enhance-security-and-privacy\/\">We have an easy uMatrix guide here<\/a>!<\/p>\n<p><b>Block behaviorally with Privacy Badger<\/b> \u2013 extensions like Disconnect and others block cookies by comparing the cookies to known ones. The EFF\u2019s <a href=\"https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/privacy-badger17\/\">Privacy Badger<\/a> blocks cookies by tracking their behavior rather than comparing them to repositories. This allows Privacy Badger to actively block new threats as they appear, even with no frame of reference to work from.<\/p>\n<p><b>Make sure your web is encrypted by default with HTTPS Everywhere<\/b> \u2013 While the web is increasingly encrypted by default thanks to Let\u2019s Encrypt, many sites are still unencrypted or running both encrypted and unencrypted content, either out of laziness or error. HTTPS everywhere makes sure that all of the requests coming from your browser request SSL encryption, so that if it is available, it is used by default.<\/p>\n<p><b>Check your work with Firefox Lightbeam<\/b> \u2013 Once you\u2019ve made the changes in this guide, you can check the impact of your changes using Lightbeam. Lightbeam monitors the requests that are made when you are visiting a website and gives you a visual layout so that you can see where your data is going. <a href=\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-lightbeam-visually-seeing-the-benefits-of-privacy-in-real-time\/\">We have a short LightBeam guide here<\/a>!<\/p>\n<p><a title=\"Back to Firefox Security Guide Navigation\" href=\"#navigationX\">Back to the Top<\/a><\/p>\n<h2 id=\"section2\">Section 2: Options in Firefox Quantum to Improve Security and Privacy<\/h2>\n<p><b>General \u2013 No Major Changes<\/b><\/p>\n<p>The built in Firefox spell checker operates using local language libraries that are built into the browser. This means that your keystrokes and what you write are not uploaded to Mozilla or any 3rd party by the spellchecker. Do note that websites can disable the built-in spell checker and use their own, like gmail. <i>This means when you are on websites you should be aware that your keystrokes within that page can always be recorded by the site and\/or any 3rd party scripts running on that site.<\/i><\/p>\n<p><b>Home \u2013 New Windows and Tabs Should be Blank Pages \u2013 Disable All \u201cHome\u201d Checkboxes<\/b><\/p>\n<p>Having a homepage that is not a blank page allows the site in question to know every time you\u2019ve opened Firefox or started a new tab.<\/p>\n<p>Pocket is a semi-controversial system that is built into Firefox that attempts to give users a relevant homepage without receiving any data from the user. It works by Firefox downloading a list of high quality articles from pocket servers daily, and then locally, pocket compares your browsing history against the list of articles to make relevant recommendations. This allows Mozilla to push relevant content to users without ever seeing their browser history. It also has a \u201csponsored article\u201d system that shows paid-for articles alongside the high quality content. The criticisms of the system are that Mozilla gets to decide what is high quality content and what is not, and that this a way to get ads (paid content) on a user\u2019s home page by default. While pocket doesn\u2019t pose any blatant security or privacy risks and it is open-source, I recommend disabling it for performance reasons as well as the criticisms above.<\/p>\n<p><b>Search \u2013 Change the default search engine to DuckDuckGo \u2013 Disable Suggestions<\/b><\/p>\n<p>DuckDuckGo is a private search engine that does not store or cache user results. This means that your searches remain private and are not traded or sold for marketing or surveillance purposes. Because of the non-invasive approach of DuckDuckGo, some focused searches may not give you the most relevant results. To fix this, you can use a feature called Bangs to have DuckDuckGo redirect your search to another engine like Wikipedia or Startpage in a private way. For Startpage you do this by preceding your search in the navigation bar with a !sp. For example, if I wanted to search for information on Alabaster and use Startpage through DuckDuckGo, I\u2019d type:<\/p>\n<p>!sp Alabaster<\/p>\n<p>And I\u2019d get a <i>private Google search result from Startpage<\/i>.<\/p>\n<p>Search Suggestions is a feature that tries to predict what you\u2019re typing in the search bar and provide you with relevant results before you finish typing out your search. It does this by analyzing your keystrokes in real-time through an interactive service. This means that the search provider is getting all of your information on keystrokes that type into the bar as soon as you hit the spacebar, not when you complete typing your search. This isn\u2019t a huge privacy concern unless you leave a non-private search engine as your default.<\/p>\n<p><b>Privacy and Security <\/b><\/p>\n<p>Do not save passwords or autofill \u2013 Both of these store information that can be exfiltrated from you.<\/p>\n<p>Do Not Store History as it can be pulled by plugins and shared.<\/p>\n<p>Do not allow 3rd party cookies as these are nearly exclusively used for tracking.<\/p>\n<p>You should leave first party cookies enabled because this gives you the option of allowing a cookie for a specific site with the uMatrix plugin. This corrects a lot of site-breaking issues for sites that you frequently visit in which specific cookies are okay.<\/p>\n<p>Do not allow any suggestions in the search bar, as these broadcast your activity to 3rd parties.<\/p>\n<p>Tracking protection can be enabled, but it is handled by addons as well, so it is redundant.<\/p>\n<p>Block popups because not only are they annoying, but also because they are a common method of delivering malware payloads through malicious pages.<\/p>\n<p>You want Firefox to warn you when sites try to install addons, as these have all kinds of security and privacy consequences.<\/p>\n<p>Accessibility services are typically used in surveillance plugins for corporate networks and privacy unfriendly addons for Firefox, they should be disabled.<\/p>\n<p>Do not share telemetry data with Mozilla.<\/p>\n<p>On Blocking Dangerous and Deceptive Content \u2013 There is some false information circulating around in other guides about how this feature works in Firefox due to confusion about <a href=\"https:\/\/developers.google.com\/safe-browsing\/v4\/\">Google\u2019s SafeBrowsing<\/a> initiative. Google has two different methods of doing safe browsing, one is private and one is not. The <a href=\"https:\/\/developers.google.com\/safe-browsing\/v4\/lookup-api\">Lookup API<\/a> is the non-private method of checking URLs. This sends queries to Google servers every time you browse to a site to check if they are \u201csafe.\u201d This essentially hands Google all of your browsing information. The second, safer method is called the <a href=\"https:\/\/developers.google.com\/safe-browsing\/v4\/update-api\">Update API<\/a>. This stores a list of unsafe sites and domains locally, and you download a list from Google periodically that updates this list of domains. This method does not give Google any information from the user and <a href=\"https:\/\/wiki.mozilla.org\/Security\/Safe_Browsing\/V4_Implementation#Introduction\">it is what Firefox uses<\/a>. You DO NOT need to disable this feature for privacy reasons and it does generally boost your security by checking your browsing against the blacklisted sites.<\/p>\n<p><b>Special Section for Trusted Root CAs<\/b><\/p>\n<p>This section is revisited in detail at the end of this article.<\/p>\n<p><b>Firefox Account<\/b><\/p>\n<p>Synchronizing your account across multiple devices has multiple privacy and security risks that should be avoided. Do not sign in to a Firefox account.<\/p>\n<p><a title=\"Back to Firefox Security Guide Navigation\" href=\"#navigationX\">Back to the Top<\/a><\/p>\n<p><a href=\"https:\/\/www.privateinternetaccess.com\/\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8739\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Data-Floating_970x250b.jpg\" alt=\"Buy VPN Service\" width=\"970\" height=\"250\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Data-Floating_970x250b.jpg 970w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Data-Floating_970x250b-300x77.jpg 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Data-Floating_970x250b-768x198.jpg 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><\/p>\n<h2 id=\"section3\">Section 3: Advanced privacy and security improvements with about:config settings changes<\/h2>\n<p>Firefox is highly configurable for privacy, and to access hundreds of advanced settings, you type about:config into the navigation bar where you normally type web addresses.<\/p>\n<p>You will see a warning telling you to be careful! It is a warning worth heeding as setting things up incorrectly can make your browser crash or cause all kinds of issues. Misconfiguration can require a full reset of browser settings that will make you have to start over the process of hardening your browser.<\/p>\n<p>The changes below are designed to significantly reduce the number of methods that websites can profile your activity. Why each setting is selected to be changed is included in the description of the setting.<\/p>\n<p><b>Disable WebRTC<\/b> \u2013 WebRTC is a protocol related to digital rights management that helps content websites track users. It has the capability to give up your real IP address even while connected to a VPN or Tor.<\/p>\n<p>To disable WebRTC, in the search bar type media.peerconnection.enabled and double click on the setting to change it to false. This disables WebRTC.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8630\" title=\"Disable WebRTC | Firefox Security Guide\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-webrtc.png\" alt=\"Disable WebRTC\" width=\"592\" height=\"174\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-webrtc.png 592w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-webrtc-300x88.png 300w\" sizes=\"auto, (max-width: 592px) 85vw, 592px\" \/><\/p>\n<p><b>Enable Fingerprint Resistance<\/b> \u2013 This setting actually manages many behaviors in Firefox, it is a group of settings that are used by the <a href=\"https:\/\/2019.www.torproject.org\/projects\/torbrowser\/design\/\">Uplift project<\/a> (a sub-project of Tor) to make the browser <a href=\"https:\/\/wiki.mozilla.org\/Security\/Fingerprinting\">ignore most types of fingerprinting requests<\/a>.<\/p>\n<p>To enable Fingerprint Resistance \u2013 Type privacy.resistfingerprinting into the search bar and double click on the setting to set it to \u201ctrue.\u201d This hardens the browser against most types of fingerprinting.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8632\" title=\"Avoid browser fingerprinting to harden Firefox\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/resist-fingerprinting.png\" alt=\"Resist Fingerprinting\" width=\"584\" height=\"309\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/resist-fingerprinting.png 584w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/resist-fingerprinting-300x159.png 300w\" sizes=\"auto, (max-width: 584px) 85vw, 584px\" \/><\/p>\n<p><b>Disable the 3DES cipher<\/b> \u2013 This setting allows the 3DES cipher, which has multiple known security weaknesses. It needs to be disabled.<\/p>\n<p>To disable 3DES \u2013 Type security.ssl3.rsa_des_ede3_sha into the search bar, and double click on the setting to set it to \u201cfalse.\u201d This prevent 3des from being supported.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8621\" title=\"Disable 3DES for stronger Firefox security\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-3des.png\" alt=\"Disable 3DES\" width=\"597\" height=\"168\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-3des.png 597w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-3des-300x84.png 300w\" sizes=\"auto, (max-width: 597px) 85vw, 597px\" \/><\/p>\n<p><b>Require Safe Negotiation<\/b> \u2013 This setting is for preventing a serious <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2009-3555\">code injection attack<\/a> related to how clients and servers negotiate which encryption settings to use. This setting forces only safe negotiation methods to be used.<\/p>\n<p>To enable Require safe negotiation \u2013 Type security.ssl.require_safe_negotiation into the search bar, and double click the setting to set it to \u201ctrue.\u201d This prevents this code injection attack from working.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8631\" title=\"Require Safe Negotiation | Firefox Hardening Guide\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/require-safe-negotiation.png\" alt=\"Require safe negotiation for strong Firefox security\" width=\"596\" height=\"171\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/require-safe-negotiation.png 596w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/require-safe-negotiation-300x86.png 300w\" sizes=\"auto, (max-width: 596px) 85vw, 596px\" \/><\/p>\n<p><b>Disable TLS versions 1.0 and 1.1<\/b> \u2013 Transport Layer Security (TLS) is a protocol created by industry consensus for creating secure connections between web resources and applications. The current standard version of TLS is 1.2 and version 1.3 is rapidly being adopted at the time of this writing. TLS version 1.0 and 1.1 (1.0 esecially) have some known flaws with negotiation and cryptography in certain situations, and should be disabled for security reasons.<\/p>\n<p>To Disable TLS 1.0 and TLS 1.1 \u2013 Type security.tls.version.min into the search bar, and double click on the setting. In the box that pops up, type 3 and hit okay. This will force Firefox to only use TLS 1.2 and TLS 1.3.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8633\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/tls-version-min.png\" alt=\"\" width=\"595\" height=\"325\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/tls-version-min.png 595w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/tls-version-min-300x164.png 300w\" sizes=\"auto, (max-width: 595px) 85vw, 595px\" \/><\/p>\n<p><b>Disable 0-RTT<\/b> \u2013 Zero Round Trip Time Resumption (0-RTT) is a feature that is new in TLS 1.3 that allows a client and server to negotiate a connection with fewer steps, allowing https websites to load more quickly. There are two problems with this. First, in order to do this you lose forward secrecy (generating a new key for every session and throwing away the key when the session is over). Secondly, 0-RTT requires special implementation in order to prevent <a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/draft-ietf-tls-tls13-28\">replay attacks<\/a>, which some web developers will certainly fail to protect from. Disabling 0-RTT enhances security and privacy.<\/p>\n<p>To Disable 0-RTT \u2013 Type security.tls.enable_0rtt_data into the search bar, and double click on the setting to set the feature to false. This will force full secure negotiation for all connections made by Firefox.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8620\" title=\"Disable 0-RTT for strong Firefox security\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-0rtt.png\" alt=\"Disable 0-RTT\" width=\"597\" height=\"169\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-0rtt.png 597w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-0rtt-300x85.png 300w\" sizes=\"auto, (max-width: 597px) 85vw, 597px\" \/><\/p>\n<p><b>Disable Automatic Formfill<\/b> \u2013 Formfilling requires that information be cached in the browser, this can include valuable information like usernames and passwords and the information can reference visited sites even with history disabled.<\/p>\n<p>To Disable Formfill \u2013 Type browser.formfill.enable into the search bar, and double click on the setting to set the feature to false. This will prevent Formfill from caching any information about your browsing.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8624\" title=\"Disable formfill\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-formfill.png\" alt=\"Disable Formfill for strong Firefox security\" width=\"595\" height=\"187\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-formfill.png 595w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-formfill-300x94.png 300w\" sizes=\"auto, (max-width: 595px) 85vw, 595px\" \/><\/p>\n<p><b>Disable All Disk Caching<\/b> \u2013 Websites can write temporary information to hard drives such as access tokens, security keys, browsing data, secure scripts, and more. This information is usually deleted after a secure session is terminated, however, deleted information is trivially recoverable if it is not overwritten. Complicated firmware and drivers for flash memory based devices like SSDs introduce features like wear leveling that hide components of the storage from the OS entirely, making it very hard to verify that deleted information is actually deleted in an unrecoverable way.<\/p>\n<p>To Disable all Disk Caching \u2013 Type browser.cache into the search bar. This will pull up many settings. Look for these specific settings: browser.cache.disk.enable and double click to set it to false, browser.cache.disk_cache_ssl and double click to set it to false, browser.cache.memory.enable and double click it to set it to false, browser.cache.offline.enable and double click it to set it to false, browser.cache.insecure.enable and double click it to set it to false. This will disable all types of disk caching in Firefox.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8623\" title=\"Disable Cache | Firefox Hardening Guide\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-cache.png\" alt=\"Disable Cache for Strong Firefox Security\" width=\"607\" height=\"715\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-cache.png 607w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-cache-255x300.png 255w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p><b>Disable Geolocation Services<\/b> \u2013 Geolocation services are bad for privacy for obvious reasons. You don\u2019t want people lasering on your exact location.<\/p>\n<p>To Disable Geolocation \u2013 Type geo.enabled into the search bar, and double click the setting to set it to false. This will prevent geolocation services from working. (Note: WebRTC should also be disabled as mentioned above, as it uses a different method of generating location data.)<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8625\" title=\"Disable geolocation | Firefox Security Guide\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-geolocation.png\" alt=\"Disable Geolocation for stronger Firefox Privacy\" width=\"589\" height=\"164\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-geolocation.png 589w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-geolocation-300x84.png 300w\" sizes=\"auto, (max-width: 589px) 85vw, 589px\" \/><\/p>\n<p><b>Disable Plugin Scanning<\/b> \u2013 Plugins can query what extensions and plugins that you have installed on Firefox to profile users. Disabling this feature improves both privacy and functionality while browsing privately.<\/p>\n<p>To Disable Plugin Scanning \u2013 Search for plugin.scan.plid.all and double click the setting to set it to false. This will disable the feature.<\/p>\n<p><b>Disable ALL Telemetry Features<\/b> \u2013 These are features that explicitly collect data.<\/p>\n<p>To Disable All Telemetry \u2013 Type \u201ctelemetry\u201d into the search bar. A large number of settings will pop up in the search. Search for the following and set them all to false:<\/p>\n<p>browser.newtabpage.activity-stream.feeds.telemetry browser.newtabpage.activity-stream.telemetry<br>\nbrowser.pingcentre.telemetry<br>\ndevtools.onboarding.telemetry-logged<br>\nmedia.wmf.deblacklisting-for-telemetry-in-gpu-process<br>\ntoolkit.telemetry.archive.enabled<br>\ntoolkit.telemetry.bhrping.enabled<br>\ntoolkit.telemetry.firstshutdownping.enabled<br>\ntoolkit.telemetry.hybridcontent.enabled<br>\ntoolkit.telemetry.newprofileping.enabled<br>\ntoolkit.telemetry.unified<br>\ntoolkit.telemetry.updateping.enabled<br>\ntoolkit.telemetry.shutdownpingsender.enabled<\/p>\n<p>These changes prevent all kinds of metadata from being stored about your connection both locally and by Mozilla.<\/p>\n<p><b>Disable Prefetching<\/b> \u2013 Firefox by default will pre-load all linked pages on pages that you visit. This becomes a privacy issue because this leads to your browser broadcasting a list of the links that are on the page you are currently visiting, which can allow outside parties to profile your browsing habits from your DNS traffic, or, if you\u2019re not on a VPN it can allow your ISP to infer what web pages you visit within secure sites by looking at the prefetch resources.<\/p>\n<p>To Disable DNS Prefetching \u2013 Type network.dns.disableprefetch into the search bar and double click on the option to set the option to True. This will prevent the browser from broadcasting your browsing habits through DNS requests. You also need to disable network.prefetch-next<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8626\" title=\"\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-prefetch.png\" alt=\"Disable Prefetch to Harden Firefox\" width=\"738\" height=\"170\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-prefetch.png 738w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-prefetch-300x69.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p>To Disable Network Prefetching \u2013 Type network.prefetch-next into the search bar and double click the option to set it to false.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8627\" title=\"Disable prefetch | Firefox Hardening Guide\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-prefetch2.png\" alt=\"Disable prefetch for strong Firefox Security\" width=\"741\" height=\"163\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-prefetch2.png 741w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-prefetch2-300x66.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p><b>Disable Referral Headers<\/b> \u2013 Websites use referral headers to track users movements from one site to another. This tells the website you are visiting what site that you came from.<\/p>\n<p>To Disable HTTP Referral Headers \u2013 Type network.http.sendRefererHeader into the search bar and double click the setting which will open a dialog box. Type 0 into the box that pops up and hit okay to completely disable Referral headers.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8628\" title=\"Disable Referrers | Firefox Hardening Guide\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-referrers.png\" alt=\"Disable Referrers for Strong Firefox Security\" width=\"740\" height=\"327\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-referrers.png 740w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-referrers-300x133.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p><b>Disable WebGL <\/b>\u2013 WebGL is an application interface that allows websites direct access to your graphics card. This introduces a huge attack surface for potential security risks as well as unique types of fingerprinting. It should be disabled.<\/p>\n<p>To Disable WebGL \u2013 \u00a0Type webgl.disabled into the search bar, and double click on the option that is displayed to set it to true.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8629\" title=\"Disable WebGL | Firefox Security Guide\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-webgl.png\" alt=\"Disable WebGL for strong Firefox Security\" width=\"737\" height=\"168\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-webgl.png 737w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-webgl-300x68.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p><b>Disable Battery API \u2013 <\/b>The Mozilla API can allow a site to track the current battery life of a device, which can be used in conjunction with other methods to identify and track users.<\/p>\n<p>To Disable the Battery API \u2013 Type dom.battery.enabled into the search bar and double click the option listed to set it to false.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8622\" title=\"Disable Battery Reads | Firefox Security Guide\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-battery-reads.png\" alt=\"Disable Battery Reads | Firefox Security Guide\" width=\"735\" height=\"164\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-battery-reads.png 735w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/disable-battery-reads-300x67.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p>Disable web handshakes that re-use credentials \u2013 (more info: SuperCooKeys)<\/p>\n<p><strong>Disable Session Identifiers (HIDDEN FEATURE)<\/strong><\/p>\n<p>To disable session identifiers: Type about:config into your navigation bar in Firefox, in the screen that pops up, you must right click on a blank area of the page and select new -&gt; boolean.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-9049\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-1024x278.png\" alt=\"\" width=\"840\" height=\"228\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-1024x278.png 1024w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-300x81.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-768x209.png 768w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature.png 1123w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>In the window that pops up, we have to enter the exact name of the hidden feature: security.ssl.disable_session_identifiers and hit OK.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9050\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-2.png\" alt=\"\" width=\"973\" height=\"547\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-2.png 973w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-2-300x169.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-2-768x432.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>Then we have to search for the feature that we added and make sure that it is set to TRUE.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9051\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-3.png\" alt=\"\" width=\"797\" height=\"146\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-3.png 797w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-3-300x55.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/hidden-feature-3-768x141.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/p>\n<p><strong>Enable First-Party Isolation<br>\n<\/strong><\/p>\n<p>This feature prevents the browser from making requests to sites outside of the primary domain from the site. This prevents large ubiquitous services from following your keys around the web like a supercookie, and it also prevents all kinds of 3rd party data tracking.<\/p>\n<p>To enable first party isolation: Type about:config into your navigation bar in Firefox. In the screen that pops up, enter privacy.firstparty.isolate into the search bar, and make sure that the setting is set to TRUE. (This setting can break websites that rely heavily on 3rd party libraries and scripts.)<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9053\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/Firstpartyisolate.png\" alt=\"\" width=\"994\" height=\"168\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/Firstpartyisolate.png 994w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/Firstpartyisolate-300x51.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/Firstpartyisolate-768x130.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p><strong>Disable TLS False Start <\/strong><\/p>\n<p>This is because it does not allow the client to fully complete its handshake before starting the actual session. There is more info here from the IETF: <a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc7918\">https:\/\/datatracker.ietf.org\/doc\/html\/rfc7918<\/a>\u00a0(See section 5. Security Considerations)<\/p>\n<p>To disable TLS false start: Type about:config into your navigation bar in Firefox. In the screen that pops up, enter security.ssl.enable_false_start into the search bar, and make sure that the setting is set to FALSE.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-9054\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/False-Start.png\" alt=\"\" width=\"847\" height=\"142\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/False-Start.png 847w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/False-Start-300x50.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/False-Start-768x129.png 768w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/11\/False-Start-846x142.png 846w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p><b>About Camera and Microphone Access<\/b> \u2013 There are many settings in Firefox related to access to the Camera and Microphone. Recently, Firefox has implemented a number of good security and privacy features surrounding access that make editing these settings unnecessary. Disabling these features in about:config will disable Mic and Camera access globally, rather than allow you to permit access to services that you want (like <a href=\"https:\/\/jitsi.org\/jitsi-meet\/\">Jitsi Meet<\/a> for audio\/video chat).<\/p>\n<p>If you NEVER want to use a microphone or webcam through your browser, you can manually disable access. Otherwise, you should allow your permissions built into Firefox to manage access.<\/p>\n<p><a title=\"Back to Firefox Security Guide Navigation\" href=\"#navigationX\">Back to the Top<\/a><\/p>\n<p><a href=\"https:\/\/www.privateinternetaccess.com\/\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8746\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Computer-Eyes_970x250.jpg\" alt=\"PIA For Me | VPN Service\" width=\"970\" height=\"250\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Computer-Eyes_970x250.jpg 970w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Computer-Eyes_970x250-300x77.jpg 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Computer-Eyes_970x250-768x198.jpg 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><\/p>\n<h2 id=\"section4\">Section 4: Editing Trusted Certificate Authorities<\/h2>\n<p>This step takes some trial and error, but dramatically helps reduce your attack surface by outside parties.<\/p>\n<p>First, we need to discuss how the certificate system works. Certificates around the web tell your browser if a site is genuine and they are managed by a group of \u201croot certificates\u201d from organizations around the world. These organizations vouch for the security of their own root certificate and vouch for the validity of all certificates that are made from it. This means that when Typhoon (fake name used for example) creates a certificate for a website, they are telling your browser \u201cthis site is genuine because Typhoon says it is.\u201d You are relying on the reputation of Typhoon to keep your browser safe from spoofing.<\/p>\n<p>There\u2019s some inherent problems with this system. How do we know that Typhoon\u2019s security standards are perfect? How do we know that Typhoon would never create an invalid certificate for someone else accidentally? How do we know that Typhoon would never create a fake certificate for a law enforcement agency or spy organization?<\/p>\n<p>Therein lies a large problem. Firefox (and all browsers and operating systems) trust hundreds of these root certificates by default, and for most users around the world, you don\u2019t encounter most of these root certificates in your day to day web use.<\/p>\n<p>For an example of certificate authorities that people may not want to blindly trust:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-8720\" title=\"SSL Certificate | Firefox Security Guide\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-3-1024x712.png\" alt=\"SSL Certificate Security\" width=\"840\" height=\"584\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-3-1024x712.png 1024w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-3-300x209.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-3-768x534.png 768w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-3.png 1130w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>As a privacy and free information activist, I probably do not want to blindly trust certificates originating from China.<\/p>\n<p>You can remove many of these root certificates from Firefox to make it so that you trust far fewer authorities. To access the certificate manager, you go to the settings menu in Firefox, and click on the Privacy and Security pane on the left side. Then you scroll to the bottom of the page and click on \u201cView Certificates\u2026\u201d In the window that opens up, you can scroll through all of the possible certificate authorities and remove trust (by clicking on the Delete or Distrust\u2026 button) from all of the authorities for sites that you do not visit or do not trust for ethical reasons.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-8721\" title=\"SSL Certificate | Firefox Security Guide\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-1024x798.png\" alt=\"SSL Certificate Security\" width=\"840\" height=\"655\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-1024x798.png 1024w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-300x234.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-768x599.png 768w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust.png 1157w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-8722\" title=\"SSL Certificate | Firefox Security Guide\" src=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-2.png\" alt=\"SSL Certificate in Firefox\" width=\"993\" height=\"557\" srcset=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-2.png 993w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-2-300x168.png 300w, https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/certificate-trust-2-768x431.png 768w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/p>\n<p>This step does require some research, you have to find out which certificates are used by the sites you visit, and limit your trusted certificates to those. Also, many of the big American certificate authorities (such as the Amazon Root CAs, DigiTrust, RapidSSL, GeoTrust, GlobalSign) will break a majority of the Internet if you mistrust them.<\/p>\n<p>Personally I tend to mistrust all certificates from languages that I do not speak (which means it is unlikely that i\u2019ll ever run into those certificates around the web) and also eliminate any certificates that cater to local regions such as Taiwan, Switzerland, the Netherlands, etc.<\/p>\n<p>If you accidentally mistrust a certificate that you want to trust once again, you can click on the \u201cedit trust\u201d button in the certificate manager window, and check the boxes for the services that should trust this certificate authority.<\/p>\n<h3>These steps should help you be substantially safer on the web! Be sure to watch for follow-up articles on how to use the privacy plugins that we recommend and check back frequently for updates to this guide!<\/h3>\n<p><a title=\"Back to Firefox Security Guide Navigation\" href=\"#navigationX\">Back to the Top<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Purpose: This guide shows a user in an easy-to-follow way how to improve the privacy and security settings of Firefox, which, when combined with a privacy VPN, gives a user a strong framework for protecting their information. This guide is broken down into sections, each addressing different areas of security and privacy settings within Firefox. &hellip; <a href=\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Firefox Hardening Guide 2018&#8221;<\/span><\/a><\/p>\n","protected":false},"author":32,"featured_media":8748,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_stopmodifiedupdate":true,"_modified_date":"","footnotes":""},"categories":[12,1],"tags":[842,898,85,899],"class_list":["post-8615","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-news","tag-firefox","tag-guide","tag-security-2","tag-webrtc"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.9 (Yoast SEO v26.9) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Firefox Hardening Guide 2018<\/title>\n<meta name=\"description\" content=\"This is an easy to use step-by-step guide to make Firefox safer, more private, and more secure. When used with a VPN, it hardens your security and privacy.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Firefox Hardening Guide 2018\" \/>\n<meta property=\"og:description\" content=\"This is an easy to use step-by-step guide to make Firefox safer, more private, and more secure. When used with a VPN, it hardens your security and privacy.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/\" \/>\n<meta property=\"og:site_name\" content=\"PIA\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/privateinternetaccess\/\" \/>\n<meta property=\"article:published_time\" content=\"2018-09-26T16:30:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-07-05T07:22:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Firefox-Hardening-Guide-2018-with-text.png\" \/>\n\t<meta property=\"og:image:width\" content=\"2400\" \/>\n\t<meta property=\"og:image:height\" content=\"1260\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Derek Zimmer\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@http:\/\/www.twitter.com\/ostifofficial\" \/>\n<meta name=\"twitter:site\" content=\"@buyvpnservice\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Derek Zimmer\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"22 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/\"},\"author\":{\"name\":\"Derek Zimmer\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/e9f24badc1559621e721d94ecb18d6e1\"},\"headline\":\"Firefox Hardening Guide 2018\",\"datePublished\":\"2018-09-26T16:30:24+00:00\",\"dateModified\":\"2020-07-05T07:22:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/\"},\"wordCount\":3922,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Firefox-Hardening-Guide-2018-with-text.png\",\"keywords\":[\"firefox\",\"guide\",\"security\",\"webrtc\"],\"articleSection\":[\"Cybersecurity\",\"General Privacy News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/\",\"name\":\"Firefox Hardening Guide 2018\",\"isPartOf\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Firefox-Hardening-Guide-2018-with-text.png\",\"datePublished\":\"2018-09-26T16:30:24+00:00\",\"dateModified\":\"2020-07-05T07:22:00+00:00\",\"description\":\"This is an easy to use step-by-step guide to make Firefox safer, more private, and more secure. When used with a VPN, it hardens your security and privacy.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#primaryimage\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Firefox-Hardening-Guide-2018-with-text.png\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Firefox-Hardening-Guide-2018-with-text.png\",\"width\":2400,\"height\":1260,\"caption\":\"Firefox Hardening Guide 2018\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.privateinternetaccess.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Firefox Hardening Guide 2018\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#website\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"name\":\"PIA\",\"description\":\"Online privacy news from around the world.\",\"publisher\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#organization\",\"name\":\"Private Internet Access\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"contentUrl\":\"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png\",\"width\":1200,\"height\":1200,\"caption\":\"Private Internet Access\"},\"image\":{\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/privateinternetaccess\/\",\"https:\/\/x.com\/buyvpnservice\",\"https:\/\/www.instagram.com\/piavpn\/\",\"https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/e9f24badc1559621e721d94ecb18d6e1\",\"name\":\"Derek Zimmer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/399c45f76a929cfe8ed46349f8166d975f7fa088108970562cf67fa46ab0176d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/399c45f76a929cfe8ed46349f8166d975f7fa088108970562cf67fa46ab0176d?s=96&d=mm&r=g\",\"caption\":\"Derek Zimmer\"},\"description\":\"Derek is a cryptographer, security expert and privacy activist. He has twelve years of security experience and six years of experience designing and implementing privacy systems. He founded the Open Source Technology Improvement Fund (OSTIF) which focuses on creating and improving open-source security solutions through auditing, bug bounties, and resource gathering and management.\",\"sameAs\":[\"https:\/\/ostif.org\/\",\"https:\/\/www.linkedin.com\/in\/derek-zimmer-2164a441\/\",\"https:\/\/x.com\/http:\/\/www.twitter.com\/ostifofficial\"],\"url\":\"https:\/\/www.privateinternetaccess.com\/blog\/author\/derek-zimmer\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Firefox Hardening Guide 2018","description":"This is an easy to use step-by-step guide to make Firefox safer, more private, and more secure. When used with a VPN, it hardens your security and privacy.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/","og_locale":"en_US","og_type":"article","og_title":"Firefox Hardening Guide 2018","og_description":"This is an easy to use step-by-step guide to make Firefox safer, more private, and more secure. When used with a VPN, it hardens your security and privacy.","og_url":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/","og_site_name":"PIA","article_publisher":"https:\/\/www.facebook.com\/privateinternetaccess\/","article_published_time":"2018-09-26T16:30:24+00:00","article_modified_time":"2020-07-05T07:22:00+00:00","og_image":[{"width":2400,"height":1260,"url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Firefox-Hardening-Guide-2018-with-text.png","type":"image\/png"}],"author":"Derek Zimmer","twitter_card":"summary_large_image","twitter_creator":"@http:\/\/www.twitter.com\/ostifofficial","twitter_site":"@buyvpnservice","twitter_misc":{"Written by":"Derek Zimmer","Est. reading time":"22 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#article","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/"},"author":{"name":"Derek Zimmer","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/e9f24badc1559621e721d94ecb18d6e1"},"headline":"Firefox Hardening Guide 2018","datePublished":"2018-09-26T16:30:24+00:00","dateModified":"2020-07-05T07:22:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/"},"wordCount":3922,"commentCount":0,"publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Firefox-Hardening-Guide-2018-with-text.png","keywords":["firefox","guide","security","webrtc"],"articleSection":["Cybersecurity","General Privacy News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/","name":"Firefox Hardening Guide 2018","isPartOf":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#primaryimage"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#primaryimage"},"thumbnailUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Firefox-Hardening-Guide-2018-with-text.png","datePublished":"2018-09-26T16:30:24+00:00","dateModified":"2020-07-05T07:22:00+00:00","description":"This is an easy to use step-by-step guide to make Firefox safer, more private, and more secure. When used with a VPN, it hardens your security and privacy.","breadcrumb":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#primaryimage","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Firefox-Hardening-Guide-2018-with-text.png","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/09\/Firefox-Hardening-Guide-2018-with-text.png","width":2400,"height":1260,"caption":"Firefox Hardening Guide 2018"},{"@type":"BreadcrumbList","@id":"https:\/\/www.privateinternetaccess.com\/blog\/firefox-hardening-guide\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.privateinternetaccess.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Firefox Hardening Guide 2018"}]},{"@type":"WebSite","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#website","url":"https:\/\/www.privateinternetaccess.com\/blog\/","name":"PIA","description":"Online privacy news from around the world.","publisher":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.privateinternetaccess.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#organization","name":"Private Internet Access","url":"https:\/\/www.privateinternetaccess.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","contentUrl":"https:\/\/www.privateinternetaccess.com\/blog\/wp-content\/uploads\/2018\/07\/pialogowhitekglogo.png","width":1200,"height":1200,"caption":"Private Internet Access"},"image":{"@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/privateinternetaccess\/","https:\/\/x.com\/buyvpnservice","https:\/\/www.instagram.com\/piavpn\/","https:\/\/www.youtube.com\/channel\/UClyJZ47Rizb1xnwuKXDI0_w"]},{"@type":"Person","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/e9f24badc1559621e721d94ecb18d6e1","name":"Derek Zimmer","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.privateinternetaccess.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/399c45f76a929cfe8ed46349f8166d975f7fa088108970562cf67fa46ab0176d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/399c45f76a929cfe8ed46349f8166d975f7fa088108970562cf67fa46ab0176d?s=96&d=mm&r=g","caption":"Derek Zimmer"},"description":"Derek is a cryptographer, security expert and privacy activist. He has twelve years of security experience and six years of experience designing and implementing privacy systems. He founded the Open Source Technology Improvement Fund (OSTIF) which focuses on creating and improving open-source security solutions through auditing, bug bounties, and resource gathering and management.","sameAs":["https:\/\/ostif.org\/","https:\/\/www.linkedin.com\/in\/derek-zimmer-2164a441\/","https:\/\/x.com\/http:\/\/www.twitter.com\/ostifofficial"],"url":"https:\/\/www.privateinternetaccess.com\/blog\/author\/derek-zimmer\/"}]}},"_links":{"self":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/8615","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/users\/32"}],"replies":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/comments?post=8615"}],"version-history":[{"count":29,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/8615\/revisions"}],"predecessor-version":[{"id":29538,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/posts\/8615\/revisions\/29538"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media\/8748"}],"wp:attachment":[{"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/media?parent=8615"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/categories?post=8615"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.privateinternetaccess.com\/blog\/wp-json\/wp\/v2\/tags?post=8615"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}