mullvad / mullvad-browser

Privacy-focused browser for Linux, macOS and Windows. Made in collaboration between @torproject and @mullvad
https://mullvad.net/browser
1.14k stars 21 forks source link

Block all permissions by default #72

Closed ruihildt closed 3 months ago

ruihildt commented 1 year ago

in Account:Preferences--> Privacy & Security --> Permissions ... I've always checked all the boxes in there to BLOCK, PREVENT, anything from occuring, e.g. my location, my camera, microphone, etc. ... only opening them when necessary - then rechecking them again immediately afterward.

Shouldn't Mullvad's new browser CHECK those permissions boxes as its default ??

Thorin-Oakenpants commented 1 year ago

my location, my camera, microphone, etc

let's look at these

With the exception of autoplay, all these settings are a fingerprint. Autoplay becomes a lot easier to FP in FF112+ via the Autoplay API (no need to actually try and run any video). Aside from autoplay in the next ESR, none of these have any security or privacy concerns with the current setup. But they should all be locked down as part of a larger tightening of UI prefs for fingerprinting - see https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/40656