Post B5cYOcXQ9bg2KKSToG by khm@hj.9fs.net
 (DIR) More posts by khm@hj.9fs.net
 (DIR) Post #B5bXwFAnEj5CayNpbs by khm@hj.9fs.net
       0 likes, 0 repeats
       
       To Whom it May Concern,I have updated my guide to configuring Firefox, which now moves a lot of manual labor into a policies.json file you can just put on your computer.  There are still some manual steps, but toil is greatly reduced.  This is a big change from the do-every-step-by-hand approach previously used in this guide, and I would appreciate feedback.Thank you for your time,khm
       
 (DIR) Post #B5bYXogu91cVT0JrVY by catsalad@infosec.exchange
       0 likes, 0 repeats
       
       @khm Does not work with Internet Explorer, please advise :neocat_woozy:
       
 (DIR) Post #B5bYXorBWnqLyt84X2 by khm@hj.9fs.net
       0 likes, 0 repeats
       
       working on porting this to ActiveX or some kind of CORBA service
       
 (DIR) Post #B5bbAaJ5l33u3cnLVo by scottwilson@infosec.exchange
       0 likes, 0 repeats
       
       @khm I like your guide. I’m surprised you don’t recommend the extension Privacy Badger. Do you have thoughts about it?
       
 (DIR) Post #B5bbAaV92Ehef0QyIa by khm@hj.9fs.net
       0 likes, 0 repeats
       
       I don't have any objections to it, but in my experience it's not particularly effective, especially given the alacrity with which uBlock Origin's filter lists update.  Cookie AutoDelete is a better default for cleaning out the garbage the modern web tries to store on your computer.  Delete everything by default, tracking or not, and manually approve sites you actually care about!
       
 (DIR) Post #B5bbKb9JTtE9Z7znzE by jerbear@kind.social
       0 likes, 0 repeats
       
       @khm ooo saved. I just recently started using policies.json plus a template FF profile for machine deployments at work. Curious to go through your file and see what else I can do. I also main Firefox at home so this will be useful there. Thank you!
       
 (DIR) Post #B5bbKbJwqLja66yIYy by khm@hj.9fs.net
       0 likes, 0 repeats
       
       Glad you like it, and happy to listen to suggestions for it!
       
 (DIR) Post #B5bk1fpQl5gWACkMls by wickedshell@mastodon.social
       0 likes, 0 repeats
       
       @khm It appears that the noai duckduck go entry is unhappy. It turns all searches into being searches for "%s" (Firefox 150). Manually adding the same search engine to the list however does work (and is pretty easy to do).
       
 (DIR) Post #B5bk1g2BzdtQnmiYfA by khm@hj.9fs.net
       0 likes, 0 repeats
       
       Thanks for the heads-up!  I flubbed the edit (the stuff you type in interactively is not the same as the stuff you put in the json file; it wants {searchTerms} instead of %s).This has been fixed and the new version is on the site!
       
 (DIR) Post #B5bmtNk4Q46FcCyf68 by kepstin@tenforward.social
       0 likes, 0 repeats
       
       @khm hmm. I'm personally not sold on disabling automatic updates and setting "DisableRemoteImprovements" to true, but I guess this guide just isn't intended for my use case. I personally think that getting automatic security updates and out-of-band fixes is important. (For example, in the past day or two they reverted a DTLS change in 150.0 that broke some open-source web conferencing systems via the remote improvements mechanism; a full fix will come later in a point release).Showing punycode for idn is somewhat locale-specific - works for people who speak english and some other latin-script languages, but other folks might need to revert it to get readable domains.
       
 (DIR) Post #B5bmtNxBdIakGt78Xg by khm@hj.9fs.net
       0 likes, 0 repeats
       
       Both valid concerns!As far as I'm aware (and I'm happy to be corrected) there's no public criteria for what Mozilla decides is a remote improvement, and there's no way to garner user consent on a per-improvement basis.  Given Firefox's release cadence, I don't personally think the consent-bypass is worth it.  With a distro package manager you've at least got another set of eyes on whatever Mozilla is cranking out.   If they had a "AskAboutRemoteImprovements" flag I'd probably go for that.Showing punycode for IDN is definitely a personal-taste issue.  I'm disgruntled that this was the half-assed 'solution' we got instead of real localization, and that kind of failure of leadership is the IETF's fault, not Mozilla's.  However, until punycode attacks stop being A Thing, this is something I unreservedly recommend to users who don't see much IDN traffic.
       
 (DIR) Post #B5boCLl27bfMuu2JY8 by kepstin@tenforward.social
       0 likes, 0 repeats
       
       @khm at least they've made one improvement in recent versions - they have split the setting so "studies" (experiments run remotely which often change ui and almost always collect data) can be disabled while leaving  remote improvements (which do not collect data) enabled, tho I think you still need to go to the about:studies page to see which remote improvements you have installed.
       
 (DIR) Post #B5boCM5atA73wfejb6 by khm@hj.9fs.net
       0 likes, 0 repeats
       
       Yep, a definite step forward.  Do you happen to know if it's documented anywhere that remote improvements don't collect data?  Otherwise I'll put finding out on the to-do list
       
 (DIR) Post #B5cSYvokjDzxIB6AxE by CppGuy@infosec.space
       0 likes, 0 repeats
       
       @khm Thanks for this!  I learned about a couple of browser extensions I didn't know about. It'd be great if you could document the policies.json file somewhere (or point to a file where it's documented) so that people knew what it did and whether they might want to change it.  You've been clear about what the other settings and extensions do and why someone might not want to apply some of them, but the policies file is a bit of a mystery and that makes me hesitate before applying it.
       
 (DIR) Post #B5cSYvxyAxN3klPXJw by khm@hj.9fs.net
       0 likes, 0 repeats
       
       Workin on this!
       
 (DIR) Post #B5cSp5ihgAWwdZyUdc by prahou@merveilles.town
       0 likes, 0 repeats
       
       @khm what are apps in this context? `ManualAppUpdateOnly`
       
 (DIR) Post #B5cSp5tL2d2NAYwzDM by khm@hj.9fs.net
       0 likes, 0 repeats
       
       Firefox is the app.  That setting stops Firefox from checking for its own updates; you either have to wait for an OS package to update or manually initiate the update check.
       
 (DIR) Post #B5cYOcKev3T7gkUHuy by Albirew@soshar.dess.ga
       0 likes, 0 repeats
       
       @khm@hj.9fs.net is cookie autodelete still useful with 1st party isolation enabled by default?on another note, i'm not familiar with policies.json, but does the "Status": "user" means param value is set only at profile creation and allow permanent change by user (against user.js that allow change only until FF is closed)?
       
 (DIR) Post #B5cYOcXQ9bg2KKSToG by khm@hj.9fs.net
       0 likes, 0 repeats
       
       Cookie AutoDelete remains useful, since it can clean up stuff like indexeddb and service workers and so forth.  Tracking isn't the only abusive thing companies do with a web browser.As far as I know policies.json is used at every launch.  The "user" status has more to do with how the values show up in about:config (non-default values are bold text, as though a user set them) and to differentiate from "locked" which the user can't override.  The other statuses are "default" which makes them appear in not-bold text in about:config and "clear" which makes the browser reset the setting on startup.If you don't want a setting to persist, in other words, remove it from the policies.json file.
       
 (DIR) Post #B5cmZaJABSqFxEuaWm by CppGuy@infosec.space
       0 likes, 0 repeats
       
       @khm Thank you! 🙏🏼
       
 (DIR) Post #B5cmZaYPGn2EiW2lHs by khm@hj.9fs.net
       0 likes, 0 repeats
       
       hey, I've got some notes up here:https://sciops.net/information/technology/firefox/infohopefully this is helpful!
       
 (DIR) Post #B5cnlEHbzwdd4fIp1s by Steve_Lindsay@fediscience.org
       0 likes, 0 repeats
       
       @khm Ah! I see.  Relatedly, I am looking for studies assessing the effect of traffic calming "road diets" and bike lanes on emergency vehicle response times.  Know of such?
       
 (DIR) Post #B5cnlESbL5QdckRb9s by khm@hj.9fs.net
       0 likes, 0 repeats
       
       this is the only explicit study I'm aware of: https://www.sciencedirect.com/science/article/pii/S2590198224001441this report touches on it a bit: https://nacto.org/wp-content/uploads/safety_and_operation_analysis_lyles.pdfI'm not aware of any actual evidence that bike lanes slow down emergency response times, but my experience is a little more hands-on and a little less academic
       
 (DIR) Post #B5d7FJj2E6RBlnBq8e by khm@hj.9fs.net
       0 likes, 0 repeats
       
       I have updated this again to include extension installation in the policies.json file.  In addition, I've fixed a few bugs that were reported.  You can follow release at this site, which supports RSS.
       
 (DIR) Post #B5dHUDCTlfnPPyhfUG by Steve_Lindsay@fediscience.org
       0 likes, 0 repeats
       
       @khm Super helpful. Thanks! I had found the Corcoran study, and been in touch with them.  But the MI one was new to me.
       
 (DIR) Post #B5dHUDOB4B9a0GB0im by khm@hj.9fs.net
       0 likes, 0 repeats
       
       Might be worth reaching out to NACTO or TRR, who I think are the most likely to have fingers on this pulse...  also CC @HayiWena@mastodon.online who has forgotten more about this than I'll ever know
       
 (DIR) Post #B5eADI4psVRt6C4XtA by pixx@merveilles.town
       0 likes, 0 repeats
       
       @khm @Steve_Lindsay > slow downI've seen studies linked that purported to show the opposite; bike lanes => fewer cars on the road => faster response timesnot to mention *gestures at Europe*they get a lot wrong, buuut
       
 (DIR) Post #B5eADIMCpvLLy4CPxo by cgnarne@hj.9fs.net
       0 likes, 0 repeats
       
       @pixx@merveilles.town @khm@hj.9fs.net @Steve_Lindsay@fediscience.orgIn the netherlands bikelanes double as a fastpath for emergency vehicleshttps://dutchcycling.nl/knowledge/general/bridging-bicycle-promotion-and-emergency-response/