Advertisement
Guest User

VPN, privacy & Firefox (+ other Gecko browsers)* rev. 0.3.14

a guest
Jan 6th, 2020
6,756
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.11 KB | None | 0 0
  1. +----------------------------------------------------------------------------------+
  2. | VPN, privacy & Firefox (+ other Gecko browsers)* rev. 0.3.14 |
  3. +----------------------------------------------------------------------------------+
  4.  
  5.  
  6. ========== VPN section ==========
  7.  
  8. + You can try free OpenVPN configs or Softether:
  9.  
  10. + OpenVPN:
  11. - OpenVPN - you can edit configs (.ovpn) with notepad to change encryption (line 88 - standard is not so good: AES-128-CBC - try AES-256-CBC instead)
  12. - OpenVPN - you can edit configs (.ovpn) with notepad to add option "block-outside-dns" (for example in line 104) to avoid DNS leaks
  13. - OpenVPN - if you add option "block-outside-dns" you can avoid "DNS leaks" & you don't need (Simple) DNSCrypt
  14. (my testing suggest that when you using OpenVPN without "block-outside-dns" option together with Simple DNSCrypt you are affected by DNS leaks)
  15. (Simple DNSCrypt not working for me, anyway this needs further testing...)
  16. - OpenVPN - you can edit configs (.ovpn) with notepad to add option "--remote-cert-tls server" (for example in line 21) to avoid "Man-in-the-Middle" attack
  17. https://openvpn.net/index.php/open-source/documentation/howto.html#secnotes [OpenVPN 2.1 and above]
  18. - https://www.vpnbook.com/ (few free OpenVPN configs)
  19. - http://www.vpngate.net/en/ (a lot of free OpenVPN configs)
  20.  
  21. + OpenVPN manuals:
  22. - https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage
  23. - https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage
  24. - https://openvpn.net/index.php/open-source/documentation/howto.html
  25. - https://openvpn.net/index.php/open-source/documentation/security-overview.html
  26.  
  27. + Softether:
  28. - http://www.vpngate.net/en/
  29. - I recommend to try DNSCrypt to avoid DNS leaks (check your DNS leaks - links are below)
  30. - Changed the default algorithm for SSL from RC4-MD5 to AES128-SHA
  31. - http://www.softether.org/5-download/history
  32. - http://www.softether.org/1-features/3._Security_and_Reliability
  33. - https://torrentfreak.com/free-access-to-dozens-of-anonymous-vpns-via-new-university-project-130324/
  34.  
  35. + Softether disadvantages:
  36. - logging policy: 2 weeks [default]
  37. - when you will be disconnected then your IP will be exposed (there is no 'kill switch' feature)
  38. - DNS leaks...
  39.  
  40. + Security of popular algorithms:
  41. - https://en.wikipedia.org/wiki/RC4#Security
  42. - https://en.wikipedia.org/wiki/MD5#Security
  43.  
  44.  
  45. ========== Browser section ==========
  46.  
  47. + Secure your privacy in Firefox:
  48. - by using addons like in IceCat [https://directory.fsf.org/wiki/IceCat] I mean:
  49. Adblock Plus (ABP), Disable WebRTC, Fat-Free Fox, No Resource URI Leak, NoScript, Privacy Badger, uBlock Origin (uBO), uMatrix etc.
  50. Additionally you can add: CanvasBlocker, Disconnect, FoxyProxy, Https Everywhere, Privacy Settings, Random Agent Spoofer.
  51. Take a look @ these sites:
  52. - https://web.archive.org/web/20170404173124/http://b.agilob.net/better-security-privacy-and-anonymity-in-firefox
  53. - http://configfox.sourceforge.net/
  54. - https://www.bestvpn.com/make-firefox-secure-using-aboutconfig/
  55. - https://www.bestvpn.com/privacy-news/control-firefox-privacy-settings-with-an-add-on/
  56. - https://vikingvpn.com/cybersecurity-wiki/browser-security/guide-hardening-mozilla-firefox-for-privacy-and-security
  57. - https://www.howtogeek.com/102032/how-to-optimize-mozilla-firefox-for-maximum-privacy/
  58. - http://www.ghacks.net/2015/07/01/control-privacy-settings-in-firefox-easily/
  59.  
  60. + If you would like to use Google Chrome anyway you can replace it with Chromium or Iron:
  61. - https://en.wikipedia.org/wiki/Chromium_(web_browser)
  62. - https://en.wikipedia.org/wiki/SRWare_Iron
  63.  
  64. + Use Tor or Tor Browser (based on Firefox):
  65. - "We will never be able to de-anonymize all Tor users all the time. • With manual analysis we can de-anonymize a very small fraction of Tor users"
  66. - https://edwardsnowden.com/docs/doc/tor-stinks-presentation.pdf‎
  67. - https://commons.wikimedia.org/wiki/File:Tor_Stinks.pdf
  68. - https://en.wikipedia.org/wiki/Tor_(anonymity_network)#Tor_Browser
  69. - https://www.torproject.org/docs/tor-manual.html.en
  70. - https://www.torproject.org/docs/faq.html.en
  71. - https://blog.torproject.org/improving-tors-anonymity-changing-guard-parameters
  72.  
  73. + SSH/SOCKS/proxy:
  74. - Privoxy - https://en.wikipedia.org/wiki/Privoxy
  75. - https://lifehacker.com/5763170/how-to-secure-and-encrypt-your-web-browsing-on-public-networks-with-hamachi-and-privoxy
  76. - https://lifehacker.com/237227/geek-to-live--encrypt-your-web-browsing-session-with-an-ssh-socks-proxy
  77. - https://outflux.net/blog/archives/2006/12/07/paranoid-browsing-with-squid/
  78. - https://embraceubuntu.com/2006/12/08/ssh-tunnel-socks-proxy-forwarding-secure-browsing/
  79. - https://pl.terminal28.com/instalacja-i-konfiguracja-squid3-tor-privoxy-anonimowosc-w-sieci [translate with your favourite translator]
  80. - https://www.reaper-x.com/2011/10/17/how-to-install-squid-proxy-on-windows/
  81. - https://www.unixmen.com/install-configure-squid-proxy-ubuntu-debian/
  82. - https://www.cyberciti.biz/faq/debian-ubuntu-linux-install-onionrouter-software/
  83. - Pirate Tor Browser - http://www.softpedia.com/get/Internet/Browsers/PirateBrowser.shtml or http://www.majorgeeks.com/files/details/piratebrowser.html
  84.  
  85. + Change your UserAgent frequently (get UA addon for your browser). Example of UA sites:
  86. - Random Agent Spoofer addon for firefox: https://addons.mozilla.org/en-US/firefox/addon/random-agent-spoofer/
  87. List of UA sites:
  88. - http://www.browser-info.net/useragents
  89. - http://mybrowseraddon.com/custom-useragent-string.html
  90. - https://developers.whatismybrowser.com/useragents/explore/
  91. - https://udger.com/resources/ua-list
  92. - https://techblog.willshouse.com/2012/01/03/most-common-user-agents/
  93. - http://www.useragentstring.com/pages/useragentstring.php
  94.  
  95. + Fingerprint (fingerprinting algorithms):
  96. - https://en.wikipedia.org/wiki/Fingerprint_(computing)
  97. - https://en.wikipedia.org/wiki/Canvas_fingerprinting
  98. - https://en.wikipedia.org/wiki/Device_fingerprint
  99. - https://browserleaks.com/canvas
  100.  
  101. + Check your browser privacy/security:
  102. - https://browserleaks.com/
  103. - http://browserspy.dk/
  104. - https://panopticlick.eff.org/
  105. - https://www.howsmyssl.com/
  106.  
  107. + Other sites worth mentioning:
  108. - riseup.net/en/better-web-browsing
  109. - privacytools.io
  110. - https://en.wikipedia.org/wiki/Category:Internet_privacy
  111. - https://en.wikipedia.org/wiki/Category:Crypto-anarchism
  112.  
  113.  
  114. ========== OS section ==========
  115.  
  116. + Check Tails Linux:
  117. - https://en.wikipedia.org/wiki/Tails_(operating_system)
  118. - https://www.wired.com/2014/04/tails/
  119.  
  120. + Check Whonix Linux:
  121. - https://en.wikipedia.org/wiki/Whonix
  122. - https://www.whonix.org/
  123.  
  124. + Secure you DNS with DNSCrypt:
  125. - For Linux follow this: http://www.webupd8.org/2014/08/encrypt-dns-traffic-in-ubuntu-with.html
  126. - For Windows - you need: "dnscrypt-winclient" or "Simple DNSCrypt".
  127. URLs:
  128. - https://simplednscrypt.org/
  129. - https://github.com/jedisct1/dnscrypt-proxy/wiki
  130. - https://github.com/Noxwizard/dnscrypt-winclient
  131. (Simple DNSCrypt not working for me (I'm still using "block-outside-dns" option in OpenVPN config file).
  132. (Anyway this needs further testing...)
  133.  
  134. + Check your DNS leaks:
  135. - https://ipleak.net/
  136. - https://www.dnsleaktest.com/
  137. - https://whoer.net/
  138.  
  139.  
  140. ========== P2P section ==========
  141.  
  142. + Use peerblock
  143. - https://en.wikipedia.org/wiki/PeerBlock
  144. + Use ipfilter.dat
  145. - for example: ed2k://|file|ipfilter_v0153.dat|19871409|93474AE3F1D3A0A7C4EEC7E52A146721|/
  146.  
  147.  
  148. __________________________________________________________
  149. * Other Gecko browsers - this means it may also work with:
  150. Airfox, Beonex Communicator, Camino, Comodo IceDragon, Conkeror, Classilla, Firefox for Android, Flock, Galeon, Ghostzilla, HP Secure Web Browser, IceCat (GNU IceWeasel), K-Meleon, Kazehakase, Kirix Strata, Lotus Symphony, Lunascape, MicroB, Minimo, Netscape 6, Nightingale, Oxygen, Pale Moon, Portable FireFox, SeaMonkey, Swiftfox, Swiftweasel, Sylera (for mobile), TenFourFox, Timberwolf (AmigaOS 4), Tor Browser, Waterfox, xB Browser
  151.  
  152. https://en.wikipedia.org/wiki/Gecko_(software)
  153.  
  154. Any suggestions are welcomed.
  155.  
  156. Source:
  157. https://beamstat.com/chan/privacy
  158. https://beamstat.com/chan/Crypto-Anarchist%20Federation
  159. (Bitmessage channel)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement