Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Some tests with Firefox (video)


  • Please log in to reply
10 replies to this topic

#1 Sampei_Nihira

Sampei_Nihira

  •  Avatar image
  • Members
  • 697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Italy
  • Local time:06:06 AM

Posted 04 June 2023 - 06:14 AM

I prepared this video highlighting some tests performed with Firefox.
 
Midimusicman79 I hope it is useful for you. :thumbup2:
If you do not have these results it would be best to change the relevant settings in about:config.
 
I cannot perform the WebRTC test for visible IP.
 
 
P.S.
 
3.jpg

Edited by hamluis, 04 June 2023 - 08:03 AM.
Moved from Web Browsing to Tips/Tricks - Hamluis.


BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  •  Avatar image
  • Moderator
  • 63,879 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:12:06 AM

Posted 04 June 2023 - 08:04 AM

And...what might be the purpose/results of such tests?

 

Louis



#3 Sampei_Nihira

Sampei_Nihira
  • Topic Starter

  •  Avatar image
  • Members
  • 697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Italy
  • Local time:06:06 AM

Posted 04 June 2023 - 08:07 AM

Increased privacy,increased security.



#4 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 5,070 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:07:06 AM

Posted 04 June 2023 - 09:32 AM

Thank you, Sampei_Nihira! :)

 

And yes, upon visiting WebRTC Leak Test - BrowserLeaks, as my screenshot shows, I already have most, if not all, the same results.

 

So, I did change my relevant media.peerconnection.enabled=false setting in Mozilla Firefox - about:config.

 

browserleaks3.png


Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), RuckZuck, PatchMyPC, UpdateHub, WingetUI, UCheck, and Winget. I have 29 Years of PC Experience.

#5 Sampei_Nihira

Sampei_Nihira
  • Topic Starter

  •  Avatar image
  • Members
  • 697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Italy
  • Local time:06:06 AM

Posted 04 June 2023 - 11:36 AM

Each test in the video should be not similar (similar is not good), but identical. :wink:



#6 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 5,070 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:07:06 AM

Posted 04 June 2023 - 01:01 PM

Thank you, Sampei_Nihira! :)

 

However, on the Ping Spotter Test in Mozilla Firefox, I get this result: Beacon API Status Request Sent 🔥, but the other tests are blocked.

 

So, I would like to ask you, what are the pros and cons of changing the Beacon.enabled=false setting in Firefox - about:config. :question:

 

On the Encrypted Client Hello (ECH) test, I get this result: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.

 

On the Canvas Fingerprinting Test, I get this result: Uniqueness of 99.97% (50 of 181189 user agents have the same signature), and your web browser is Firefox, and your operating system is Windows.

 

On the WebGL Browser Report Test, I get this result: This browser supports WebGL ✔ True, and This browser supports WebGL 2 ✔ True.

 

On the Geolocation API test, I get this result: Origin Permissions ? "prompt" – you ask when browserleaks.com tries to request your location...,

 

...Global Permissions × "denied" – you don't allow third-party websites to request your location Geolocation API API Status ✔ Your browser supports Geolocation API.

 

On the Content Filters and Proxy Detection Test, I get this result: Subscriptions ✔ Detected 9 Filters: 8 General, 1 Regional.

 

And on the SSL/TLS Client Test, I get this result: HTTP User-Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/113.0.


Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), RuckZuck, PatchMyPC, UpdateHub, WingetUI, UCheck, and Winget. I have 29 Years of PC Experience.

#7 Sampei_Nihira

Sampei_Nihira
  • Topic Starter

  •  Avatar image
  • Members
  • 697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Italy
  • Local time:06:06 AM

Posted 04 June 2023 - 01:34 PM

For the first question, it is always the usual answer.
More privacy.
Websites can violate your privacy (when you surf the net) ,if you want to avoid this you have to take countermeasures.
 
More privacy also means more security because usually you don't initiate an attack on a "castle with imposing walls well defended" it is easier to successfully attack a "straw house"
 
Read this:
 
 
For the last question, the Insecure Cipher Suites are important.
But try to drop this aspect and focus your attention on the part following Beacon.
 
 

Study in the various parts this famous user.js:

 

https://github.com/arkenfox/user.js/blob/master/user.js


Edited by Sampei_Nihira, 04 June 2023 - 01:37 PM.


#8 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 5,070 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:07:06 AM

Posted 04 June 2023 - 04:00 PM

Thank you, Sampei_Nihira! :)

Your links make for essential reading! :thumbup2:

However, with all due respect, if it is okay with you, tomorrow, I am going to try to help my dad (soon 80 years old)...,

...with a BSOD/Crash issue by posting a new topic in the Windows Crashes and Blue Screen of Death (BSOD) Help and Support Forum. :whistle:
Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), RuckZuck, PatchMyPC, UpdateHub, WingetUI, UCheck, and Winget. I have 29 Years of PC Experience.

#9 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 5,070 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:07:06 AM

Posted 26 October 2023 - 01:00 PM

You probably already know this, but Mozilla Firefox, version 119, which recently was published, features Encrypted Client Hello (ECH). :thumbup2:

 

The browser's Release Notes state, "Encrypted Client Hello (ECH) is now available to Firefox users, delivering a more private browsing experience.

 

ECH extends the encryption used in TLS connections to cover more of the handshake and better protect sensitive fields. Read more about the launch of ECH on Mozilla Distilled."

 

On the Encrypted Client Hello (ECH) test, I get this result: SSL_ECH_OUTER_SNI: cover.defo.ie, SSL_ECH_INNER_SNI: defo.ie, and SSL_ECH_STATUS: success greentick-small.png. :thumbup2:

 

Out of curiosity, I decided to test all my Chromium-based browsers with the Encrypted Client Hello (ECH) test, and here are the results:

 

In Microsoft Edge Chromium, I get this: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.

 

In Google Chrome, I get this: SSL_ECH_OUTER_SNI: cover.defo.ie, SSL_ECH_INNER_SNI: defo.ie, and SSL_ECH_STATUS: success greentick-small.png.

 

In Opera, I get this: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.

 

In Sleipnir, I get this: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.

 

In Vivaldi, I get this: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.

 

In Brave Chromium, I get this: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.

 

In Chromium Stable, I get this: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.

 

In Opera GX, I get this: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.

 

In Mozilla Firefox Portable, I get this: SSL_ECH_OUTER_SNI: cover.defo.ie, SSL_ECH_INNER_SNI: defo.ie, and SSL_ECH_STATUS: success greentick-small.png. :thumbup2:

 

In Vivaldi Portable, I get this: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.

 

In Sleipnir Portable, I get this: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.

 

In Brave Portable, I get this: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.

 

In Google Chrome Portable, I get this: SSL_ECH_OUTER_SNI: cover.defo.ie, SSL_ECH_INNER_SNI: defo.ie, and SSL_ECH_STATUS: success greentick-small.png.

 

In Opera Portable, I get this: SSL_ECH_OUTER_SNI: NONE, SSL_ECH_INNER_SNI: NONE, and SSL_ECH_STATUS: not attempted redx-small.png.


Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), RuckZuck, PatchMyPC, UpdateHub, WingetUI, UCheck, and Winget. I have 29 Years of PC Experience.

#10 Sampei_Nihira

Sampei_Nihira
  • Topic Starter

  •  Avatar image
  • Members
  • 697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Italy
  • Local time:06:06 AM

Posted 27 October 2023 - 05:32 AM

In Firefox, ECH, it was available even before that.
You had not activated it.
As it is available in all other Chromium-based browsers.


#11 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 5,070 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:07:06 AM

Posted 27 October 2023 - 01:08 PM

When Encrypted Client Hello (ECH) first became available in Mozilla Firefox version 85 on January 7, 2021, it was only experimental or a draft. :mellow:

 

In the above article, it says, "Though we recommend that users wait for ECH to be enabled by default, some may want to enable this functionality earlier."

 

That is one difference between you and me because I waited until ECH was enabled by default, but you enabled this functionality earlier. :thumbup2:

 

Feature: TLS Encrypted Client Hello (ECH) became generally available in Chromium-based browsers version 117, and I waited for that as well. :thumbup2:

 

As mentioned, Encrypted Client Hello (ECH) is nowadays apparently only available by default in Google Chrome, but you enabled this functionality earlier in Microsoft Edge Chromium. :thumbup2:

 

I have decided to wait for that functionality to become available by default in my other Chromium-based browsers because I do NOT enjoy enabling features in chrome://flags/. :thumbup2:

 

The Encrypted Client Hello (ECH) setting in Google Chrome is configurable via chrome://flags/#encrypted-client-hello.

 

And in Microsoft Edge Chromium via the --enable-features=EncryptedClientHello Command Line switch and via edge://flags/#dns-https-svcb and edge://flags/#use-dns-https-svcb-alpn.


Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), RuckZuck, PatchMyPC, UpdateHub, WingetUI, UCheck, and Winget. I have 29 Years of PC Experience.




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users