Browser Privacy Settings
The browser is our primary window to the internet and also a major channel for privacy leaks. This article explains how to configure Firefox and system network settings on Ubuntu 26.04 to protect your privacy.
Firefox Privacy Settings
Ubuntu 26.04 ships with Firefox (Snap version) by default, which comes with rich privacy protection features.
Enhanced Tracking Protection
Firefox includes built-in Enhanced Tracking Protection (ETP), enabled in “Standard” mode by default:
- Open Firefox, click the menu button (three horizontal lines)
- Select “Settings” > “Privacy & Security”
- In the “Enhanced Tracking Protection” section, choose your protection level:
| Level | Description |
|---|---|
| Standard | Balances privacy and compatibility, blocks known trackers |
| Strict | Stronger protection, may affect some websites |
| Custom | Manually choose what to block |
The “Strict” mode is recommended; you can downgrade protection for specific sites that have issues.
about:config Advanced Privacy Settings
Enter about:config in the address bar to access advanced settings and modify the following:
# Disable telemetry data collection
toolkit.telemetry.enabled = false
toolkit.telemetry.unified = false
toolkit.telemetry.archive.enabled = false
datareporting.healthreport.uploadEnabled = false
datareporting.policy.dataSubmissionEnabled = false
# Disable Pocket recommendations
extensions.pocket.enabled = false
# Disable Firefox account promotions
identity.fxaccounts.enabled = false
# Enhanced cookie isolation
privacy.firstparty.isolate = true
# Resist browser fingerprinting
privacy.resistFingerprinting = true
# Prevent WebRTC from leaking local IP
media.peerconnection.ice.default_address_only = true
media.peerconnection.ice.no_host = true
# Send DNT header in all windows
privacy.donottrackheader.enabled = true
# Disable prefetching (may reveal browsing intent)
network.prefetch-next = false
network.dns.disablePrefetch = true
network.http.speculative-parallel-limit = 0
# HTTPS-Only mode
dom.security.https_only_mode = true
dom.security.https_only_mode_ever_enabled = true
# Clear data on exit
privacy.sanitize.sanitizeOnShutdown = true
privacy.clearOnShutdown.cache = true
privacy.clearOnShutdown.cookies = false
privacy.clearOnShutdown.history = false
privacy.clearOnShutdown.sessions = trueCookie Management
In “Settings” > “Privacy & Security” > “Cookies and Site Data”:
- Check “Delete cookies and site data when Firefox is closed”
- Or set exceptions to keep cookies for frequently used sites
HTTPS-Only Mode
Enable HTTPS-Only mode to force all connections to use HTTPS:
- Settings > Privacy & Security
- Scroll to “HTTPS-Only Mode”
- Select “Enable HTTPS-Only Mode in all windows”
Recommended Browser Extensions
uBlock Origin
The most powerful ad and tracker blocker:
- Install: Search for “uBlock Origin” in the Firefox Add-ons store
- Recommended filter lists:
- EasyList (ad blocking)
- EasyPrivacy (privacy protection)
- Fanboy’s Annoyances (pop-up blocking)
- Regional supplementary rules as needed
Other Recommended Extensions
| Extension | Function |
|---|---|
| Privacy Badger | Made by EFF, automatically learns and blocks trackers |
| Cookie AutoDelete | Automatically deletes unneeded cookies |
| Decentraleyes | Locally replaces CDN resources to prevent CDN tracking |
| NoScript | Fine-grained JavaScript execution control |
| Bitwarden | Open-source password manager |
| Firefox Multi-Account Containers | Isolate different websites in separate containers |
Container Tabs
Firefox’s Container Tabs feature can isolate cookies and data between different websites:
- Install the “Firefox Multi-Account Containers” extension
- Create different containers (e.g., “Work”, “Personal”, “Shopping”, “Social”)
- Open different websites in different containers — they cannot track each other
DNS over HTTPS (DoH)
Enabling DoH in Firefox
DoH encrypts DNS queries, preventing ISPs and man-in-the-middle attacks from monitoring which websites you visit.
- Settings > Privacy & Security
- Scroll to the bottom to “DNS over HTTPS”
- Select “Max Protection” or “Increased Protection”
- Choose a DNS provider
Or via about:config:
network.trr.mode = 2 # 2=prefer DoH, 3=DoH only
network.trr.uri = https://cloudflare-dns.com/dns-queryCommon DoH providers:
| Provider | DoH URL |
|---|---|
| Cloudflare | https://cloudflare-dns.com/dns-query |
https://dns.google/dns-query | |
| Quad9 | https://dns.quad9.net/dns-query |
Enabling DoH at the System Level
Ubuntu 26.04’s systemd-resolved supports DNS over TLS (DoT):
sudo nano /etc/systemd/resolved.conf[Resolve]
DNS=1.1.1.1#cloudflare-dns.com 8.8.8.8#dns.google
FallbackDNS=9.9.9.9#dns.quad9.net
DNSOverTLS=yes
DNSSEC=allow-downgradesudo systemctl restart systemd-resolved
# Verify DNS configuration
resolvectl status
resolvectl query example.comConfiguring DNS with NetworkManager
# View current connections
nmcli connection show
# Set DNS servers
nmcli connection modify "Wired connection 1" ipv4.dns "1.1.1.1 8.8.8.8"
nmcli connection modify "Wired connection 1" ipv4.ignore-auto-dns yes
# Reactivate the connection
nmcli connection up "Wired connection 1"Network Privacy
VPN Configuration
# Install OpenVPN support
sudo apt install openvpn network-manager-openvpn-gnome
# Install WireGuard
sudo apt install wireguard
# WireGuard configuration
sudo nano /etc/wireguard/wg0.conf[Interface]
PrivateKey = YOUR_PRIVATE_KEY
Address = 10.0.0.2/24
DNS = 1.1.1.1
[Peer]
PublicKey = SERVER_PUBLIC_KEY
Endpoint = vpn.example.com:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25# Start WireGuard
sudo wg-quick up wg0
# Enable at boot
sudo systemctl enable wg-quick@wg0
# Check status
sudo wg showPreventing DNS Leaks
Ensure DNS queries also go through the VPN when using one:
# Check for DNS leaks
# Visit https://dnsleaktest.com
# Ensure DNS points to the VPN-provided DNS
resolvectl status
# If there is a leak, configure WireGuard to use VPN DNS
# In [Interface], set: DNS = VPN-provided DNSTor Browser
For the highest level of anonymity:
# Install Tor Browser via Flatpak
flatpak install flathub org.torproject.torbrowser-launcher
# Or download from the official website
# https://www.torproject.org/download/System-Level Privacy Settings
GNOME Privacy Settings
# Disable location services
gsettings set org.gnome.system.location enabled false
# Disable automatic problem reporting
gsettings set org.gnome.desktop.privacy report-technical-problems false
# Set file history retention days
gsettings set org.gnome.desktop.privacy recent-files-max-age 7
# Set trash auto-cleanup days
gsettings set org.gnome.desktop.privacy remove-old-trash-files true
gsettings set org.gnome.desktop.privacy old-files-age 7
# Disable camera
gsettings set org.gnome.desktop.privacy disable-camera true
# Disable microphone
gsettings set org.gnome.desktop.privacy disable-microphone trueClearing Browsing Traces
# Clear Firefox cache
rm -rf ~/snap/firefox/common/.cache/mozilla/firefox/*/cache2
# Clear thumbnail cache
rm -rf ~/.cache/thumbnails/*
# Clear recent files record
rm ~/.local/share/recently-used.xbel
# Clear Bash history
history -c
rm ~/.bash_history
# Clear clipboard
xclip -selection clipboard < /dev/null 2>/dev/nullBrowser Fingerprinting Protection
Browser fingerprinting is a technique that uniquely identifies users by collecting various characteristics of the browser and system.
Checking Fingerprint Uniqueness
Visit the following websites to test your browser fingerprint:
- https://coveryourtracks.eff.org (EFF’s fingerprint detection)
- https://browserleaks.com
Measures to Reduce Fingerprint Uniqueness
- Use Firefox’s anti-fingerprinting feature:
privacy.resistFingerprinting = true - Use a common screen resolution (1920x1080)
- Reduce the number of installed fonts
- Limit the number of browser extensions (too many extensions actually increase fingerprint uniqueness)
- Use Container Tabs to isolate different websites
Privacy Checklist
- Firefox Enhanced Tracking Protection set to “Strict”
- uBlock Origin installed with updated filter lists
- HTTPS-Only Mode enabled
- DNS over HTTPS enabled
- about:config privacy options configured
- Browsing data cleared regularly
- Container Tabs used for different purposes
- No DNS leaks when connected to VPN
- System location services disabled
- Browser fingerprint uniqueness within acceptable range