Skip to Content
DocsOperationsSecurity & PrivacyBrowser Privacy Settings

Browser Privacy Settings

The browser is our primary window to the internet and also a major channel for privacy leaks. This article explains how to configure Firefox and system network settings on Ubuntu 26.04 to protect your privacy.

Firefox Privacy Settings

Ubuntu 26.04 ships with Firefox (Snap version) by default, which comes with rich privacy protection features.

Enhanced Tracking Protection

Firefox includes built-in Enhanced Tracking Protection (ETP), enabled in “Standard” mode by default:

  1. Open Firefox, click the menu button (three horizontal lines)
  2. Select “Settings” > “Privacy & Security”
  3. In the “Enhanced Tracking Protection” section, choose your protection level:
LevelDescription
StandardBalances privacy and compatibility, blocks known trackers
StrictStronger protection, may affect some websites
CustomManually choose what to block

The “Strict” mode is recommended; you can downgrade protection for specific sites that have issues.

about:config Advanced Privacy Settings

Enter about:config in the address bar to access advanced settings and modify the following:

# Disable telemetry data collection toolkit.telemetry.enabled = false toolkit.telemetry.unified = false toolkit.telemetry.archive.enabled = false datareporting.healthreport.uploadEnabled = false datareporting.policy.dataSubmissionEnabled = false # Disable Pocket recommendations extensions.pocket.enabled = false # Disable Firefox account promotions identity.fxaccounts.enabled = false # Enhanced cookie isolation privacy.firstparty.isolate = true # Resist browser fingerprinting privacy.resistFingerprinting = true # Prevent WebRTC from leaking local IP media.peerconnection.ice.default_address_only = true media.peerconnection.ice.no_host = true # Send DNT header in all windows privacy.donottrackheader.enabled = true # Disable prefetching (may reveal browsing intent) network.prefetch-next = false network.dns.disablePrefetch = true network.http.speculative-parallel-limit = 0 # HTTPS-Only mode dom.security.https_only_mode = true dom.security.https_only_mode_ever_enabled = true # Clear data on exit privacy.sanitize.sanitizeOnShutdown = true privacy.clearOnShutdown.cache = true privacy.clearOnShutdown.cookies = false privacy.clearOnShutdown.history = false privacy.clearOnShutdown.sessions = true

In “Settings” > “Privacy & Security” > “Cookies and Site Data”:

  • Check “Delete cookies and site data when Firefox is closed”
  • Or set exceptions to keep cookies for frequently used sites

HTTPS-Only Mode

Enable HTTPS-Only mode to force all connections to use HTTPS:

  1. Settings > Privacy & Security
  2. Scroll to “HTTPS-Only Mode”
  3. Select “Enable HTTPS-Only Mode in all windows”

uBlock Origin

The most powerful ad and tracker blocker:

  • Install: Search for “uBlock Origin” in the Firefox Add-ons store
  • Recommended filter lists:
    • EasyList (ad blocking)
    • EasyPrivacy (privacy protection)
    • Fanboy’s Annoyances (pop-up blocking)
    • Regional supplementary rules as needed
ExtensionFunction
Privacy BadgerMade by EFF, automatically learns and blocks trackers
Cookie AutoDeleteAutomatically deletes unneeded cookies
DecentraleyesLocally replaces CDN resources to prevent CDN tracking
NoScriptFine-grained JavaScript execution control
BitwardenOpen-source password manager
Firefox Multi-Account ContainersIsolate different websites in separate containers

Container Tabs

Firefox’s Container Tabs feature can isolate cookies and data between different websites:

  1. Install the “Firefox Multi-Account Containers” extension
  2. Create different containers (e.g., “Work”, “Personal”, “Shopping”, “Social”)
  3. Open different websites in different containers — they cannot track each other

DNS over HTTPS (DoH)

Enabling DoH in Firefox

DoH encrypts DNS queries, preventing ISPs and man-in-the-middle attacks from monitoring which websites you visit.

  1. Settings > Privacy & Security
  2. Scroll to the bottom to “DNS over HTTPS”
  3. Select “Max Protection” or “Increased Protection”
  4. Choose a DNS provider

Or via about:config:

network.trr.mode = 2 # 2=prefer DoH, 3=DoH only network.trr.uri = https://cloudflare-dns.com/dns-query

Common DoH providers:

ProviderDoH URL
Cloudflarehttps://cloudflare-dns.com/dns-query
Googlehttps://dns.google/dns-query
Quad9https://dns.quad9.net/dns-query

Enabling DoH at the System Level

Ubuntu 26.04’s systemd-resolved supports DNS over TLS (DoT):

sudo nano /etc/systemd/resolved.conf
[Resolve] DNS=1.1.1.1#cloudflare-dns.com 8.8.8.8#dns.google FallbackDNS=9.9.9.9#dns.quad9.net DNSOverTLS=yes DNSSEC=allow-downgrade
sudo systemctl restart systemd-resolved # Verify DNS configuration resolvectl status resolvectl query example.com

Configuring DNS with NetworkManager

# View current connections nmcli connection show # Set DNS servers nmcli connection modify "Wired connection 1" ipv4.dns "1.1.1.1 8.8.8.8" nmcli connection modify "Wired connection 1" ipv4.ignore-auto-dns yes # Reactivate the connection nmcli connection up "Wired connection 1"

Network Privacy

VPN Configuration

# Install OpenVPN support sudo apt install openvpn network-manager-openvpn-gnome # Install WireGuard sudo apt install wireguard # WireGuard configuration sudo nano /etc/wireguard/wg0.conf
[Interface] PrivateKey = YOUR_PRIVATE_KEY Address = 10.0.0.2/24 DNS = 1.1.1.1 [Peer] PublicKey = SERVER_PUBLIC_KEY Endpoint = vpn.example.com:51820 AllowedIPs = 0.0.0.0/0, ::/0 PersistentKeepalive = 25
# Start WireGuard sudo wg-quick up wg0 # Enable at boot sudo systemctl enable wg-quick@wg0 # Check status sudo wg show

Preventing DNS Leaks

Ensure DNS queries also go through the VPN when using one:

# Check for DNS leaks # Visit https://dnsleaktest.com # Ensure DNS points to the VPN-provided DNS resolvectl status # If there is a leak, configure WireGuard to use VPN DNS # In [Interface], set: DNS = VPN-provided DNS

Tor Browser

For the highest level of anonymity:

# Install Tor Browser via Flatpak flatpak install flathub org.torproject.torbrowser-launcher # Or download from the official website # https://www.torproject.org/download/

System-Level Privacy Settings

GNOME Privacy Settings

# Disable location services gsettings set org.gnome.system.location enabled false # Disable automatic problem reporting gsettings set org.gnome.desktop.privacy report-technical-problems false # Set file history retention days gsettings set org.gnome.desktop.privacy recent-files-max-age 7 # Set trash auto-cleanup days gsettings set org.gnome.desktop.privacy remove-old-trash-files true gsettings set org.gnome.desktop.privacy old-files-age 7 # Disable camera gsettings set org.gnome.desktop.privacy disable-camera true # Disable microphone gsettings set org.gnome.desktop.privacy disable-microphone true

Clearing Browsing Traces

# Clear Firefox cache rm -rf ~/snap/firefox/common/.cache/mozilla/firefox/*/cache2 # Clear thumbnail cache rm -rf ~/.cache/thumbnails/* # Clear recent files record rm ~/.local/share/recently-used.xbel # Clear Bash history history -c rm ~/.bash_history # Clear clipboard xclip -selection clipboard < /dev/null 2>/dev/null

Browser Fingerprinting Protection

Browser fingerprinting is a technique that uniquely identifies users by collecting various characteristics of the browser and system.

Checking Fingerprint Uniqueness

Visit the following websites to test your browser fingerprint:

Measures to Reduce Fingerprint Uniqueness

  1. Use Firefox’s anti-fingerprinting feature: privacy.resistFingerprinting = true
  2. Use a common screen resolution (1920x1080)
  3. Reduce the number of installed fonts
  4. Limit the number of browser extensions (too many extensions actually increase fingerprint uniqueness)
  5. Use Container Tabs to isolate different websites

Privacy Checklist

  • Firefox Enhanced Tracking Protection set to “Strict”
  • uBlock Origin installed with updated filter lists
  • HTTPS-Only Mode enabled
  • DNS over HTTPS enabled
  • about:config privacy options configured
  • Browsing data cleared regularly
  • Container Tabs used for different purposes
  • No DNS leaks when connected to VPN
  • System location services disabled
  • Browser fingerprint uniqueness within acceptable range
Last updated on