🔒 Proposal: Strengthening Privacy Baseline with Standardized Browser Policies #26

Open
opened 2026-02-19 14:43:48 +00:00 by janhalen · 2 comments
janhalen commented 2026-02-19 14:43:48 +00:00 (Migrated from github.com)

TLDR: I propose we adopt centralized browser policies based on open standards to move toward a more privacy-respecting and secure default environment.

The Proposal

  1. Adopt Standardized Mozilla Policy Templates

Instead of manual configuration, we should leverage the Mozilla Policy Templates.

Benefit: This allows us to enforce critical security settings (like disabling telemetry, managing password manager behavior, and forcing HTTPS) across the board via a simple JSON configuration.

Consistency: It removes "it works on my machine" issues related to browser extensions or rogue settings.

  1. Standardize on LibreWolf

While Firefox is great, LibreWolf takes privacy a step further by removing telemetry and baked-in proprietary components out of the box.

Security: It follows the best-practice "privacy settings" by default, reducing our attack surface.

Efficiency: Developers won't need to spend 20 minutes hardening their browser manually.

Why This Matters

By standardizing our browser policies, we:

✅ Protect sensitive project data from browser-level leaks.

✅ Improve performance by cutting out background tracking scripts.

✅ Create a "set it and forget it" environment for new hires.

How to Participate

I'd love to hear your thoughts on this:

Are there specific policies in the Mozilla template you think are mandatory (or too restrictive)?

Have you used LibreWolf in your daily workflow? Are there any site-compatibility issues we should be aware of?

> TLDR: I propose we adopt centralized browser policies based on open standards to move toward a more privacy-respecting and secure default environment. ## The Proposal 1. Adopt Standardized Mozilla Policy Templates Instead of manual configuration, we should leverage the [Mozilla Policy Templates](https://mozilla.github.io/policy-templates/). Benefit: This allows us to enforce critical security settings (like disabling telemetry, managing password manager behavior, and forcing HTTPS) across the board via a simple JSON configuration. Consistency: It removes "it works on my machine" issues related to browser extensions or rogue settings. 2. Standardize on LibreWolf While Firefox is great, [LibreWolf](https://librewolf.net/) takes privacy a step further by removing telemetry and baked-in proprietary components out of the box. Security: It follows the best-practice "privacy settings" by default, reducing our attack surface. Efficiency: Developers won't need to spend 20 minutes hardening their browser manually. Why This Matters By standardizing our browser policies, we: ✅ Protect sensitive project data from browser-level leaks. ✅ Improve performance by cutting out background tracking scripts. ✅ Create a "set it and forget it" environment for new hires. How to Participate I'd love to hear your thoughts on this: Are there specific policies in the Mozilla template you think are mandatory (or too restrictive)? Have you used LibreWolf in your daily workflow? Are there any site-compatibility issues we should be aware of?
janhalen commented 2026-02-19 14:45:22 +00:00 (Migrated from github.com)

Im currently testing this security-by-default policy.json:

{
  "policies": {
    "Homepage": { 
      "URL": "https://firefox-admin-docs.mozilla.org/reference/policies/", 
      "Locked": true,
      "StartPage": "homepage"
    },
    "OverrideFirstRunPage": "",
    "OverridePostUpdatePage": "",
    "NewTabPage": true,
    "BlockAboutAddons": true,
    "BlockAboutConfig": true,
    "BlockAboutProfiles": true,
    "BlockAboutSupport": true,
    "BlockAboutPreferences": true,
    "DisableTelemetry": true,
    "DisableFirefoxAccounts": true,
    "DisableFormHistory": true,
    "DisableFirefoxStudies": true,
    "DisableAppUpdate": true,
    "DisableFirefoxTranslate": true,
    "NetworkPrediction": false,
    "ExtensionUpdate": false,
    "DisplayMenuBar": "never",
    "DisplayBookmarksToolbar": false,
    "SanitizeOnShutdown": {
      "Cache": true,
      "Cookies": true,
      "History": true,
      "FormData": true,
      "Downloads": true,
      "Sessions": true,
      "Locked": true
    },
    "Preferences": {
      "browser.startup.page": 1,
      "privacy.resistFingerprinting": true,
      "privacy.resistFingerprinting.letterboxing": true,
      "privacy.firstparty.isolate": true,
      "network.proxy.socks_remote_dns": true,
      "permissions.default.geo": 2,
      "permissions.default.desktop-notification": 2,
      "permissions.default.camera": 2,
      "permissions.default.microphone": 2,
      "dom.event.clipboardevents.enabled": false,
      "media.peerconnection.enabled": false,
      "browser.translations.enable": false
    }
  }
}

📚 READ MORE: https://firefox-admin-docs.mozilla.org/reference/policies/

Im currently testing this security-by-default policy.json: ~~~json { "policies": { "Homepage": { "URL": "https://firefox-admin-docs.mozilla.org/reference/policies/", "Locked": true, "StartPage": "homepage" }, "OverrideFirstRunPage": "", "OverridePostUpdatePage": "", "NewTabPage": true, "BlockAboutAddons": true, "BlockAboutConfig": true, "BlockAboutProfiles": true, "BlockAboutSupport": true, "BlockAboutPreferences": true, "DisableTelemetry": true, "DisableFirefoxAccounts": true, "DisableFormHistory": true, "DisableFirefoxStudies": true, "DisableAppUpdate": true, "DisableFirefoxTranslate": true, "NetworkPrediction": false, "ExtensionUpdate": false, "DisplayMenuBar": "never", "DisplayBookmarksToolbar": false, "SanitizeOnShutdown": { "Cache": true, "Cookies": true, "History": true, "FormData": true, "Downloads": true, "Sessions": true, "Locked": true }, "Preferences": { "browser.startup.page": 1, "privacy.resistFingerprinting": true, "privacy.resistFingerprinting.letterboxing": true, "privacy.firstparty.isolate": true, "network.proxy.socks_remote_dns": true, "permissions.default.geo": 2, "permissions.default.desktop-notification": 2, "permissions.default.camera": 2, "permissions.default.microphone": 2, "dom.event.clipboardevents.enabled": false, "media.peerconnection.enabled": false, "browser.translations.enable": false } } } ~~~ 📚 READ MORE: https://firefox-admin-docs.mozilla.org/reference/policies/
janhalen commented 2026-02-19 14:45:54 +00:00 (Migrated from github.com)

@ChatBotBerg, this was the config used in the demo i showed you earlier today.

@ChatBotBerg, this was the config used in the demo i showed you earlier today.
Sign in to join this conversation.
No description provided.