• betterdeadthanreddit@lemmy.world
    link
    fedilink
    arrow-up
    135
    arrow-down
    1
    ·
    5 days ago

    Settings, About Firefox. Tap the logo several times until it enables the debug menu. Back to settings, Nimbus Experiments. Find the VPN setting at the bottom of the list and you should be able to turn it off there.

    A super straightforward process, 100% seriously good design by Mozilla.

    • dgdft@lemmy.world
      link
      fedilink
      English
      arrow-up
      22
      arrow-down
      3
      ·
      5 days ago

      In what world is a public email sensitive PII, mate? Sure, “never post anything on the internet ever” is the best OPSEC posture by default, but this user is a clearly-experienced self-hoster who understands the risks and consequences of what they’re doing.

      It’s listed as their whois domain contact, and anyone with OSINT chops can find a long-term email tied to a custom domain with enumeration tools + breach data. Why hide it?

      • Humanius@lemmy.world
        link
        fedilink
        English
        arrow-up
        18
        arrow-down
        1
        ·
        edit-2
        5 days ago

        It can now pretty reasonably be assumed what OP’s first name is, and that can be associated with his username.

        Granted, his username might also be a derivative, but on its own there is a certain amount of plausible deniability there.

        The more crumbs of identifiable information you leave around, the easier it becomes for malicious parties to gather them together and build a profile on you.

        • dgdft@lemmy.world
          link
          fedilink
          English
          arrow-up
          7
          ·
          5 days ago

          Right, but speaking for the dev crowd, plenty of us have public identities. Anyone can find my email trivially by scraping github. If you have a public online identity in the first place, it’s far preferable to treat your public-facing email as public information, rather than to rely on security by obscurity and assume no one will ever discover it.

          The only glaring risk from an online attacker is credential stuffing, and falling victim to that one is a skill issue tied right back to assuming your email address won’t become public.

          • CrimeIsLegalNow@ani.social
            link
            fedilink
            arrow-up
            1
            arrow-down
            1
            ·
            4 days ago

            I know you just didn’t flag yourself that hard, you should have figured out by now these script writers are hacks.

      • OrganicMustard@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        5 days ago

        Email is an unique identifier, so whatever content and metadata goes along it is identified. For example now we know accounts lena and gregor use the same device and most probably belong to the same person.

        • Lena@gregtech.euOP
          link
          fedilink
          arrow-up
          5
          arrow-down
          1
          ·
          5 days ago

          You could’ve also simply gone through my post history and seen that I switched accounts like two years ago. Both of my accounts were also admins of my instance at some point.

      • TragicNotCute@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        5 days ago

        I mean, I just sat through annual privacy training and was taught that email addresses are legally PII in many jurisdictions.

        • dgdft@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          ·
          5 days ago

          Legally, of course it’s PII — but is it sensitive information if you treat it as public and distribute it yourself?

          I’m speaking to the functional cybersecurity angle, not the semantics of PII.

  • the_riviera_kid@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    4 days ago

    A lot of forks of firefox don’t have forced shit like this, try one. Personally I like waterfox, no AI bullshit, built in ad blocker, and (luckily for you) the VPN banner does not appear.

  • RougeEric@lemmy.zip
    link
    fedilink
    arrow-up
    16
    arrow-down
    1
    ·
    5 days ago

    Considering someone else gave that actual answer, here’s something to consider: switching to Waterfox will give you essentially all the benefits of Firefox, but without the bloat, and with some extra privacy features baked in.

    • Lena@gregtech.euOP
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      3 days ago

      See my instance’s sidebar

      The domain name

      This instance is named “gregtech” simply because my name is used to be Gregor, and I didn’t check whether there is already something called “gregtech” before registering my domain name. Yes, even EU, which is a thing in the minecraft mod, is simply a coincidence. I guess you can also post about Gregtech, the minecraft mod, here.

  • JustPlainDave@lemmy.zip
    link
    fedilink
    arrow-up
    3
    arrow-down
    2
    ·
    4 days ago

    Now that you’ve gotten some answers,.why would you want to get rid of it? Is there something about VPNs that I don’t know?

    • spwyll@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      4
      ·
      3 days ago

      Not OP, but I already have a VPN and have no interest in Mozillavad. If I have no interest in what they are advertising, it would be nice not to have to constantly work around the persistent ad.

    • mrgoosmoos@lemmy.ca
      link
      fedilink
      English
      arrow-up
      4
      ·
      4 days ago

      it’s like how I now have a big Claude button in my Excel toolbar, despite not using Claude or having access to it. and the button takes priority over other toolbar sections that I actually use but are now hidden, so it has a quantifiable effect on my work.

      I don’t want it, so I should be able to not see it

  • ChonkyOwlbear@lemmy.world
    link
    fedilink
    arrow-up
    3
    arrow-down
    1
    ·
    5 days ago

    I assume any VPN integrated into a browser is useless at best. Anyone know specifically the problems with it?

    • moonpiedumplings@programming.dev
      link
      fedilink
      arrow-up
      9
      ·
      5 days ago

      It’s actually pretty damn good in terms of privacy. It’s Mozilla VPN, which is white labelled and resold Mullvad (but at the same price).

      Mullvad is a no logs provider with a good track record.

      Unfortunately,: https://korben.info/en/mullvad-cofounder-funding-far-right.html

      I typically avoid VPN’s, becuaee in my opinion DNS over TLS/HTTPs + HTTPS are enough for my privacy/security needs, but I will happily use the free VPN every once in a while to get around a firewall or test if a website is universally down. I find it very useful, and am happy that firefox has added. And although I’m not entirely pleased given recent relevations about Mullvad, I’m happy to see that Mozilla is attempting to make money by offering privacy, rather than taking it away.

      • DeepDown@leminal.space
        link
        fedilink
        arrow-up
        2
        ·
        5 days ago

        But it doesn’t obscure any traffic that isn’t on your browser, does it? That feels like it would defeat the purpose

        • moonpiedumplings@programming.dev
          link
          fedilink
          arrow-up
          5
          ·
          5 days ago

          What is the purpose of a VPN?

          To obscure the traffic of your whole machine?

          To obscure 99% of the traffic on your machine since it’s from your browser?

          To bypass censorship for a website or two?

          • DeepDown@leminal.space
            link
            fedilink
            arrow-up
            2
            ·
            5 days ago

            For me, yeah all of the above. I don’t trust my ISP with my info, they’re famously corrupt where I live. And I watch region gated content on programs that aren’t my browser. And I use 3rd party frontends for social media. And I share torrents. My browser is only 20% of my traffic at most on any device.