Wednesday, October 1, 2014

Hardening Aviator Browser

 Hardening Aviator browser for privacy/security.

Click Show advanced settings.
Change search to duckduckgo (disconnect)
Privacy > Content settings button

Block sites from setting any data.
Manage exceptions >
Add cookies to allow until browser is closed.

Do not allow any site to run java script.
Do not allow sites to handle protocols.
Click to play plug-ins(Also disables annoying auto-play vids)
Manage exceptions > Add youtube/video sites
-----------------
Click disable invidual plug-ins
-----------------
Disable Chromoting Viewer
Disable Photo Gallery
Might also want to disable Flash
-----------------
Do not allow any site to track your location
Do not allow any site to show desktop notifications
Do not allow any site to disable the mouse cursor
****
Uncheck Allow identifiers for protected content(ask if you upload pics or w/e)
****
Do not allow sites to access your camera or microphone
Do not allow sites to use a plug-in to access your computer
Do not allow any site to download multiple files auto.
-Exceptions for w/e download sites.
====================================================
Disable predict network actions
Disable phishing and malware protection
Disable DNT request(nobody cares what you want, they don't honor these requests)
---------------
Set up proxy of your choice
---------------
Click language and input settings and disable spell checking

Disable offer to translate
Disable continue running background apps
Disable hardware acceleration

=====================================================
Allowing javascript and cookies is right next to the PROTECTED green bar.
=====================================================
Chrome Store Addons
================
Click extensions and disable pdf viewer
Click get more extensions
-------
-adguard
-donottrackme
-ghostery(uncheck alert bubble & select all)
-http switchboard
-https everywhere(eff.org)
-privacy badger(eff.org)
-VTchromizer(optional)
-csfire

=================
http switchboard
=================
click addon then gears
enable strict blocking
select auto create domain level scope
copy all rules from global scope
auto delete unused temp scopes

privacy
--------
select all
change non-blocked session cookies/browser cache to 180 or however long you need them

Add new lines to user-agent w/
Mozilla/5.0 (X11; Linux i686; rv:24.0) Gecko/20100101 Firefox/24.0
Mozilla/5.0 (X11; Linux x86_64; rv:28.0) Gecko/20100101 Firefox/28.0

-------------
Setting up domain scope per site
-------------
***http switchboard(and im pretty sure noscript does too) forces javascript on so you can manage it
-leave javascript as disabled because the plugin will force enable it, and if the plugin breaks...it will get disabled by falling back to settings.
***
Set plugin to domain-level scope > *.twitch.tv
Then set the permissions for the domain to connect to:
Example: twitch.tv

BLOCK
google-analytics.com
googletagservices.com
lifedna.com
mxpnl.com
petametrics.com
quantserve.com
scorecardresearch.com
facebook.net

ALLOW
twitch.tv
betterttv.com
jtvnw.com
amazonaws.com
firebaseio.com

After the scope changes are finished, click the lock to save temp. settings permanently.

https://github.com/gorhill/httpswitchboard/wiki/How-to-use-HTTP-Switchboard:-Two-opposing-views
-----------------
Ubiquitous rules
click at bottom parse and enforce adblock+ element hiding filters Then apply changes
===============
-zenmate(sign up and use medium strength password)

No comments:

Post a Comment