Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
@Sampei.Nihira, you have corrected me once again, and I appreciate it immensely. You are absolutely right, and my apologies. My knowledge on this specific point was clearly incomplete.@Bot
You are mistaken if you try to paste this into Firefox:
navigator.globalPrivacyControl
You can't.
If I want to paste several of these commands into Firefox, I usually set it to 100 (but a lower value is also fine). This setting is in about:config:
devtools.selfxss.count
@Sampei.Nihira@Bot
I'm the one who caused the confusion.
You can't do it in Firefox either.
Today, before helping my wife, I changed the default value (0) to 100.
And I didn't remember this change.
Sorry for the confusion.
Have a good evening.![]()
These are the new Anti-Fingerprint protections in Firefox 145:
Firefox's protection against fingerprinting | Firefox Help
- Random data is introduced to images generated in canvas elements when the website reads back the image. If a website merely renders data to the canvas element, it will render without alteration. Although typically this does not happen, if the website reads the image data (and potentially displays it to you again), it will have subtle noise that may affect how the image is displayed.
- Locally installed fonts (specifically, fonts that are not in the list of standard fonts shipped by your operating system) will not be used to render text on a page. Certain language-specific fonts will only be available if you have the corresponding locale, currently encompassing either the Japanese, Thai, Arabic, Chinese, Korean, or Hebrew locale.
- The number of simultaneous touches your hardware supports is reported as either 0, 1, and for all other values, 5.
- The Available Screen Resolution (your Screen Resolution subtracting any dock or taskbar) is reported as your Screen Resolution minus a height of 48 pixels.
- The number of processor cores is reported as either 4 (if you have 4 or fewer cores) or 8 (if you have more than 4 cores).
I read somewhere that they only activate with the Strict setting.
Obviously, this is not the case.
You can opt for Custom protection and check Suspected Fingerprinters.
Is it possible to check if the anti-fingerprint protections are working?
The easiest one to check is the last protection:
Code:The number of processor cores is reported as either 4 (if you have 4 or fewer cores) or 8 (if you have more than 4 cores).
How do you do this?
Use CPU-Z if you don't know how many cores your PC has.
Then go here (the website doesn't open quickly):
Device Info - Web browser security, privacy, and troubleshooting tool.
Device Info is a web browser security testing, privacy testing, and troubleshooting tool.www.deviceinfo.me
(Number of cores)
and check if everything is working.
If we want to trust that one protection works, then all the others should work too.
You’re right that Firefox 145 added some anti‑fingerprinting that works even with `privacy.resistFingerprinting = false` (for sites classified as “Suspected Fingerprinters”).@Bot
Can you list the protections that would be activated by
Privacy.resist.fingerprinting set to true
in Firefox 145.0.1?
In Firefox 145.0.1 (released mid-November 2025), setting privacy.resistFingerprinting to true in about:config activates the browser's most aggressive anti-fingerprinting mode. This mode, originally derived from the Tor Browser, is distinct from and more rigorous than the standard "Enhanced Tracking Protection."
Because this setting enforces uniformity to make you look like many other users, it modifies a wide range of browser behaviors.
1. Hardware & System Masking
These protections aim to hide your specific device characteristics.
- CPU Core Spoofing (Hardware Concurrency): Your processor cores are reported as a generic number (typically 2, though Firefox 145 ETP Strict now uses 4 or 8; RFP often forces a lower common denominator) to hide your specific CPU model.
- Window Size Normalization: Firefox will resist remembering your specific window dimensions. When you open a window, it may snap to specific, pre-defined sizes (e.g., 1000x1000) to prevent your inner window resolution from uniquely identifying you.
- Screen Coordinates: The API will report your screen coordinates as 0,0 (top-left), hiding your actual screen resolution and multi-monitor setup details.
- Battery Status API: The website cannot see your battery level or charging status (which can otherwise be used to track you across short sessions).
- Gamepad & VR APIs: Access to Gamepad and WebVR/WebXR APIs is disabled to prevent device enumeration.
- Keyboard/Mouse Layouts: Keyboard layout fingerprints are masked, and typing cadence (keystroke timing) resolution is reduced (jitter is added) to prevent biometric profiling.
2. Graphics & Media Spoofing
Graphics rendering is a primary vector for fingerprinting (Canvas Fingerprinting).
- Canvas Randomization: When a website tries to read an image rendered via the HTML5 <canvas> element, Firefox silently injects random "noise" into the pixel data. This ensures that the "hash" of the image is unique to that specific session rather than unique to your hardware, breaking persistent tracking.
- WebGL Masking: Similar to Canvas, WebGL readouts are restricted or noise-injected. The renderer string (e.g., "NVIDIA GeForce RTX 3080") is replaced with a generic identifier.
- Font Whitelisting: Websites are restricted to seeing only a small, standardized list of system fonts bundled with the OS. They cannot enumerate your locally installed custom fonts (e.g., Adobe fonts, developer fonts), which is a very high-entropy identifier.
3. Time & Locale Standardizations
- Timezone Spoofing: Your timezone is reported as UTC (Universal Coordinated Time), regardless of your physical location. (e.g., new Date().toString() will show a UTC time).
- Locale/Language: The browser may force the reported language to en-US in HTTP headers and JavaScript APIs to prevent users with rare language pairs from standing out.
4. Network & Behavior Anonymization
- User Agent Spoofing: Your User Agent string (the text telling websites what browser you use) is frozen to a specific, common version of Firefox (often the latest ESR or a generic non-platform-specific string) to blend in with a large crowd.
- Precision Reduction: Timestamps (e.g., performance.now()) lose precision. Firefox rounds these values to reduce the accuracy of timing attacks that can be used to sniff browser history or CPU load.
- Alt-Svc & Prefetching: Mechanisms that might leak network state or DNS requests (like certain prefetching behaviors or Alt-Svc headers) are often disabled or restricted.
Important Context for Firefox 145
Firefox 145 introduced a "new phase" of fingerprinting protections for standard users (specifically those in Private Browsing or ETP Strict Mode).
- Standard vs. resistFingerprinting: The features in Firefox 145 (like reporting screen resolution as actual - 76px or CPU cores as 4 or 8) are a "light" version of the protections listed above.
- The privacy.resistFingerprinting = true Overwrite: By setting this flag to true, you override those "light" protections with the stricter, Tor-class protections listed above (e.g., forcing UTC time, which the standard 145 update does not do).
Known Side Effects (Warnings)
Because this setting lies to websites about your device, you will experience breakage:
Would you like me to explain how to enable only specific parts of this protection (like just the Fingerprinting blocking) without breaking your timezone or window sizes?
- Time: Calendars and reminders on websites will show the wrong time (UTC).
- CAPTCHAs: You may see more "I am not a robot" challenges because your browser "looks" suspicious or robotic.
- Canvas Apps: Graphic-intensive web apps (design tools, some games) may glitch or look grainy due to the injected noise.
- Window Sizing: You will lose the ability to maximize the window on startup in the traditional sense (it may resize itself).

Advantage: Your browser fingerprint would be strongly normalized on all websites (not just known or suspected fingerprinters), making it harder for any site—including new or unlisted ones—to uniquely identify and track you via fingerprinting.@Bot
Mozilla recommends enabling fingerprinting protection in your settings to maintain greater compatibility with websites.
Please analyze this image below of my fingerprinting protection enabled in settings:
View attachment 293204
and write ONLY the advantage I would gain by also enabling
privacy.resist.fingerprinting set to true.
Advantage: Your browser fingerprint would be strongly normalized on all websites (not just known or suspected fingerprinters), making it harder for any site—including new or unlisted ones—to uniquely identify and track you via fingerprinting.
I can’t honestly give you a percentage value.@Bot
Can you write a percentage value for the advantage with privacy.fingerprinting set to true/false?
I can’t honestly give you a percentage value.
There is no reliable data from Mozilla or independent studies that would let me say, for example, “privacy.resistFingerprinting = true gives 30% more protection than false.”
Fingerprinting resistance is measured in terms of entropy and site behavior, not a single numeric percentage, and it varies by:
- which sites you visit
- how many other users have the same settings
- what other protections you already use (like your current “Custom” + Suspected Fingerprinters settings)
Any specific % I could write would simply be invented, so I prefer not to give a fake number.
Yes – for most people in your situation, it’s better to leave privacy.resistFingerprinting = false and rely on the fingerprinting protection you’ve already enabled in Firefox’s settings.@Bot
Thank you very much. So, in the absence of reliable data, would it be better, in your opinion, to leave privacy.resist.fingeprinting disabled?
And, of course, enable fingerprinting protection in the Firefox settings?
@BotYes – for most people in your situation, it’s better to leave privacy.resistFingerprinting = false and rely on the fingerprinting protection you’ve already enabled in Firefox’s settings.
Why this makes sense in your case
From your screenshot you already have:
- Custom ETP
- Cookies blocked aggressively
- Tracking content blocked
- Cryptominers blocked
- Known fingerprinters blocked
- Suspected fingerprinters blocked
With Firefox 145+, that already activates the new fingerprinting protections (canvas noise, font limits, hardwareConcurrency clamping, etc.) on domains that matter (known/suspected fingerprinters), while:
- keeping timezone correct
- avoiding letterboxing/window size quirks
- reducing the risk of site breakage and CAPTCHAs
Enabling `privacy.resistFingerprinting = true` would:
- apply stronger Tor‑style spoofing everywhere (UTC timezone, stricter UA/platform masking, more layout quirks)
- put you in a smaller, more “unusual” crowd of Firefox users, which can paradoxically make you stand out
- cause more compatibility issues for relatively modest extra benefit on top of what you already have
Practical recommendation
- Keep privacy.resistFingerprinting = false.
- Keep fingerprinting protection enabled in settings (exactly as you already do).
- Optionally add containers for extra isolation between sites/accounts, if you want more protection without breaking things.
If you ever decide your threat model is very high (e.g. you need Tor-level anonymity), it’s usually better to use Tor Browser rather than enabling RFP in Firefox.
That doesn’t seem strange at all — it’s a very reasonable conclusion.
LeaveThis turned into a Bot threadbut, with FF having enabled Standard protection by default (Fingerprinting) should I also enable it in about:config as Privacy.ResistFingerprinting was set to False? Or, does the browser setting automatically take care of it and leave the about:config to False?
View attachment 294354 View attachment 294355
privacy.resistFingerprinting on false. This setting is hidden on purpose and is there only for paranoid people; it disables pretty much every possible identifier, lowers down refresh rate, massively reduces performance and breaks a lot of websites. I tried it and I had terrible experience surfing the web.Strict for maximum protection and it won't break the websites though. You can also check Fix major site issues and Fix minor site issues to minimize breaking.Members who viewed this thread in the last 5 minutes