In a previous post I talked about one aspect of making sure URLs you visit are safe. While writing that post, I started thinking about what I do and would recommend to browse securely while still keeping the experience usable. Of course the “usable” requirement here means excluding efforts such using a separate computer or browser for sensitive activity or only browsing in a VM or LiveCD environment.
First off, my recommended browser of choice is Firefox … not because it’s necessarily the best browser out there but more based on the number of available add-ons … especially the security ones I suggest below. One thing to consider though is to try to keep the number of add-ons to a minimum. This not only helps Firefox start and run faster but it also minimizes the risk of getting p0wned by a vulnerable add-on. Anyway, the security add-ons I use in almost all of my Firefox installs include:
- HTTPS-Everywhere: Ever since FireSheep was released last year this add-on is a must-have. It forces your browser to always use HTTPS when visiting a number of popular websites. Of course better yet is to purchase a personal VPN or use your company’s if they allow.
- Adblock Plus: This add-on is a fairly new one I’ve added to the mix based on the proliferation of malicious ads. Since most content on the web is free and ad supported, I almost hate to use it … but I value online safety more.
- Google (SSL) Search Engine: This nice search engine add-on forces you browser to use Google’s encrypted search engine when using the built-in browser search bar. I use it just in case HTTPS-Everywhere misses requests sent from this field rather than a web page.
Over the years I’ve tried many other security plugins but these are the ones I always come back to from a usability perspective. And of course be sure to add some quick bookmarks to UnmaskURL, URLVoid, and VirusTotal as these services provide additional ways to research potential malicious websites.
Now from a usable privacy perspective I usually head on over to Firefox’s Privacy preferences area and uncheck “Automatically start Firefox in a private browsing session.” Make sure all the other sub-options are checked except for “Accept third-party cookies.” Under the “Settings” button associated with “Clear history when Firefox closes,” verify everything is checked.
One of the usability consequences of locking your browser down is that you may loose your open tabs and/or sessions if your browser crashes or is running slow and you want to restart. This could be a problem if you’re like me and keep tabs open as placeholders for pages you want to look at later. To make sure Firefox gives you the option to save your tabs, verify the following preferences.
- General: Select “Show my home page” from the Startup drop-down.
- Tabs: Ensure “Warn me when closing multiple tabs” is checked.
- Privacy: Under the “Settings” button associated with “Clear history when Firefox closes,” uncheck “Browsing History.”
Unchecking “Browser History” does create a risk that some sensitive information could be carried over between sessions indefinitely. On the main Privacy tab changing “Remember my browsing history for at least” to 0 days helps mitigate this concern since any history storage would expire in less than a day.
Now if the browser crashes with 30 or so tabs opened, you at least get all your tabs back however your active sessions were probably lost. And if your browser is running slow and you want to restart, simply go to Preferences -> Privacy and uncheck “Clear history when Firefox closes.” Then close the browser and select the option to save your tabs. Now everything from your prior session should mostly reappear as you left it. Just be sure to go back in and recheck “Clear history when Firefox closes.”
Do you like some of the plugins I mentioned above? Do you know that many of these plugin authors don’t make a dime off of their work? If you use any of these plugins on a regular basis, please consider heading over to their site and donating a few bucks. This kind donation helps ensure that these valuable tools remain free and up to date for the community to enjoy. See ya!