YSK: Garuda Lunux default browser (FireDragon) contains problematic extensions - eviltoast

Google, Amazon, Bing extensions have been added to Firedragon browser. These do not show up under “Addons and Themes”. I only found them in “about:debugging”

This is a default install, with default settings. It is completely unaltered from what is shipped w/ Garuda. It does seem to be related to search provider settings.

Though Garuda is not a privacy based distro, FireDragon is based on LibreWolf. It seems the Garuda team decided to add these extensions in after the fact. Default Librewolf does not contain these extensions. (or at least the flatpak version I installed to verify didn’t)

This may, or may not, directly affect your privacy. I would guess that info is only sent to these providers if they are specifically requested. But it is JUST a guess.

I’m sure this has been done to monetize the distro, provide support, yada yada.

I personally do not care what the reasoning, or whether or not any information is sent to providers. I will be moving away from Garuda ASAFP. If they do this, what else has been done?

As always, stick w/ recommended on privacyguides.

  • tartar@lemmy.fmhy.ml
    link
    fedilink
    English
    arrow-up
    80
    ·
    edit-2
    1 year ago

    These are literally default search extensions from Mozilla that come with every vanilla Firefox install - some basic digging would’ve told you that (in fact, your very screenshot shows that the extension IDs come from Mozilla). They’re what allows the search options for those sites in Firefox. If you go to search settings and turn those search engines off, they have zero effect on you. Or better yet, simply hit “remove” in those settings to completely get rid of them, which makes them no longer show up anywhere, even about:debugging.

    You’re welcome to move away from Garuda; it just wouldn’t change anything. You could also fork the code to remove the extensions by default, but at that point ask yourself why neither LibreWolf nor the Garuda team found it necessary to remove these extensions by default if they were actually a privacy threat (and again, you could just remove them yourself in 5 seconds through search settings).

    Honestly, these default search providers could potentially be removed simply because more privacy-focused users have no reason to use such search engines, but that’s something you should take up with the LibreWolf/Garuda team in a polite discussion.

    Here, this post could potentially affect Garuda’s reputation for something that’s completely harmless and is 2 layers upstream from them (FF > LibreWolf > FireDragon). It also makes privacy enthusiasts look silly and paranoid.

    I understand why seeing these would make you suspicious, but the next step would be to look it up somewhere rather than jumping to a conclusion.

    OP, I’m not trying to scold you (and I’m sorry this comment feels that way) . Rather, this is a reminder to everyone here: please do some due diligence before posting stuff.

    (P.S. As someone who once also used this distro and browser, I would also recommend to just setup FF or even LibreWolf the way you want instead of using this specialized distro fork. Not for any malicious reason, but simply because important security updates are bound to come late to a fork of a fork.)

      • tartar@lemmy.fmhy.ml
        link
        fedilink
        English
        arrow-up
        11
        ·
        edit-2
        1 year ago

        Thanks, but I worry it may have been a little too assholish on my part. Again, I wasn’t trying to bring OP down and definitely don’t want to be one of those smug “I know better than you and will jump on every mistake of yours” types. I know what it’s like to have those kind of people jumping on your throat for a relatively minor thing, because I’ve made this kind of mistake before. Just want to state again that my intent isn’t to dogpile on OP but to remind everyone to be cautious before assuming.

        I edited the comment to remove the unnecessary snarky chromium bit. !@elltee@lemmy.one I’m sorry if this comment made you feel shitty. It isn’t what I intended to do.

        • rodneyck@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 year ago

          LOL, we can all come off sounding a little assholish, don’t worry about it. You made sound points. The OP came off sounding a bugle of fear without doing any research, or backing up any of their concerns. You stepped up.