TLDR: I propose we adopt centralized browser policies based on open standards to move toward a more privacy-respecting and secure default environment.
The Proposal
- Adopt Standardized Mozilla Policy Templates
Instead of manual configuration, we should leverage the Mozilla Policy Templates.
Benefit: This allows us to enforce critical security settings (like disabling telemetry, managing password manager behavior, and forcing HTTPS) across the board via a simple JSON configuration.
Consistency: It removes "it works on my machine" issues related to browser extensions or rogue settings.
- Standardize on LibreWolf
While Firefox is great, LibreWolf takes privacy a step further by removing telemetry and baked-in proprietary components out of the box.
Security: It follows the best-practice "privacy settings" by default, reducing our attack surface.
Efficiency: Developers won't need to spend 20 minutes hardening their browser manually.
Why This Matters
By standardizing our browser policies, we:
✅ Protect sensitive project data from browser-level leaks.
✅ Improve performance by cutting out background tracking scripts.
✅ Create a "set it and forget it" environment for new hires.
How to Participate
I'd love to hear your thoughts on this:
Are there specific policies in the Mozilla template you think are mandatory (or too restrictive)?
Have you used LibreWolf in your daily workflow? Are there any site-compatibility issues we should be aware of?
The Proposal
Instead of manual configuration, we should leverage the Mozilla Policy Templates.
Benefit: This allows us to enforce critical security settings (like disabling telemetry, managing password manager behavior, and forcing HTTPS) across the board via a simple JSON configuration.
Consistency: It removes "it works on my machine" issues related to browser extensions or rogue settings.
While Firefox is great, LibreWolf takes privacy a step further by removing telemetry and baked-in proprietary components out of the box.
Security: It follows the best-practice "privacy settings" by default, reducing our attack surface.
Efficiency: Developers won't need to spend 20 minutes hardening their browser manually.
Why This Matters
By standardizing our browser policies, we:
✅ Protect sensitive project data from browser-level leaks.
✅ Improve performance by cutting out background tracking scripts.
✅ Create a "set it and forget it" environment for new hires.
How to Participate
I'd love to hear your thoughts on this:
Are there specific policies in the Mozilla template you think are mandatory (or too restrictive)?
Have you used LibreWolf in your daily workflow? Are there any site-compatibility issues we should be aware of?