Firefox Privacy and Security Guide (2026)

Firefox 152 reorganised the privacy panel, and three recommendations in the old version of this guide are now wrong. One of them, disabling automatic updates, made readers less safe.

This guide covers Firefox 153, released 11 August 2026. Firefox reorganised its Privacy and security panel in version 152, grouping settings into sections behind Advanced settings links, so paths written before that point send you to screens that no longer look the same.

Three pieces of advice in the previous version of this guide have been removed rather than updated, and the reasons are covered at the end. One of them made readers less safe.

Start with Enhanced Tracking Protection

This is Firefox's headline privacy feature and the earlier version of this guide did not mention it at all, which was a significant omission.

Click the shield icon in the address bar, choose Protection Settings, then under Enhanced Tracking Protection click Advanced settings. On Firefox 151 and earlier the shield menu says Privacy Settings instead.

There are three levels.

Standard is the default. It blocks social media trackers, cross-site tracking cookies, cryptominers and fingerprinters, and it blocks tracking content in Private Windows only. Total Cookie Protection is on, which confines cookies to the site that set them.

Strict blocks all cross-site cookies, and blocks tracking content in every window rather than just private ones. It adds Enhanced Cookie Clearing and Bounce Tracking Protection, which targets the redirect chains used to launder identity between sites.

Custom lets you pick individually. Useful for diagnosing which category breaks a particular site.

Set it to Strict. Expect occasional breakage on sites that use cross-site cookies for login. When something breaks, use the shield icon to turn protection off for that one site rather than dropping the whole browser back to Standard.

HTTPS-Only Mode

Settings → Privacy and security → the Connection and software security section → Advanced settingsHTTPS-Only Mode. On Firefox 151 and earlier, scroll to HTTPS-Only Mode directly in Privacy & Security.

Enable it in all windows. Firefox will upgrade connections to HTTPS and show a warning page when a site only offers unencrypted HTTP, which is now rare enough that the warnings are informative rather than annoying.

This is the setting that replaced the HTTPS Everywhere extension. See the corrections section below.

DNS over HTTPS

Settings → Privacy & SecurityDNS over HTTPSAdvanced settings.

Firefox offers five modes. Default Protection enables secure DNS where available and falls back. Increased Protection keeps DoH active with your chosen provider, switching only on failure. Max Protection always uses secure DNS and warns you if the resolver is unreachable. Custom Protection pins a provider of your choosing. Off reverts to your system resolver.

Increased or Max, with a provider you have actually chosen, is the sensible setting. Understand the trade you are making: DoH hides your lookups from your network operator and your ISP, and hands them instead to the resolver you selected. You are moving trust, not eliminating it. If you already run your own filtering resolver, Off plus that resolver may be the better answer.

Telemetry and data collection

Settings → Privacy & SecurityFirefox Data Collection and Use. Uncheck everything.

While you are on that panel, turn off sponsored content: Settings → Home, and disable sponsored shortcuts and recommended stories on the new tab page. Also check Settings → Privacy & SecurityAddress Bar, and turn off suggestions from sponsors and from Firefox.

Permissions

Settings → Privacy & SecurityPermissions. Open each of Location, Camera, Microphone and Notifications, clear any site you do not recognise, and tick Block new requests for each.

Notifications in particular: blocking new requests removes an entire category of nuisance and a common malvertising vector, and costs you nothing.

Containers

Install Firefox Multi-Account Containers from Mozilla's add-on site. Containers keep cookies and site data separated per container, so a session in one does not see a session in another.

The practical pattern is one container per identity rather than one per site: personal, work, shopping, finance. Pin the sites that should always open in a given container. This is the single most effective thing on this page for stopping cross-context linkage, because it addresses identity separation rather than blocking individual trackers.

Extensions, kept short

uBlock Origin. Install it. Content and tracker blocking, low overhead, and it remains the one extension worth recommending without qualification.

That is the list. Every additional extension is a distinguishing detail in your fingerprint, and an unusual extension set makes you more identifiable, not less. Two or three widely used extensions beat a stack of niche ones.

NoScript is genuinely powerful and genuinely breaks the web. Install it only if you are prepared to debug why a site is not loading, several times a week.

Fingerprinting, honestly

Standard and Strict both block known fingerprinting scripts, which handles commercial fingerprinting. It does not make you unfingerprintable.

Firefox has a stronger option, privacy.resistFingerprinting in about:config, which normalises many of the values used to fingerprint you. Be aware of what it costs: it letterboxes windows, forces a fixed timezone, and blocks some legitimate APIs. It also makes you resemble a Tor Browser user, which on a small network is its own signal. If your threat model genuinely requires this, the Tor Browser is the better tool, because that is where the crowd is.

If you want a configuration file

The previous version of this guide pointed at a user.js project that has not kept pace. The maintained option is arkenfox/user.js, at version 144.0 released 20 April 2026, which targets desktop Firefox specifically.

Read its wiki before deploying it. It is opinionated, it will break things, and applying it blind and then debugging for a week is a worse outcome than the settings above applied deliberately. Do not use it in Tor Browser; the project says so explicitly.

Corrections to the previous version of this guide

Do not disable automatic updates. The previous version told readers to set Firefox to check for updates but let you choose when to install them. That was wrong, and it is the one change on this page that made people measurably less safe. Browser updates are overwhelmingly security fixes for vulnerabilities being exploited in the wild, and a browser you update when you get round to it is a browser running known-exploitable code. Leave updates automatic: Settings → GeneralFirefox UpdatesAutomatically install updates.

HTTPS Everywhere is gone. The EFF sunset the extension. In its own words, "You no longer need HTTPS Everywhere to set HTTPS by default. Major browsers now offer native support for an HTTPS only mode." Use the built-in setting above.

Decentraleyes has been dropped. It shielded requests to third-party content delivery networks, a gap modern browsers largely closed by partitioning caches per site. It is now mostly an extra entry in your fingerprint for little return.

"Menu > Options" no longer exists. Firefox renamed it to Settings some years ago, which is why every path in the old guide began with a menu item that is not there.

The geolocation preference in the old config file is dead. It pointed at Mozilla Location Services, which Mozilla retired in 2024. Anything still setting that URL is configuring a service that no longer answers.

Ignore advice to disable Privacy-Preserving Attribution. You will find guides telling you to turn this off. Mozilla's own documentation now describes PPA as an experimental feature in Firefox 128 that "was never activated and was later removed." There is nothing to disable, and a guide that tells you otherwise has not checked since 2024.

What this does not fix

Browser hardening addresses what the browser reveals. It does nothing about accounts. Signing into a service identifies you far more reliably than any fingerprint, and no setting on this page changes that. It also does nothing about your IP address, which is why containers and tracking protection pair with network-level decisions rather than replacing them.

Treat this as reducing what is collected passively while you browse. The identifiers you hand over deliberately are a separate problem, and a larger one.

Verified against Mozilla support documentation, EFF and the arkenfox project on 17 August 2026, for Firefox 153.0.4. Firefox 152 reorganised the Privacy and security panel, so paths differ on 151 and earlier; where they do, both are given. If a step does not match, search the Settings search box for the bolded term.

Subscribe to SparkForge

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe