Bonum Certa Men Certa

Don’t Use Mozilla VPN (Security Problems and Incompetence); Just Get Mullvad. Bonus: SeaMonkey 2.53.17, WEI, Firefox on Linux Getting Worse.



No FirefoxReprinted with permission from Ryan

Don’t Use Mozilla VPN (Security Problems and Incompetence); Just Get Mullvad. Bonus: SeaMonkey 2.53.17, WEI, Firefox on Linux Getting Worse.



The special client that Mozilla VPN has for Mullvad (they use Mullvad’s VPN network) has a really nasty security hole that Mozilla has failed to address properly.



The long story short is that Mozilla incompetently designed their client software, then refused to fix the problem for over three months after a security researcher at SUSE reported it to them, at which time it was publicly disclosed.



This is Microsoft-like in how Mozilla responds to security problems. Microsoft typically waits until it’s an emergency and there’s malware making the rounds and they’ve taken a completely unnecessary PR black eye by having to be outed as not caring about security.



And why would you want security in an operating system or some Virtual PRIVATE Network software, right?



Mozilla essentially just repackages Mullvad VPN which already has an excellent privacy policy and open source client that has worked fine for me. Every once in a while I just grab the latest RPM, verify it, and then unpack it on top of the last one using dnf. It works great. I have had no problems with Mullvad VPN.



Basically, Mozilla’s contributions here are raising the price, having a privacy and terms of use policy that go on for miles so you could be selling them a kidney (Who knows? I’m not a lawyer and I don’t have time for this shit.), creating a really piss-poorly designed client (calling it bad would be praise at this point), and then not fixing gaping security holes in it.



To make matters worse, the idiots running Mozilla seem to think that “Linux support” means you shit out an Ubuntu package and ignore the RPM users when making an RPM isn’t even that hard. So apparently they don’t need the money badly enough to have an RPM build bot.



Roy Schestowitz asked me what I’m using lately for Web browsing. I have a really highly custom-configured SeaMonkey 2.53.17 from Fedora RPM, followed by GNOME Web (WebkitGTK), followed by Firefox ESR 115.1, as of this writing. I also have Brave because it’s Chromium without the spyware and garbage. Like Google’s new total Web DRM and super-cookie (WEI and FLoC).



SeaMonkey is certainly not perfect, but NoScript and ubo-legacy make it much more tolerable and secure. I only allow limited amounts of JavaScript and I have some useragent hacks (including so Google won’t log me out of GMail and say my app isn’t secure), and overall I mostly have it set to tell Web sites I’m using Firefox ESR 102.14. It’s a lie, but any sites that detect UAs and break themselves on purpose don’t deserve the truth.



Since I don’t know what will happen when I click on a link for a bank or something, I use “Standalone SeaMonkey Mail” and told it to open /opt/firefox, but not to open links I middle click on anywhere else in Firefox.



The extension also added a right-click menu item to SeaMonkey called “Open in External Browser” so if I hit a page that really doesn’t want to cooperate, I can press that and open the link in Firefox and then close Firefox again. In a way, Firefox ESR is sort of like the “Open in Internet Explorer” I was using in Mozilla Suite sometimes on Windows back in the day. The wheel turns, does it not?



Then I have Palefill (intended for Pale Moon) which applies hacks to make some bad Web sites work in SeaMonkey by rewriting the offending function in a way that works. That’s why I can use my WordPress editor right now.



SeaMonkey 2.53.17 (at least on Fedora) seems to have made some good improvements to Web standards and quality of life (you can more easily add search engines to it now and HLS video sites and MPEG-4 codecs are working again.



Another reason I like SeaMonkey is you can set global prefs and then give individual sites the right to do something else. Something Mozilla pretty much got rid of in Firefox a long time ago. Like, I don’t let sites set cookies in SeaMonkey that persist longer than that browser session, but my search engine and a few others get exemptions (“Allow”) as easily as right-click, view page info, Permissions.



This is important because sites like Reddit track what users who don’t have accounts look at with a 15 year cookie. The point is mainly to tie together a user profile across multiple VPN servers, on and off the VPN, and through different ISPs and WiFi networks. Truly nasty.



Then there’s ChatZilla. So I have an IRC client too.



The Mozilla Suite (which is what Netscape 6/7 were based on) went on as SeaMonkey for a lot of reasons, but mainly because the development practices at Mozilla went on in the wrong direction to the point where they ship a lot of broken crap. The particular person they complained about is at Google now working on Chrome, but there’s bigger problems.



Going back to Mozilla VPN.



Given their generalized incompetence in making software for Linux (Firefox is basically being held together by bird shit and Red Hat patches at this point.), it does not surprise me at all that nobody there, at this company looking to make a quick buck and then call it done, bothered to use PolKit correctly. They obviously gave this one to some pissed off intern or something, and it’s not at all secure and you have to wonder what other horrors are in there.



Even when it comes to Firefox, Mozilla still defaults to giving Linux users software-decoded video, X11, and non-accelerated “WebRender”. You have to dive deep and set environment variables and about:config crap to get it running as well as it does on other platforms.



They half-ass everything on Linux, the only platform where their stinking rotting mess is even the default, and then they pack it full of adware, spyware, and DRM, and wonder why everyone moves to another browser.



The problem is that this other browser is often Google Chrome, and as Vivaldi put it, Google seems to abuse their marketshare to inflict another horrible “proposed standard” that chips away at the open Web every day.



When Google Chrome started out in 2008, it was obvious to me then that Google had ambitions far beyond being a search engine. The only possible reason to not keep sitting back and paying Mozilla to be a Web browser company was that they planned to dump unlimited money into Chrome while slowly bleeding out Mozilla until it couldn’t operate any longer.



As Chrome grows, the open Web is in more and more danger. They’re now in a position to demand not only crippled ad blockers, but a “standard” that won’t allow you to view a site even if you use a proprietary one that has been attested to by an NSA/CIA-affiliate such as Google, Apple, Microsoft, and MAYBE Mozilla.



Tor would be finished, SeaMonkey would be finished, GNOME Web finished. Linux with anything? Who knows. “Here, run this!” What’s in it. “Fuck you.” -Google



That is WEI in a nutshell. And Mozilla will pretend to push back and then go ahead and swallow, like Widevine.



Recent Techrights' Posts

Silent Layoffs, Cool-down, and Cool-off: How GAFAM and IBM Operate (the Law Doesn't Apply to Them)
Laws? What laws?
 
People Who Enforce the GPL Banned From Linux Foundation Board (After Bribes From Prolific GPL Violators), Now They're Banned From Giving Talks at Events
about the "LF" ('Linux' Foundation)
Gemini Links 06/09/2026: The Slop Plagiarism 'Holy War' (Hype, Scam, Scheme), Burning CD-Rs, and Hardcopy Mono
Links for the day
Solicitors Regulation Authority (SRA) Inaction and Incompetence - Part IV - Insufficient Resources in the Face of Distributed Denial of Service (DDoS) by Lawyers
it's about 120KG
OpenStreetMap is the Future, Dictatorship is the Past
OpenStreetMap helped us check maps for transport, various overlays with addresses, and there was 0% reliance on GAFAM or "Google" anything
How Strikes at the European Patent Office Are Seen by Striking Staff in Berlin, Germany
We have some more EPO scandals to cover later this year and next year
Association for Computing Machinery Cites Techrights in Relation to GemText and Gemini Protocol
published yesterday, Open Access
Links 06/09/2026: More XBox Trouble (Microsoft Unrest, Many Silent Layoffs This Month), John Duffy as Next USPTO General Counsel
Links for the day
Gemini Links 06/09/2026: Avoiding 'Smart' 'Phones' and Setting up Gemini for the First Time
Links for the day
Links 06/09/2026: Sabotage by Slop and "What Happens If 'Open' 'AI' Dies?"
Links for the day
How Back Doors Became the 'Normal' or 'Norm'
"We also allowed a lethal monoculture to fester"
Solicitors Regulation Authority (SRA) Inaction and Incompetence - Part III - The SRA is Vastly Worse Than Brits Realise, We Have a "Wild West" in London
In the next part we'll begin looking at correspondence with the SRA
SRA and Manslaughter: How the SRA Contributed to Agony in Proprietary Software Scandals With Clear Misuse of "Without Prejudice"
Trying to prevent the public from finding out the criminal stuff that went on, resulting in many deaths
Canonical (or Ubuntu) Rejecting IRC Isn't the Widespread Trend
Internet Relay Chat (IRC) adoption still growing by some yardsticks
SLAPP Censorship - Part 173 Out of 200: Two Years
It was exactly 2 years ago that we filed lawsuits against Garrett
Linux of America
We could not help but notice GNU/Linux in North America yesterday
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, September 05, 2026
IRC logs for Saturday, September 05, 2026
Gemini Links 06/09/2026: Internet Limiting (Limited Time Allotted) and Solar MiniServer
Links for the day
Eight Months of Strikes in EPO, Organised by the Staff Union (SUEPO) Also in Berlin
In Berlin, only one member of staff voted against the action plan
Links 05/09/2026: "Let’s Stop Buying New Phone" and 'Open' 'AI' (Proprietary Slop) Drowning in Lawsuits
Links for the day
Gemini Links 05/09/2026: Polarization, Warped Maps, and Emacs rectangle-number-lines
Links for the day
Software Freedom, Even If Difficult to Attain Due to Outside Pressure, Does Make You Happier
Peer pressure and opinionated employers can make friends and staff more miserable if they dictate bad software
You Can Run GNU/Linux on a Desktop/Laptop for 1,000+ Days Nonstop
To me, the long uptime is a way of "marketing" GNU/Linux as robust and stable
Profiting From Global Warming (and Making More Money the More You Cause Warming)
Unregulated bank and pyramid scheme
SLAPP Censorship - Part 172 Out of 200: The Solicitors Regulation Authority (SRA) Complicit in the SLAPPs by Inaction (Didn't Even Study Any Evidence, Only Wasted Time and Budget)
"SRA placed into special measures due to 'disappointing standard of leadership'"
China Does Not Need American (US) Products Like GAFAM's
China has abundance of technical things it can leverage to preserve its autonomy
RMS Didn't Make Enough Backups
Making backups is important
Refresher: Why EPO Staff is on Strike This Year (Aside From the EPO Acting Like a Corrupt, Above-the-Law, For-Profit Corporation That Violates Its Own Charter)
One core issue at the EPO is erosion of purchasing power
Gemini Links 05/09/2026: Fireflies, Shore Pine, and ASCII Art
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, September 04, 2026
IRC logs for Friday, September 04, 2026
The Legal Services Board (LSB) Takes on Solicitors Regulation Authority (SRA) for Utter Failures, We'll Resume Our SRA Series to Illuminate How Bad the SRA Really Is
a quick overview of the latest news
Links 04/09/2026: Notorious Patent Trolls' Judge Enters the Private Sector (Corruption, Revolving Doors), Gloria Steinem's Life in Pictures
Links for the day
Gemini Links 04/09/2026: Worries, Upgrades, and CS Students
Links for the day
Richard Stallman's Web Site Back Online, But It Seems Like a 2-Months-Old Snapshot
Latest political notes are dated July 2 (2026)
SPAM Disguised as Benchmark or Comparison: The Register MS "PARTNER CONTENT" is Getting Weirder by the Month
Sites that promote fake 'coins' or pyramid schemes to their audience(s) aren't worth tolerating
PIPs at IBMs are Layoffs Because They're Impossible to Satisfy (or They Terminate Workers Despite Satisfying Them)
What insiders say
In the United Kingdom You Can No Longer Make the Assumption People Use Windows (or 'Smart' 'Phone')
As autumn arrives Microsoft faces a crisis
SLAPP Censorship - Part 171 Out of 200: Talking About Corruption and Violence Against Women
Today the Labour Party (UK) speaks about corruption
Warming Up for Investigative Journalism About the European Patent Office (EPO), Europe's Second-Largest and Probably Most Corrupt Institution in Europe
It continues to exploit diplomatic immunity for impunity
Microsoft Handing Out PIPs by the Thousands, Anxiety in GAFAM Building Up
Years ago I heard from people who pretended to be ill to avoid getting fired
BRICS in the Windows: Brazil's GNU/Linux Share (as Measured by CDN) Has Hit Highest Point in a Month
The largest Web CDN, Clownflare, sees GNU/Linux at 8.1% right now in Brazil
Corporate Media Will Always Glorify Its Owners (Corporations That Value Nothing But Capital)
Collecting "money" like it's a form of competition where they track "score"
We'll Never Do Slop!
Being against slop is not being "left behind"
Thieves Complain About the People They Steal From
"When you point the finger at someone, there are three fingers pointing back to you"
Links 04/09/2026: "The Rise of the Billionaire Lobby", the "Imperialist Delusions", and Digital Restrictions (DRM) From Nvidia
Links for the day
Buying From China
Nations must begin to speak about their digital sovereignty, which Free software is best equipped to grant and best positioned to assure in the face of outside resistance
GNU/Linux Continues to Grow in China
GNU/Linux reached its highest point in a month
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, September 03, 2026
IRC logs for Thursday, September 03, 2026
Gemini Links 04/09/2026: Forgotten Realms Avatar Series and Slop Plagiarism's Footprint in Gopher/Geminispace
Links for the day