Bonum Certa Men Certa

Don’t Use Mozilla VPN (Security Problems and Incompetence); Just Get Mullvad. Bonus: SeaMonkey 2.53.17, WEI, Firefox on Linux Getting Worse.



No FirefoxReprinted with permission from Ryan

Don’t Use Mozilla VPN (Security Problems and Incompetence); Just Get Mullvad. Bonus: SeaMonkey 2.53.17, WEI, Firefox on Linux Getting Worse.



The special client that Mozilla VPN has for Mullvad (they use Mullvad’s VPN network) has a really nasty security hole that Mozilla has failed to address properly.



The long story short is that Mozilla incompetently designed their client software, then refused to fix the problem for over three months after a security researcher at SUSE reported it to them, at which time it was publicly disclosed.



This is Microsoft-like in how Mozilla responds to security problems. Microsoft typically waits until it’s an emergency and there’s malware making the rounds and they’ve taken a completely unnecessary PR black eye by having to be outed as not caring about security.



And why would you want security in an operating system or some Virtual PRIVATE Network software, right?



Mozilla essentially just repackages Mullvad VPN which already has an excellent privacy policy and open source client that has worked fine for me. Every once in a while I just grab the latest RPM, verify it, and then unpack it on top of the last one using dnf. It works great. I have had no problems with Mullvad VPN.



Basically, Mozilla’s contributions here are raising the price, having a privacy and terms of use policy that go on for miles so you could be selling them a kidney (Who knows? I’m not a lawyer and I don’t have time for this shit.), creating a really piss-poorly designed client (calling it bad would be praise at this point), and then not fixing gaping security holes in it.



To make matters worse, the idiots running Mozilla seem to think that “Linux support” means you shit out an Ubuntu package and ignore the RPM users when making an RPM isn’t even that hard. So apparently they don’t need the money badly enough to have an RPM build bot.



Roy Schestowitz asked me what I’m using lately for Web browsing. I have a really highly custom-configured SeaMonkey 2.53.17 from Fedora RPM, followed by GNOME Web (WebkitGTK), followed by Firefox ESR 115.1, as of this writing. I also have Brave because it’s Chromium without the spyware and garbage. Like Google’s new total Web DRM and super-cookie (WEI and FLoC).



SeaMonkey is certainly not perfect, but NoScript and ubo-legacy make it much more tolerable and secure. I only allow limited amounts of JavaScript and I have some useragent hacks (including so Google won’t log me out of GMail and say my app isn’t secure), and overall I mostly have it set to tell Web sites I’m using Firefox ESR 102.14. It’s a lie, but any sites that detect UAs and break themselves on purpose don’t deserve the truth.



Since I don’t know what will happen when I click on a link for a bank or something, I use “Standalone SeaMonkey Mail” and told it to open /opt/firefox, but not to open links I middle click on anywhere else in Firefox.



The extension also added a right-click menu item to SeaMonkey called “Open in External Browser” so if I hit a page that really doesn’t want to cooperate, I can press that and open the link in Firefox and then close Firefox again. In a way, Firefox ESR is sort of like the “Open in Internet Explorer” I was using in Mozilla Suite sometimes on Windows back in the day. The wheel turns, does it not?



Then I have Palefill (intended for Pale Moon) which applies hacks to make some bad Web sites work in SeaMonkey by rewriting the offending function in a way that works. That’s why I can use my WordPress editor right now.



SeaMonkey 2.53.17 (at least on Fedora) seems to have made some good improvements to Web standards and quality of life (you can more easily add search engines to it now and HLS video sites and MPEG-4 codecs are working again.



Another reason I like SeaMonkey is you can set global prefs and then give individual sites the right to do something else. Something Mozilla pretty much got rid of in Firefox a long time ago. Like, I don’t let sites set cookies in SeaMonkey that persist longer than that browser session, but my search engine and a few others get exemptions (“Allow”) as easily as right-click, view page info, Permissions.



This is important because sites like Reddit track what users who don’t have accounts look at with a 15 year cookie. The point is mainly to tie together a user profile across multiple VPN servers, on and off the VPN, and through different ISPs and WiFi networks. Truly nasty.



Then there’s ChatZilla. So I have an IRC client too.



The Mozilla Suite (which is what Netscape 6/7 were based on) went on as SeaMonkey for a lot of reasons, but mainly because the development practices at Mozilla went on in the wrong direction to the point where they ship a lot of broken crap. The particular person they complained about is at Google now working on Chrome, but there’s bigger problems.



Going back to Mozilla VPN.



Given their generalized incompetence in making software for Linux (Firefox is basically being held together by bird shit and Red Hat patches at this point.), it does not surprise me at all that nobody there, at this company looking to make a quick buck and then call it done, bothered to use PolKit correctly. They obviously gave this one to some pissed off intern or something, and it’s not at all secure and you have to wonder what other horrors are in there.



Even when it comes to Firefox, Mozilla still defaults to giving Linux users software-decoded video, X11, and non-accelerated “WebRender”. You have to dive deep and set environment variables and about:config crap to get it running as well as it does on other platforms.



They half-ass everything on Linux, the only platform where their stinking rotting mess is even the default, and then they pack it full of adware, spyware, and DRM, and wonder why everyone moves to another browser.



The problem is that this other browser is often Google Chrome, and as Vivaldi put it, Google seems to abuse their marketshare to inflict another horrible “proposed standard” that chips away at the open Web every day.



When Google Chrome started out in 2008, it was obvious to me then that Google had ambitions far beyond being a search engine. The only possible reason to not keep sitting back and paying Mozilla to be a Web browser company was that they planned to dump unlimited money into Chrome while slowly bleeding out Mozilla until it couldn’t operate any longer.



As Chrome grows, the open Web is in more and more danger. They’re now in a position to demand not only crippled ad blockers, but a “standard” that won’t allow you to view a site even if you use a proprietary one that has been attested to by an NSA/CIA-affiliate such as Google, Apple, Microsoft, and MAYBE Mozilla.



Tor would be finished, SeaMonkey would be finished, GNOME Web finished. Linux with anything? Who knows. “Here, run this!” What’s in it. “Fuck you.” -Google



That is WEI in a nutshell. And Mozilla will pretend to push back and then go ahead and swallow, like Widevine.



Recent Techrights' Posts

Northern Africa: GNU/Linux Measured at Around 5%
by Clownflare
 
Slop Plagiarism and Chatbots Are Killing Evri (They Infuriate and Insult Clients)
Slop destroys companies and leads to misery (miserable clients, time-wasting)
Links 24/08/2026: Re-defining the IndieWeb and "Data Center Backlash Bursts Into the Midterms"
Links for the day
The Issue With Omarchy is the Slop, the Politics Are a Side Issue
Those corporations do not oppose slop, they participate in it
In South Korea, Steady Increases for GNU/Linux
authorities said they would migrate to GNU/Linux or consider moving in that direction
SLAPP Censorship - Part 160 Out of 200: In Astounding Repetition of Last Year, Brett Wilson LLP Deliberately Ignores Holidays of People It is Attacking and Crushes Principles of Access to Justice
Disconnected from the law
Links 24/08/2026: Vision and Skill, Doing Good, Chiperia Project
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 23, 2026
IRC logs for Sunday, August 23, 2026
Gemini Links 23/08/2026: Turning 60, PineTime, and Simulation Hypothesis
Links for the day
Will Your "Modern" New Car Still be on the Road in 2060?
Are people now expected to change a car as often as they replace a mobile phone and, if so, how fast would costs add up?
The Sniff Test
Be sceptical of "CoCs"
Cloudflare Sees a Quarter of Requests in China Coming From GNU/Linux Today
Will 23% ever be the average for GNU/Linux rather than a mere peak?
You Can Lose Some Battles and Still Win the War
Winning or losing isn't something for a scoreboard
GNU/Linux Usage Measured at 23% in Russia Today
the average was almost 10%
Things Not to Fear Missing Out on
Life is too short to pay attention to social control media
Gemini Links 23/08/2026: Exercising Again, Tackling Phone Addiction, and Putting Graal Online Back Online
Links for the day
PIPs and Lawsuits: On the Future of IBM Trying to Spit Out Its Own Staff at Minimal Cost
"I'd rather be laid off than be put on a PIP"
France: GNU/Linux Averaging at 7%, Peaked at 14% Today
When will 14% be the average?
Links 23/08/2026: Water Crises, Illegal Tariffs, and Carney Confronts US Over Patent Imperialism
Links for the day
Links 23/08/2026: Slop "Children's Stories Contain Bizarre Patterns" and "Butterflies at the One Garden"
Links for the day
SLAPP Censorship - Part 159 Out of 200: Telling Courts False Information and Spoon-feeding Them Insults, Hoping or Expecting Them to Repeat These Insults
When lawyers trick courts into repeating something false
Microsoft is in Double Trouble in Singapore
Android+GNU/Linux+ChromeOS are near 20%
The Slop Industry Bribed the Media to Pretend It Has Something New and Revolutionary. Now It Bribes Politicians Too. Anything to Avoid Scrutiny and Regulation.
borrowed money has long been used to bribe the media
"AGI" is Decades Old and It Never Found a Viable Business Model or Real, Actually Useful Use Cases
I keep reminding people of local firms (right here in Manchester) doing the same thing the media now calls "AGI"...
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 22, 2026
IRC logs for Saturday, August 22, 2026
Microsoft to Its Workers in April-May: You're Too Old, Go Away. Microsoft in August: Young People, Go Away.
What does this company even sell anymore?
Clownflare Data US-Centric
We are assuming that for national security reasons not many sites in Chinese (or based in China) outsource their traffic to Clownflare
Gemini Links 22/08/2026: Broken Car, Devuan, and Thundermail
Links for the day
Links 22/08/2026: Prince Harry, Elton John and Others Pay High Price for Frivolous Litigation in the UK
Links for the day
'Voluntary' Mass Layoffs at IBM/Red Hat
IBM does not want people to notice what truly goes on there
Another Round of GAFAM Layoffs, This Time Apple
Now Apple "is shutting down an entire Vision Pro team focused on developing gaming features for the mixed-reality headset."
Gemini Links 22/08/2026: The Bodyguard (1992), Minimalism, Backups, and IPFS
Links for the day
SLAPP Censorship - Part 158 Out of 200: Making Alliances With Men Arrested for Strangling Women Was Always a Terrible Strategy
They work for American slop companies
Links 22/08/2026: TikTok Settles With Feds, Harms Caused by Social Control Media Gaining Attention
Links for the day
New Data Shows Microsoft's XBox is Really Dying
XBox is a "burning platform"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, August 21, 2026
IRC logs for Friday, August 21, 2026