• dustycups@aussie.zone
      link
      fedilink
      arrow-up
      19
      ·
      3 days ago

      Librewolf is the best answer I can think of, but I just can’t resist:

      Have you seen the better browsing experience? It’s on Zen. It’s literally kb Librewolf. It’s on Floorp without ads. It’s literally on Waterfox. You can probably find it on Ironfox. Dude it’s on Ladybird. It’s a Servo original. It’s on GNOME Web. You can browse on GNOME Web. You can go to GNOME Web and browse it.

    • ℭ𝔞𝔱 @lemmy.worldOP
      link
      fedilink
      arrow-up
      1
      arrow-down
      5
      ·
      3 days ago

      It’s a great start, but remember that no browser is 100% secure. Even LibreWolf can’t protect you if your OS is leaking data or if you’re not using a VPN/Tor.

      • Reannlegge@lemmy.ca
        link
        fedilink
        arrow-up
        1
        ·
        3 days ago

        I do not currently use a VPN but I am thinking of getting Proton VPN, I do however use different forks of Debian on most things. All of my IoT things do not have access out of my 10.6.66.0 vLAN (which has its own wifi) and most do not have access to the WAN. I use Home Assistant for most things on my 10.0.69.0 homelab vLAN (does not have wifi it is all wired) to reach into the IoT vLAN to do stuff which has limits to my personal vLAN 10.42.0.0 (Does have its own wifi). My guest vLAN 10.4.20.0 (Does have its own wifi but does not have eth) does not have acess to anything other than the WAN, just for shits and giggles I have a child friendly vLAN 10.6.7.0 (Does have its own wifi but does not have eth) that only has wifi and does not acess to anything other than the WAN during certain times. My personal wireguard vLAN 10.69.42.0, has the same acess as my personal vLAN, and my guest wireguard vLAN has the same acess as my guest vLAN but limits them to 2 hours before OpenWRT kicks them off.

        I do not use my ISPs firewall/router just the fiber modem into my OpenWRT firewall. The DNS I use is two piholes with unbound.

        • ℭ𝔞𝔱 @lemmy.worldOP
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          3 days ago

          That’s an impressive network architecture. Your VLAN segmentation and the use of OpenWRT with Pi-hole/Unbound effectively mitigate most of the internal risks. In your case, the local security is definitely top-notch