How to Harden Firefox on Linux (Beginner's Guide)

Table of Contents
I've used Firefox for about six years now. Switched away from Chrome when I realized I was basically handing Google my entire browsing history. The decision was easy. The execution... took some learning.
Firefox comes with better defaults than most browsers, but "better than Chrome" isn't the same as "private." Out of the box, it still sends telemetry data, enables tracking protections that feel more performative than practical, and defaults to a search engine that logs your queries.
I spent a lazy Sunday afternoon hardening my setup. Here's what I learned, what broke, and what actually made a difference.
Backup Your Profile First
Don't skip this. I bricked my configuration twice before I learned. Close Firefox completely, then run: cp -r ~/.mozilla/firefox/ ~/firefox-backup/. Takes ten seconds. Saves hours of frustration.
The Steps That Matter
Kill the Telemetry
Open Settings, head to Privacy and Security. Scroll to Firefox Data Collection and Use. Uncheck everything. Every single box. While you're there, find AI Controls and disable those too. I forgot that step the first time and wondered why queries were still reaching mozilla's servers.
Ditch Google Search
Settings, Search tab. Swap Google for something that isn't logging your searches. I've bounced between DuckDuckGo and Brave Search. DuckDuckGo is more established. Brave Search is actually private and doesn't lean on Bing for results. Either beats the alternative.
Lock Down Tracking Protection
Enhanced Tracking Protection sounds aggressive, but Default mode is still weak. Change it to Custom. Block all cross-site cookies. Block fingerprinters and cryptominers. Enable it for all windows, not just private ones.
Force Secure Connections
HTTPS-Only Mode is buried in the Privacy settings. Turn it on for all windows. Then find DNS over HTTPS and set it to Max Protection. I use Quad9 because they're non-profit and have a decent no-logging policy. Cloudflare is fine too if you don't care about who runs it.
The About:Config Rabbit Hole
So here's where things get interesting.
You can type about:config in your address bar and override Firefox's defaults at a deep level. It sounds scary. It really isn't. You'll see a warning, accept the risk, and then you're in.
The changes that made a real difference in my experience:
privacy.resistFingerprinting = true makes your browser look like everyone else's. No unique screen resolution, no weird font lists, no canvas signatures that fingerprint you across sites. Some sites break. Banking apps, mostly. Worth it.
privacy.partition.network_state = true gives you what Firefox calls Total Cookie Protection. Each site gets its own cookie jar. A site can't peek at cookies from another site anymore. This one surprised me how much it changed.
extensions.pocket.enabled = false just disables Pocket. Pocket is Mozilla's read-later service. I never used it. Turning it off removes another endpoint that doesn't need to exist.
One Warning
About:config changes persist across updates and don't sync between devices. Keep notes on what you changed. I use a simple text file.
Extensions: Less Is Actually More
Here's something I got wrong at first.
I installed every privacy extension I could find. uBlock Origin, Privacy Badger, Decentraleyes, Canvas Blocker, and three others. Felt like I was building a fortress.
Then I read about browser fingerprinting. Every extension you add changes your browser's fingerprint. Ten extensions make you more unique than two. Unique is bad. You want to look like everyone else.
So I cut it down to three.
uBlock Origin is the only one I'd call essential. It's a content blocker that actually works. Enable the extra filter lists in its dashboard. I like the EasyList, EasyPrivacy, and Annoyances lists. Turns out most websites load dozens of trackers per page.
Firefox Multi-Account Containers lets you isolate sites into separate boxes. Google in one tab, your personal stuff in another. Google's scripts can't see your Amazon session. This alone is worth the setup time.
Bitwarden for passwords. Not Firefox's built-inPassword Manager. Bitwarden is open source, audited, and doesn't lock you into Firefox. The most locked-down browser won't save you if you're using "password123" on every site.
Multiple Profiles Changed How I Work
Type about:profiles and create separate profiles. I have one for banking and healthcare, another for general browsing, and a third for testing stuff that might be sketchy. Launch them simultaneously with firefox -P "ProfileName" --no-remote. Isolated sessions, isolated cookies, isolated everything.
What Didn't Work
Some things sounded good in blog posts but didn't pan out.
I tried turning off WebRTC entirely. Some sites need it. Video calling breaks. VoIP apps break. It's a cat-and-mouse game that isn't worth losing sleep over unless you've got a specific threat model.
I also experimented with a custom CSS userContent.css to block dark patterns. Firefox keeps changing how this works. Half the rules I found online were outdated. Moved on.
The takeaway? You don't need a two-hour configuration session. Start with the telemetry and DNS changes. Those alone cut my tracking exposure significantly. Add extensions one at a time and see what breaks.
Is This Enough?
Here's a question I asked myself: am I just checking boxes, or is this actually working?
I tested withcovery's cover your tracks page. After all the changes, my browser showed "randomized" rather than "unique." That felt like validation.
But I also realized something simpler: I don't think about Firefox anymore. It just works, stays out of the way, and doesn't track me by default. That's the real goal.
You don't need to become a privacy maximalist. You just need a browser that doesn't passively surveil you while you're trying to read the news.
Start with the backup. Make one change at a time. See what breaks. Adjust accordingly.
You Might Also Like
Free In-Browser Developer Tools
Clean AI CLI logs, build cron expressions, decode JWTs, and calculate chmod permissions offline.
Related Articles

Ubuntu Server Security: The Pragmatic Linux Hardening Checklist
Production Ubuntu server hardening guide: SSH key enforcement, UFW firewalls, Fail2ban intrusion prevention, unattended upgrades, and auditd logging.
Read more
VPN vs Proxy: Differences, Fingerprinting, Leaks, and Privacy Testing
I spent months testing VPNs and proxies on Linux, finding IPv6 leaks in my own setup, breaking my browser fingerprint with too many extensions, and learning what actually works for privacy. Here's what I wish someone told me from the start.
Read more
SSH and SCP: The Two Tools Every Developer Should Actually Understand
A no-fluff guide to SSH and SCP — covering port 22, key-based auth, the SSH config file, secure file transfers, and server hardening tips every developer should know.
Read more