What the author actually claims
Hearn says Firefox has felt slower and has fallen behind competitors. He calls it "a shell of its former self". He says LibreWolf feels fast and snappy and reminds him of Firefox in its heyday.
Those are subjective impressions. Nobody has benchmarked them, so treat them as one user's experience, not a measured comparison.
His case for LibreWolf rests on four points:
- uBlock Origin is built in.
- It has anti-fingerprinting features.
- It defaults to private search engines.
- It isn't Chromium-based, so it doesn't depend on Google's engine.
He also admits the project's future isn't guaranteed.
What LibreWolf's documentation confirms
The project's feature list backs up most of the defaults Hearn describes. LibreWolf's feature page lists the following, among other items:
- Cookies and website data are deleted on close.
- uBlock Origin ships with custom default filter lists, alongside Tracking Protection in strict mode.
- Tracking elements are stripped from URLs.
- dFPI, also known as Total Cookie Protection, is enabled.
- Resist Fingerprinting (RFP) is on, the user language is always reported as en-US, and WebGL is disabled.
- Search and form history, form autofill, and disk cache are disabled.
- HTTPS-only mode is on, and telemetry, including crash reporting, is disabled.
Two caveats apply. These are design goals and defaults. They are not a guarantee that no site can track you. Hearn's "optional lists" such as EasyList Cookie and AdGuard Annoyances are also something you switch on yourself. They aren't part of the out-of-the-box setup.
Correcting the DNS over HTTPS point
Hearn writes that he can turn on DNS over HTTPS to hide his activity further. That's true, but readers shouldn't assume it's already on. LibreWolf's FAQ says the browser disables DoH by default, and it explains why: DoH protects your lookups on insecure networks, but it also lets your chosen DNS provider see them.
To turn it on, go to Settings > Privacy & Security and use the "Enable DoH using" option. The FAQ's recommended mode is "Increased protection". Check which DoH server is selected first, and consider where that server is based.
DoH does not hide your IP address. The FAQ says LibreWolf cannot protect your public IP. It points to a VPN for that, and to Tor Browser if you need real anonymity. It specifically warns against using LibreWolf with Tor. A VPN also moves trust to the VPN provider. "LibreWolf plus VPN" is therefore a reasonable layered setup, but it isn't complete protection.
Fingerprinting and the EFF test
Hearn used the EFF's Cover Your Tracks tool. He reports that Chrome showed almost no protection and LibreWolf showed strong protection. That is a single personal test, and it can't rank browsers in general. EFF itself says its simulator doesn't cover every tracking or protection method.
The design idea behind RFP is to make many users look alike. LibreWolf's FAQ warns that tweaking RFP-related settings or adding extensions can make you stand out more. It recommends keeping extensions to a minimum for the same reason. If you want to harden things further, you can easily end up making yourself more unique.
The trade-offs you'll notice on Windows
Privacy defaults change how the browser behaves day to day. The FAQ lists these effects:
- You get signed out. Cookies are cleared on close. To stay logged in to chosen sites, go to Settings > Privacy & Security > History > Manage Exceptions. Add the site before you sign in, and add both the HTTP and HTTPS versions. Alternatively, click the shield icon in the address bar and toggle "Always store cookies/data for this site".
- To change what's cleared, enable "Clear history when LibreWolf closes" under Settings > Privacy & Security > History. Then use the adjacent "Settings…" button to choose what gets removed.
- Session restore needs history. It won't work unless you keep your browsing history.
- RFP causes some breakage. The FAQ lists canvas-related site problems, a spoofed timezone, and suppressed alt-key modifier events. The FAQ also says LibreWolf forces a light theme for web content as part of RFP.
- DRM and WebGL are restricted. The FAQ says DRM-protected streaming services can need DRM turned on, under Settings > General > Digital Rights Management (DRM) Content. WebGL is also restricted by default, and the FAQ says to enable it per site only when a site breaks without it.
- Google Safe Browsing is off. The project calls it a censorship concern. It also says Safe Browsing is a good security tool and that less technical users in particular can and should enable it. The project adds that it can't currently offer a fully functional version, because Safe Browsing requires a developer key at build time. Readers who rely on browser phishing warnings should weigh this.
- Antivirus HTTPS scanning can break. Strict public key pinning means user-level man-in-the-middle inspection isn't supported by default. The FAQ describes a MOZILLA_PKIX_ERROR_KEY_PINNING_FAILURE error and says the fix involves changing
security.cert_pinning.enforcement_levelto 1 in about:config. Think before loosening that, because pinning is a security feature.
Installing and updating on Windows
LibreWolf's Windows page lists several routes. The current download is version 157.0.1-1, with x86-64 and ARM64 installers. There are also these options:
- Installer. The installer includes the option to install LibreWolf WinUpdater. Enable "Schedule Automatic Updates" to have WinUpdater create the update task.
- Microsoft Store. The Store package is updated automatically by the system.
- Portable build. The portable zip is meant for removable media or testing, and it includes WinUpdater.
- Package managers. The page lists Chocolatey (
choco install librewolf) and Scoop (scoop bucket add extras, thenscoop install librewolf). For WinGet, the command iswinget install LibreWolf.LibreWolf. WinGet requires Windows 10 1709 (build 16299) or later.
Updates deserve attention. The project FAQ says releases usually arrive within three days of an upstream Firefox stable release, sometimes the same day. It also says LibreWolf has no built-in auto-update, so it relies on package managers or users. For a browser, that matters. If you pick the plain installer and skip WinUpdater, you're responsible for patching it.
The WinUpdater project's own documentation adds detail. The scheduled task runs while your account is logged on, at start-up and every four hours. With an administrator account the update is fully automatic. Otherwise it downloads and asks you to start the update, which needs administrator permission. If LibreWolf is running, the updater notifies you and the update starts once you close the browser.
Windows binaries are signed through OSSign. The FAQ says this may show up in the UAC prompt as a verified publisher named OSSign (Scheibling Consulting AB).
Search engines and extensions
DuckDuckGo is the default, and the FAQ says users can change it with one click. Hearn lists several alternatives, including Startpage, Mojeek and SearXNG. The official pages I could verify confirm DuckDuckGo and mention Searx-style engines. I haven't confirmed the full current menu or Hearn's claim that none of the listed engines collect personal data. A search engine's data practices are separate from the browser's defaults, so check your chosen provider's policy.
Hearn says LibreWolf works with most Firefox extensions. LibreWolf's own advice is to install few add-ons, since each one adds attack surface and can make your browser more distinctive. The built-in password manager is disabled, and the project suggests alternatives such as KeePassXC or Bitwarden.
Is LibreWolf's future a concern?
Hearn says the project depends on volunteers and could stall if core contributors leave. The FAQ supports a narrower point. It says LibreWolf deliberately doesn't accept donations, to avoid dependence on funding, and that contributors are free to move on. That's a stated philosophy, not evidence of decline. Hearn's argument that a community project is harder to kill is an opinion, not a guarantee.
The practical takeaway is to watch the update cadence. LibreWolf is only as safe as its last release. A stalled project would leave you running an aging browser with known upstream vulnerabilities.
Bottom line
LibreWolf is a reasonable option for Windows users who want Firefox's engine with privacy settings already tightened. The documentation backs up its blocking, cookie-clearing and anti-fingerprinting defaults. In exchange you get more sign-ins, more site breakage, and no Safe Browsing out of the box. You also have to make sure updates actually happen.
Hearn's speed claims and EFF results are his own. Don't read them as proof. The easiest way to find out whether it suits you is to try the portable build alongside your current browser, import nothing, and see which defaults you can live with.
References
- I'm uninstalling Firefox for good. Here's what I'm using instead XDA · 2026-10-11T13:30:17+00:00
- Frequently Asked Questions – LibreWolf librewolf.net
- GitHub - ltguillaume/librewolf-winupdater: Mirror of https://librewolf.dev/librewolf/winupdater. An attempt to make (automatic) updating of LibreWolf for Windows much easier. Can be used for installed and portable instances (https://github.com/ltguillaume/librewolf-portable). · GitHub github.com