While its main emphasis appears to be customizability, Pale Moon besides places a average total of emphasis on being a legato, secure, and private browser .
today, we do our best to find out whether Pale Moon can be considered a viable privacy browser for your average exploiter .
Without further, let ‘s get to it !
This is the Pale Moon browser at a glance …
- No telemetry, data collection, or phoning home ()
- Free, open source, and truly independent product ()
- NPAPI and XUL Plugin support (may be a pro for some users)
- Not compatible with either Firefox or Chromium extensions
- Excludes support for some common modern browser features ()More info
- No Mobile or dedicated macOS support (may be a con for some users)
What is Pale Moon?
Pale Moon is a very interest browser with a very long history .
But inaugural, I should clarify : Pale Moon is not fair another “ outdated and insecure Firefox fork. ” Sources that claim this about Pale Moon are credibly, at least for the most region, misinformed .
Moving on, let ‘s establish that Pale Moon is a difficult crotch of pre-Australis Firefox. truthfully, you can say that Pale Moon is its own independent product, wholly separated from Mozilla Firefox despite its origin .
reasonably similar to the Waterfox browser, Pale Moon has very humble beginnings. ( But that ‘s probably where the similarities end ! ) Pale Moon is an older branch than Waterfox and has completely moved in a different management than other Firefox forks ; it presently uses its own engine, Goanna and its own platform, UXP .
Pale Moon forked from Firefox a early as Firefox 1.5.x, however it took years for it to grow and mature to the project it is presently .
It seems that Pale Moon ‘s independence, customizability, and a impression in its UXP platform remain its main draw .
Download Pale Moon
Pale Moon is available on Windows and most Linux platforms. It besides features a portable translation ( not to be confused with a mobile version – there is no mobile support for Pale Moon as of writing ) that can be run from removable media such as a USB stick .
What ‘s more is that Pale Moon need not be formally “ install ” to run on Linux systems. It can run from an educe tarball, much like an appimage .
There are minimum system requirements for running this browser. These requirements differ slenderly across different operating systems :
|Windows 7 SP1
|A “modern Linux
|CPU||SSE2 support||SSE2 support|
|RAM||1 GB||1 GB|
|Libraries||N/A||GTK 2.24 OR GTK 3.22
GLib 2.22 or higher
Pango 1.14 or higher
libstdc++ 4.6.1 or higher
|Disk Space||300 MB uncompressed||40 MB|
Launch and set up
note : For this Pale Moon review, I am using Windows 10 .
Installing Pale Moon on my Windows 10 machine was simple and easy. I chose the Standard installation method acting :
Everything went politic and immediate. I launched the browser immediately post-install, where two tab key greeted me :
On this initial beginning of Pale Moon, it besides initiated quite a series of DNS queries. These were captured by the Sysmon tool on my window machine :
additionally, after allowing Pale Moon to idle for approximately 10 minutes, it besides made these queries :
Some of these queries were made multiple times each. And to be honest, that ‘s … a lot of queries for equitable a first gear launching .
naturally, I did my best to dig deeper and figure out more data about them .
To start, aus.palemoon.org is Pale Moon ‘s automatic rifle update service. The browser queries this domain to check for updates to the browser .
blocklist.palemoon.org is queried to check for updates to the browser ‘s built-in extension/plugin/driver block list and dua.palemoon.org is for “ high precedence ” updates to the user-agent override ( which gives Pale Moon the ability to change the drug user agent string when connecting with different domains ) .
www.palemoon.org is queried because on Pale Moon ‘s foremost launch, it takes you to the dedicated page for foremost launches on Pale Moon ‘s official web site. Funny enough, you can visit that page on any other browser .
start.palemoon.org is the default option home foliate for Pale Moon. It redirects to palemoon.start.me. You can actually visit both domains from any other browser and be presented with the lapp home page .
This is because palemoon.start.me is a third-party military service Pale Moon uses to give you its default begin page that features all those easy to click shortcuts to park world wide web apps, web services, and social media. consequently, the start.me domains Pale Moon queries ( such as f.start.me, c.start.me, whatismylocale.start.me, and api.start.me ) are services used and queried to render this home page .
More information on start.me
Depending on you and your threat model, this may not sit quite proper with some users as start.me is a third-party service. fortunately, disabling/not using start.me is american samoa easy as changing Pale Moon ‘s home page within its settings. Doing then should stop the queries to the respective start.me services and domains .
We ‘ll dive into the privacy and security features of Pale Moon here. We ‘ll besides cover any special and/or alone features this browser has .
Claims no telemetry or data solicitation
Pale Moon boasts a no telemetry or data collection claim .
Pale Moon features a unique permissions coach .
The permissions director allows you to set permissions for the unique domains you ‘ve visited :
As you can see in the above screenshot, for each domain you can determine whether to :
- Store passwords
- Load images
- Allow pop-ups
- Store cookies/site data
- Display notifications
- Install extensions/themes
- Share location
I found this permissions director actually well designed and surprisingly commodious, specially when when it came to managing cookies and site data for each domain .
Most people might say, “ Well geez, avoidthehack, you can do that in good about any browser, ” which is true – you can easily set ball-shaped cookie preferences in Pale Moon. however, most browsers wo n’t allow you to micromanage settings for individual sites to this same degree .
Pale Moon allows you to :
Which is pretty neat and handy .
Encrypted Sync Service
Pale Moon has its own sync-ing capabilities .
In order to use the synchronize military service, you must create an explanation. fortunately, you only need to provide an email address and password in ordering to create an account .
Pale Moon receives and uses your IP address, login credentials, date & time of device, your OS, browser adaptation, and host names your device. It does n’t look like this datum is stored or permanently logged .
All data is throughout code. furthermore, the datum is encrypted on the customer ( read : your ) side anterior to upload to the waiter .
pale Moon does n’t sell/disclose information to any third parties. however, they will comply with orders from government and police enforcement within rationality, which is n’t a deal breaker .
Despite being a crotch of pre-Australis Firefox, Pale Moon does not run on Firefox ‘s Gecko engine .
alternatively, unlike most other Firefox forks, Pale Moon runs on its own browser engine called Goanna. This engine itself is hard forked from Mozilla ‘s own Gecko engine .
The Goanna engine is based on the now independently developed UXP ( Unified XL Platform ), which is yet another branch of Mozilla ‘s defunct XUL language .
Please be mindful, the fork ( UXP ) is well-maintained as of publish, however Mozilla ‘s discontinued XUL _is not_ ! additionally, UXP is the platform for other applications as well .
It is Pale Moon ‘s use of this Goanna locomotive that makes it more than good an outdated adaptation of Firefox, despite being forked from “ old Firefox ” or “ erstwhile Gecko ” code.
Read more: How to Change Your IP Address
More information on Goanna
Pale Moon receives frequent updates. The lapp can be said for its engine ( Goanna ) equally well .
Pale Moon ‘s updates fix bugs, improve overall timbre of life sentence, and sporadically adds/builds on fresh feature within both the browser and the engine .
additionally, Pale Moon has an active community of developers and users who seem dedicated to keeping the project active with these patronize updates .
NPAPI and XUL plugin documentation
interestingly, Pale Moon silent supports respective NPAPI ( Netscape Plugin Application Programming Interface ) plugins. “ still, ” because most modern browsers do not support these plugins. Some of these supported albeit deprecated plugins include :
- Adobe Flash
- Microsoft Silverlight
- Java applet
- Unity Web Player
Please note that despite Pale Moon ‘s compatibility with these plugins, that does n’t inevitably mean the plugins themselves are “ safe ” or well maintained. In fact, many NPAPI plugins have reached their respective end of life .
independent addition “ memory ”
Pale Moon has its own plugins/add-ons/extensions web site. This is autonomous of Mozilla Add-ons web site for Firefox and the Chrome Web Store for Chromium-powered browsers :
additionally, Pale Moon besides has the option for custom themes .
It ‘s worth nothing that newer versions of Pale Moon no longer support bequest Firefox add-ons that are n’t specifically ported to Pale Moon .
Pale Moon is an impressive project that continues to grow in independence .
The Pale Moon undertaking has forked so forked sol much from the pre-Australis Firefox source code that it has become something “ new ” entirely. basically, it ‘s its very own intersection that has a cheeseparing zero dependability on anything that Mozilla or evening Google is doing presently .
Remember, while the Pale Moon browser is in itself this wholly autonomous fork, sol is :
- Goanna, the rendering engine of Pale Moon
- UXP, the underlying platform that powers other applications (in addition to Pale Moon)
- Pale Moon’s plugins
additionally, this project has spawned other browser forks :
- White Star
All in all, Pale Moon is a shining case of why open informant software is amazing !
No telemetry/phoning dwelling
As previously mentioned, Pale Moon has a no telemetry and no data collection claim .
Long history short, I did find this to be true. More specifically, I did n’t notice any particularly excessive DNS requests from Pale Moon logged in Sysmon .
however, I did want to note that if you keep the default home page ( from start.me ), it does systematically make a number of requests to variations of the start.me knowledge domain. These are the lapp domains found in the First Launch section of this follow-up .
The easiest way to mitigate this, if desired, is to plainly change the default home page .
additionally, the browser does make periodic requests to :
As noted previously, aus.palemoon.org is Pale Moon ‘s automatic update service. blocklist.palemoon.org is the browsers default blocklist and dua.palemoon.org is a critical update servicing for modifying Pale Moon ‘s user agent string it shares with domains you connect to .
From my practice of this browser, I feel confident in saying that Pale Moon does n’t collect data nor telemetry. The act of connections it initiates may be of some concern to some users, however, many of these connections are not cause for refer – and can be easily mitigated .
Does n’t use Google Location Data
interestingly, Pale Moon does n’t use Google ‘s Location Service API for placement reliant tasks within the browser .
This is a big cope because, well, a long ton of browsers use Google ‘s Location Service – tied if the service is proxied or otherwise augmented to hopefully improve the end drug user ‘s privacy. even Firefox makes use of Google Location Service, albeit it ‘s modified and can be disabled within Firefox ‘s about : config settings .
alternatively, Pale Moon appears to use ipapi for its localization services .
lack of some modern features
Pale Moon lacks smooth capability with a fortune of modern features found within browsers today .
This is besides the biggest convict I could find about this browser, but it ‘s one that users should weigh in accordance with their personal needs, and to an extent, threat model .
These are some of the more celebrated modern in-browser features not supported in Pale Moon :
No Flickroom Support
Put merely, Flickroom enables P2P ( Peer-to-Peer ) sharing from inside the browser. For model, it allows users the ability to voice and/or video chat without an mediator waiter or downloading any early extensions/add-ons .
therefore, in other words, performing P2P relate tasks like video chatting would not be potential within Pale Moon without the avail of some classify of compatible addition .
The top to a lack of Flickroom confirm is that you do n’t have to deal with the likes of Flickroom leaks, which can leak your IP address even from behind a VPN and can be easily leveraged as a singular identifier in fingerprinting methods .
No Integrated PDR reader
You know how most browsers will open a
pale Moon does n’t do that – because it does n’t have an in-browser PDF proofreader .
therefore, if you plan on openings a long ton of PDFs, then you ‘ll either need a secondary browser that has an integrated PDF subscriber ( which, naturally does come with some security risks ) or a dedicate PDF reader installed on your machine .
No in-browser DRM
The Pale Moon browser does n’t support in-browser DRM ( “ Digital Rights Management ” ) software .
DRM software has a long, complicate history. There have been many advocates against DRM software due to its privacy invasiveness and questionable potency in preventing plagiarism, but alas it has only proliferated in the past few years .
therefore, Pale Moon is n’t the ideal browser for using streaming services that make use of in-browser DRMs. For example : Flickroom uses DRM software for its Flickroom Web Player. Because of this, it wo n’t play within Pale Moon :
Pale Moon besides features a few more “ modern browser features ” that have been removed .
While I can both understand and respect the developers ‘ decisions to not include these features, I do feel a lot of users may disagree .
I besides feel that these lack of “ modern browser features, ” do n’t resonate good with a draw of users, which ultimately hurts the browser ‘s ability to make a ample shock in the background browser marketplace share, which besides in turn keeps the browser in sort of a “ niche browser ” corner .
Granted, it could be that the developers do n’t necessarily care about this, but I feel it ‘s an important topic to bring up concerning Chromium ‘s absolute domination of the browser market share in late years .
No fluid or macOS support
This could be a deal-breaker for some users. For others, not so much .
There does not appear to be any plans for actively developing a Pale Moon mobile version on either Android or io .
For what it ‘s worth, pale Moon does feature a portable translation of the browser for Linux environments. This portable adaptation is not to be confused with a mobile version. The portable adaptation allows users to launch and use the browser from removable media such as a USB stick .
besides, it ‘s worthy to note that there seems to be some community members that attempt to maintain releases of Pale Moon for macOS. however, none of this is “ official. ” additionally, there is a crotch of Pale Moon called White Star, with a big stress on macOS users .
It needs to be reiterated that Pale Moon is an excellent case of the ability of true free and open generator software .
then, now the interview, “ is Pale Moon a viable privacy browser ? ” however stands .
I say it is. After all, you can find it on avoidthehack ‘s best browser picks for Windows .
But even without our recommendation, Pale Moon is set up to be fairly individual and/or procure by plan – or at least as close up you can get to it, given the status and complexity of the modern browser .
however, on the flip side, Pale Moon ‘s rejection of some common advanced in-browser features such as can be looked at as a double-edged sword .
While the rejection of some of these normally incorporated browser features allows Pale Moon to stay true to its “ mission, ” I feel it besides makes it less of a lineal rival to browsers such as Firefox, Safari, and Chromium-powered browsers. particularly then in the eyes of the more “ median ” drug user whose expectations may hold unlike than the expectations of a truthful “ exponent ” exploiter.
In early words, its miss of support for some of these features can make wide spread adoption hard ( erbium ), which consequently affects its ability to nab market contribution .
This concludes avoidthehack ‘s Pale Moon browser review. Hopefully you ‘ve found it an instructive read .
As constantly, stay safe out there !