08 Oct 2026
Planet Mozilla
Mozilla Privacy Blog: Canada’s bill C-22 threatens encryption, users’ privacy and the security of digital economies
Encryption is woven into everyday digital life. It protects our messages and passwords, but also banking and payments, health data, government services and the digital infrastructure societies rely on every day. Yet across jurisdictions, governments are increasingly considering laws that expand lawful access to data for law enforcement and national security purposes. In practice, this can mean requiring companies to create new ways to access encrypted data, introduce technical capabilities that bypass existing protections, or make otherwise secure systems insecure. These measures can weaken the very security encryption is designed to provide, with consequences for cybersecurity, privacy, fundamental rights and the wider economy. Canada's Bill C-22 is the latest example of this trend, raising serious concerns about the security and privacy consequences of expanding government access to data.
For Mozilla, protecting that security is fundamental to both the products we build and the principles we advocate for. One of the foundational principles that guide Mozilla's mission and work holds that individuals' security and privacy on the internet are fundamental and must not be treated as optional. Protecting people's privacy and security is not an aspiration for us, but shapes the products we build every day: Firefox blocks trackers, protects you from profiling via cookies and fingerprinting, comes with malware protection and a built-in VPN, offers HTTPs-only mode and protects your passwords and credit card information by encrypting them.
Some of these protections are being threatened by Canada's Lawful Access Act, also known as bill C-22. Part two of the bill, the "Supporting Authorized Access to Information Act" (SAAIA) would introduce sweeping new powers to require electronic service providers to build and maintain capabilities that facilitate government access to information. If passed in its current form, companies could be asked to introduce vulnerabilities, build backdoors, bypass, weaken or otherwise defeat encryption, access data before encryption or decrypt encrypted data to provide access to law enforcement. Service providers could also be compelled to retain and access data they have purposefully chosen not to collect.
Let us be clear: there is no safe way to create exceptional access to encrypted data that only the intended actor can use. An access mechanism created for law enforcement can also be discovered, exploited or abused by potentially bad actors.
Such vulnerabilities and backdoors do not only undermine people's fundamental rights to privacy and data protection, but also the trust and security premises societies everywhere depend on. The same encryption that protects a private conversation also protects financial transactions, sensitive health information, business systems and critical digital services.
Expanding capabilities of AI systems are only exacerbating these risks - governments should encourage the disclosure and patching of vulnerabilities, not compel companies to introduce insecurities deliberately. Only trustworthy and transparently governed digital infrastructures can be the basis for digitally sovereign societies.
We are also concerned by C-22's scope, which does not stop at Canadian services or users. C-22 expansive surveillance capabilities and data retention obligations would undermine people's privacy and security everywhere, and the bill's confidentiality requirements would make it impossible for services to inform their users about security breaches or backdoors introduced.
Guided by our Surveillance Principles for a Secure, Trusted Internet, we call on Canadian policymakers not to rush the legislative process to take experts' feedback into account in amending C-22 to protect everyone's security and privacy. Canada's interests are best served by regulation that protects encryption, strengthens cybersecurity and emphasizes transparency, checks and balances.
The post Canada's bill C-22 threatens encryption, users' privacy and the security of digital economies appeared first on Open Policy & Advocacy.
08 Oct 2026 9:35am GMT
The Mozilla Blog: Firefox partners with Anschutz Entertainment Group at the Uber Arena and Uber Eats Music Hall in Berlin
Firefox is teaming up with AEG and taking to the main stage at Berlin's biggest and best indoor arenas. Starting this October, as the indoor music scene heats up and the basketball and ice hockey seasons are in full swing, fans flocking to the Uber Arena, Uber Eats Music Hall, and Uber Platz will see Firefox highly visible around the venue. They may even bump into our very own mascot, Kit, who will be on hand to help them skip the main queues courtesy of Firefox.
We know that the experiences people care about often begin online. The internet is the gateway to how they discover, plan, and navigate their way to concerts, sports events, and nights out before they happen in real life.
Firefox's presence will help make every step of that journey simple and smoother, starting at the door.

People with Firefox downloaded on their phone will have access to a dedicated Firefox Fast Lane that allows them to skip the main line at the Uber Arena. To ensure the smoothest possible entry, a QR code for downloading Firefox will also be available at the Fast Lane.
"People who use Firefox tend to choose things deliberately, their browser, their music, their nights out. This partnership is for them. A first for Firefox. Most browsers want more of your time online. We want you at the show, faster. Berlin is where we are starting, right across the river from our office. See you there," said John Solomon, Mozilla-Firefox Chief Marketing Officer.
We are excited to bring what we stand for to Berlin's premier entertainment venue - choice, control, and a better experience to the moments that people want to enjoy and truly care about.
The post Firefox partners with Anschutz Entertainment Group at the Uber Arena and Uber Eats Music Hall in Berlin appeared first on The Mozilla Blog.
08 Oct 2026 7:00am GMT
07 Oct 2026
Planet Mozilla
The Mozilla Blog: Jambu Palaniappan and David Parry-Jones join the Mozilla Corporation Board of Directors
Today, we are very pleased to announce two new additions to the Mozilla Corporation Board of Directors: Jambu Palaniappan and David Parry-Jones.
As we build the next chapter of Mozilla, we've been focused on bringing people onto our Board who combine deep operating experience with a real commitment to the values Mozilla stands for. Jambu and David bring deep experience building and leading technology businesses, and each brings a unique perspective to our Board.

Jambu Palaniappan is the Chief Executive Officer of Checkatrade, where he drives the company's mission of Powering Great Work. The home improvement platform connects consumers across the UK with quality tradespeople - every year, Checkatrade improves millions of homes and delivers billions of pounds of work to small and medium-sized businesses.
Before joining Checkatrade, Jambu was Managing Partner and Head of Europe at OMERS Ventures, where he invested in and supported high-growth technology companies. Earlier in his career, he spent several years at Uber and Uber Eats, joining as one of the first 100 employees and leading expansion across Europe, the Middle East, and Africa. Jambu holds a degree in Public Policy and Economics from Vanderbilt University.

David Parry-Jones is a board director and former Chief Revenue Officer (CRO) with more than 30 years of experience scaling technology businesses internationally. Most recently, he served as CRO at DeepL and previously held senior leadership roles at Microsoft, VMware, and Twilio. He has led large teams across diverse markets and cultures, working with both early-stage companies and global enterprises.
As a board member and adviser, he brings a practical perspective on growth, international expansion, and building strong teams that turn strategy into results.
Please join me in welcoming Jambu and David to the Mozilla Corporation Board of Directors.
The post Jambu Palaniappan and David Parry-Jones join the Mozilla Corporation Board of Directors appeared first on The Mozilla Blog.
07 Oct 2026 6:37pm GMT
The Mozilla Blog: 100 days later: Microsoft still steers Windows and Copilot users to Edge, everywhere the law lets it
One hundred days ago, Mozilla released Over The Edge 2.0, the second independent report from leading experts on deceptive design Dr. Harry Brignull and Cennydd Bowles, on how Windows, Edge, Bing, and Copilot are designed to steer people away from the browser they chose.
We published the report, and the researchers published the evidence for anyone to analyze.
Browsers are a powerful tool. So it's no surprise that the history of the web has many examples of powerful platforms trying to deny people browser choice. Now, as AI reshapes our online experiences, the stakes couldn't be higher. Browsers are a key distribution layer for AI tools and services, while still determining many of the privacy and security functionality people rely on every day. Steering people toward one browser can therefore shape which AI services reach users and the protections that come with it.
We also shared the report with Microsoft and talked to them about the issues raised in the report. We knew that an immediate change was unlikely, but we hoped that, when faced with independent evidence of harmful design practices impacting Windows users, they would also want better for people.
Instead, it became clear that Microsoft will respect user choice only when it is forced to. It is important to think about what that means for a company whose operating system runs on more than a billion machines. Microsoft's standard for respecting people's choices is legal compliance. Not what's best for its users. Not its own published principles. Not what's technically feasible. Not even what it already does for users in Europe.
That's the most shocking part. Not that Microsoft engages in such tactics - we've seen that before. It's the fact that a better version of Windows already exists, and it is already available today - but only if you live in the European Economic Area (EEA), where the Digital Markets Act (DMA) forced the issue. If you live in the United States, India, the United Kingdom, or most other locations around the world, your experience and your freedom to choose for yourself are worse.
One hundred days later, here is what people outside of the EEA still get:
- The Windows 10 message "You're almost done setting up your PC" uses tricky wording to pull people off the default they picked.
- Windows Search and Widgets open links in Edge instead of the browser set as default.
- Windows keeps Edge as the default for common browser file types like PDFs and SVG images, even after another browser has been set as default.
And people in the EEA also deserve better:
- Edge remains pre-pinned to the taskbar; this seems to directly violate the "principled approach to app pinning and app defaults."
- Copilot, Microsoft's AI tool opens web links in a side-panel instead of the browser people chose, in every region tested, Europe included.
- Windows Backup, the tool Microsoft uses to guide people through the migration to Windows 11, silently tries to set Edge as the default when it restores a PC and fails to properly bring the user's own browser along.
Most of the 2024 patterns are still there. The 2026 patterns are worse. Microsoft is using new surfaces like Copilot and the migration to Windows 11 to further undermine user choice.
Our ask has always been simple: First, give all Windows users the fairer designs that are live in the EEA - regardless of where they are located. Second, stop the remaining harmful design practices that persist in the EEA. That means:
- Stopping the remaining harmful design tactics in the EEA and ship that standard worldwide.
- Honoring people's browser choice everywhere it is currently ignored, including Windows Search, Widgets, Copilot, and Windows Backup restoration.
- Applying Microsoft's own 2023 app pinning principles to Edge itself.
The Mozilla-commissioned report has never been about intent. It's about accountability and Microsoft's responsibility to stop undermining people's choices. The practices we documented need to change. Statements about intent are not a substitute for action.
In the past 100 days, we've stopped waiting for Microsoft to act. Instead, we've stepped up public pressure on the company to respect people's choices.
We are also taking the report's findings to regulators and policymakers. In Europe, the DMA is the only thing that has moved Microsoft. Everywhere else, the lesson is the same: Microsoft ships only when a regulator requires fairer design.
We hope that regulators in the US, the UK, India, and Brazil are paying attention.
Microsoft can do better. It already has, for people in the EEA.
Until it does the same in all jurisdictions, we will keep pointing out the company's choices and the impact they have on hundreds of millions of users who want something different.
The post 100 days later: Microsoft still steers Windows and Copilot users to Edge, everywhere the law lets it appeared first on The Mozilla Blog.
07 Oct 2026 10:00am GMT
This Week In Rust: This Week in Rust 672
Hello and welcome to another issue of This Week in Rust! Rust is a programming language empowering everyone to build reliable and efficient software. This is a weekly summary of its progress and community. Want something mentioned? Tag us at @thisweekinrust.bsky.social on Bluesky or @ThisWeekinRust on mastodon.social, or send us a pull request. Want to get involved? We love contributions.
This Week in Rust is openly developed on GitHub and archives can be viewed at this-week-in-rust.org. If you find any errors in this week's issue, please submit a PR.
Want TWIR in your inbox? Subscribe here.
Updates from Rust Community
Official
Foundation
Newsletters
- This Month in Rust OSDev: September 2026
- Rust Trends Issue 83 - NVIDIA Brings Rust to the GPU Kernel
- Rust Trends Issue 84 - Google Puts Agents on the Rust Rewrite
Project/Tooling Updates
- Generate PDFs from Rust with HTML and CSS
- Catharsis for Noisy Audio: A Pure-Rust Restoration Toolkit with No ffmpeg and No Black Boxes
- Release mold 3.0.0 · rui314/mold
Observations/Thoughts
- Rust for CPython (Python Language Summit 2026)
- Lies, damned lies, and Rust in the TechEmpower Web Framework Benchmarks
- Beyond the
& - The Performance Cost of RwLock in Our Read-Heavy Workload
- The TokioConf 2027 Call For Talk Proposals is now open
- Shipping JPEG XL in Chrome
- Proving Rust Web Application Correctness with Lean 4
- Hardware-Aware Programming in Rust
Rust Walkthroughs
- The Missing Piece in Rust Error Handling
- Compiling the kernel with gccrs
- Declarative Macros in Rust: A Simple and Practical Introduction
- A dynamic drone fail-safe system that adapts as the situation changes.
- Build a Burglar Alarm with ESP32-C5 That Sends Telegram Alerts
Crate of the Week
This week's crate is karatepe, a statically typed localisation language and library.
Thanks to miro for the self-suggestion!
Please submit your suggestions and votes for next week!
Calls for Testing
An important step for RFC implementation is for people to experiment with the implementation and give feedback, especially before stabilization.
If you are a feature implementer and would like your RFC to appear in this list, add a call-for-testing label to your RFC along with a comment providing testing instructions and/or guidance on which aspect(s) of the feature need testing.
No calls for testing were issued this week by Rust, Cargo, Rustup or Rust language RFCs.
Let us know if you would like your feature to be tracked as a part of this list.
Call for Participation; projects and speakers
CFP - Projects
Always wanted to contribute to open-source projects but did not know where to start? Every week we highlight some tasks from the Rust community for you to pick and get started!
Some of these tasks may also have mentors available, visit the task page for more information.
- issuerd - Add a French (fr) message bundle for login pages and emails
- issuerd - Add proptest suites for issuerd-protocol parsers
- issuerd - Add an additional client installation provider (adapter config download format)
- ruxen - Expand globs in include
- ruxen - Use nginx's status reason phrases everywhere
- ruxen - Implement proxy_method
If you are a Rust project owner and are looking for contributors, please submit tasks here or through a PR to TWiR or by reaching out on Bluesky or Mastodon!
CFP - Events
Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.
- RustWeek 2027 | CFP closes 2027-01-10 | Utrecht, The Netherlands | Event date: 2027-05-24
- TokioConf 2027 | CFP closes 2026-11-30 | Portland, Oregon, USA | 2027-04-26 - 2027-04-27
If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a PR to TWiR or by reaching out on Bluesky or Mastodon!
Updates from the Rust Project
653 pull requests were merged in the last week
Compiler
- add a single-entry parent
SpanDatacache - add fast path to generalization
- optimize Cranelift with PGO
Library
- add
mul_add_relaxedmethods for floating-point types - add
std::fs::{Home|Media}Dirs - expose
Rc::is_unique - stabilize
CStr::display - stabilize
debug_closure_helpers
Cargo
- add new peak memory table to cargo timings enabled via
-Zmem-stats config: Proper dotted tuple support with legacy fallback- git: default to net.git-fetch-with-cli if git is present
- improved testsuite file permissions cleanup
lint: Making the lint name a terminal hyperlink to docstrim-paths: stabilizeprofile.trim-paths- use trusted publishing for Cargo crates
Rustdoc
- Correctly handle
rustc_allow_incoherent_implon primitive methods - Correctly link to (imported)
enumvariants with "jump to def" - Fix how
Derefitems are handled
Rustfmt
items: format comments after where usingclause_shapebudget- use saturating arithmetics for
adjust_max_width
Clippy
manual_range_patterns: support char and byte literallet_unit_valuebail out if initializer is cfg-dependent- extend
needless_borrowed_referenceto lint mutable ref patterns - fix exponential-time performance bug in
has_non_owning_mutable_access_inner - improve
items_after_test_module: don't let derive expansions hide trailing items - new lint:
unnecessary_as_slice - optimize msrv calls (again)
Rust-Analyzer
- complete 'let' 'letm' in arm expr and closure expr
- complete turbofish when fn can't infer param
- do not suggest arg-list in expected callable arg
- fix
unicode-ident, take 2 - add missing HIR database when running unresolved-references
- complete let in macro when expand at macro stmts
- don't panic on malformed let-pattern with mismatched or-arm arities
- generate variant for self in impl
- improve in-block heuristic check in nested ambiguous
- name-match ignore leading tailing underscore
- transform usage path when extract trait to module
- fixed Implement
opaques_with_sub_unified_hidden_typefor the next-sol…
Rust Compiler Performance Triage
A relatively quiet week, but a very positive one nonetheless. Highlights are a 3.1% improvement in rustdoc speed from not using the metadata based crate_hash for rustdoc runs, a 0.5% improvement from a new fast path in the trait solver, and a 0.4% improvement from a cache for the parents of SpanData.
Triage done by @JonathanBrouwer. Revision range: c1070d69..cc9a14f7
Summary:
| (instructions:u) | mean | range | count |
|---|---|---|---|
| Regressions ❌ (primary) |
0.6% | [0.4%, 1.0%] | 12 |
| Regressions ❌ (secondary) |
0.4% | [0.1%, 0.9%] | 26 |
| Improvements ✅ (primary) |
-1.1% | [-6.2%, -0.2%] | 212 |
| Improvements ✅ (secondary) |
-1.9% | [-15.7%, -0.1%] | 208 |
| All ❌✅ (primary) | -1.0% | [-6.2%, 1.0%] | 224 |
4 Regressions, 3 Improvements, 1 Mixed; 5 of them in rollups 33 artifact comparisons made in total
Approved RFCs
Changes to Rust follow the Rust RFC (request for comments) process. These are the RFCs that were approved for implementation this week:
Final Comment Period
Every week, the team announces the 'final comment period' for RFCs and key PRs which are reaching a decision. Express your opinions now.
Tracking Issues & PRs
- Make
std::fs::{File, ReadDir, DirEntry}alwaysneeds_dropeven when unsupported. - [rustdoc] Add tabs to settings popover
- rustc: Stabilize the WebAssembly
wide-arithmeticfeature - Error on non-literal expressions in doc attributes on macro calls
- stabilize ptr_cast_slice
- Add extra types to
VaArgSafe - Reject cfg on expressions that cannot be safely removed
- fn_addr_eq: we actually can guarantee basically nothing
- Stop using dlltool for generating import libraries on MinGW
- Stabilize
ptr::try_cast_aligned - [disposition: close] 1.99 beta crater regression: overflow evaluating the requirement
- Move
hir::Params fromBodyof functions toFnDecl. - MCP: Add -Zasync-panic for binary size
- Upstreaming BorrowSanitizer Experimentally in Nightly Rust
No Items entered Final Comment Period this week for Rust RFCs, Cargo, Language Team, Leadership Council or Unsafe Code Guidelines. Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.
New and Updated RFCs
- RFC: Add
required-targetsfor workspace package selection - RFC: unsafe
global_asm - Cromulent
Copyclosure captures - RFC for limited crates.io self-service version deletion
This RFC will appear in the Call for Testing section of the next issue (#) of This Week in Rust (TWiR). You may remove the call-for-testing label. Please feel free to leave the call-for-testing label in place if you would like this RFC to appear again in another issue of TWiR.
Upcoming Events
Rusty Events between 2026-10-07 - 2026-11-04 🦀
Virtual
- 2026-10-07 | Virtual (Indianapolis, IN, US) | Indy Rust
- 2026-10-08 | Virtual (Berlin, DE) | Rust Berlin
- 2026-10-08 | Virtual (Nürnberg, DE) | Rust Nuremberg
- 2026-10-10 | Virtual (Gdansk, PL) | Stacja IT Trójmiasto
- 2026-10-10 | Hybrid (Kuala Lumpur, Malaysia) | Rust Malaysia Meetup
- 2026-10-11 | Virtual (Bengaluru, India) | Embedded Rust Discord
- 2026-10-13 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-14 - 2026-10-17 | Hybrid (Barcelona, ES) | EuroRust
- 2026-10-18 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-20 | Virtual (Washington, DC, US) | Rust DC
- 2026-10-21 | Hybrid (Vancouver, CA) | Vancouver Rust
- 2026-10-22 | Virtual (Berlin, DE) | Rust Berlin
- 2026-10-22 | Virtual | Rust 🦀 Maven
- 2026-10-26 | Virtual | Rust 🦀 Maven
- 2026-10-27 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-27 | Virtual (London, UK) | Women in Rust
- 2026-10-29 | Virtual | Rust 🦀 Maven
- 2026-11-01 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-11-03 | Virtual (London, UK) | Women in Rust
- 2026-11-04 | Virtual (Indianapolis, IN, US) | Indy Rust
Asia
- 2026-10-09 | Hybrid (Kuala Lumpur, MY) | Rust Malaysia Meetup
- 2026-11-03 | Tel Aviv-yafo, IL | Rust 🦀 TLV
Europe
- 2026-10-08 | Oslo, NO | Rust Oslo
- 2026-10-08 | Geneva, CH | Rust Geneva
- 2026-10-14 | Barcelona, ES | BcnRust
- 2026-10-14 - 2026-10-17 | Hybrid (Barcelona, ES) | EuroRust
- 2026-10-20 | Leipzig, SN, DE | Rust - Modern Systems Programming in Leipzig
- 2026-10-22 | Karlsruhe, DE | Rust Hack & Learn Karlsruhe
- 2026-10-22 | Toulouse, FR | Rust Toulouse
- 2026-10-27 | Aarhus, DK | Rust Aarhus
- 2026-10-31 | Stockholm, SE | Stockholm Rust
- 2026-11-01 - 2026-11-03 | Italy, IN | RustLab
North America
- 2026-10-08 | Lehi, UT, US | Utah Rust
- 2026-10-08 | New York, NY, US | Rust NYC
- 2026-10-08 | San Diego, CA, US | San Diego Rust
- 2026-10-10 | Boston, MA, US | Boston Rust Meetup
- 2026-10-14 | Los Angeles, CA, US | Rust Los Angeles
- 2026-10-20 | San Francisco, CA, US | San Francisco Rust Study Group
- 2026-10-21 | Hybrid (Vancouver, CA) | Vancouver Rust
- 2026-10-21 | San Francisco, CA, US | Bay Area Rust
- 2026-10-28 | Austin, TX, US | Rust ATX
South America
- 2026-10-08 | Buenos Aires, AR | Rust en Español
If you are running a Rust event please add it to the calendar to get it mentioned here. Please remember to add a link to the event too. Email the Rust Community Team for access.
Jobs
Please see the latest Who's Hiring thread on r/rust
Quote of the Week
There ain't no rules here in Quote of the Week - it's survival of the wittest
Thanks to Jonas Fassbender for the suggestion!
Please submit quotes and vote for next week!
This Week in Rust is edited by:
- nellshamrell
- llogiq
- ericseppanen
- extrawurst
- U007D
- mariannegoldin
- bdillo
- opeolluwa
- bnchi
- KannanPalani57
- tzilist
Email list hosting is sponsored by The Rust Foundation
07 Oct 2026 4:00am GMT
06 Oct 2026
Planet Mozilla
Firefox Tooling Announcements: Happy BMO Push Day! (20261006.1)
The following changes have been pushed to bugzilla.mozilla.org:
- Bug 2075358 - Native Mojo REST endpoints serve anonymous requests when requirelogin is enabled
- Bug 2074690 - BMO REST API cannot set any DATE-type custom field
- Bug 2059957 - Reject Mojolicious-truncated request bodies before native routes dispatch
- Bug 1273193 - Get Comments webservice docs don't mention author
- Bug 2078352 - Selenium test 4_test_votes.t fails with Firefox ESR 153 because go_to_bug doesn't wait for the module expand animation
Discuss these changes in the BMO Matrix Room
1 post - 1 participant
06 Oct 2026 9:43pm GMT
The Mozilla Blog: Strengthen your online security for free with Firefox
Every October, Cybersecurity Awareness Month reminds us the importance of protecting our digital lives.
The theme for 2026 is 'Don't Make It Easy for Them,' with the National Cybersecurity Alliance (NCA) and the Cybersecurity and Infrastructure Security Agency (CISA) providing simple, actionable steps users can take to make it harder for cybercriminals to attack.
Everyone wants to be safe online, but one of the most common excuses we hear is "I don't have the time or the money to invest in it right now." Well, we have good news: you can improve your online security easily, for the low price of $0.
Firefox provides several free features designed to make it easier to protect your online life and harder for cybercriminals to target you.
Password manager: Use a unique password for every account

Reused passwords are one of the easiest ways attackers break into multiple accounts. If one site is breached, your login details could be tested on many others.
Firefox's free password manager can generate and securely store a strong, unique password per site, which is the single highest-leverage fix against password stuffing. For convenience, Firefox can automatically fill in your saved login information the next time you access a previously visited site. However, you still have the option to turn off password saving for specific websites, or completely if you're using a shared device or simply prefer to enter it each time.
You can manage your stored logins on a singular device at any time. To get a head start, you also have the option to import passwords saved on several other popular browsers. In addition, you can create a free Mozilla account to safely sync them across your signed-in devices.
VPN: Privacy built into the browser

Imagine you're settling into a corner table at a bustling airport cafe, checking some emails on your phone before you board your flight. Or perhaps you took your laptop to the campus library to finally start that research paper you've been putting off. Maybe you're polishing off that last presentation slide between sessions at an out-of-state conference.
While these moments are routine, connecting to public Wi-Fi anywhere can open a small window of risk - as your IP address, approximate location, and browsing activity can be more exposed on networks you don't control.
That's where Firefox's free built-in, browser-based VPN steps in. While Firefox already encrypts your traffic with HTTPS, the built-in VPN feature routes your browsing traffic through a proxy network, hiding your IP address before it reaches a website. This means the sites you visit will see a proxy IP address instead of your own. It offers an industry-leading 50 gigabytes of free VPN-browsing each month, with no extension or extra app to install. Simply sign in, turn it on, and start browsing.
Firefox's free built-in VPN first launched on desktop in March, later expanding to Android in July. Unlike a standalone or full-service VPN, it's designed specifically to protect your browsing traffic within Firefox, not your entire device. This means apps, downloads, and other system traffic are not routed through the browser-based VPN. For people who need broader, device-wide VPN protection, Mozilla also offers a separate paid VPN service.
You can check the full list of regions where built-in VPN in Firefox is currently available here, and learn more about the differences between Firefox's free built-in VPN and Mozilla VPN here.
Relay: Contain the damage of any one breach

Think about how often you give out your personal email address - for an online purchase, RSVPing to an event, or signing up to a new app. Each time, you trust the site owner will protect your information, but, spam piles up and breaches can still happen - even when you think you're being careful.
Firefox Relay gives you a smarter way to share. Instead of handing out your real email address, this feature provides secure, random email masks to use any time a website, store, or app asks you for your information. It forwards messages to your real email, while keeping your identity hidden to senders. This means if one service gets compromised, your other accounts stay safe.
You can also use Relay in the U.S. and Canada to shield your phone number, so you can receive calls and texts through masks and reply without exposing your real number.
The best part? To make protecting your privacy even easier, Firefox increased its limit to 50 free email masks earlier this year, allowing you to shield dozens of logins at no cost.
Browse freely: Firefox protects you by default
Even if you sometimes forget to use Firefox protection tools like password manager, VPN, and Relay, there are multiple always-on features operating within the browser to help keep your session secure and private. These include enhanced tracking protection to block hidden scripts and known trackers that follow you across the web, browser fingerprinting protection to prevent sites from building a unique profile of your device, and warnings about deceptive or malicious websites.
Together, Firefox's individual and always-on security features work to help keep your browsing safe and your data private. So, this Cybersecurity Awareness Month, take a moment to build new habits, try out our free cybersecurity tools, and make life more difficult for cybercriminals. Small steps add up, and we are here to help. Stay safe, stay smart, and keep exploring the web with confidence on Firefox.
The post Strengthen your online security for free with Firefox appeared first on The Mozilla Blog.
06 Oct 2026 4:00pm GMT
Ryan Hunt: Wasm Stack Switching in SpiderMonkey
WebAssembly stack switching in SpiderMonkey is the most complex feature I've ever implemented.
It's one of those projects where you get lost and start rethinking the basics, like "what is the stack even really?"
It was fun to give a talk on it. Check out the recording below, or on YouTube.
06 Oct 2026 3:00pm GMT
05 Oct 2026
Planet Mozilla
Mozilla Data YouTube Channel: Towards a Telemetry Taxonomy
Leif Oines talks about an effort to define a more complete taxonomy for Mozilla's data.
05 Oct 2026 6:47pm GMT
Mozilla Data YouTube Channel: Data Club Talk: Jan-Erik Rediger - The Glean UniFFI migration and how no one noticed
Given at the Mozilla Data Club on August 12th, 2022.
05 Oct 2026 3:53pm GMT
Firefox Developer Experience: Firefox WebDriver Newsletter 157
WebDriver is a remote control interface that enables introspection and control of user agents. As such, it can help developers to verify that their websites are working and performing well with all major browsers. The protocol is standardized by the W3C and consists of two separate specifications: WebDriver classic (HTTP) and the new WebDriver BiDi (Bi-Directional).
This newsletter gives an overview of the work we've done as part of the Firefox 157 release cycle.
Contributions
Firefox is an open source project, and we are always happy to receive external code contributions to our WebDriver implementation. We want to give special thanks to everyone who filed issues, bugs, and submitted patches.
In Firefox 157, multiple WebDriver bugs were fixed by contributors:
- Sameem merged two internal helpers (remote/shared/Sync.sys.mjs and remote/marionette/sync.sys.mjs), which removed some code duplication.
- Khalid AlHaddad unified the navigation commands in Marionette and WebDriver BiDi to always initiate navigations via browsingContext.loadURI().
- Khalid AlHaddad updated the WebDriver BiDi client used by WebDriver tests so that browsing_context.locate_nodes returns the nodes array directly instead of the enclosing result object, matching the updated command response.
WebDriver code is written in JavaScript, Python, and Rust, so any web developer can contribute! Read how to set up the work environment and check the list of mentored issues for Marionette or the list of mentored JavaScript bugs for WebDriver BiDi. Join our chatroom if you need any help to get started!
All Changes
A complete list of developer-facing changes included in this Firefox release is available in the MDN Firefox 157 Release Notes.
05 Oct 2026 2:21pm GMT
Mozilla Data YouTube Channel: Outreachy Mentorship: A Retrospective
Will Lachance does a retrospective on the Glean Dictionary outreachy internship. See also "Linh's Outreachy Internship Highlights" https://www.youtube.com/watch?v=UJdIkHDPgGQ To learn more about Outreachy, see https://www.outreachy.org/
05 Oct 2026 10:59am GMT
04 Oct 2026
Planet Mozilla
Mozilla Data YouTube Channel: Responsible Data Collection is Good, Actually (Ubisoft Data Summit 2021)
Firefox Telemetry Engineer and Data Steward Chris H-C (:chutten) gives a talk at Ubisoft's Data Summit 2021 about how Responsible Data Collection as practised at Mozilla makes cataloguing easy, stops instrumentation mistakes before they ship, and allows you to build self-serve analysis tooling that gets everyone invested in data quality. Oh, and it's cheaper, too.
04 Oct 2026 11:55pm GMT
Mozilla Data YouTube Channel: Data Club: Jan-Erik Rediger - Little Bobby Tables - from metrics.yaml to data-filled columns
A short story about Little Bobby Tables and how we know what data to fill in where.
04 Oct 2026 7:17pm GMT
Mozilla Data YouTube Channel: Data Club Lightning Talk: Jan-Erik Rediger - Your personal Glean data pipeline
This talk was given as part of the Data Club Lightning Talk Session on February 11th, 2022. More on https://blog.mozilla.org/data/2022/02/25/this-week-in-glean-your-personal-glean-data-pipeline Information about Glean: https://mozilla.github.io/glean/book/index.html
04 Oct 2026 4:52pm GMT
Mozilla Data YouTube Channel: GLAM Datasets
Marina Samuel and Anthony Miyaguchi talk about the ETL pipeline created for the GLAM project (https://github.com/mozilla/glam).
04 Oct 2026 7:56am GMT