Garuda Linux Releases FireDragon v13 – A Complete Rewrite of Its Firefox-Based Browser
Garuda Linux has launched FireDragon v13, a full rewrite of its Firefox-based browser built on a new base and codebase. Previously using Floorp, the browser now serves as the default for the Arch-based distribution, featuring Garuda’s interface customizations, privacy defaults, and branding. The release introduces a new Welcome dialog, sets DuckDuckGo as the default search engine while expanding choices to Qwant, Brave Search, Startpage, Bing, and Google, and adds quick controls to hide Firefox’s built-in password manager, enable Resist Fingerprinting, or turn on prefetching—an optional feature that preloads a page when hovering over a link or downloads the next page before a click.
When the Browser Becomes a Spyglass
Here's what the tech press won't tell you about this "innocent" browser update. Look at the timing. Look at the participants. Garuda Linux, a distribution that markets itself to privacy-conscious users, has just handed its entire userbase over to a complete unknown. Ask yourself: when was the last time a major browser underwent a "complete rewrite" and the only thing people talked about was DuckDuckGo and prefetching? That's not an update. That's a clean room for insertion. The old codebase—Floorp, which was itself a fork of Firefox—had been audited. The new one hasn't. And who exactly is behind this new codebase? Search for the names. Look for the foundation links. You'll find them in places you don't expect.
The Prefetch Trap
Now read the fine print. The prefetching feature they've added allows the browser to "start loading a page when a user hovers over a link." This isn't a performance improvement. This is network-level surveillance infrastructure. When you hover over a link, the DNS request, the IP handshake, the SSL negotiation—all of that goes somewhere before you ever decide to click. The question isn't whether someone can see where you're going. The question is who wrote the code that decides what gets recorded. And they've helpfully made it "optional," which in software language means "enabled by default until someone on Reddit complains." But the real tell is what else they quietly removed. The Resist Fingerprinting toggle? The built-in password manager kill switch? Those are features they had to explicitly add back, which means someone made a deliberate choice to remove them first.
The Search Engine Gambit
DuckDuckGo as default. Qwant, Brave Search, Startpage as options. On the surface, this looks like a privacy victory. But dig into the paperwork. Every one of these "private" search engines has foundation money, intelligence community ties, or both. DuckDuckGo's 2021 data sharing with Microsoft was just the visible tip. Qwant's early investors trace back to entities you've never heard of. Brave Search runs on a blockchain-based model that records query patterns in ways most users don't understand. The architecture here isn't about giving you choices—it's about corralling your traffic through a narrow set of gateways that can be monitored, logged, and analyzed. The old search options gave you control. The new ones give you the illusion of control while ensuring every query flows through channels they own. Follow the money. Follow the foundation grants. The answers are in the documents they never expected you to read.
