Maze Linux ships a layered anonymity and privacy stack that is active by default. This page explains each component, why it matters, and how to use it.
| Layer | Tool | Default State |
|---|---|---|
| MAC address randomization | Maze Cloak (maze-cloak.service) + NetworkManager | Active |
| Anonymity stack (Tor / DNSCrypt / I2P) | Entropy Shield | Installed — you start it |
| Anonymous browsing | Tor Browser | Installed |
| Anonymous file sharing | OnionShare | Installed |
| Hardened browser | Firefox (enterprise policies) | Default browser |
| VPN | ProtonVPN, WireGuard, OpenVPN | Installed |
| Private messenger | Session | Installed |
| KDE telemetry | All KDE / Plasma usage reporting | Disabled |
| Network monitoring | Wireshark, nmap | Installed |
| Tor daemon | tor | Enabled at boot |
Not preinstalled: Mullvad Browser, Mullvad VPN and Brave are not on the ISO. Install them yourself if you want them.
No standalone DNSCrypt service. Encrypted DNS comes with Entropy Shield when you turn it on; the default resolver is
systemd-resolved.
Every network card has a hardware MAC address that uniquely identifies your
device on local networks. On Maze this is handled by Maze Cloak
(maze-cloak.service), a Maze-native daemon — not by macchanger.
Maze Cloak works in three layers:
It drives the interface with ip link and writes NetworkManager configuration
to /etc/NetworkManager/conf.d/99-maze-cloak.conf.
Three modes are available: fully random, keep vendor prefix (looks like the same brand of hardware), and random vendor prefix.
Maze Cloak pauses rotation while a VPN is up, so a rotation cannot drop your tunnel mid-session.
Maze Cloak is tray-first — a PyQt6 interface with English and Turkish, switchable live. From the shell:
systemctl status maze-cloak
ip link show # link/ether is the current (cloaked) address
Every DNS query is a potential privacy leak — your ISP can see every domain you resolve.
Maze does not run a standalone dnscrypt-proxy service; the package is not
on the ISO. Encrypted DNS is one of the layers Entropy Shield enables when
you start it (see below). Out of the box the resolver is systemd-resolved.
Entropy Shield is a Maze-native tool that activates Tor + DNSCrypt-proxy + I2P simultaneously with a single command, layering all three anonymity systems at once.
entropy-shield --help
Tor 0.4.8.12 routes your traffic through a volunteer-operated relay network with three hops, making it very difficult to trace traffic back to your IP address.
The most private way to use Tor:
torbrowser-launcher
On first run it fetches the latest Tor Browser. Tor Browser is pre-hardened: JavaScript is restricted, fonts and canvas are fingerprint-resistant, no history is kept between sessions.
For routing other applications through Tor:
sudo systemctl start tor
This starts a SOCKS5 proxy on 127.0.0.1:9050:
curl --proxy socks5h://127.0.0.1:9050 https://check.torproject.org/api/ip
Tor is already enabled at boot. To check it:
systemctl status tor
Share files or host a web service accessible only over a Tor .onion address:
onionshare /path/to/file
The receiver accesses the .onion URL in Tor Browser. The file is never uploaded to a third-party server.
| Browser | Best for | Fingerprint resistance | Tor support |
|---|---|---|---|
| Firefox (hardened) | Daily use | High (hardened defaults) | Via SOCKS proxy |
| Brave | Everyday + Chromium compat | High (built-in shielding) | Via SOCKS proxy or Tor windows |
| Mullvad Browser | VPN users wanting Tor-Browser-level hardening | Very high | Designed for VPN, not Tor |
| Tor Browser | Maximum anonymity | Very high (shared fingerprint) | Native |
Maze configures Firefox through enterprise policies
(/etc/firefox/policies/policies.json), not a prepared user profile. The
difference matters: policies apply to every profile, including new ones you
create, and users cannot silently undo them.
Disabled by policy:
Enabled by policy:
Also set: the first-run page and homepage point at the Maze site. Firefox Accounts are not disabled, so you can still sync if you want to.
No extension required.
The comparison table above lists Brave and Mullvad Browser — note that neither is installed by default; install them yourself if you want them.
All KDE Plasma and application usage reporting is disabled by default in Maze. KDE's opt-in telemetry (User Feedback) is turned off in the Maze system configuration — no usage data is sent to KDE.
The Mullvad VPN client is preconfigured. Keeps no logs, accepts anonymous payment, no email required.
mullvad-vpn
The GUI client is installed (account required):
proton-vpn-gtk-app
Import a WireGuard configuration file from your VPN provider:
sudo cp your-vpn.conf /etc/wireguard/wg0.conf
sudo wg-quick up wg0
Enable at boot:
sudo systemctl enable wg-quick@wg0
Import an .ovpn file through NetworkManager or via CLI:
sudo openvpn --config your-vpn.ovpn
Session is an end-to-end encrypted messenger with no account required (uses a Session ID instead of a phone number) and no central metadata server.
session-desktop
Capture and inspect network packets. Your user is in the wireshark group so you can capture without sudo.
wireshark
Scan for open ports on your own system or an authorized network:
nmap -sV -p 1-65535 localhost
Wi-Fi security testing. Use only on networks you own or are authorized to test.
CLI packet capture:
sudo tcpdump -i eth0 -n
Haze — a Tor-based onion messenger using the Haze Protocol. Run haze --help for usage.
HazeDrop — anonymous file and text transfer over Tor. Run hazedrop --help for usage.
Open maze-control-center and select the Privacy tab to see:
systemctl status maze-cloak)/etc/firefox/policies/policies.json is in place