Maze Linux / Wiki

Privacy Reference

Maze Linux ships a layered anonymity and privacy stack that is active by default. This page explains each component, why it matters, and how to use it.


Privacy at a Glance

LayerToolDefault State
MAC address randomizationMaze Cloak (maze-cloak.service) + NetworkManagerActive
Anonymity stack (Tor / DNSCrypt / I2P)Entropy ShieldInstalled — you start it
Anonymous browsingTor BrowserInstalled
Anonymous file sharingOnionShareInstalled
Hardened browserFirefox (enterprise policies)Default browser
VPNProtonVPN, WireGuard, OpenVPNInstalled
Private messengerSessionInstalled
KDE telemetryAll KDE / Plasma usage reportingDisabled
Network monitoringWireshark, nmapInstalled
Tor daemontorEnabled at boot

Not preinstalled: Mullvad Browser, Mullvad VPN and Brave are not on the ISO. Install them yourself if you want them.

No standalone DNSCrypt service. Encrypted DNS comes with Entropy Shield when you turn it on; the default resolver is systemd-resolved.


MAC Address Randomization — Maze Cloak

Every network card has a hardware MAC address that uniquely identifies your device on local networks. On Maze this is handled by Maze Cloak (maze-cloak.service), a Maze-native daemon — not by macchanger.

What it does

Maze Cloak works in three layers:

  1. Scan randomisation — randomises the address used while scanning for networks, so you are not trackable just by looking for Wi-Fi.
  2. Connection randomisation — a different address per network you join.
  3. Scheduled rotation — periodically rotates the address while connected.

It drives the interface with ip link and writes NetworkManager configuration to /etc/NetworkManager/conf.d/99-maze-cloak.conf.

Address strategies

Three modes are available: fully random, keep vendor prefix (looks like the same brand of hardware), and random vendor prefix.

VPN awareness

Maze Cloak pauses rotation while a VPN is up, so a rotation cannot drop your tunnel mid-session.

Using it

Maze Cloak is tray-first — a PyQt6 interface with English and Turkish, switchable live. From the shell:

systemctl status maze-cloak
ip link show            # link/ether is the current (cloaked) address

Encrypted DNS

Every DNS query is a potential privacy leak — your ISP can see every domain you resolve.

Maze does not run a standalone dnscrypt-proxy service; the package is not on the ISO. Encrypted DNS is one of the layers Entropy Shield enables when you start it (see below). Out of the box the resolver is systemd-resolved.


Entropy Shield

Entropy Shield is a Maze-native tool that activates Tor + DNSCrypt-proxy + I2P simultaneously with a single command, layering all three anonymity systems at once.

entropy-shield --help

Tor

Tor 0.4.8.12 routes your traffic through a volunteer-operated relay network with three hops, making it very difficult to trace traffic back to your IP address.

Tor Browser

The most private way to use Tor:

torbrowser-launcher

On first run it fetches the latest Tor Browser. Tor Browser is pre-hardened: JavaScript is restricted, fonts and canvas are fingerprint-resistant, no history is kept between sessions.

Tor Daemon (SOCKS proxy)

For routing other applications through Tor:

sudo systemctl start tor

This starts a SOCKS5 proxy on 127.0.0.1:9050:

curl --proxy socks5h://127.0.0.1:9050 https://check.torproject.org/api/ip

Tor is already enabled at boot. To check it:

systemctl status tor

OnionShare

Share files or host a web service accessible only over a Tor .onion address:

onionshare /path/to/file

The receiver accesses the .onion URL in Tor Browser. The file is never uploaded to a third-party server.


Browsers: Privacy Comparison

BrowserBest forFingerprint resistanceTor support
Firefox (hardened)Daily useHigh (hardened defaults)Via SOCKS proxy
BraveEveryday + Chromium compatHigh (built-in shielding)Via SOCKS proxy or Tor windows
Mullvad BrowserVPN users wanting Tor-Browser-level hardeningVery highDesigned for VPN, not Tor
Tor BrowserMaximum anonymityVery high (shared fingerprint)Native

Firefox hardening details

Maze configures Firefox through enterprise policies (/etc/firefox/policies/policies.json), not a prepared user profile. The difference matters: policies apply to every profile, including new ones you create, and users cannot silently undo them.

Disabled by policy:

Enabled by policy:

Also set: the first-run page and homepage point at the Maze site. Firefox Accounts are not disabled, so you can still sync if you want to.

No extension required.

The comparison table above lists Brave and Mullvad Browser — note that neither is installed by default; install them yourself if you want them.


KDE Telemetry

All KDE Plasma and application usage reporting is disabled by default in Maze. KDE's opt-in telemetry (User Feedback) is turned off in the Maze system configuration — no usage data is sent to KDE.


VPN

Mullvad VPN

The Mullvad VPN client is preconfigured. Keeps no logs, accepts anonymous payment, no email required.

mullvad-vpn

ProtonVPN

The GUI client is installed (account required):

proton-vpn-gtk-app

WireGuard

Import a WireGuard configuration file from your VPN provider:

sudo cp your-vpn.conf /etc/wireguard/wg0.conf
sudo wg-quick up wg0

Enable at boot:

sudo systemctl enable wg-quick@wg0

OpenVPN

Import an .ovpn file through NetworkManager or via CLI:

sudo openvpn --config your-vpn.ovpn

Session — Private Messaging

Session is an end-to-end encrypted messenger with no account required (uses a Session ID instead of a phone number) and no central metadata server.

session-desktop

Network Analysis Tools

Wireshark

Capture and inspect network packets. Your user is in the wireshark group so you can capture without sudo.

wireshark

nmap

Scan for open ports on your own system or an authorized network:

nmap -sV -p 1-65535 localhost

aircrack-ng

Wi-Fi security testing. Use only on networks you own or are authorized to test.

tcpdump

CLI packet capture:

sudo tcpdump -i eth0 -n

Haze and HazeDrop

Haze — a Tor-based onion messenger using the Haze Protocol. Run haze --help for usage.

HazeDrop — anonymous file and text transfer over Tor. Run hazedrop --help for usage.


Maze Control Center — Privacy Tab

Open maze-control-center and select the Privacy tab to see:


Privacy Checklist