404PrivacyDocs

Frequently asked questions

Start here for common questions, then follow the linked guide for the full explanation or installation steps. For a first installation, choose Desktop or Self-hosted / CLI.

Privacy and scope

Does 404 make me anonymous online?

No. 404 coordinates selected browser and network signals to reduce fingerprint inconsistencies and linkability. It does not hide your account identity, the content you submit, your public IP, or every observable browser feature. It is not a guarantee of anonymity or protection against a particular commercial fingerprinting vendor. The architecture and limits explain what each layer controls.

How does 404 work?

Your browser sends supported traffic to STATIC, a proxy on your device. For intercepted HTTPS, the browser establishes TLS with STATIC using a locally trusted CA; STATIC makes a separate connection to the website. It applies the selected profile to supported headers, upstream transport options, and eligible page scripts. On a configured Linux path, a separate eBPF classifier can apply packet settings. See STATIC and Rose.

Does 404 change my IP address?

No. Websites see the public IP of your chosen route. A VPN or another network route serves a different purpose from fingerprint shaping; it does not automatically make the remaining signals coherent or anonymous.

Does 404 ever see my data and/or logs?

The local STATIC process can read supported traffic it terminates, including sensitive data in intercepted HTTPS. It has logging and process-local telemetry facilities; do not assume that local output is harmless to share. Websites still receive the requests you send them. “Local” describes where the proxy runs, not a promise that no data leaves your computer. The CA and trust page explains the interception boundary.

Does the desktop app upload my traffic anywhere?

The documented browsing path uses a local proxy, not a hosted 404 browsing relay. The product also has separate account, licensing, download, and update services. That distinction does not establish that every desktop build has zero outbound diagnostics; consult its current Privacy Policy and the installed build. The repository map separates product delivery from the local data plane.

Can I use my normal accounts?

Signing in directly identifies an account regardless of the selected fingerprint. The legacy guidance recommends alternate or disposable accounts for testing login and OAuth flows, because changed signals can trigger challenges or account restrictions. Do not assume that someone else’s successful testing guarantees the same outcome for your account.

Choosing and installing 404

Is 404 a desktop app or an open source repository?

Both. The desktop app manages installation and host integration. The AGPLv3 open-source stack can be built and operated directly. These are separate workflows with different responsibilities for trust, routing, and updates. Choose Desktop for the managed workflow or CLI to operate it yourself.

Do I need an account?

The desktop product uses its account and licensing distribution flow; follow the requirements of your downloaded build. Building and running the self-hosted open-source stack does not require the managed desktop application or its account workflow. The desktop terms and EULA are separate from the open-source license.

Does Windows still run STATIC as a native binary?

The documented Windows operator and desktop paths use a Linux root filesystem in WSL2. The managed app uses a distro named 404; the new CLI guide uses 404-cli to avoid collisions. Native Windows code paths in STATIC are separate from that packaged runtime. See Windows installation.

Is Rose a custom Linux kernel?

The current release packages an Alpine-based userspace root filesystem. WSL2 supplies the Linux kernel. Rose contains STATIC, the eBPF object, dependencies, and a manual launcher; its packaged /etc/wsl.conf does not automatically start STATIC. See Distribution anatomy.

What is localhost?

localhost names your own computer; 127.0.0.1 is its IPv4 loopback address. A port selects a service on that address. The bundled/sample proxy uses 4040 and its control API uses 4042; standalone CLI defaults use 8443 and 8445. A bind to 0.0.0.0 listens on all IPv4 interfaces in that environment, so it is not equivalent to loopback. See Configuration and launch.

Does starting STATIC automatically route my browser through it?

No. The engine must be running, the browser must use its proxy listener, and the browser must trust the correct public CA for intercepted HTTPS. These are separate conditions. Follow the Windows, macOS, or Linux guide in order.

Can I run the CLI and desktop installations together?

Keep their distro names, ports, configuration, tokens, and CA identities distinct. On Windows, the new CLI guide uses 404-cli, while the desktop’s documented managed distro is 404. A browser must trust the certificate from the instance it actually uses. Never unregister one distro when intending to remove the other.

Profiles and coverage

Which profile should I choose?

Use chrome-windows for Chrome or another Chromium-family browser, edge-windows for Edge, and firefox-windows for Firefox. The presented platform in the profile name does not require the host OS to be Windows. Engine matching is more important than the host OS name; STATIC does not enforce every coherent combination. See Profile anatomy.

Does switching profiles change every open request immediately?

The shared profile selection applies to new Flows; an already active Flow retains the profile data it captured. Seeded overlays are materialized for the process, rather than generating an unrelated persona on every request. API selection also attempts to sync the Linux packet map when available. See Control endpoints.

Why can a fingerprint test still recognize my browser?

Coverage is limited by eligible injection, runtime timing, browser-native behavior, the transport backend, and configured packet handling. A site may inspect unwrapped APIs or correlate accounts, cookies, and behavior. A changed value or hash proves only that measurement changed, not that an entire identity became unlinkable. See the JavaScript runtime and TLS boundary.

Are workers and iframes covered?

The runtime wraps newly created classic workers and propagates selected state into accessible same-origin iframes. Module workers, service workers, pre-existing workers, and cross-origin contexts have different limits. Read Workers and same-origin iframes.

Does eBPF work on every platform?

It requires a supported Linux kernel, an attached TC egress classifier, a pinned profile map, and permissions for STATIC to update that map. The Windows WSL2 distribution supplies a Linux environment; the standalone macOS path does not. Process readiness alone does not prove packet shaping. See eBPF packet path.

Trust and troubleshooting

Why do I have to trust a local CA?

STATIC issues browser-facing certificates for intercepted HTTPS. Trusting its public root lets applications using that trust store accept those certificates when routed through STATIC. The private signing key stays with STATIC. This gives the local proxy access to decrypted traffic; review CA and trust before installation.

Which certificate or key can I copy?

Install or export only the public static-ca.crt/cert_pem for the hosts that deliberately trust your instance. Keep the private CA key private. A WSL file ending in .key.dpapi is not evidence of Windows DPAPI encryption: the Linux file backend writes key material in the distro. Do not import the private key into a system CA directory or paste it into a support report.

Why does Firefox show a certificate error when another browser works?

Firefox may require an import into its Authorities store even after OS trust is installed. Confirm that the trusted root matches the running instance’s /ca/status, then follow the Firefox step in your platform guide. A successful /status response does not verify browser trust.

Why did my browser stop loading pages after I stopped 404?

It may still point at a stopped proxy. Disable browser or system routing before stopping the engine, or restore the affected proxy setting. For the managed app, use its routing and cleanup flow; see What 404 changes.

How do I remove 404’s changes?

Stop routing first, then remove the corresponding public CA from every host/browser store where you installed it. Use the desktop cleanup flow for managed state. Removing a WSL distro with wsl --unregister deletes its Linux filesystem; distinguish 404 from 404-cli. Do not delete only one half of STATIC’s CA state and expect a silent repair. See removal and diagnosis.

How do I check that my download is authentic?

Follow release signature verification: authenticate the STATIC manifest with its exact Sigstore workflow identity, or verify the distro manifest with an independently trusted Ed25519 public key, then match the artifact SHA-256 and expected release version. The published distro workflow does not currently distribute that public key as a release asset; obtain it through a trusted publisher channel before proceeding. Reading a manifest or comparing a hash from the same untrusted download is not signature verification.

Development and support

Can I inspect, modify, or contribute to the open-source stack?

Yes, under its AGPLv3 terms. Start with Build from source, the repository map, and the project’s contribution guide. Testing fingerprint leaks, improving profiles and packet handling, researching surfaces, and improving documentation are useful contributions.

How do I report a bug or ask for help?

Use GitHub Issues for reproducible core bugs, GitHub Discussions for implementation questions, or the community Discord. Include the version, OS, browser family, selected profile, launch mode, and a minimal reproduction. Review logs before sharing them; remove tokens, private keys, credentials, URLs or content that identifies sensitive activity.

For support, email support@404privacy.com. For desktop rollout or pricing, email honda@404privacy.com or use the contact page.

How do I disclose a security issue?

Send sensitive reports privately to support@404privacy.com. Avoid public issue trackers and chat for undisclosed vulnerabilities or private traffic data.

Links from the previous documentation