Packages

  • Status Closed
  • Percent Complete
    100%
  • Task Type Freedom Issue
  • Category Any
  • Assigned To No-one
  • Operating System All
  • Severity Low
  • Priority Very Low
  • Reported Version Any
  • Due in Version Undecided
  • Due Date Undecided
  • Votes
  • Private
Attached to Project: Packages
Opened by gnusupport - 08/06/2018
Last edited by g4jc - 23/06/2018

FS#923 - [iceweasel-no-resource-uri-leak]: using "contents" in description

Description:

community/iceweasel-no-resource-uri-leak 1.1.0-1 (iceweasel-addons)
    Deny resource:// access to Web content. Fill the hole to defend against fingerprinting.

Description is vague because of the word “content”. Does it deny to “content” or it denies to files, URLs or to what?

See:
https://www.gnu.org/philosophy/words-to-avoid.html#Content

Closed by  g4jc
23.06.2018 04:04
Reason for closing:  Fixed
Admin
g4jc commented on 23.06.2018 04:04

Thank you for the report.

Does it deny to “content” or it denies to files, URLs or to what?

It protects against a long-standing and unsolved Mozilla bug that fingerprints the user, see: https://browserleaks.com/firefox

The new FF60 manages to break the above test, but introduced another more critical bug that can precisely identify the user with WebExt UUID.

I have backported the latest version from git, which also protects against WebExt fingerprinting. It was not released on AMO because they no longer allow legacy addons. I also patched the wording to clarify the situation and replaced the wording.

Description is now:

Deny access to local URI paths in omni.jar: Very important to privacy. A direct workaround for bugzil.la/863246 and bugzil.la/1372288

You can test the new version here: https://repo.hyperbola.info:50000/other/no-resource-uri-leak/

I would also like some leak-tests made to confirm that the new extension:// filter is working properly. If you know of anyone capable of this please have them try it.

Meanwhile, I think this issue can be considered solved.

Date User Effort (H:M)
watch my effort tracking timers

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing