Commit Graph
100 Commits
Author SHA1 Message Date
Thorin-OakenpantsandGitHub 38dc90a947 dom.allow_cut_copy
https://github.com/arkenfox/user.js/commit/80f69a6f3d1d34f49496064d9199d885a28c6c4f
2021-08-26 06:27:32 +00:00
Thorin-OakenpantsandGitHub 80f69a6f3d 2406: remove
This doesn't achieve anything. AFAICT, it's an old gecko only API, not used on the web: superseded by the Clipboard API (added in FF21+)
2021-08-26 06:26:41 +00:00
Thorin-OakenpantsandGitHub 498a25c759 0806: remove confusing line 2021-08-26 06:04:57 +00:00
Thorin-OakenpantsandGitHub 64e8dfad0a 1004: remove setup tag
IDK if this is true: no one has ever complained, and I'm not interested in maintaining/testing it
2021-08-26 05:55:11 +00:00
Thorin-OakenpantsandGitHub 5ec4fef4ed dedupe 0808 2021-08-26 05:40:59 +00:00
Thorin-OakenpantsandGitHub 881a2d22eb cleanup tags
- there was only one perf left
- warning is down to 5: two in section headers, 3 on inactive prefs: no need to mention it, people will see them if they read each item/section
2021-08-25 16:14:59 +00:00
Thorin-OakenpantsandGitHub 76c8ecd10d tidy 2021-08-25 15:56:57 +00:00
Thorin-OakenpantsandGitHub 677b81765f tidy webgl 2021-08-25 15:36:15 +00:00
Thorin-OakenpantsandGitHub 9f43d48a32 targetBlankNoOpener -> don't touch 2021-08-25 14:09:39 +00:00
Thorin-OakenpantsandGitHub 6077d09b9f window.name -> don't touch
Also FPI FF65+ patch is not part of FPI, it is part of 4002 which is a separate pref
2021-08-25 14:04:50 +00:00
Thorin-OakenpantsandGitHub 7144f8b7f8 cleanup continued, #1239
More minor tweaks to come. This isn't final
- 0102: ambiguous that the clearing was related to PB mode
- 0900s:
   - get rid of 0901, it has no pref, stick link in header
   - 0905: values on multi-lines use spaces = more readable
- 1000s:
   - rename as disk avoidance and remove sub-section headers
   - remove the outdated section header
- 4001: it will never be perfected, it's doing it's job
- 5500s: optional hardening
   - legit security measures, but commonality in caveats, so I made them a separate section
   - this flips graphite, asm.js and wasm from active to inactive: these are overkill: exhibit A: hundreds of millions of Firefox users
   - e.g. graphite and wasm are enabled on Tor Browser
   - new CVE keyword links
- 7000s: don't bother - two more items added
- 5000s: optional opsec and cleanout 0800s header
- re-number
   - 0900s, 1000s, 1400s, 2400s

PS: I need a new parrot: "9000 syntax error: I ran out of parrots"
2021-08-24 22:51:48 +00:00
Thorin-OakenpantsandGitHub 778421cad4 #1241 2021-08-24 08:59:11 +00:00
Thorin-OakenpantsandGitHub 35ccaff58e calrify password prompt, #1241 2021-08-24 08:52:12 +00:00
Thorin-OakenpantsandGitHub 69132b588f 7000s: mathml, svg, #1235 2021-08-24 05:43:38 +00:00
Thorin-OakenpantsandGitHub 51748ea25a leverage cve keyword 2021-08-24 03:09:33 +00:00
Thorin-OakenpantsandGitHub 269cf965bd renumber 1700s 2021-08-23 10:03:13 +00:00
Thorin-OakenpantsandGitHub b177c73f0d typo
technically it's "or" - FPI overrides network partitioning
2021-08-23 09:47:34 +00:00
Thorin-OakenpantsandGitHub 613e55ae8c 7000s: add MOAR; renumber 0700s, #1235 2021-08-23 09:42:21 +00:00
Thorin-OakenpantsandGitHub 3697bd8d3a 1603 -> inactive
Yes it's pretty much useless. Yes it's fingerprintable, and what that entropy is, who knows. Since it's sent regardless with ETP, which we enable in all windows, then who cares. And if you don't use ETP in all windows, then I don't care either - just saying
2021-08-23 06:26:45 +00:00
Thorin-OakenpantsandGitHub 9f08c7c0f4 7000s: referer policy #1235
and re-number 1600s
2021-08-23 06:04:19 +00:00
Thorin-OakenpantsandGitHub 05b7d61735 7000s: non cross origin referers 2021-08-23 04:54:49 +00:00
Thorin-OakenpantsandGitHub e31a6876e6 section 6000 2021-08-23 04:40:29 +00:00
Thorin-OakenpantsandGitHub 47be7ba42f 1203 is a reset not enforce 2021-08-23 04:08:49 +00:00
Thorin-OakenpantsandGitHub 033977fe10 move personal to last
probably more professional to keep it at the end since it isn't strictly project related. It also opens up space for `DON'T TOUCH` and `OPTIONAL OPSEC`
2021-08-23 03:39:15 +00:00
Thorin-OakenpantsandGitHub ab42deb541 Four more items to 7000s, #1235 2021-08-23 02:55:36 +00:00
Thorin-OakenpantsandGitHub c55e6dcd68 flip order, order within groups
- note: keeping 91 separate for now for the easy info factpr
2021-08-22 08:27:15 +00:00
Thorin-OakenpantsandGitHub cf379bcce0 typos 2021-08-22 05:45:08 +00:00
Thorin-OakenpantsandGitHub 2b26cd4f41 7000s: ciphers, #1235
- merged 3DES cipher to bottom: it is still the same order of [1]
- 3DES pref will be deprecated: pref name changes, and the cipher slated to be unavailable unless you downgrade to < TLS1.2 - see https://bugzilla.mozilla.org/show_bug.cgi?id=1724072
   - FYI: we reset TLS downgrades to session only by resetting the pref currently in 1203
- "Minimal/non-existent threat of downgrade attacks"
   - FYI: these old ciphers are about 1-2% of traffic (from memory) - but that's still significant breakage
   - So the only reason to do this would be to harden against downgrade attacks (and inadvertently use weak sites = breakage): but that doesn't fit most user's threat model: and is probably never going to happen for them. Not sure if I can word that much better and just as succinct
2021-08-22 05:18:54 +00:00
Thorin-OakenpantsandGitHub 8bfee5b59f hardware acceleration
see https://github.com/arkenfox/user.js/commit/04d648d55b4aeff5aada935356b59031ab75b482
2021-08-22 01:55:28 +00:00
Thorin-OakenpantsandGitHub 04d648d55b remove 2508
- inactive in user.js since
   - v55: gfx.direct2d.disabled
   - v67: layers.acceleration.disabled
- the way to counter hardware fingerprinting is within each API that may expose it
- this may have made some sense way back in the day, when there were less options/protections, but not any more
- [are we web render yet](https://arewewebrenderyet.com/) - yes, 100% - there is no need to cripple your browser's perf
2021-08-22 01:53:01 +00:00
Thorin-OakenpantsandGitHub 7cdc76ecf9 dom.vibrator.enabled
see https://github.com/arkenfox/user.js/commit/aded0707a4ad6c91f68d81d5b0fc75578d5aa048
2021-08-21 04:40:11 +00:00
Thorin-OakenpantsandGitHub aded0707a4 misc
- renumber 0200s, 2500s
- remove 2414: doesn't apply to desktop, and I think it has been neutered in android
2021-08-21 04:39:08 +00:00
Thorin-OakenpantsandGitHub 2a011f1053 media.media-capabilities.enabled
see https://github.com/arkenfox/user.js/commit/213467d91bb1bc4f5c517c2d542b11fe41422387
2021-08-21 03:23:17 +00:00
Thorin-OakenpantsandGitHub 213467d91b remove 2517
- inactive since we added it in v63
- this is not how you defeat fingerprinting (unless done in an enforced set)
- for the record: not even tor browser disable this
- fingerprinting this is not cheap in gecko (for now)
- from [2]
   - decoding/encoding capabilities: "it is expected that the entropy ... isn’t going to be significant"
   - HDR detection: "... has the potential to add significant entropy .. however .. but ... thus minimizing effective entropy" - it is what it is
   - note that RFP has some mitigations in FF82+ 1461454
2021-08-21 03:21:32 +00:00
Thorin-OakenpantsandGitHub da0c291127 update to ESR91 2021-08-21 02:26:17 +00:00
Thorin-OakenpantsandGitHub 27ce48f319 trim fluff 2021-08-21 02:00:43 +00:00
Thorin-OakenpantsandGitHub 37ded2a519 remove redundant warning 2021-08-20 14:10:09 +00:00
Thorin-OakenpantsandGitHub c9bdceb8d6 1244: fix no upgrade test 2021-08-20 13:23:59 +00:00
Thorin-OakenpantsandGitHub 95136382e1 improve 1244, closes #1047 again 2021-08-20 13:18:43 +00:00
Thorin-OakenpantsandGitHub 78d953bfda remove 1032
dead wood: marked as default false since at least v68, inactive since at least v78, and web notifications are controlled in 2300s
2021-08-20 03:16:25 +00:00
Thorin-OakenpantsandGitHub 2d3d8ae5b0 alerts.showFavicons 2021-08-20 03:12:59 +00:00
Thorin-OakenpantsandGitHub cef08b63f1 4520 -> personal 2021-08-20 02:52:55 +00:00
Thorin-OakenpantsandGitHub a8e95e7310 dexter would be proud #1235
- just to be clear, this section is not supported: not interested in references or explanations or  FF version numbers or default info etc
- "do more harm than good" - ambiguous, not interested in explaining why exactly: but FYI
  - some leak
  - most break shit
  - almost all are easily fingerprinted and the combo of them would make you really stand out
- removed the duplicate `ui.prefersReducedMotion` - this should move to personal as well
- moved `ui.systemUsesDarkTheme` to personal
2021-08-20 02:13:53 +00:00
Thorin-OakenpantsandGitHub 5ab3c47b6b 7001: tweak
F11 has nothing to do with the API or why
2021-08-19 15:26:22 +00:00
Thorin-OakenpantsandGitHub 45c52b6620 start section 7000s 2021-08-19 14:44:06 +00:00
Thorin-OakenpantsandGitHub 93f6aea06a 1605: change to active enforced 2021-08-19 13:17:07 +00:00
Thorin-OakenpantsandGitHub 00fa8f1b50 general.warnOnAboutConfig
https://github.com/arkenfox/user.js/commit/ac84da2af4b1c9454b3d97a93e67d58b1f448c38
2021-08-19 02:14:23 +00:00
Thorin-OakenpantsandGitHub ac84da2af4 remove XHTML config warning
dead weight: ESR users will already be aware of and ticked the warning box by now
2021-08-19 02:07:03 +00:00
Thorin-OakenpantsandGitHub f19d850845 tidy #1235
8000s (was 4600s)
- move below personal, so user-relevant part is shorter
- swap out font vis with document fonts + font whitelist
   - font vis still has usability/visual purposes: it just won't really help much with fingerprinting
   - ESR78 users (who can't use font vis), sorry, but we made doc fonts inactive for a while now, and now recommend you don't use it anyway
2021-08-19 01:46:47 +00:00
Thorin-OakenpantsandGitHub 7264271063 rusty-snake improvements, #1235 2021-08-19 00:15:30 +00:00
Thorin-OakenpantsandGitHub dc63a752a5 tidy 0300 + 0301 2021-08-18 13:55:41 +00:00
Thorin-OakenpantsandGitHub a70c312938 goodbye battery
- dead weight since 2017-06-13 when ESR45 reached EOL .. good riddance
- if someone does use it, it's not going to do any harm, so no need to carry it for prefsCleaner
2021-08-18 12:46:24 +00:00
Thorin-OakenpantsandGitHub 2ce269362e dom.battery.enabled 2021-08-18 12:40:27 +00:00
Thorin-OakenpantsandGitHub 29ad768a22 RFP tweak
letterboxing is not part of RFP, it is a separate pref: bugzilla and FF version info is in 4504
2021-08-18 09:08:36 +00:00
Thorin-OakenpantsandGitHub 679648b33e RFP info tweak 2021-08-18 09:03:16 +00:00
Thorin-OakenpantsandGitHub 783786290d tidy
- geo -> warning
- merge container prefs
- remove redundant "see"s
- remove corresponding 4600's item number in RFP mitigations
   - it's pretty clear by the preference names in 4600
   - could be misconstrued that the 4600 pref is the same result
- RFP's language prompt only checks for en*, not en-US (so en-GB, en-CA etc do not get prompted)
   - https://searchfox.org/mozilla-central/source/toolkit/components/resistfingerprinting/RFPHelper.jsm#196
2021-08-18 08:24:44 +00:00
Thorin-OakenpantsandGitHub e7e6cfffe8 0503: tidy 2021-08-18 07:30:55 +00:00
Thorin-OakenpantsandGitHub 08e9fb35fd update some references 2021-08-18 07:16:19 +00:00
Thorin-OakenpantsandGitHub fdc9376c69 tidy
- 0105*: merge into a single block
- 1220: make values more readable with spaces, like 2701 (no need for value 2), add default, update advise (get a new AV, SHA1 is dead baby)
- 2619: remove fluff
2021-08-18 01:50:09 +00:00
Thorin-OakenpantsandGitHub 41c3c0ec26 tweak 2522: webgl
- we already disable webgl, that's enough
- the other two prefs are not going to provide much protection if a user decides they want webgl
- "disable-fail-if-major-performance-caveat" only applies to ESR78 and will removed in the future
- one (or two) less pref(2) for users to troubleshoot/flip
2021-08-17 03:47:33 +00:00
Thorin-OakenpantsandGitHub d7208ccf34 tidy 2021-08-17 03:41:56 +00:00
Thorin-OakenpantsandGitHub 77410bf86d musical chairs part 2
merge plugins with webrtc (camera + mic) and "media"
2021-08-17 03:08:48 +00:00
Thorin-OakenpantsandGitHub 1d63e836ee musical chairs part 1
- move 2200s into respective sections
- move FPing items into 2500s
2021-08-17 02:52:19 +00:00
Thorin-OakenpantsandGitHub 668e843fce misc
- remove 2720
   - this is a very old pref, been inactive since at least our first github release: v51
   - disabling the API is not how you control client side state: you do that by blocking cookies which also controls other state such as IDB etc
- 2700 section header
  - history/downloads is redundant
  - Offline Website Data info -> relevant item number with Active Logins info
  - ^ technically it still includes appCache for ESR78 users, but that will be moot in less than three months
- tidy RFP
  - update to FF91 userAgent spoofing: there is no Android ESR so we don't need to mention "Android 9"
  - we don't need to say if the API is enabled for mediaDevices
2021-08-16 15:34:57 +00:00
Thorin-OakenpantsandGitHub 51e388ae86 dom.storage.enabled 2021-08-16 15:06:06 +00:00
Thorin-OakenpantsandGitHub e7872b193b !yoda
no bytes were harmed in the making of this commit
2021-08-16 04:22:46 +00:00
Thorin-OakenpantsandGitHub 8d6ee7c0c7 oophs 2021-08-16 04:18:12 +00:00
Thorin-OakenpantsandGitHub 7d1e244f5a 0506: clarify
oh noes! what's blocked, the pref or the ping? .. also save MOAR bytes
2021-08-16 04:10:20 +00:00
Thorin-OakenpantsandGitHub dcc736bb85 I meant 14 lines, u lucky bastards 2021-08-16 04:03:56 +00:00
Thorin-OakenpantsandGitHub 68568c1abf trim 1198 bytes (u lucky bastards!) + 13 lines 2021-08-16 04:02:15 +00:00
Thorin-OakenpantsandGitHub 1b33f574bb RFP stuff 2021-08-14 04:44:50 +00:00
Thorin-OakenpantsandGitHub 568a05ad7d 2502: trim
this info is useless .. save three lines
2021-08-14 04:18:04 +00:00
Thorin-OakenpantsandGitHub c3b7f7538c i do not like mixed case lists 2021-08-10 01:21:04 +00:00
Thorin-OakenpantsandGitHub 4b38e20f14 change 4600s into do not use, #1221 (#1225)
see https://github.com/arkenfox/user.js/issues/1221#issuecomment-895623028
2021-08-10 00:18:19 +00:00
Thorin-OakenpantsandGitHub d19d4ba784 final update
in hindsight, the original name is more accurate
2021-08-09 20:42:51 +00:00
Thorin-OakenpantsandGitHub dd112a167d final update 2021-08-09 20:39:47 +00:00
Thorin-OakenpantsandGitHub 92b7fb81d0 fixup STATS year 2021-08-04 18:45:15 +00:00
Thorin-OakenpantsandGitHub 404d1d466a update [STATS]
- just in time for ESR91
2021-08-04 17:23:38 +00:00
Thorin-OakenpantsandGitHub 06e5de4332 tweak windows SSO info/reference 2021-08-04 10:32:33 +00:00
Thorin-OakenpantsandGitHub eb4363dc18 tweak info in section 2800 header, #1223 2021-08-01 17:36:04 +00:00
Thorin-OakenpantsandGitHub 5c93ebb54f misc, closes #1220 2021-07-30 05:48:17 +00:00
Thorin-OakenpantsandGitHub b8f3d93a5c v90 2021-07-26 03:11:09 +00:00
Thorin-OakenpantsandGitHub f53f01823f 1203 default info 2021-07-24 12:56:27 +00:00
Thorin-OakenpantsandGitHub 18dbb56a3d put 1203 back
see https://github.com/arkenfox/user.js/commit/3bb9fc713f141d794fc4adfb38d3fcf86c9307ab
2021-07-24 12:51:15 +00:00
Thorin-OakenpantsandGitHub cc8674c16d revert last commit 2021-07-24 12:49:39 +00:00
Thorin-OakenpantsandGitHub f394fd0290 move webgl to hardware fingerprinting
- merge into a single number, update the alt pref number
- update RFP info to reflect that it is not a cure-all
2021-07-24 01:56:46 +00:00
Thorin-OakenpantsandGitHub f24899fcac cleanup language specific links 2021-07-24 01:04:03 +00:00
Thorin-OakenpantsandGitHub a7ba61c0d4 0304: background service app update [windows]
- the service implies a check is done first, I'm more concerned with the actual updating: not that updates are bad, it's about controlling when (if ever e.g. my test suite)
- since 0301 has to be done manually in Windows, 0302 is a good fallback **IF** the background service is applicable (read the link)
- clean up the numbering
2021-07-24 00:52:38 +00:00
Thorin-OakenpantsandGitHub babb9f3682 4612: remove outdated confusing line 2021-07-22 03:41:39 +00:00
Thorin-OakenpantsandGitHub b22e349d44 make 4620 more accurate and match RFP section info 2021-07-20 03:38:49 +00:00
Thorin-OakenpantsandGitHub bb48fe4ebe RFP: 4612 is not disabled (by default) 2021-07-20 03:34:49 +00:00
Thorin-OakenpantsandGitHub 44a8088481 tidy
- "enforce" is for when we set the default value
- use [WARNING] for inactive (they're inactive for a reason and people really do not need to turn them on) but less scary [NOTE] for active (tweak away at your own risk)
  - seems neater, easier and less scary for users setting up the first time: i.e they only need to initially look at active items
  - FYI: I was going to add something to LSNG (2760) that it is required for Fission, but will wait, and it struck me that 2680 was the only active item with a warning: seems inconsistent
- 2684: security delay .. make enforce mean enforce (default) ... not worth occasionally saving .3 seconds
   - for now it's one less item in differences/flips
   - might make this inactive in 91+, and add a warning
   - it has been a very long time since we added this due to bad advise/references on the internet on how to speed up Firefox
2021-07-20 02:51:52 +00:00
Thorin-OakenpantsandGitHub 4c8c9bc01f security.tls.version.enable-deprecated
default false since it was added in FF71 - see https://bugzilla.mozilla.org/1579285
2021-07-20 02:02:26 +00:00
Thorin-OakenpantsandGitHub 3bb9fc713f remove 1203
default false since it was added in FF71 - see https://bugzilla.mozilla.org/1579285
2021-07-20 02:00:33 +00:00
Thorin-OakenpantsandGitHub b761a9dd32 4505: experimental RFP prefs
and tidy up all instances (eight) of "do not use": all caps, no asterisks, immediately after [warning]
2021-07-08 07:08:38 +00:00
Thorin-OakenpantsandGitHub 0da2ecdb4d keep current rather than every ESR 2021-07-08 06:41:59 +00:00
Thorin-OakenpantsandGitHub 31e864c16c 0913: disable windows SSO FF91+
- and make 2730 more accurate and add bugzilla
- future RFP additions will be FF91+
2021-07-08 06:21:53 +00:00
Thorin-OakenpantsandGitHub f229a3cb75 fixup FF90 deprecated (#1207) 2021-07-07 11:51:44 +00:00
Thorin-OakenpantsandGitHub 981462ee54 FF90 deprecated 2021-07-06 13:26:44 +00:00
Thorin-OakenpantsandGitHub d940ffb3c6 105c: add "sponsored shortcuts" 2021-07-06 06:32:58 +00:00