[tor-talk] Tor Browser Bundle Suggestion
Kenya Don baser_z-001 at yahoo.com
Thu May 8 08:05:52 UTC 2014
Previous message: [tor-talk] Unimportant Error in FAQ
Next message: [tor-talk] Finding the catch probability
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
I would like to point out that:
"Since Firefox 4, the Add-ons Manager displays additional information
about each add-on you have installed, including screenshots,
description, ratings, downloads, Contributions, and other metadata.
In order to keep this information updated, Firefox will ask the Mozilla Add-ons gallery for information about the add-ons you have installed once a day. This
involves sending the identifiers of each add-on you have installed to
Mozilla, as well as information on how long it last took Firefox to
start up.
The add-on identifiers are used to return updated information to you, as well as in aggregate to provide personalized recommendations in the
Get Add-ons pane of the Add-ons Manager. Start-up time information is
used to improve Firefox and identify add-ons that may be causing Firefox to be slow. This data is collected as described in the Mozilla Firefox Privacy Policy."
This is a flaw in the Tor Browser Bundle.
By default this is enabled in the Tor Browser Bundle.
Full detail and instructions to disable this is given on:
https://blog.mozilla.org/addons/how-to-opt-out-of-add-on-metadata-updates/This feature should be disabled by default in the Tor Browser Bundle to further protect users' privacy
#11817 closed defect (fixed)
Avoid sending browser startup time information to Mozilla
Сообщил: mikeperry Владелец: mikeperry
Приоритет: normal Этап разработки:
Компонент: Firefox Patch Issues Версия:
Ключевые слова: MikePerry201405, tbb-pref Копия:
Actual Points: Parent ID:
Points:
Описание (последним изменил mikeperry)
In https://lists.torproject.org/pipermail/tor-talk/2014-May/032889.html, someone suggested disabling the addon metadata queries to Mozilla. The data doesn't seem that harmful (they don't mention tying it to a unique identifier or cookies) but I guess we might as well disable it. I don't like the fact that it sends browser startup time at least. That should be part of Telemetry, not addon metadata retrieval.
https://blog.mozilla.org/addons/how-to-opt-out-of-add-on-metadata-updates/
The pref is extensions.getAddons.cache.enabled -> false.
Child Tickets
Oldest first Newest first
Comments only
История изменений (4)
comment:1 Changed 5 недель ago by mikeperry
Описание изменено (отличие)
comment:2 Changed 5 недель ago by mikeperry
Краткое описание изменён с Avoid querying addon metadata in TBB на Avoid sending browser startup time information to Mozilla
comment:3 Changed 5 недель ago by cypherpunks
Are there any other feature connecting in the background? I thought there wouldn't be any already. Every connection, even if looks harmless, could be an additional attack factor or fingerprintability issue in many types of ways. Better minimize them all.
comment:4 Changed 10 дней ago by mikeperry
Решение установлен в fixed
Состояние изменён с new на closed
This pref was set in TBB 3.6.1.