|
1
|
1
|
#include 001-base-profile.js
|
|
2
|
2
|
|
|
3
|
|
-pref("app.update.notifyDuringDownload", true);
|
|
4
|
|
-pref("app.update.badgeWaitTime", 0);
|
|
5
|
|
-// point to our feedback url rather than Mozilla's
|
|
6
|
|
-pref("app.feedback.baseURL", "https://support.torproject.org/%LOCALE/get-in-touch/bug-or-feedback");
|
|
7
|
|
-
|
|
8
|
|
-pref("browser.shell.checkDefaultBrowser", false);
|
|
9
|
|
-
|
|
10
|
3
|
// Proxy and proxy security
|
|
|
4
|
+pref("network.proxy.type", 1);
|
|
11
|
5
|
pref("network.proxy.socks", "127.0.0.1");
|
|
12
|
6
|
pref("network.proxy.socks_port", 9150);
|
|
13
|
7
|
pref("network.proxy.socks_remote_dns", true);
|
|
14
|
|
-pref("network.proxy.no_proxies_on", ""); // For fingerprinting and local service vulns (#10419)
|
|
15
|
|
-pref("network.proxy.allow_hijacking_localhost", true); // Allow proxies for localhost (#31065)
|
|
16
|
|
-pref("network.proxy.type", 1);
|
|
17
|
|
-// localhost is already blocked by setting `network.proxy.allow_hijacking_localhost` to
|
|
18
|
|
-// true, allowing users to explicitly block ports makes them fingerprintable; for details, see
|
|
19
|
|
-// Bug 41317: Tor Browser leaks banned ports in network.security.ports.banned
|
|
20
|
|
-pref("network.security.ports.banned", "", locked);
|
|
21
|
|
-pref("network.dns.disabled", true); // This should cover the #5741 patch for DNS leaks
|
|
22
|
8
|
pref("network.http.max-persistent-connections-per-proxy", 256);
|
|
23
|
|
-// Disable DNS over HTTPS. Set to explicitly off MODE_TRROFF = 5.
|
|
24
|
|
-// See tor-browser#41906.
|
|
25
|
|
-pref("network.trr.mode", 5, locked);
|
|
|
9
|
+// https://gitlab.torproject.org/legacy/trac/-/work_items/10419: prevent
|
|
|
10
|
+// fingerprinting and exploiting of local services vulnerabilities.
|
|
|
11
|
+pref("network.proxy.no_proxies_on", "");
|
|
|
12
|
+// tor-browser#31065: Force proxies also for localhost
|
|
|
13
|
+pref("network.proxy.allow_hijacking_localhost", true);
|
|
|
14
|
+// tor-browser#41317: banned port can be fingerprinted and is not necessary,
|
|
|
15
|
+// since there are multiple protections that prevent localhost access.
|
|
|
16
|
+// Lock ratoinale: prevent fingerprinting of old configurations.
|
|
|
17
|
+pref("network.security.ports.banned", "", locked);
|
|
26
|
18
|
// tor-browser#44155: Block Local Network Access (LNA)
|
|
27
|
19
|
pref("network.lna.enabled", true);
|
|
28
|
20
|
pref("network.lna.blocking", true);
|
|
29
|
21
|
pref("network.lna.block_trackers", true);
|
|
|
22
|
+// https://gitlab.torproject.org/legacy/trac/-/work_items/5741 and
|
|
|
23
|
+// tor-browser#33962: disable DNS resolution to avoid potential proxy bypasses.
|
|
|
24
|
+// In our setup, the proxy is going to do DNS resolution.
|
|
|
25
|
+pref("network.dns.disabled", true);
|
|
|
26
|
+// tor-browser#41906: disable DNS over HTTPS to prevent linkability thorugh use
|
|
|
27
|
+// of a fixed DNS server rather than the exit relay's. 5 is MODE_TRROFF.
|
|
|
28
|
+// Also, there are concerns about the interaction with network.dns.disabled
|
|
|
29
|
+// (tor-browser#40034).
|
|
|
30
|
+pref("network.trr.mode", 5);
|
|
30
|
31
|
|
|
31
|
32
|
// Treat .onions as secure
|
|
32
|
33
|
pref("dom.securecontext.allowlist_onions", true);
|
|
33
|
34
|
|
|
34
|
|
-// Disable HTTPS-Only mode for .onion domains (tor-browser#19850)
|
|
|
35
|
+// tor-browser#19850: disable HTTPS-Only mode for .onion domains.
|
|
|
36
|
+// This is already false in Firefox, but we set it again in case upstream
|
|
|
37
|
+// changes default value.
|
|
35
|
38
|
pref("dom.security.https_only_mode.upgrade_onion", false);
|
|
36
|
39
|
|
|
37
|
|
-// Bug 40423/41137: Disable http/3
|
|
38
|
|
-// We should re-enable it as soon as Tor gets UDP support
|
|
|
40
|
+// tor-browser#40423, tor-browser#41137: Disable HTTP/3.
|
|
|
41
|
+// We should re-enable it if Tor gets UDP support.
|
|
39
|
42
|
pref("network.http.http3.enable", false);
|
|
40
|
43
|
|
|
41
|
|
-// 0 = do not use a second connection, see all.js and #7656
|
|
|
44
|
+// https://gitlab.torproject.org/legacy/trac/-/work_items/7656: rely on tor to
|
|
|
45
|
+// rebuild streams rather than on browser's retry mechanisms.
|
|
|
46
|
+// 0 means "do not use a second HTTP connection" (see also all.js).
|
|
42
|
47
|
pref("network.http.connection-retry-timeout", 0);
|
|
43
|
48
|
|
|
44
|
49
|
// Tor Browser used to be compatible with non-Tor proxies. This feature is not
|
| ... |
... |
@@ -49,19 +54,24 @@ pref("network.http.connection-retry-timeout", 0); |
|
49
|
54
|
// be reduced to the strictly required time).
|
|
50
|
55
|
pref("extensions.torbutton.use_nontor_proxy", false);
|
|
51
|
56
|
|
|
52
|
|
-// Browser home page:
|
|
|
57
|
+// Browser home page
|
|
53
|
58
|
pref("browser.startup.homepage", "about:tor");
|
|
54
|
59
|
|
|
55
|
|
-// General browser support url. tor-browser#43864 and tor-browser#40899.
|
|
|
60
|
+// tor-browser#43864, tor-browser#40899: general browser support url.
|
|
56
|
61
|
pref("browser.base-browser-support-url", "https://support.torproject.org/tor-browser");
|
|
|
62
|
+// Point to our feedback url rather than Mozilla's
|
|
|
63
|
+pref("app.feedback.baseURL", "https://support.torproject.org/%LOCALE%/get-in-touch/bug-or-feedback");
|
|
57
|
64
|
|
|
58
|
|
-// tor-browser#40701: Add new download warning
|
|
|
65
|
+// tor-browser#40701: add our custom download warning.
|
|
59
|
66
|
pref("browser.download.showTorWarning", true);
|
|
60
|
67
|
|
|
61
|
|
-// tor-browser#45262: Hide "reset PBM" burn/fire button.
|
|
|
68
|
+// tor-browser#45262: hide "reset PBM" burn/fire button.
|
|
62
|
69
|
pref("browser.privatebrowsing.resetPBM.enabled", false);
|
|
63
|
70
|
|
|
|
71
|
+pref("browser.shell.checkDefaultBrowser", false);
|
|
|
72
|
+
|
|
64
|
73
|
// Tor connection setting preferences.
|
|
|
74
|
+// See TorSettings.sys.mjs for more information.
|
|
65
|
75
|
|
|
66
|
76
|
pref("torbrowser.settings.quickstart.enabled", false);
|
|
67
|
77
|
pref("torbrowser.settings.bridges.enabled", false);
|
| ... |
... |
@@ -85,9 +95,6 @@ pref("torbrowser.settings.firewall.enabled", false); |
|
85
|
95
|
pref("torbrowser.settings.firewall.allowed_ports", "");
|
|
86
|
96
|
|
|
87
|
97
|
|
|
88
|
|
-// This pref specifies an ad-hoc "version" for various pref update hacks we need to do
|
|
89
|
|
-pref("extensions.torbutton.pref_fixup_version", 0);
|
|
90
|
|
-
|
|
91
|
98
|
// Formerly tor-launcher defaults
|
|
92
|
99
|
|
|
93
|
100
|
pref("extensions.torlauncher.start_tor", true);
|