|
1
|
1
|
// Preferences to harden Firefox's security and privacy
|
|
2
|
2
|
// Do not edit this file.
|
|
3
|
3
|
|
|
4
|
|
-// Use the OS locale by default (tor-browser#17400)
|
|
|
4
|
+// tor-browser#17400: use the OS locale by default.
|
|
5
|
5
|
pref("intl.locale.requested", "");
|
|
6
|
6
|
|
|
7
|
7
|
// Home page is blank rather than Firefox Home (Activity Stream).
|
| ... |
... |
@@ -21,11 +21,6 @@ pref("startup.homepage_welcome_url.additional", ""); |
|
21
|
21
|
// Disable Firefox Welcome Dialog
|
|
22
|
22
|
pref("browser.aboutwelcome.enabled", false);
|
|
23
|
23
|
|
|
24
|
|
-#if MOZ_UPDATE_CHANNEL == release
|
|
25
|
|
-// tor-browser#42640: Disable Firefox Flame button due to unknown interactions with New Identity
|
|
26
|
|
-pref("browser.privatebrowsing.resetPBM.enabled", false, locked);
|
|
27
|
|
-#endif
|
|
28
|
|
-
|
|
29
|
24
|
#ifndef ANDROID
|
|
30
|
25
|
// Bug 41668: allow users to apply updates. This is set also in firefox.js for
|
|
31
|
26
|
// all platforms, except for Windows. As explained on firefox.js, Firefox uses a
|
| ... |
... |
@@ -53,6 +48,9 @@ pref("app.update.staging.enabled", false); |
|
53
|
48
|
pref("browser.startup.homepage_override.buildID", "20100101");
|
|
54
|
49
|
|
|
55
|
50
|
// Disable the "Refresh" prompt that is displayed for stale profiles.
|
|
|
51
|
+// TODO: Re-evaluate (tor-browser#45341): this was needed because the new
|
|
|
52
|
+// profile it created did not contain NoScript. Now profiles work, so the main
|
|
|
53
|
+// technical reason for this preference does not hold anymore.
|
|
56
|
54
|
pref("browser.disableResetPrompt", true);
|
|
57
|
55
|
|
|
58
|
56
|
// Disk activity: Disable Browsing History Storage
|
| ... |
... |
@@ -60,15 +58,18 @@ pref("browser.privatebrowsing.autostart", true); |
|
60
|
58
|
pref("browser.cache.disk.enable", false);
|
|
61
|
59
|
pref("permissions.memory_only", true);
|
|
62
|
60
|
pref("security.nocertdb", true);
|
|
|
61
|
+
|
|
|
62
|
+// tor-browser#42094: do not collect stats about WebRTC.
|
|
|
63
|
+// Defense-in-depth: this is already false in upstream release builds.
|
|
63
|
64
|
pref("media.aboutwebrtc.hist.enabled", false);
|
|
64
|
65
|
|
|
65
|
|
-// tor-browser#45214: Disable the megalist (contextual password manager).
|
|
|
66
|
+// tor-browser#45214: disable the megalist (contextual password manager).
|
|
66
|
67
|
pref("browser.contextual-password-manager.enabled", false);
|
|
67
|
68
|
|
|
68
|
69
|
// Disk Activity
|
|
69
|
70
|
|
|
70
|
|
-// Disable auto-downloading to ~/Downloads and other download tweaks to minimize
|
|
71
|
|
-// disk leaks (tor-browser#42050).
|
|
|
71
|
+// tor-browser#42050: disable auto-downloading to ~/Downloads and other download
|
|
|
72
|
+// tweaks to minimize disk leaks.
|
|
72
|
73
|
pref("browser.download.useDownloadDir", false);
|
|
73
|
74
|
pref("browser.download.always_ask_before_handling_new_types", true);
|
|
74
|
75
|
pref("browser.download.manager.addToRecentDocs", false);
|
| ... |
... |
@@ -139,16 +140,29 @@ pref("browser.pagethumbnails.capturing_disabled", true); |
|
139
|
140
|
// pref("privacy.exposeContentTitleInWindow", false);
|
|
140
|
141
|
// pref("privacy.exposeContentTitleInWindow.pbm", false);
|
|
141
|
142
|
|
|
142
|
|
-// tor-browser#42054: Opt-out from any built-in backup system, even though
|
|
|
143
|
+// tor-browser#42630: Disable LaterRun.
|
|
|
144
|
+//
|
|
|
145
|
+// This preference is set in a few places in code, so we lock it to keep this
|
|
|
146
|
+// feature off.
|
|
|
147
|
+// Even though it's locked, setting it will still change the value in
|
|
|
148
|
+// `prefs.js`, but it will be ignored.
|
|
|
149
|
+// If this is ever unlocked, the value in prefs.js will be used.
|
|
|
150
|
+pref("browser.laterrun.enabled", false, locked);
|
|
|
151
|
+
|
|
|
152
|
+// tor-browser#42054: opt-out from any built-in backup system, even though
|
|
143
|
153
|
// local, as it might be a violation of our standalone mode.
|
|
144
|
154
|
// Users can still opt-in if they wish.
|
|
145
|
155
|
pref("browser.backup.enabled", false);
|
|
146
|
156
|
pref("browser.backup.scheduled.enabled", false);
|
|
147
|
|
-// tor-browser#45123: Disable the profile automated backup and restore service.
|
|
|
157
|
+// tor-browser#45123: disable the profile automated backup and restore service.
|
|
148
|
158
|
pref("browser.backup.archive.enabled", false);
|
|
149
|
159
|
pref("browser.backup.restore.enabled", false);
|
|
150
|
160
|
|
|
151
|
|
-// Empty clipboard content from private windows on exit (tor-browser#42154)
|
|
|
161
|
+// tor-browser#45073 (153.0 preference review): do not send media metadata to
|
|
|
162
|
+// the OS when in PBM (defense-in-depth).
|
|
|
163
|
+pref("media.privatebrowsing.metadata.enabled", false);
|
|
|
164
|
+
|
|
|
165
|
+// tor-browser#42154: empty clipboard content from private windows on exit
|
|
152
|
166
|
pref("browser.privatebrowsing.preserveClipboard", false);
|
|
153
|
167
|
|
|
154
|
168
|
// tor-browser#42611: Do not include the URL of the image, when copying it.
|
| ... |
... |
@@ -164,6 +178,9 @@ pref("dom.security.https_only_mode_pbm", true); |
|
164
|
178
|
// tor-browser#43197, defense in depth if ever https-only got disabled
|
|
165
|
179
|
pref("dom.security.https_first_add_exception_on_failure", false);
|
|
166
|
180
|
|
|
|
181
|
+// tor-browser#44123: never trim the protocol off of URLs.
|
|
|
182
|
+pref("browser.urlbar.trimURLs", false);
|
|
|
183
|
+
|
|
167
|
184
|
// tor-browser#22320: Hide referer when coming from a .onion address
|
|
168
|
185
|
// We enable this here (rather than in Tor Browser) in case users of other
|
|
169
|
186
|
// base-browser derived browsers configure it to use a system Tor daemon
|
| ... |
... |
@@ -182,12 +199,8 @@ pref("network.http.referer.hideOnionSource", true); |
|
182
|
199
|
// [4] https://www.ssllabs.com/ssl-pulse/
|
|
183
|
200
|
pref("security.ssl.require_safe_negotiation", true);
|
|
184
|
201
|
|
|
185
|
|
-// lock those disabled by https://bugzilla.mozilla.org/show_bug.cgi?id=1036765
|
|
186
|
|
-pref("security.ssl3.dhe_rsa_aes_128_sha", false, locked);
|
|
187
|
|
-pref("security.ssl3.dhe_rsa_aes_256_sha", false, locked);
|
|
188
|
|
-
|
|
189
|
|
-// Wrapping a static pref to lock it and prevent changing.
|
|
190
|
|
-// See tor-browser#40565.
|
|
|
202
|
+// tor-browser#40565: lock as the UI offered to enable TLS 1.0 and 1.1 without
|
|
|
203
|
+// explaining the actual reasons.
|
|
191
|
204
|
pref("security.tls.version.enable-deprecated", false, locked);
|
|
192
|
205
|
|
|
193
|
206
|
// tor-browser#44187: Disable session identifiers to make PBM and normal mode
|
| ... |
... |
@@ -227,15 +240,12 @@ pref("browser.urlbar.maxCharsForSearchSuggestions", 0); |
|
227
|
240
|
|
|
228
|
241
|
// Misc privacy: Remote
|
|
229
|
242
|
pref("browser.send_pings", false);
|
|
230
|
|
-// Space separated list of URLs that are allowed to send objects (instead of
|
|
231
|
|
-// only strings) through webchannels. The default for Firefox is some Mozilla
|
|
232
|
|
-// domains.
|
|
233
|
|
-pref("webchannel.allowObject.urlWhitelist", "");
|
|
|
243
|
+
|
|
|
244
|
+// Geolocation preferences.
|
|
234
|
245
|
pref("geo.enabled", false);
|
|
235
|
246
|
pref("geo.provider.network.url", "");
|
|
236
|
247
|
pref("geo.provider.ms-windows-location", false);
|
|
237
|
248
|
pref("geo.provider.use_corelocation", false);
|
|
238
|
|
-pref("geo.provider.use_gpsd", false);
|
|
239
|
249
|
pref("geo.provider.use_geoclue", false);
|
|
240
|
250
|
|
|
241
|
251
|
pref("browser.safebrowsing.malware.enabled", false);
|
| ... |
... |
@@ -248,6 +258,9 @@ pref("browser.safebrowsing.provider.google.updateURL", ""); |
|
248
|
258
|
pref("browser.safebrowsing.provider.google.gethashURL", "");
|
|
249
|
259
|
pref("browser.safebrowsing.provider.google4.updateURL", "");
|
|
250
|
260
|
pref("browser.safebrowsing.provider.google4.gethashURL", "");
|
|
|
261
|
+pref("browser.safebrowsing.provider.google5.enabled", false);
|
|
|
262
|
+pref("browser.safebrowsing.provider.google5.updateURL", "");
|
|
|
263
|
+pref("browser.safebrowsing.provider.google5.gethashURL", "");
|
|
251
|
264
|
pref("browser.safebrowsing.provider.mozilla.updateURL", "");
|
|
252
|
265
|
pref("browser.safebrowsing.provider.mozilla.gethashURL", "");
|
|
253
|
266
|
|
| ... |
... |
@@ -267,26 +280,29 @@ pref("toolkit.telemetry.shutdownPingSender.enabled", false); // Added in tor-bro |
|
267
|
280
|
pref("toolkit.telemetry.firstShutdownPing.enabled", false); // Added in tor-browser#41496
|
|
268
|
281
|
pref("toolkit.telemetry.updatePing.enabled", false); // Make sure updater telemetry is disabled; see #25909.
|
|
269
|
282
|
pref("toolkit.telemetry.bhrPing.enabled", false);
|
|
270
|
|
-pref("toolkit.telemetry.coverage.opt-out", true);
|
|
271
|
283
|
pref("datareporting.healthreport.uploadEnabled", false);
|
|
272
|
284
|
pref("datareporting.policy.dataSubmissionEnabled", false);
|
|
273
|
|
-// Force all telemtry identifier to their canary values tor-browser#43750
|
|
|
285
|
+// tor-browser#43750: force all telemtry identifier to their canary values.
|
|
|
286
|
+// Locked to prevent the browser from changing them.
|
|
274
|
287
|
pref("toolkit.telemetry.cachedClientID", "c0ffeec0-ffee-c0ff-eec0-ffeec0ffeec0", locked);
|
|
275
|
288
|
pref("toolkit.telemetry.cachedProfileGroupID", "decafdec-afde-cafd-ecaf-decafdecafde", locked);
|
|
276
|
289
|
pref("datareporting.dau.cachedUsageProfileID", "beefbeef-beef-beef-beef-beeefbeefbee", locked);
|
|
277
|
290
|
pref("datareporting.dau.cachedUsageProfileGroupID", "b0bacafe-b0ba-cafe-b0ba-cafeb0bacafe", locked);
|
|
|
291
|
+pref("datareporting.usage.uploadEnabled", false);
|
|
278
|
292
|
pref("toolkit.coverage.opt-out", true);
|
|
279
|
293
|
pref("toolkit.coverage.endpoint.base", "");
|
|
280
|
294
|
pref("browser.tabs.crashReporting.sendReport", false);
|
|
281
|
295
|
pref("browser.crashReports.unsubmittedCheck.autoSubmit2", false);
|
|
282
|
|
-// Added in tor-browser#41496 even though false by default
|
|
|
296
|
+// tor-browser#41496: do not offer to send unsubmitted crash reports.
|
|
|
297
|
+// (Defense in detph: we do not have the crash reporter and this is false on the
|
|
|
298
|
+// release channel also in Firefox).
|
|
283
|
299
|
pref("browser.crashReports.unsubmittedCheck.enabled", false);
|
|
|
300
|
+// tor-browser#45073 (153.0 preference review): add also this pref not to send
|
|
|
301
|
+// unsubmitted crash reports.
|
|
|
302
|
+pref("browser.crashReports.onDemand", false);
|
|
284
|
303
|
// tor-browser#44026: Disable the modal that shows upstream terms of usage,
|
|
285
|
304
|
// since we opt out of their telemetry and data collection.
|
|
286
|
305
|
pref("browser.preonboarding.enabled", false);
|
|
287
|
|
-// Disable checkbox in about:neterror that controls
|
|
288
|
|
-// security.xfocsp.errorReporting.automatic. See tor-browser#42653.
|
|
289
|
|
-pref("security.xfocsp.errorReporting.enabled", false);
|
|
290
|
306
|
// tor-browser#45080: disable the reporting API.
|
|
291
|
307
|
pref("dom.reporting.enabled", false);
|
|
292
|
308
|
pref("dom.reporting.header.enabled", false);
|
| ... |
... |
@@ -317,9 +333,11 @@ pref("services.sync.engine.prefs", false); |
|
317
|
333
|
pref("services.sync.engine.tabs", false);
|
|
318
|
334
|
pref("extensions.getAddons.cache.enabled", false); // https://blog.mozilla.org/addons/how-to-opt-out-of-add-on-metadata-updates/
|
|
319
|
335
|
pref("privacy.donottrackheader.enabled", false); // (mullvad-browser#17)
|
|
320
|
|
-// Make sure there is no Tracking Protection active in Tor Browser, see: #17898.
|
|
|
336
|
+// tor-browser#17898: disable Tracking Protection in Tor Browser because of
|
|
|
337
|
+// doubts about the blocklist-based approach and the breakage.
|
|
321
|
338
|
pref("privacy.trackingprotection.enabled", false);
|
|
322
|
339
|
pref("privacy.trackingprotection.pbmode.enabled", false);
|
|
|
340
|
+pref("privacy.trackingprotection.emailtracking.enabled", false);
|
|
323
|
341
|
pref("privacy.trackingprotection.emailtracking.pbmode.enabled", false);
|
|
324
|
342
|
pref("privacy.trackingprotection.annotate_channels", false);
|
|
325
|
343
|
pref("privacy.trackingprotection.cryptomining.enabled", false);
|
| ... |
... |
@@ -329,9 +347,9 @@ pref("privacy.trackingprotection.socialtracking.enabled", false); |
|
329
|
347
|
// This is mostly for consistency, since we disable the safe browsing lists,
|
|
330
|
348
|
// which are needed for this feature to work properly.
|
|
331
|
349
|
pref("privacy.trackingprotection.harmfuladdon.enabled", false);
|
|
332
|
|
-// Hide the Unified Trust Panel until we have new designs. tor-browser#44814.
|
|
|
350
|
+// tor-browser#44814: hide the Unified Trust Panel until we have new designs.
|
|
333
|
351
|
pref("browser.urlbar.trustPanel.featureGate", false);
|
|
334
|
|
-// tor-browser#43986: Explicitly disable bounce tracking protection
|
|
|
352
|
+// tor-browser#43986: explicitly disable bounce tracking protection
|
|
335
|
353
|
pref("privacy.bounceTrackingProtection.mode", 0);
|
|
336
|
354
|
pref("privacy.socialtracking.block_cookies.enabled", false);
|
|
337
|
355
|
pref("privacy.annotate_channels.strict_list.enabled", false);
|
| ... |
... |
@@ -339,14 +357,11 @@ pref("privacy.annotate_channels.strict_list.enabled", false); |
|
339
|
357
|
// Notice that it should not apply to RFP anyway...
|
|
340
|
358
|
pref("privacy.fingerprintingProtection.remoteOverrides.enabled", false);
|
|
341
|
359
|
|
|
342
|
|
-// Disable Privacy-Preserving-Attribution (Bug #42687)
|
|
343
|
|
-pref("dom.private-attribution.submission.enabled", false);
|
|
344
|
|
-
|
|
345
|
360
|
// Custom extensions preferences tor-browser#41581
|
|
346
|
361
|
pref("extensions.hideNoScript", true);
|
|
347
|
362
|
pref("extensions.hideUnifiedWhenEmpty", true);
|
|
348
|
363
|
|
|
349
|
|
-// Disable activity stream in about:home (Bug #41029)
|
|
|
364
|
+// tor-browser#41029: disable activity stream in about:home
|
|
350
|
365
|
pref("browser.newtabpage.activity-stream.discoverystream.enabled", false);
|
|
351
|
366
|
pref("browser.newtabpage.activity-stream.feeds.section.topstories", false);
|
|
352
|
367
|
pref("browser.newtabpage.activity-stream.showSponsored", false);
|
| ... |
... |
@@ -369,37 +384,34 @@ pref("browser.newtabpage.activity-stream.asrouter.useRemoteL10n", false); |
|
369
|
384
|
// tor-browser#42054: make sure search result telemetry is disabled.
|
|
370
|
385
|
pref("browser.search.serpEventTelemetryCategorization.enabled", false);
|
|
371
|
386
|
|
|
372
|
|
-
|
|
373
|
|
-
|
|
374
|
387
|
// ML components that we want to hide from the user. See tor-browser#44045.
|
|
375
|
|
-// Many of these preferences are locked because the component is entirely
|
|
376
|
|
-// removed, so they could not be functionally enabled.
|
|
377
|
|
-
|
|
|
388
|
+// The component is entirely removed, so many functionalities will not work even
|
|
|
389
|
+// if flipped.
|
|
378
|
390
|
// tor-browser#42872, #42555, #44045: Disable ML translations.
|
|
379
|
391
|
// Maybe re-enable after auditing and fixing the UX (tor-browser#41837).
|
|
380
|
392
|
// NOTE: whilst the "translations" component is still included in the build, we
|
|
381
|
393
|
// lock the preference because the engine is excluded and the
|
|
382
|
394
|
// "translations-models" RemoteSettings needed for the engine is empty.
|
|
383
|
|
-pref("browser.translations.enable", false, locked);
|
|
|
395
|
+pref("browser.translations.enable", false);
|
|
384
|
396
|
// Hide some AI settings outside the "ai" setting pane. See tor-browser#44764.
|
|
385
|
397
|
// NOTE: This preference tracks whether the *user* opted out of all AI features
|
|
386
|
398
|
// in about:preferences. By itself, it does not provide global blocking of the
|
|
387
|
399
|
// AI features, which are often controlled by separate preferences below.
|
|
388
|
400
|
// However, some parts of the UI will react to this preference. See
|
|
389
|
401
|
// tor-browser#44541.
|
|
390
|
|
-pref("browser.ai.control.default", "blocked", locked);
|
|
|
402
|
+pref("browser.ai.control.default", "blocked");
|
|
391
|
403
|
// Disables many (but not all) ML engines. Note, this does not have overall
|
|
392
|
404
|
// control over exposure to ML features. tor-browser#44045.
|
|
393
|
|
-pref("browser.ml.enable", false, locked);
|
|
|
405
|
+pref("browser.ml.enable", false);
|
|
394
|
406
|
// Disable third party AI chatbot. tor-browser#43989.
|
|
395
|
|
-pref("browser.ml.chat.enabled", false, locked);
|
|
|
407
|
+pref("browser.ml.chat.enabled", false);
|
|
396
|
408
|
// Disable LinkPreview. tor-browser#44045 and tor-browser#43867.
|
|
397
|
|
-pref("browser.ml.linkPreview.enabled", false, locked);
|
|
398
|
|
-// Disable Smart Tab Groups. tor-browser#44045.
|
|
399
|
|
-pref("browser.tabs.groups.smart.enabled", false, locked);
|
|
400
|
|
-pref("browser.tabs.groups.smart.userEnabled", false, locked);
|
|
|
409
|
+pref("browser.ml.linkPreview.enabled", false);
|
|
|
410
|
+// tor-browser#44045: disable Smart Tab Groups.
|
|
|
411
|
+pref("browser.tabs.groups.smart.enabled", false);
|
|
|
412
|
+pref("browser.tabs.groups.smart.userEnabled", false);
|
|
401
|
413
|
// Don't expose ModelHub API for extensions. tor-browser#44045.
|
|
402
|
|
-pref("extensions.ml.enabled", false, locked);
|
|
|
414
|
+pref("extensions.ml.enabled", false);
|
|
403
|
415
|
// Don't enable ML generated alt text. tor-browser#44045.
|
|
404
|
416
|
// pdfjs.enableAltText controls whether MLManager is created,
|
|
405
|
417
|
// pdfjs.enableGuessAltText controls whether the MLManager can create an ML
|
| ... |
... |
@@ -407,25 +419,26 @@ pref("extensions.ml.enabled", false, locked); |
|
407
|
419
|
// changed by the user in the UI, but also has the side effect of hiding the
|
|
408
|
420
|
// UI controls for the non-ML preference pdfjs.enableNewAltTextWhenAddingImage.
|
|
409
|
421
|
// See bugzilla bug 1943456 comment 12.
|
|
410
|
|
-pref("pdfjs.enableAltText", false, locked);
|
|
411
|
|
-pref("pdfjs.enableAltTextForEnglish", false, locked);
|
|
412
|
|
-pref("pdfjs.enableGuessAltText", false, locked);
|
|
413
|
|
-pref("pdfjs.enableAltTextModelDownload", false, locked);
|
|
|
422
|
+pref("pdfjs.enableAltText", false);
|
|
|
423
|
+pref("pdfjs.enableAltTextForEnglish", false);
|
|
|
424
|
+pref("pdfjs.enableGuessAltText", false);
|
|
|
425
|
+pref("pdfjs.enableAltTextModelDownload", false);
|
|
414
|
426
|
// Disable SuggestBackendMl. tor-browser#44045.
|
|
415
|
|
-pref("browser.urlbar.quicksuggest.mlEnabled", false, locked);
|
|
|
427
|
+pref("browser.urlbar.quicksuggest.mlEnabled", false);
|
|
416
|
428
|
// Disable SemanticHistory search. tor-browser#44045.
|
|
417
|
|
-pref("places.semanticHistory.featureGate", false, locked);
|
|
418
|
|
-// tor-browser#45120: Disable AIWindow.
|
|
419
|
|
-// tor-browser#45338: Locked as a precaution against entry points that try to
|
|
420
|
|
-// flip this value.
|
|
|
429
|
+pref("places.semanticHistory.featureGate", false);
|
|
|
430
|
+// tor-browser#45120: disable AIWindow.
|
|
|
431
|
+// tor-browser#45338: locked as a precaution against entry points that try to
|
|
|
432
|
+// flip this value. Also, policies also lock it.
|
|
421
|
433
|
pref("browser.smartwindow.enabled", false, locked);
|
|
422
|
|
-
|
|
|
434
|
+// tor-browser#45073 (153 preference review): lock to pretend we have disabled
|
|
|
435
|
+// AI through policies (see AIWindow.isManagedByPolicy).
|
|
|
436
|
+pref("browser.ai.control.smartWindow", "blocked", locked);
|
|
423
|
437
|
|
|
424
|
438
|
// tor-browser#41945 - disable automatic cookie banners dismissal until
|
|
425
|
439
|
// we're sure it does not causes fingerprinting risks or other issues.
|
|
426
|
440
|
pref("cookiebanners.service.mode", 0);
|
|
427
|
441
|
pref("cookiebanners.service.mode.privateBrowsing", 0);
|
|
428
|
|
-pref("cookiebanners.ui.desktop.enabled", false);
|
|
429
|
442
|
|
|
430
|
443
|
// Disable moreFromMozilla pane in the preferences/settings (tor-browser#41292).
|
|
431
|
444
|
pref("browser.preferences.moreFromMozilla", false);
|
| ... |
... |
@@ -457,12 +470,9 @@ pref("browser.tabs.remote.separatedMozillaDomains", ""); |
|
457
|
470
|
// Avoid DNS lookups on search terms
|
|
458
|
471
|
pref("browser.urlbar.dnsResolveSingleWordsAfterSearch", 0);
|
|
459
|
472
|
|
|
460
|
|
-// Disable about:newtab and "first run" experiments
|
|
461
|
|
-pref("messaging-system.rsexperimentloader.enabled", false);
|
|
462
|
473
|
// true means that you are *not* opting out. See its usage in various file.
|
|
463
|
474
|
pref("app.shield.optoutstudies.enabled", false);
|
|
464
|
|
-// Disable nimbus rollouts.
|
|
465
|
|
-// See bugzilla bug 2003350. See tor-browser#44520.
|
|
|
475
|
+// tor-browser#44520: disable nimbus rollouts (see bugzilla bug 2003350).
|
|
466
|
476
|
pref("nimbus.rollouts.enabled", false);
|
|
467
|
477
|
// Disable Normandy/Shield
|
|
468
|
478
|
pref("app.normandy.enabled", false);
|
| ... |
... |
@@ -520,11 +530,6 @@ pref("dom.xslt.enabled", false); |
|
520
|
530
|
#if MOZ_UPDATE_CHANNEL == release
|
|
521
|
531
|
pref("privacy.resistFingerprinting", true, locked);
|
|
522
|
532
|
pref("privacy.resistFingerprinting.exemptedDomains", "", locked);
|
|
523
|
|
-// tor-browser#42125: Some misleading guides suggest to set this to false, but
|
|
524
|
|
-// the result would be that the canvas is completely white
|
|
525
|
|
-// (see StaticPrefList.yaml), so lock it to true.
|
|
526
|
|
-// Might be removed (MozBug 1670447).
|
|
527
|
|
-pref("privacy.resistFingerprinting.randomDataOnCanvasExtract", true, locked);
|
|
528
|
533
|
#else
|
|
529
|
534
|
pref("privacy.resistFingerprinting", true);
|
|
530
|
535
|
pref("privacy.resistFingerprinting.exemptedDomains", "");
|
| ... |
... |
@@ -542,8 +547,6 @@ pref("webgl.enable-webgl2", false); |
|
542
|
547
|
// tor-browser#44763: disable WebGPU until audited.
|
|
543
|
548
|
pref("dom.webgpu.enabled", false);
|
|
544
|
549
|
pref("browser.link.open_newwindow.restriction", 0); // Bug 9881: Open popups in new tabs (to avoid fullscreen popups)
|
|
545
|
|
-// tor-browser#42767: Disable offscreen canvas until verified it is not fingerprintable
|
|
546
|
|
-pref("gfx.offscreencanvas.enabled", false);
|
|
547
|
550
|
// Prevent scripts from moving and resizing open windows
|
|
548
|
551
|
pref("dom.disable_window_move_resize", true);
|
|
549
|
552
|
// Set video VP9 to 0 for everyone (bug 22548)
|
| ... |
... |
@@ -596,9 +599,8 @@ pref("dom.netinfo.enabled", false); |
|
596
|
599
|
pref("network.http.referer.defaultPolicy", 2); // Bug 32948: Make referer behavior consistent regardless of private browing mode status
|
|
597
|
600
|
pref("network.http.referer.defaultPolicy.pbmode", 2);
|
|
598
|
601
|
pref("network.http.referer.XOriginTrimmingPolicy", 2); // Bug 17228: Force trim referer to scheme+host+port in cross-origin requests
|
|
599
|
|
-// Bug 40463: Disable Windows SSO
|
|
600
|
|
-pref("network.http.windows-sso.enabled", false, locked);
|
|
601
|
|
-// Bug 43165: Disable Microsoft SSO on macOS
|
|
|
602
|
+// tor-browser#40463 (91 preference review): disable Windows SSO
|
|
|
603
|
+pref("network.http.windows-sso.enabled", false);
|
|
602
|
604
|
pref("network.http.microsoft-entra-sso.enabled", false);
|
|
603
|
605
|
pref("network.microsoft-sso-authority-list", "");
|
|
604
|
606
|
// tor-browser#40424
|
| ... |
... |
@@ -620,6 +622,9 @@ pref("security.restrict_to_adults.respect_platform", false); |
|
620
|
622
|
// Xwayland as the default.
|
|
621
|
623
|
pref("widget.wayland.fractional-scale.enabled", false);
|
|
622
|
624
|
|
|
|
625
|
+// tor-browser#45171: Disabled split view which is janky.
|
|
|
626
|
+pref("browser.tabs.splitView.enabled", false);
|
|
|
627
|
+
|
|
623
|
628
|
// tor-browser#41943: defense-in-depth, but do not lock anymore (enabled in Firefox 119, http://bugzil.la/1851162)
|
|
624
|
629
|
pref("_javascript_.options.spectre.disable_for_isolated_content", false);
|
|
625
|
630
|
|
| ... |
... |
@@ -628,13 +633,11 @@ pref("privacy.firstparty.isolate", true); // Always enforce first party isolatio |
|
628
|
633
|
// Only accept cookies from the originating site (block third party cookies)
|
|
629
|
634
|
pref("network.cookie.cookieBehavior", 1);
|
|
630
|
635
|
pref("network.cookie.cookieBehavior.pbmode", 1);
|
|
631
|
|
-pref("network.predictor.enabled", false); // Temporarily disabled. See https://bugs.torproject.org/16633
|
|
632
|
|
-pref("network.predictor.enable-prefetch", false);
|
|
633
|
636
|
pref("network.http.speculative-parallel-limit", 0);
|
|
634
|
637
|
pref("browser.places.speculativeConnect.enabled", false);
|
|
635
|
638
|
pref("network.prefetch-next", false);
|
|
636
|
639
|
pref("browser.urlbar.speculativeConnect.enabled", false);
|
|
637
|
|
-// Bug 40220: Make sure tracker cookie purging is disabled.
|
|
|
640
|
+// tor-browser#40220: make sure tracker cookie purging is disabled.
|
|
638
|
641
|
// It depends on Firefox's tracking protection, which we currently do not enable
|
|
639
|
642
|
// See also tor-browser#30939.
|
|
640
|
643
|
pref("privacy.purge_trackers.enabled", false);
|
| ... |
... |
@@ -648,6 +651,8 @@ pref("network.dns.disablePrefetchFromHTTPS", true); |
|
648
|
651
|
pref("dom.prefetch_dns_for_anchor_http_document", false);
|
|
649
|
652
|
pref("dom.prefetch_dns_for_anchor_https_document", false);
|
|
650
|
653
|
|
|
|
654
|
+// Notice: some of these values are already false on Firefox, but we still
|
|
|
655
|
+// define them as defense-in-depth.
|
|
651
|
656
|
pref("network.protocol-handler.external-default", false);
|
|
652
|
657
|
pref("network.protocol-handler.external.mailto", false);
|
|
653
|
658
|
pref("network.protocol-handler.external.news", false);
|
| ... |
... |
@@ -661,24 +666,20 @@ pref("network.protocol-handler.warn-external.snews", true); |
|
661
|
666
|
pref("network.protocol-handler.external.ms-windows-store", false);
|
|
662
|
667
|
pref("network.protocol-handler.warn-external.ms-windows-store", true);
|
|
663
|
668
|
#endif
|
|
664
|
|
-pref("network.proxy.allow_bypass", false, locked); // #40682
|
|
665
|
|
-// Bug 40548: Disable proxy-bypass
|
|
|
669
|
+
|
|
|
670
|
+// tor-browser#40682: some API (e.g., telemetry) might try to bypass the proxy
|
|
|
671
|
+// if this is true. At the moment, the browser will not try to set this
|
|
|
672
|
+// anywhere, but it makes sense to lock it as a defense-in-depth in case of
|
|
|
673
|
+// future changes.
|
|
|
674
|
+pref("network.proxy.allow_bypass", false, locked);
|
|
|
675
|
+// tor-browser#40548: disable another proxy-bypass for system requests.
|
|
|
676
|
+// This is also disabled at build time (tor-browser#45336).
|
|
666
|
677
|
pref("network.proxy.failover_direct", false, locked);
|
|
667
|
|
-// Lock to 'true', which is already the firefox default, to prevent users
|
|
668
|
|
-// from making themselves fingerprintable by disabling. This pref
|
|
669
|
|
-// alters content load order in a page. See tor-browser#24686
|
|
670
|
|
-pref("network.http.tailing.enabled", true, locked);
|
|
671
|
678
|
|
|
672
|
|
-// Block 0.0.0.0
|
|
|
679
|
+// tor-browser#43811: block 0.0.0.0
|
|
673
|
680
|
// https://bugzilla.mozilla.org/show_bug.cgi?id=1889130
|
|
674
|
|
-// tor-browser#43811
|
|
675
|
681
|
pref("network.socket.ip_addr_any.disabled", true);
|
|
676
|
682
|
|
|
677
|
|
-// tor-browser#23044: Make sure we don't have any GIO supported protocols
|
|
678
|
|
-// (defense in depth measure).
|
|
679
|
|
-// As of Firefox 118 (Bug 1843763), upstream does not add any protocol by
|
|
680
|
|
-// default, but setting it to blank seems a good idea (tor-browser#42054).
|
|
681
|
|
-pref("network.gio.supported-protocols", "");
|
|
682
|
683
|
// Mullvad Browser enables WebRTC by default, meaning that there the following prefs
|
|
683
|
684
|
// are first-line defense, rather than "in depth" (mullvad-browser#40)
|
|
684
|
685
|
// tor-browser#41667 - Defense in depth: use mDNS to avoid local IP leaks on Android too if user enables WebRTC
|
| ... |
... |
@@ -729,7 +730,7 @@ pref("network.file.path_blacklist", "/net"); |
|
729
|
730
|
pref("svg.disabled", false);
|
|
730
|
731
|
pref("mathml.disabled", false);
|
|
731
|
732
|
|
|
732
|
|
-// Bug 40408
|
|
|
733
|
+// tor-browser#40408
|
|
733
|
734
|
pref("svg.context-properties.content.allowed-domains", "");
|
|
734
|
735
|
|
|
735
|
736
|
// Network and performance
|
| ... |
... |
@@ -794,7 +795,9 @@ pref("security.certerrors.mitm.priming.enabled", false); |
|
794
|
795
|
// Don't automatically enable enterprise roots, see bug 40166
|
|
795
|
796
|
pref("security.certerrors.mitm.auto_enable_enterprise_roots", false);
|
|
796
|
797
|
|
|
797
|
|
-// Disable share menus on Mac and Windows tor-browser#41117
|
|
|
798
|
+// tor-browser#41117: disable share menus on Mac and Windows.
|
|
|
799
|
+// Locked as user might not realize sharing might result in proxy bypasses or
|
|
|
800
|
+// general linkability.
|
|
798
|
801
|
pref("browser.menu.share_url.allow", false, locked);
|
|
799
|
802
|
|
|
800
|
803
|
// tor-browser#45133: Disable share button
|
| ... |
... |
@@ -844,6 +847,10 @@ pref("toolkit.winRegisterApplicationRestart", false); |
|
844
|
847
|
// tor-browser#43051: Hide the checkbox to open the browser automatically on
|
|
845
|
848
|
// Windows startup.
|
|
846
|
849
|
pref("browser.startup.windowsLaunchOnLogin.enabled", false);
|
|
|
850
|
+
|
|
|
851
|
+// tor-browser#45293: force devices to be detected as not capable of tablet mode
|
|
|
852
|
+// on Windows 11+ (defense-in-depth for fingerprinting).
|
|
|
853
|
+pref("widget.windows.tablet_detection_override", -1);
|
|
847
|
854
|
#endif
|
|
848
|
855
|
|
|
849
|
856
|
#ifdef ANDROID
|
| ... |
... |
@@ -1154,16 +1161,3 @@ pref("font.name-list.monospace.x-unicode", "Cousine, Noto Sans Balinese, Noto Sa |
|
1154
|
1161
|
// The rest are not customized, because they are covered only by one font
|
|
1155
|
1162
|
#endif
|
|
1156
|
1163
|
#endif |
|
1157
|
|
-
|
|
1158
|
|
-// tor-browser#42630: Disable LaterRun.
|
|
1159
|
|
-//
|
|
1160
|
|
-// This preference is set in a few places in code. Even though it's locked,
|
|
1161
|
|
-// setting it will still change the value in `prefs.js`, but it will be ignored.
|
|
1162
|
|
-// If this is ever unlocked, the value in prefs.js will be used.
|
|
1163
|
|
-pref("browser.laterrun.enabled", false, locked);
|
|
1164
|
|
-
|
|
1165
|
|
-// tor-browser#44123: Never trim the protocol off of URLs.
|
|
1166
|
|
-pref("browser.urlbar.trimURLs", false);
|
|
1167
|
|
-
|
|
1168
|
|
-// tor-browser#45171: Disabled split view which is janky.
|
|
1169
|
|
-pref("browser.tabs.splitView.enabled", false); |