User:Arroway/Secure Prefs

From MozillaWiki
Jump to navigation Jump to search

Software version taken as reference:

Legend

x not modified compared to the value of the previous cell
? don't know if it is set and to which value
- unused
DEF default value in Firefox nightly
preference shipped in Tor, i.e. breakage is low or acceptable compared to the benefits
discrepancy in the choice of values - to be looked into
preference name ParanoidPanda lv1 ParanoidPanda lv2 ParanoidPanda lv3 Tor defaults profile Torbutton defaults Torbutton medium low Torbutton medium high Torbutton high
paranoidpanda.level 1 2 3 - - - - -
app.update.promptWaitTime ? ? ? 3600 x x x x
app.update.badge ? ? ? true x x x x
app.update.staging.enabled ? ? ? false x x x x
beacon.disabled DEF true true DEF x x x x
beacon.enabled DEF x false DEF x x x x
browser.aboutHomeSnippets.updateUrl DEF x "" DEF x x x x
browser.cache.disk.enable DEF x false false false x x x
browser.cache.disk_cache_ssl DEF x false DEF x x x x
browser.cache.offline.enable DEF x false false x x x x
browser.casting.enabled DEF x false DEF x x x x
browser.disableResetPrompt ? ? ? true x x x x
browser.display.max_font_attempts ? ? ? 10 x x x x
browser.display.max_font_count ? ? ? 10 x x x x
browser.display.use_document_fonts DEF x 0 DEF x x x x
browser.download.folderList DEF x 2 DEF x x x x
browser.download.forbid_open_with ? ? ? false x x x x
browser.download.manager.addToRecentDocs DEF x x false DEF x x x
browser.download.manager.retention DEF x 0 1 1 x x x
browser.download.managerscanWhenDone ? ? ? false x x x x
browser.download.panel.shown ? ? ? true x x x x
browser.download.useDownloadDir DEF x false false x x x x
browser.eme.ui.enabled ? ? ? false x x x x
browser.fixup.alternate.enabled DEF x false false x x x x
browser.formfill.enable DEF x false false x x x x
browser.formfill.expire_days DEF x 0 DEF x x x x
browser.helperApps.deleteTempFileOnExit DEF x true DEF x x x x
browser.history_expire_days DEF x 0 DEF x x x x
browser.history_expire_sites DEF x 0 DEF x x x x
browser.history_expire_visits DEF x 0 DEF x x x x
browser.link.open_newwindow.restriction ? ? ? 0 x x x x
browser.newtab.preload DEF x false DEF x x x x
browser.newtab.url DEF x about:blank DEF x x x x
browser.newtabpage.directory.ping DEF x "" data:text/plain, x x x x
browser.newtabpage.directory.source DEF x data:text/plain,{} data:text/plain, x x x x
browser.newtabpage.enabled DEF x false DEF x x x x
browser.newtabpage.enhanced DEF x false false x x x x
browser.newtabpage.introShown ? ? ? true x x x x
browser.newtabpage.preload ? ? ? false x x x x
browser.pagethumbnails.capturing_disabled DEF x true DEF x x x x
browser.pocket.enabled DEF x false false x x x x
browser.pocket.api ? ? ? "" x x x x
browser.pocket.site ? ? ? "" x x x x
browser.pocket.enabled DEF x false false x x x x
browser.privatebrowsing.autostart DEF x true true x x x x
browser.reader.detectedFirstArticle ? ? ? true x x x ?
browser.rights.3.shown ? ? ? true x x x x
browser.safebrowsing.downloads.remote.enabled DEF x false? DEF x x x x
browser.safebrowsing.enabled DEF x true false x x x x
browser.safebrowsing.malware.enabled DEF x true false x x x x
browser.search.countryCode ? ? ? "US" x x x x
browser.search.defaultenginame ? ? ? Disconnect x x x x
browser.search.geoip.url DEF x "" "" x x x x
browser.search.geoSpecificDefaults ? ? ? false x x x x
browser.search.order.extra.1 ? ? ? Disconnect x x x x
browser.search.order.extra.2 ? ? ? Youtube x x x x
browser.search.region ? ? ? "US" x x x x
browser.search.suggest.enabled DEF x false false x x x x
browser.search.update DEF x false false x x x x
browser.selfsupport.enabled ? ? ? false x x x x
browser.selfsupport.url DEF x "" "" x x x x
browser.send_pings DEF x false false x x x x
browser.send_pings.require_same_host DEF x true DEF x x x x
browser.sessionstore.enabled DEF x false DEF x x x x
browser.sessionstore.postdata DEF x 0 DEF x x x x
browser.sessionstore.privacy_level DEF x 2 2 x x x x
browser.shell.checkDefaultBrowser DEF x x false x x x x
browser.slowStartup.notificationDisabled ? ? ? true x x x x
browser.slowStartup.maxSamples ? ? ? 0 x x x x
browser.slowStartup.samples ? ? ? 0 x x x x
browser.startup.homepage DEF x x x chrome://torbutton/content x x x
browser.startup.homepage_override.buildID ? ? ? 20100101 x x x x
browser.syncPromoViewsLeftMap ? ? ? {"addons":0, "passwords":0, "bookmarks":0} x x x x
browser.uiCustomization.state ? ? ? ... x x x x
browser.uitour.enabled ? ? ? false x x x x
browser.urlbar.autocomplete.enabled DEF x false DEF x x x x
browser.urlbar.autoFill DEF x false DEF x x x x
browser.urlbar.autoFill.typed DEF x false DEF x x x x
browser.urlbar.filter.javascript DEF x true DEF x x x x
browser.urlbar.maxRichResults DEF x 0 DEF x x x x
browser.urlbar.suggest.searches DEF x false DEF x x x x
browser.urlbar.trimURLs DEF x false DEF x x x x
browser.usedOnWindows10 ? ? ? true x x true x
browser.zoom.siteSpecific ? ? ? false false x x x
camera.control.face_detection.enabled DEF x false DEF x x x x
clipboard.autocopy DEF x false DEF x x x x
datareporting.healthreport.about.reportUrl ? ? ? data:text/plain, x x x x
datareporting.healthreport.about.reportUrlUnified ? ? ? data:text/plain, x x x x
datareporting.healthreport.service.enabled DEF x false false x x x x
datareporting.healthreport.uploadEnabled DEF x false false x x x x
datareporting.policy.dataSubmissionEnabled DEF x false false x x x x
device.sensors.enabled DEF x false false x x x x
devtools.appmanager.enabled ? ? ? false x x x x
devtools.debugger.chrome-debugging-host ? ? ? 127.0.0.1 x x x x
devtools.webide.autoinstallADBHelper ? ? ? false x x x x
devtools.webide.autoinstallFxdtAdapters ? ? ? false x x x x
devtools.webide.enabled ? ? ? false x x x x
dom.battery.enabled DEF x false false false x x x
dom.enable_performance DEF x false false false x x x
dom.enable_resource_timing ? ? ? false x x x x
dom.enable_user_timing ? ? ? false x x x x
dom.event.clipboardevents.enabled DEF x false DEF x x x x
dom.event.highrestimestamp.enabled ? ? ? true x x x x
dom.gamepad.enabled DEF x false false x x x x
dom.indexedDB.enabled ? ? ? false x x x x
dom.mozTCPSocket.enabled ? ? ? false x x x x
dom.network.enabled ? ? ? false false x x x
dom.push.serverURL ? ? ? "" x x x x
dom.quotaManager.testing ? ? ? ? true x x x
dom.telephony.enabled DEF x false DEF x x x x
dom.vr.enabled DEF x false DEF x x x x
dom.webnotifications.enabled DEF x false DEF x x x x
dom.workers.sharedWorkers.enabled ? ? ? x false x x x
experiments.enabled DEF x false DEF x x x x
experiments.supported DEF x false DEF x x x x
extensions.autoDisabledScopes ? ? ? 0 x x x x
extensions.blocklist.enabled DEF x true DEF x x x x
extensions.bootstrappedAddons ? ? ? {} x x x x
extensions.checkCompatibility.4.* ? ? ? false x x x x
extensions.databaseSchema ? ? ? 3 x x x x
extensions.enabledAddons ? ? ? https-everywhere,torbutton,tor-launcher x x x x
extensions.enabledItems ? ? ? langpack-en-US x x x x
extensions.enabledScopes ? ? ? 1 x x x x
extensions.getAddons.cache.enabled DEF x false false x x x x
extensions.ghostery.privateBrowsing DEF x true DEF x x x x
extensions.hotfix.id ? ? ? "" x x x x
extensions.pendingOperations ? ? ? false x x x x
extensions.ui.lastCategory ? ? ? adons://list/extension x x x x
extensions.update.enabled DEF x true DEF x x x x
general.appname.override ? ? ? Netscape x x x x
general.appversion.override ? ? ? 5.0 (Windows) x x x x
general.buildID.override DEF x 20100101 20100101 x x x x
general.oscpu.override ? ? ? Windows NT 6.1 x x x x
general.platform.override ? ? ? Win32 x x x x
general.productSub.override ? ? ? 20100101 x x x x
general.useragent.override ? ? ? Mozilla/5.0 (Windows NT... x x x x
general.useragent.vendor ? ? ? "" x x x x
general.useragent.vendoSub ? ? ? "" x x x x
geo.disabled DEF x true DEF x x x x
geo.enabled DEF x false false x x x x
geo.wifi.uri ? ? ? "" x x x x
gfx.direct2d.disabled DEF x true true x x x x
gfx.downloadable_fonts.fallback_delay ? ? ? -1 x x x x
gfx.font_rendering.opentype_svg.enabled DEF x false DEF x x false x
gfx.xrender.enabled ? ? ? false x x x x
intl.accept_languages ? ? ? x en-US, en x x x
intl.charset.default ? ? ? windows-1252 x x x x
javascript.options.asmjs DEF x false false x x x x
javascript.options.baselinejit.content DEF x x x x x false x
javascript.options.ion.content DEF x x x x false x x
javascript.options.methodjit.chrome DEF x false DEF x x x x
javascript.options.methodjit.content DEF x false DEF x x x x
javascript.options.typeinference DEF x x x x false x x
javascript.use_us_english_locale ? ? ? true x x x x
keyword.enabled DEF x x x x x x x
layers.acceleration.disabled DEF x true true x x x x
layout.css.visited_links_enabled DEF x false DEF x x x x
loop.logDomains DEF x false DEF x x x x
mathml.disabled ? ? ? false x true x x
media.auto_data.enabled ? ? ? false x x x x
media.cache_size ? ? ? 0 x x x x
media.eme.apiVisible ? ? ? false x x x x
media.eme.enabled ? ? ? false x x x x
media.getusermedia.screensharing.enabled DEF x false DEF x x x x
media.gmp-eme-adobe.enabled ? ? ? false x x x x
media.gmp-gmpopenh264.enabled DEF x false DEF x x x x
media.gmp-manager.url DEF x "" DEF x x x x
media.gmp-manager.url.override ? ? ? data:text/plain, x x x x
media.gmp-provider.enabled ? ? ? false x x x x
media.navigator.enabled DEF x false false x x x x
media.peerconnection.enabled DEF false false false x x x x
media.peerconnection.ice.relay_only DEF true true DEF x x x x
media.video_stats.enabled DEF x false false x x x x
media.webaudio.enabled ? ? ? DEF x false x x
media.webspeech.recognition.enable DEF x false DEF x x x x
network.cookie.cookieBehavior DEF 3 1 1 1 x x x
network.cookie.life DEF x 2 DEF x x x x
network.cookie.lifetimePolicy DEF 2 2 2 2 x x x
network.cookie.thirdparty.sessionOnly DEF x true DEF x x x x
network.dns.blockDotOnion DEF x true DEF x x x x
network.dns.disablePrefetch DEF true true true x x x x
network.dns.disablePrefetchFromHTTPS DEF x true DEF x x x x
network.http.altsvc.enabled ? ? ? false x x x x
network.http.altsvc.oe ? ? ? false x x x x
network.http.connection-retry-timeout ? ? ? 0 x x x x
network.http.max-persistent-connections-per-proxy ? ? ? 256 x x x x
network.http.pipelining ? ? ? true x x x x
network.http.pipelining.aggressive ? ? ? true x x x x
network.http.pipelining.max-optimistic-requests ? ? ? 3 x x x x
network.http.pipelining.maxrequests ? ? ? 12 x x x x
network.http.pipelining.reschedule-timeout ? ? ? 15000 x x x x
network.http.pipelining.read-timeout ? ? ? 60000 x x x x
network.http.pipelining.ssl ? ? ? true x x x x
network.http.proxy.pipelining ? ? ? true x x x x
network.http.referer.sendRefererHeader DEF x 0 DEF x x x x
network.http.referer.spoofSource DEF x true DEF x x x x
network.http.referer.trimmingPolicy DEF x 2 DEF x x x x
network.http.sendSecureXSiteReferrer DEF x false DEF x x x x
network.http.spdy.enabled.http2 ? ? ? false x x x x
network.http.spdy.enabled.http2draft ? ? ? false x x x x
network.http.spdy.enabled ? ? ? false x x x x
network.http.spdy.enabled.v2 ? ? ? false x x x x
network.http.spdy.enabled.v3 ? ? ? false x x x x
network.http.spdy.enabled.v3-1 ? ? ? false x x x x
network.http.speculative-parallel-limit DEFL x 0 DEF x x x x
network.IDN_show_punycode DEF x true DEF x x x x
network.jar.block-remote-files ? ? ? false x true x x
network.jar.open-unsafe-types DEF x false DEF x x x x
network.manage-offline-status ? ? ? false x x x x
network.negotiate-auth.allow-insecure-ntlm-v1 DEF x false DEF x x x x
network.predictor.enabled DEF x false false x x x x
network.prefetch-next DEF x false DEF x x x x
network.protocole-handler.external-default ? ? ? false x x x x
network.protocole-handler.external.mailto ? ? ? false x x x x
network.protocole-handler.external.news ? ? ? false x x x x
network.protocole-handler.external.nntp ? ? ? false x x x x
network.protocole-handler.external.snews ? ? ? false x x x x
network.protocole-handler.warn-external.mailto ? ? ? true x x x x
network.protocole-handler.warn-external.news ? ? ? true x x x x
network.protocole-handler.warn-external.nntp ? ? ? true x x x x
network.protocole-handler.warn-external.snews ? ? ? true x x x x
network.proxy.no_proxies_on ? ? ? "" x x x x
network.proxy.socks ? ? ? 127.0.0.1 x x x x
network.proxy.socks_port ? ? ? 9150 x x x x
network.proxy.socks_remote_dns DEF x true true x x x x
network.proxy.type ? ? ? 1 x x x x
network.security.ports.banned ? ? ? 9050,9051,9150,9151 x x x x
network.seer.enabled DEF x false DEF x x x x
network.stricttransportsecurity.preloadlist DEF x true DEF x x x x
noscript.forbidMedia ? ? ? DEF x x x true
noscript.forbidMedia ? ? ? DEF x true x x
noscript.global ? ? ? DEF x x false false
noscript.globalHttpsWhitelist ? ? ? DEF x x true false
pdfjs.disabled DEF x true DEF x x x x
permissions.memory_only false x true true true x x x
places.history.enabled DEF x false DEF false x x x
plugins.click_to_play DEF x true true x x x x
plugins.disable ? ? ? true x x x x
plugins.expose_full_path ? ? ? false false x x x
plugins.hide_infobar_for_missing_plugin ? ? ? true x x x x
plugins.hide_infobar_for_outdated_plugin DEF x false DEF x x x x
plugins.hideMissingPluginsNotification ? ? ? true x x x x
plugin.state.flash DEF x 0 1 x x x x
plugin.state.libgnome-shell-browser-plugin DEF x 0 DEF x x x x
plugins.update.notifyUser DEF x true DEF x x x x
privacy.clearOnShutdown.cache DEF x true DEF x x x x
privacy.clearOnShutdown.cookies DEF x true DEF x x x x
privacy.clearOnShutdown.downloads DEF x true DEF x x x x
privacy.clearOnShutdown.formdata DEF x true DEF x x x x
privacy.clearOnShutdown.history DEF x true DEF x x x x
privacy.clearOnShutdown.offlineApps DEF x true DEF x x x x
privacy.clearOnShutdown.openWindows DEF x true DEF x x x x
privacy.clearOnShutdown.passwords DEF x true DEF x x x x
privacy.clearOnShutdown.sessions DEF x true DEF x x x x
privacy.clearOnShutdown.siteSettings DEF x true DEF x x x x
privacy.donottrackheader.enabled DEF true true DEF x x x x
privacy.donottrackheader.value DEF 1 1 DEF x x x x
privacy.resistFingerprinting ? ? ? true true x x x
privacy.sanitize.sanitizeOnShutdown DEF x true DEF x x x x
privacy.suppressModifierKeyEvents ? ? ? true x x x x
privacy.thirdparty.isolate ? ? ? 2 2 x x x
privacy.trackingprotection.pbmode.enabled DEF x true false x x x x
privacy.trackingprotection.ui.enabled DEF x true DEF x x x x
privacy.trackingprotection.enabled DEF true true DEF x x x x
reader.parse-on-load.enabled ? ? ? false x x x x
security.ask_for_password DEF x 0 x x x x x
security.csp.experimentalEnabled DEF x true DEF x x x x
security.csp.enable DEF x x x x x x x
security.cert_pinning.enforcement_level DEF x 2 2 x x x x
security.enable_tls_session_tickets DEF x false false false x x x
security.fileuri.strict_origin_policy DEF x true DEF x x x x
security.mixed_content.block_display_content DEF true true DEF x x x x
security.mixed_content.block_active_content DEF x true false x x x x
security.nocertdb false false true true true x x x
security.OCSP.enabled DEF x 1 DEF x x x x
security.OCSP.require DEF x true DEF x x x x
security.pki.sha1_enforcement_level DEFL x 2 2 x x x x
security.sri.enable DEF x x x x x x x
security.ssl.disable_session_identifiers ? ? ? true x x x x
security.ssl.enable_ocsp_stapling DEF x true DEF x x x x
security.ssl.enable_false_start ? ? ? true x x x x
security.ssl.errorReporting.automatic DEF x false DEF x x x x
security.ssl.require_safe_negotiation DEF x true DEF x x x x
security.ssl.treat_unsafe_negotiation_as_broke DEF true true DEF x x x x
security.ssl.warn_missing_rfc5746 DEF x 1 DEF x x x x
security.ssl3.rsa_null_sha DEF x false DEF x x x x
security.ssl3.rsa_null_md5 DEF x false DEF x x x x
security.ssl3.ecdhe_rsa_null_sha DEF x false DEF x x x x
security.ssl3.ecdhe_ecdsa_null_sha DEF x false DEF x x x x
security.ssl3.ecdh_rsa_null_sha DEF x false DEF x x x x
security.ssl3.ecdh_ecdsa_null_sha DEF x false DEF x x x x
security.ssl3.rsa_seed_sha DEF x false DEF x x x x
security.ssl3.rsa_rc4_40_md5 DEF x false DEF x x x x
security.ssl3.rsa_rc2_40_md5 DEF x false DEF x x x x
security.ssl3.rsa_1024_rc4_56_sha DEF x false DEF x x x x
security.ssl3.rsa_camellia_128_sha DEF x false DEF x x x x
security.ssl3.ecdhe_rsa_aes_128_sha DEF x false DEF x x x x
security.ssl3.ecdhe_ecdsa_aes_128_sha DEF x false DEF x x x x
security.ssl3.ecdh_rsa_aes_128_sha DEF x false DEF x x x x
security.ssl3.ecdh_ecdsa_aes_128_sha DEF x false DEF x x x x
security.ssl3.dhe_rsa_camellia_128_sha DEF x false DEF x x x x
security.ssl3.dhe_rsa_aes_128_sha DEFL x false DEF x x x x
security.ssl3.ecdh_ecdsa_rc4_128_sha DEF x false DEF x x x x
security.ssl3.ecdh_rsa_rc4_128_sha DEF x false DEF x x x x
security.ssl3.ecdhe_ecdsa_rc4_128_sha DEF x false DEF x x x x
security.ssl3.ecdhe_rsa_rc4_128_sha DEF x false DEF x x x x
security.ssl3.rsa_rc4_128_md5 DEF x false DEF x x x x
security.ssl3.rsa_rc4_128_sha DEF x false DEF x x x x
security.ssl3.dhe_dss_des_ede3_sha DEF x false DEF x x x x
security.ssl3.dhe_rsa_des_ede3_sha DEF x false DEF x x x x
security.ssl3.ecdh_ecdsa_des_ede3_sha DEF x false DEF x x x x
security.ssl3.ecdh_rsa_des_ede3_sha DEF x false DEF x x x x
security.ssl3.ecdhe_ecdsa_des_ede3_sha DEF x false DEF x x x x
security.ssl3.ecdhe_rsa_des_ede3_sha DEF x false DEF x x x x
security.ssl3.rsa_des_ede3_sha DEF x false DEF x x x x
security.ssl3.rsa_fips_des_ede3_sha DEF x false DEF x x x x
security.ssl3.ecdh_rsa_aes_256_sha DEF x false DEF x x x x
security.ssl3.ecdh_ecdsa_aes_256_sha DEF x false DEF x x x x
security.ssl3.rsa_camellia_256_sha DEF x false DEF x x x x
security.ssl3.ecdhe_rsa_aes_256_sha DEF x true DEF x x x x
security.ssl3.ecdhe_ecdsa_aes_256_sha DEF x true DEF x x x x
security.ssl3.ecdhe_ecdsa_aes_128_gcm_sha256 DEF x true DEF x x x x
security.ssl3.ecdhe_rsa_aes_128_gcm_sha256 DEF x true DEF x x x x
security.ssl3.dhe_rsa_camellia_256_sha DEF x false DEF x x x x
security.ssl3.dhe_rsa_aes_256_sha DEF x false DEF x x x x
security.ssl3.dhe_dss_aes_128_sha DEF x false DEF x x x x
security.ssl3.dhe_dss_aes_256_sha DEF x false DEF x x x x
security.ssl3.dhe_dss_camellia_128_sha DEF x false DEF x x x x
security.ssl3.dhe_dss_camellia_256_sha DEFL x false DEF x x x x
security.ssl3.rsa_aes_256_sha DEF x true DEF x x x x
security.ssl3.rsa_aes_128_sha DEF x true DEF x x x x
security.tls.unrestricted_rc4_fallback false x x false x x x x
security.tls.version.max ? ? ? 3 x x x x
security.tls.version.min DEF 2 3 DEF x x x x
security.warn_entering_weak DEF x true DEF x x x x
security.xpconnect.plugin.unrestricted DEF x false DEF x x x x
services.sync.engine.prefs ? ? ? false x x x x
services.sync.engine.addons ? ? ? false x x x x
services.sync.engine.tabs ? ? ? false x x x x
services.sync.ui.hidden ? ? ? true x x x x
signon.autofillForms DEF false false DEF x x x x
signon.rememberSignons DEF x false DEF x x x x
startup.homepage_override_url ? ? ? https://blog.torproject.org/... x x x x
startup.homepage_welcome_url ? ? ? "" x x x x
startup.homepage_welcome_url.additional ? ? ? "" x x x x
svg.in-content.enabled ? ? ? true x x x false
ui.use_standins_for_native_colors ? ? ? true x x x x
toolkit.telemetry.enabled DEF x false DEF x x x x
toolkit.telemetry.unified DEF x false false x x x x
torbrowser.version - - - VERSION x x x x
urlclassifier.trackingWhitelistTable DEF x test-trackwhite-simple DEF x x x x
webgl.disabled DEF true true DEF x x x x
webgl.min_capability_mode ? ? ? true true x x x
webgl.disable-extensions ? ? ? true true x x x
webgl.disable-fail-if-major-performance-caveat ? ? ? true x x x x
xpinstall.whitelist.add ? ? ? "" x x x x
xpinstall.whitelist.add.36 ? ? ? "" x x x x


In the Tor borwser: font related prefs are also set. See: https://gitweb.torproject.org/tor-browser.git/plain/browser/app/profile/000-tor-browser.js?h=tor-browser-45.2.0esr-6.5-1