Security/Fingerprinting

From MozillaWiki
< Security
Revision as of 15:12, 28 October 2016 by Tritter (talk | contribs)
Jump to navigation Jump to search

Active Bugs

Bugs which are assigned and being worked on.

Full Query
ID Whiteboard Summary Status Resolution Priority Assigned to
1152448 [fingerprinting][fp-triaged] "Forget About This Site" does not forget site's enumerateDevices Ids ASSIGNED P3 Jan-Ivar Bruaroey [:jib] (needinfo? me)
1591337 [fingerprinting] RFP screen spoofs: step common spoofs based on inner window ASSIGNED P3 Pier Angelo Vendrame
1314443 [tor][fingerprinting][tor-mobile][fp-triaged] Audit the existing disable WebRTC preferences and ensure they work as advertised ASSIGNED P3 Tom Ritter [:tjr] (OOTO until 7/21)

3 Total; 3 Open (100%); 0 Resolved (0%); 0 Verified (0%);


Assigned, but not started

These bugs have an owner, but their status is 'NEW' indicating that they are not being worked on yet.

Full Query
ID Whiteboard Summary Status Resolution Priority Assigned to
1445310 [fingerprinting][fp-triaged] Clamp and Jitter Timestamps in CSS Animations NEW P3 Brian Birtles (:birtles)
1579584 [fingerprinting][fpp:future] Have window.outerHeight/outerWidth lie and report the innerHeight/innerWidth NEW P3 Tom Ritter [:tjr] (OOTO until 7/21)

2 Total; 2 Open (100%); 0 Resolved (0%); 0 Verified (0%);


Backlog (all unowned)

Bugs looking for an owner.

Full Query
ID Whiteboard Summary Status Resolution Priority Assigned to
503221 [fingerprinting] Locale can be determined using jar: protocol to test resource:///chrome/ entries NEW --
572650 [fingerprinting][necko-would-take][fp-triaged] [meta] Reduce the amount of data and entropy sent out in HTTP requests NEW P5
755284 [fingerprinting][fp-triaged][tor 6217] Fingerprintable information in update behavior UNCONFIRMED P3
959893 [fingerprinting][fp-triaged] [meta] WebRTC Internal IP Address Leakage NEW --
1041818 [fingerprinting][tor][fp-triaged] take steps to mitigate canvas fingerprinting NEW P2
1233846 [fingerprinting][tor 10283][fp-triaged] WebSpeech Synthesis API mustn't allow fingerprinting NEW P3
1315203 [fingerprinting][fp-triaged] XSHM: Cross Site History Manipulation (information leakage) NEW P3
1325874 [fingerprinting][fp-triaged][domsecurity-backlog2][userContextId] Consider seperating page content history for userContextId NEW P3
1329996 [tor][fingerprinting][domsecurity-meta][fp-triaged] [META] Tor Uplift: Fingerprinting Resistance NEW P2
1330882 [fingerprinting][tor][fp-triaged] When privacy.resistFingerprinting = true, set new windows to rounded dimensions [tor 19459] REOPENED P3
1336208 [fingerprinting][gfx-noted][fp-triaged] Bundle and whitelist fonts when privacy.resistFingerprinting = true NEW P3
1356381 [domsecurity-meta] [fingerprinting][fp-triaged] [META] Add Telemetry and Perform Experiments to measure breakage/impact of Anti-Fingerprinting Patches NEW P3
1356383 [fingerprinting][fp-triaged] Add Telemetry for Gamepad API REOPENED P3
1362184 [fingerprinting][fp-triaged] Add Telemetry for IndexedDB NEW P5
1372288 [fingerprinting][fp-triaged] [meta] WebExtensions can be used as user fingerprint NEW P3
1383656 [fingerprinting] [fxprivacy] [fp-triaged] Tweak and analyze the value and find out an appropriate way to generate the padding size for opaque response NEW P3
1394448 [fp-triaged][domsecurity-backlog1][fingerprinting] Cannot install Addon with privacy.resistFingerprinting==true NEW P3
1397996 [tor][fingerprinting][fp-triaged][tor 22137] scrollbar thickness reveals platform NEW P2
1401493 [tor][fingerprinting][fp-triaged] Perform Fingerprint Comparison of Tor Browser and Firefox NEW P3
1403747 [tor][fingerprinting][fp-triaged] When privacy.resistFingerprinting is true, warn users not to maximize their window NEW P5
1405971 [fingerprinting][fp-triaged] Webextension UUID leak to servers via Fetch request headers NEW P3
1409974 [fingerprinting][fp-triaged] KeyboardEvent.location could be used as a user behavior fingerprinting vector. NEW P3
1412814 [gfx-noted][fingerprinting][fp-triaged] privacy.resistFingerprinting should do something smarter about system metric media queries. NEW P3
1414162 [fingerprinting][fp-triaged] Investigate and improve privacy.resistFingerprinting handling when toggled on mid-session NEW P5
1414311 [fingerprinting][fp-triaged][tor 30970] New window size is different than expected after changing screen dpi (with privacy.resistFingerprinting pref enabled) NEW P3
1420653 [fingerprinting][fp-triaged] DeviceId is persisted even if cookies are disabled, allowing persistent fingerprint NEW P3
1420809 [fingerprinting][fp-triaged] Permissions that are perpetually denied should not return Reject immediately NEW P3
1422482 [fingerprinting][tor] OS username disclosure using downloads manager NEW P3
1422890 [fingerprinting][gfx-noted][fp-triaged] Add additional Canvas Fingerprinting Tests NEW P3
1426232 [fingerprinting][fp-triaged] Consider a Timezone Permission for Resist Fingerprinting NEW P5
1428033 [fingerprinting][gfx-noted][fp-triaged] Apply Resist Fingerprinting Protection to WebGL NEW P5
1428034 [fingerprinting] [gfx-noted] [fp-triaged] [tor 30541] Apply Resist Fingerprinting Protection to WebGL's readPixels method UNCONFIRMED P5
1429097 [fingerprinting][gfx-noted][fp-triaged] Pause execution when Canvas Permission Prompt is displayed NEW P3
1429519 [fingerprinting][gfx-noted][fp-triaged] Add a canvas-imagedata permission NEW P3
1429648 [fingerprinting][fp-triaged] Add tests that handle timer rounding NEW P3
1429865 [gfx-noted][fingerprinting][fp-triaged] Allow managing canvas permissions in about:preferences when resistFingerprinting is on NEW P3
1439784 [tor][fingerprinting][fp-triaged] Fix the KeyboardEvent mochitests NEW P3
1447011 [fingerprinting][psm-backlog][fp-triaged] Permit setting HSTS entries only on the host name or the eTLD+1 NEW P3
1449732 [fingerprinting][fp-triaged] Do not expose Local IP Address in Resist Fingerprinting Mode REOPENED P5
1450398 [fingerprinting][fp-triaged][fpp:m?] [meta] Resist Fingerprinting Mode should allow finer control of applicability NEW P3
1450401 [fingerprinting][fp-triaged] mozFullScreen leaks exact screen resolution NEW P3
1450564 [fingerprinting][fp-triaged] Fine-tune fonts to compensate difference in dimensions to eliminate this fingerprinting possibility UNCONFIRMED P4
1466148 [fingerprinting][fp-triaged] WebRTC leaks internal addresses even when camera/mic permissions are not granted NEW P3
1470592 [tor][fingerprinting][fp-triaged] macOS 10.14 Camera/Mic Permissions granted in Private Browsing Mode shouldn't persist NEW P3
1472808 [tor][fingerprinting][fp-triaged] For privacy.resistFingerprinting, spoof Keyboard Layout according to content locale NEW P3
1475973 [tor][fingerprinting][fp-triaged] browser/components/resistfingerprinting/test/browser/browser_roundedWindow_open_* and browser/components/resistfingerprinting/test/browser/browser_roundedWindow_windowSetting_* fail on Windows install with 150% dpi NEW P3
1485249 [tor 6370][gfx-noted][fingerprinting][fp-triaged] WebGL extensions should be disabled when private.resistFingerprinting is enabled NEW P2
1485258 [tor 20025][fingerprinting][fp-triaged] When privacy.spoof_english is true, don't reveal locale by charset fallback NEW P3
1490728 [tor][fingerprinting][domsecurity-backlog1][fp-triaged] Improve discoverability/explanation of RFP NEW P3
1502831 [fingerprinting][fp-triaged] Use software rendering to mitigate canvas fingerprinting while privacy.resistFingerprinting=True REOPENED P3
1507517 [fingerprinting][fp-triaged][domsecurity-backlog1] [META] Breakage from Fingerprinting Resistance NEW P3
1507879 [tor 29564][fingerprinting][fp-triaged] Investigate getClientRects for fingerprinting NEW P3
1522517 [fingerprinting][fp-triaged] [meta] Unify software rendering settings while privacy.resistFingerprinting=True NEW P2
1522528 [fingerprinting][fp-triaged] Disable anialiasing while privacy.resistFingerprinting=True NEW P2
1532859 [domsecurity-backlog1][tor][fingerprinting][fp-triaged][fpp:m?] Non-integer devicePixelRatio's cause blurriness with RFPTarget::WindowDevicePixelRatio NEW P3
1534581 [fingerprinting][tor 29745] Exposed chrome:// resources allow browser version, OS, and locale detection UNCONFIRMED P3
1538718 [fingerprinting] Account for Display Scaling when rendering NEW P3
1542676 [tor 26607][fingerprinting] Round subpixel accuracy of window properties to integers when resistfingerprinting is enabled NEW P3
1545527 [fingerprinting] Extend createObjectURL to support canvas UNCONFIRMED P5
1552786 [fingerprinting] Don't trigger a resistFingerprinting warning if contents of a canvas nothing has been drawn to is retrieved UNCONFIRMED P5
1562290 [fingerprinting] Need a mechanism to limit gyroscope data leakage for fingerprinting NEW P3
1575690 [tor-mobile][fingerprinting][fp-triaged] visualViewport leaks the onscreen keyboard height UNCONFIRMED P3
1581453 [fingerprinting] Resist Fingerprinting retriggers Bug 402089 - nsDOMUIEvent should cache coordinates when DuplicatePrivateData is called NEW P3
1582687 [fingerprinting] Block user-installed fonts by default NEW --
1598862 [fingerprinting][tor] When resistFingerprinting is enabled, alt+letter JS keyboard hotkey bindings don't work UNCONFIRMED P5
1603332 [fingerprinting][tor] privacy.resistFingerprinting and -moz- colors UNCONFIRMED P3
1610747 [fingerprinting][domsecurity-backlog] privacy.resistFingerprinting set to true breaks https://maps.google.com/ UNCONFIRMED P3
1617872 [fingerprinting][domsecurity-backlog1] Consider making IsResistFingerprintingEnabled affect shared memory NEW P3
1636005 [reporter-external] [client-bounty-form] [verif?][fingerprinting][domsecurity-backlog1] Default submit button label length allows browser language fingerprinting NEW P3
1717671 [mv3-future][sp3][fingerprinting] Avoid the use of a persistent UUID in the public base URL of extensions NEW P3
1719738 [fingerprinting] Simplify Timezone Names to Reduce Fingerprinting NEW --
1722181 [fingerprinting] Math Fingerprinting via Polyfills NEW P3
1772039 [fingerprinting][domsecurity-backlog3] Enabling privacy.resistFingerprinting causes the zoom cameras/screens to be a black screen. NEW P3
1854851 [fingerprinting] Inform the user about non-optimal settings when FPP or RFP is enabled UNCONFIRMED --
1916271 [client-bounty-form][fingerprinting] Gecko reveals sanitized GPU Characteristics; webkit and blink return hardcoded strings for all users NEW --
1928095 [fingerprinting] x86/x86_64 architecture are exposed through sign bit on NaN arithmetic NEW P5
1940296 [fingerprinting] Vsync is enabled on Wayland when RFP is on and leaks the monitor refresh rate NEW P3
1940879 [fingerprinting] Allow HTML5 canvas image prompt closes too quickly UNCONFIRMED P3

78 Total; 78 Open (100%); 0 Resolved (0%); 0 Verified (0%);


Meta Bugs (if any)

Bugzilla query error

Array ( [type] => error [message] => http-bad-status [params] => Array ( [0] => 400 [1] => Bad Request ) ) 1