Feature #6118

audit iceweasel config

Added by Tails 2013-07-18 07:51:13 . Updated 2013-07-19 06:12:05 .

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Target version:
Start date:
Due date:
% Done:

0%

Feature Branch:
Type of work:
Audit
Blueprint:

Starter:
Affected tool:
Deliverable for:

Description

Done

Almost everything, as long as we use an up to date Torbutton: Mike Perry, the torbutton maintainer, has a pretty good idea of what he’s doing.

TODO

browser fingerprinting

See the Panopticlick tool, by the EFF, for fingerprinting tests and stats.

For information about the relative protection torbutton offers against this kind of leak, see

Check Tails User Agent settings:

  • can Torbutton update them?
  • do we lighten Torbutton’s protection in any way? if so, shall we go on doing this? e.g.
    • do we set a custom or localized timezone, instead of Torbutton’s default (GMT)?
    • do we send custom or localized preferred languages for Content Negotiation?

The devel branch now enables Torbutton’s US English locale spoofing.

Firefox 3.5 or later

  • turn off geolocation from the beginning in the browser preferences. New versions of Torbutton disable geolocation, but only when Torbutton is in "enabled" mode
  • It may also be a good idea to disable prefetching.

Subtasks


History

#1 Updated by intrigeri 2013-07-19 01:23:00

  • Type of work set to Audit

Type of work: Audit

#2 Updated by intrigeri 2013-07-19 06:12:05

  • Subject changed from iceweasel to audit iceweasel config
  • Status changed from Confirmed to Resolved
  • Parent task set to Feature #5769