Skip to content

the open cookie jar [1447935, 1433700, 1207775: resolved since at least 76 except websockets] #489

Closed
@Thorin-Oakenpants

Description

@Thorin-Oakenpants

May-25-2020: update from the researcher:

Hi, I've done a retrospective analysis of Firefox versions, up until Firefox 76. All issues discussed in the original report appear to be resolved, except for one; the request initiated by the WebSocket API is not blocked [by Tracking Protection] when directed to a blacklisted domain


This issue is really just for myself, and FYI - I'll fix the title one day when I get the time to read the docs etc and understand what is going on

Discussions

I had a quick skim of the reddit link and article last night, and

    1. gorhill has us covered, assuming your config is "right" (good gorhill, good boy!) 💋
    1. I'm not worried personally, as I lock down basically all persistent storage

My assumption has always been that any persistent storage of website data can and will be used against you. Hence why the default user.js essentially blocked everything (until recently where we allowed first party cookies). Anyway, that's all for now

PS: I do not care about ABP, Disconnect, SafeScript etc, I only care about uM, uBO (and Firefox)

@gorhill Thanks, feel free to chime in if and when you have time (and feel it necessary), just don't like talking behind yer back :)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions