5 ms·
This is a "chrome script" extension, which downgrades some of the built-in Firefox security features. Use at your own risk.
by bugmen0t 5y ago
This is a "chrome script" extension, which downgrades some of the built-in Firefox security features. Use at your own risk.
- octoberfranklin 5y ago"Downgrades built-in Firefox security features" is a gross mischaracterization, bordering on FUD. Chrome scripts require careful security analysis, just like software that runs with root privileges. Firefox ships with zillions of lines of chrome script, and none of those zillions of lines "downgrade" any security features. Software isn't automatically secure simply because it came from Mozilla. Microsoft tried the same nonsense to scare people out of using Linux at one point... you'd have to be nuts to run kernel code that didn't come from Redmond!
- bugmen0t 5y agoThere are security checks for detecting userChrome.js. My understanding is that Firefox is going to let people customize as before but just not enable some security enhancements for those users. https://searchfox.org/mozilla-central/rev/02bd3e02b72d431f2c600a7328697a521f87d9b6/dom/security/nsContentSecurityUtils.h#47 https://searchfox.org/mozilla-central/rev/02bd3e02b72d431f2c...
- gruez 5y agoWhat are the "security enhancements" that those users are missing out on?
- nix0n 5y agoFirst one I found was blocking of eval() https://searchfox.org/mozilla-central/source/dom/security/nsContentSecurityUtils.cpp#655 https://searchfox.org/mozilla-central/source/dom/security/ns...
- roblabla 5y agoEssentially, it allows calling eval[1] and executing "privileged loads"[0] in some elevated contexts (the System Principal, which is responsible for the browser UI[2]). Those are useful mitigations, but disabling them for some custom user-chrome is unlikely to have a meaningful impact on your browser's security. [0] https://searchfox.org/mozilla-central/source/dom/security/nsContentSecurityManager.cpp#882 https://searchfox.org/mozilla-central/source/dom/security/ns... [1] https://searchfox.org/mozilla-central/source/dom/security/nsContentSecurityUtils.cpp#656 https://searchfox.org/mozilla-central/source/dom/security/ns... [2]: https://blog.mozilla.org/attack-and-defense/2020/06/10/understanding-web-security-checks-in-firefox-part-1/ https://blog.mozilla.org/attack-and-defense/2020/06/10/under...
- bugmen0t 5y agoAs pointed out by sibling-comments, this seems to be in the context of making sandbox escapes harder.
- throwawayciv651 5y agoSomeone posted downthread to use this instead: https://github.com/mozilla/policy-templates https://github.com/mozilla/policy-templates It's from Mozilla.