4 ms·
There are security checks for detecting userChrome.js. My understanding is that Firefox is going to let people customize as before but just not enable some secu
by bugmen0t 5y ago
There are security checks for detecting userChrome.js. My understanding is that Firefox is going to let people customize as before but just not enable some security enhancements for those users. https://searchfox.org/mozilla-central/rev/02bd3e02b72d431f2c600a7328697a521f87d9b6/dom/security/nsContentSecurityUtils.h#47 https://searchfox.org/mozilla-central/rev/02bd3e02b72d431f2c...
- gruez 5y agoWhat are the "security enhancements" that those users are missing out on?
- nix0n 5y agoFirst one I found was blocking of eval() https://searchfox.org/mozilla-central/source/dom/security/nsContentSecurityUtils.cpp#655 https://searchfox.org/mozilla-central/source/dom/security/ns...
- roblabla 5y agoEssentially, it allows calling eval[1] and executing "privileged loads"[0] in some elevated contexts (the System Principal, which is responsible for the browser UI[2]). Those are useful mitigations, but disabling them for some custom user-chrome is unlikely to have a meaningful impact on your browser's security. [0] https://searchfox.org/mozilla-central/source/dom/security/nsContentSecurityManager.cpp#882 https://searchfox.org/mozilla-central/source/dom/security/ns... [1] https://searchfox.org/mozilla-central/source/dom/security/nsContentSecurityUtils.cpp#656 https://searchfox.org/mozilla-central/source/dom/security/ns... [2]: https://blog.mozilla.org/attack-and-defense/2020/06/10/understanding-web-security-checks-in-firefox-part-1/ https://blog.mozilla.org/attack-and-defense/2020/06/10/under...
- bugmen0t 5y agoAs pointed out by sibling-comments, this seems to be in the context of making sandbox escapes harder.