403 lines
24 KiB
JSON
403 lines
24 KiB
JSON
{
|
|
"user": {
|
|
"Safe Browsing": {
|
|
"description": "Google Safe Browsing is a service from Google that warns users when they attempt to navigate to a dangerous website or download dangerous files.",
|
|
"preferences": {
|
|
"browser.safebrowsing.downloads.remote.enabled": {
|
|
"value": false,
|
|
"title": "Disable Google Safe Browsing for downloads",
|
|
"description": "To verify the safety of certain executable files, GeckoView may submit some information about the file, including the name, origin, size and a cryptographic hash of the contents, to the Google Safe Browsing service which helps GeckoView determine whether or not the file should be blocked.",
|
|
"requireUserOptIn": true
|
|
}
|
|
}
|
|
},
|
|
"Block Implicit Outbound": {
|
|
"description": "Control not explicitly user invoked interactions",
|
|
"preferences": {
|
|
"network.prefetch-next": {
|
|
"value": false,
|
|
"title": "Disable link prefetching",
|
|
"shouldBeDefault": true
|
|
},
|
|
"network.dns.disablePrefetch": {
|
|
"value": true,
|
|
"title": "Disable DNS prefetching",
|
|
"shouldBeDefault": true
|
|
},
|
|
"network.dns.disablePrefetchFromHTTPS": {
|
|
"value": true,
|
|
"title": "Disable HTTPS DNS prefetching"
|
|
},
|
|
"network.predictor.enabled": {
|
|
"value": false,
|
|
"title": "Disable prefetching predictor",
|
|
"shouldBeDefault": true
|
|
},
|
|
"network.predictor.enable-prefetch": {
|
|
"value": false,
|
|
"title": "Disable prefetching predictions",
|
|
"shouldBeDefault": true
|
|
},
|
|
"network.http.speculative-parallel-limit": {
|
|
"value": 0,
|
|
"title": "Disable link-mouseover opening connection to linked server",
|
|
"shouldBeDefault": true
|
|
},
|
|
"network.preconnect": {
|
|
"value": false,
|
|
"title": "Disable automatic connections to third-party domains,"
|
|
}
|
|
}
|
|
},
|
|
"DNS": {
|
|
"description": "Improve DNS and Proxy/SOCKS security",
|
|
"preferences": {
|
|
"network.trr.mode": {
|
|
"value": 3,
|
|
"title": "Enable DNS over HTTPS",
|
|
"requireUserOptIn": true
|
|
},
|
|
"network.trr.uri": {
|
|
"value": "https://dns.quad9.net/dns-query",
|
|
"title": "Use quad9 for Trusted Recursive Resolver (TRR)",
|
|
"description": "Quad9 is a privacy-focused DNS resolver that provides malware blocking and security features.",
|
|
"requireUserOptIn": true
|
|
},
|
|
"network.trr.custom.uri": {
|
|
"value": "https://dns.quad9.net/dns-query",
|
|
"title": "Use quad9 for custom Trusted Recursive Resolver (TRR)",
|
|
"description": "Quad9 is a privacy-focused DNS resolver that provides malware blocking and security features.",
|
|
"requireUserOptIn": true
|
|
},
|
|
"network.dns.native_https_query": {
|
|
"value": true,
|
|
"title": "Enable native DNS HTTPS Query",
|
|
"description": "DNS over HTTPS",
|
|
"shouldBeDefault": true
|
|
},
|
|
"network.proxy.socks_remote_dns": {
|
|
"value": true,
|
|
"title": "Set the proxy server to do any DNS lookups when using SOCKS",
|
|
"description": "e.g. in Tor, this stops your local DNS server from knowing your Tor destination as a remote Tor node will handle the DNS request"
|
|
},
|
|
"network.file.disable_unc_paths": {
|
|
"value": true,
|
|
"title": "Disable using UNC (Uniform Naming Convention) paths",
|
|
"description": "Warning: Can break extensions for profiles on network shares",
|
|
"requireUserOptIn": true
|
|
},
|
|
"network.gio.supported-protocols": {
|
|
"value": "",
|
|
"title": "Disable GIO as a potential proxy bypass vector"
|
|
},
|
|
"media.peerconnection.ice.proxy_only_if_behind_proxy": {
|
|
"value": true,
|
|
"title": "Force WebRTC inside the proxy"
|
|
},
|
|
"media.peerconnection.enabled": {
|
|
"value": false,
|
|
"title": "Disable WebRTC PeerConnection",
|
|
"description": "Prevent exposing local IP Address"
|
|
},
|
|
"media.peerconnection.ice.default_address_only": {
|
|
"value": true,
|
|
"title": "Force a single network interface for ICE candidates generation",
|
|
"description": "When using a system-wide proxy, it uses the proxy interface"
|
|
},
|
|
"network.dns.localDomains": {
|
|
"value": "250analytics.com,a.omappapi.com,activity-stream-icons.services.mozilla.com,ads.allizom.org,ads.mozilla.org,ads.nonprod.webservices.mozgcp.net,ads.prod.webservices.mozgcp.net,ads-img.mozilla.org,analytics.getpocket.com,analytics.google.com,analytics.withgoogle.com,anf1.fuzzing.mozilla.org,anonymco.com,api.divviup.org,asan-nightly-frontend-elb-1348905149.us-east-2.elb.amazonaws.com,braze.com,contile.services.mozilla.com,contile-images.services.mozilla.com,classify-client.nonprod.webservices.mozgcp.net,classify-client.prod.webservices.mozgcp.net,classify-client.services.mozilla.com,crash-reports.allizom.org,crash-reports.mozilla.com,crash-reports-xpsp2.mozilla.com,crash-stacks.mozilla.com,crash-stats.allizom.org,crash-stats.mozilla.com,crash-stats.mozilla.org,dap.services.mozilla.com,dap.nonprod.webservices.mozgcp.net,dap.prod.webservices.mozgcp.net,dap-09-3.api.divviup.org,data.mozilla.com,data-ingestion.prod.dataops.mozgcp.net,dataops.mozgcp.net,dataservices.mozgcp.net,discovery.addons.allizom.org,discovery.addons.mozilla.org,discovery.addons-dev.allizom.org,divviup.org,download-stats.mozilla.org,download-stats.r53-2.services.mozilla.com,experimenter.services.mozilla.com,experimenter.nonprod.webservices.mozgcp.net,experimenter.prod.webservices.mozgcp.net,fhr.data.mozilla.com,fhr.r53-2.services.mozilla.com,firefox-android-home-recommendations.getpocket.com,firefox-dns-perf-test.net,fuzzing.mozilla.org,google-analytics.com,google-analytics-cn.com,googleanalytics.com,googlesyndication.com,googlesyndication-cn.com,googletagmanager.com,googletagmanager-cn.com,googletagservices.com,googletagservices-cn.com,improving.duckduckgo.com,incoming.telemetry.mozilla.org,incoming.thunderbird.net,incoming-telemetry.thunderbird.net,ingestion-edge.prod.dataops.mozgcp.net,location.services.mozilla.com,locprod1-elb-eu-west-1.prod.mozaws.net,locprod2-elb-us-west-2.prod.mozaws.net,metrics-content.duckduckgo.com,new-sentry.gitlab.net,nonprod.classify-client.nonprod.webservices.mozgcp.net,normandy.cdn.mozilla.net,normandy.nonprod.cloudops.mozgcp.net,normandy.prod.cloudops.mozgcp.net,normandy-cdn.services.mozilla.com,omappapi.com,pagead2.googlesyndication.com,pipeline-incoming-prod-elb-149169523.us-west-2.elb.amazonaws.com,prod.ads.prod.webservices.mozgcp.net,prod.classify-client.prod.webservices.mozgcp.net,prod.dap.prod.webservices.mozgcp.net,prod.data-ingestion.prod.dataops.mozgcp.net,prod.dataops.mozgcp.net,prod.experimenter.prod.webservices.mozgcp.net,prod.ingestion-edge.prod.dataops.mozgcp.net,prod.sentry.prod.cloudops.mozgcp.net,prod-classifyclient.normandy.prod.cloudops.mozgcp.net,sdk.iad-05.braze.com,search.r53-2.services.mozilla.com,search.services.mozilla.com,self-repair.mozilla.org,self-repair.r53-2.services.mozilla.com,sentry.gitlab.net,sentry.io,sentry.nonprod.cloudops.mozgcp.net,sentry.prod.cloudops.mozgcp.net,sentry.prod.mozaws.net,sitereview.zscaler.com,snippets.allizom.org,snippets.cdn.mozilla.net,snippets.mozilla.com,snippets-prod.frankfurt.moz.works,snippets-prod.moz.works,snippets-prod.oregon-b.moz.works,snippets-stage.moz.works,snippets-stage.oregon-b.moz.works,snowplow.trx.gitlab.net,snowplowalb-1011729428.us-east-1.elb.amazonaws.com,snowplowprd.trx.gitlab.net,snowplowprdnlb-1490493263.us-east-2.elb.amazonaws.com,socorro.nonprod.webservices.mozgcp.net,socorro.prod.webservices.mozgcp.net,socorro-collector.services.mozilla.com,socorro-webapp-allizom.stage.mozaws.net,socorro-webapp.services.mozilla.com,spocs.getpocket.com,spocs.getpocket.dev,spocs.mozilla.net,ssl.google-analytics.com,ssl-google-analytics.l.google.com,stage.sentry.nonprod.cloudops.mozgcp.net,start.fedoraproject.org,start.thunderbird.net,start.ubuntu.com,start-stage.thunderbird.net,survey.mozilla.com,tagmanager.google.com,talkback.mozilla.org,talkback-public.mozilla.org,talkback-reports.mozilla.org,telemetry-coverage.mozilla.org,telemetry-coverage.r53-2.services.mozilla.com,telemetry-experiment.cdn.mozilla.net,telemetry-incoming.r53-2.services.mozilla.com,telemetry-incoming-a.r53-2.services.mozilla.com,telemetry-incoming-b.r53-2.services.mozilla.com,telemetry-prod-1054754349.us-east-1.elb.amazonaws.com,tiles-cdn.prod.ads.prod.webservices.mozgcp.net,updates.thunderbird.net,updates-stage.thunderbird.net,use-application-dns.net,vf.startpage.com,widgets.getpocket.com,www.250analytics.com,www.anonymco.com,www.google-analytics.com,www.google-analytics-cn.com,www.googleanalytics.com,www.googlesyndication.com,www.googlesyndication-cn.com,www.googletagmanager.com,www.googletagmanager-cn.com,www.googletagservices.com,www.googletagservices-cn.com,www.sentry.io,www-google-analytics.l.google.com,www-googletagmanager.l.google.com",
|
|
"title": "Block Tracking Domains"
|
|
},
|
|
"network.proxy.type": {
|
|
"value": 0,
|
|
"title": "Prevents using automatically the system's proxy configuration by default"
|
|
}
|
|
}
|
|
},
|
|
"Secure Connections": {
|
|
"description": "SSL/TLS / OCSP / CERTS / HPKP",
|
|
"preferences": {
|
|
"security.ssl.require_safe_negotiation": {
|
|
"value": true,
|
|
"title": "Require safe negotiation",
|
|
"description": "Blocks connections to servers that don't support RFC 5746 as they're potentially vulnerable to a MiTM attack."
|
|
},
|
|
"security.tls.enable_0rtt_data": {
|
|
"value": false,
|
|
"title": "Disable TLS1.3 0-RTT (round-trip time)",
|
|
"description": "This data is not forward secret, as it is encrypted solely under keys derived using the offered PSK. There are no guarantees of non-replay between connections."
|
|
},
|
|
"security.OCSP.enabled": {
|
|
"value": 1,
|
|
"title": "Enforce OCSP fetching to confirm current validity of certificates"
|
|
},
|
|
"security.OCSP.require": {
|
|
"value": true,
|
|
"title": "Set OCSP fetch failures to hard-fail",
|
|
"description": "When a CA cannot be reached to validate a cert, GeckoView just continues the connection (=soft-fail). Setting this pref to true tells GeckoView to instead terminate the connection (=hard-fail)."
|
|
},
|
|
"security.cert_pinning.enforcement_level": {
|
|
"value": 2,
|
|
"title": "Enable strict PKP (Public Key Pinning)"
|
|
},
|
|
"security.remote_settings.crlite_filters.enabled": {
|
|
"value": true,
|
|
"title": "Enable CRLite"
|
|
},
|
|
"security.pki.crlite_mode": {
|
|
"value": 2,
|
|
"title": "Enable CRLite for PKI",
|
|
"shouldBeDefault": true
|
|
},
|
|
"security.tls.enable_kyber": {
|
|
"value": true,
|
|
"title": "Enable Post-Quantum Kyber TLS"
|
|
},
|
|
"network.http.http3.enable_kyber": {
|
|
"value": true,
|
|
"title": "Enable HTTP3 Post-Quantum Kyber TLS"
|
|
},
|
|
"security.ssl.treat_unsafe_negotiation_as_broken": {
|
|
"value": true,
|
|
"title": "Display warning on the padlock for 'broken security'"
|
|
},
|
|
"browser.xul.error_pages.expert_bad_cert": {
|
|
"value": true,
|
|
"title": "Display advanced information on Insecure Connection warning pages"
|
|
},
|
|
"dom.security.https_first": {
|
|
"value": true,
|
|
"title": "Attempt to establish HTTPS connections first before falling back to HTTP",
|
|
"shouldBeDefault": true
|
|
}
|
|
}
|
|
},
|
|
"Privacy": {
|
|
"preferences": {
|
|
"network.http.referer.XOriginTrimmingPolicy": {
|
|
"value": 2,
|
|
"title": "Trim cross-origin referrers",
|
|
"description": "Trims down referrers to just the scheme, hostname and port"
|
|
},
|
|
"network.http.referer.XOriginPolicy": {
|
|
"value": 2,
|
|
"title": "Only send cross-origin referer if host matches"
|
|
},
|
|
"network.http.referer.disallowCrossSiteRelaxingDefault": {
|
|
"value": true,
|
|
"title": "Disallow relaxing referrer policy for cross-site requests",
|
|
"shouldBeDefault": true
|
|
},
|
|
"network.http.referer.disallowCrossSiteRelaxingDefault.top_navigation": {
|
|
"value": true,
|
|
"title": "Disallow relaxing referrer policy for cross-site requests",
|
|
"description": "On top navigation",
|
|
"shouldBeDefault": true
|
|
},
|
|
"general.useragent.updates.enabled": {
|
|
"value": false,
|
|
"title": "Disable automatic User Agent updates",
|
|
"description": "This preference controls whether Firefox automatically updates its User-Agent string. When set to false, it prevents Firefox from automatically updating the browser's User-Agent string, which is a text identifier that tells websites which browser and version you're using."
|
|
},
|
|
"privacy.query_stripping.enabled": {
|
|
"value": true,
|
|
"title": "Strip known tracking query parameters from URLs"
|
|
},
|
|
"privacy.query_stripping.enabled.pbmode": {
|
|
"value": true,
|
|
"title": "Strip known tracking query parameters from URLs (Private browsing)"
|
|
},
|
|
"privacy.query_stripping.strip_list": {
|
|
"value": "__hsfp __hssc __hstc __s _bhlid _branch_match_id _branch_referrer _gl _hsenc _kx _openstat at_recipient_id at_recipient_list bbeml bsft_clkid bsft_uid dclid et_rid fb_action_ids fb_comment_id fbclid gbraid gclid guce_referrer guce_referrer_sig hsCtaTracking igshid irclickid mc_eid mkt_tok ml_subscriber ml_subscriber_hash msclkid mtm_cid oft_c oft_ck oft_d oft_id oft_ids oft_k oft_lk oft_sk oly_anon_id oly_enc_id pk_cid rb_clickid s_cid sc_customer sc_eh sc_uid srsltid ss_email_id twclid unicorn_click_id vero_conv vero_id vgo_ee wbraid wickedid yclid ymclid ysclid",
|
|
"title": "Improve built-in query stripping"
|
|
},
|
|
"dom.private-attribution.submission.enabled": {
|
|
"value": false,
|
|
"title": "Disable Private Attribution Submission Control",
|
|
"shouldBeDefault": true
|
|
},
|
|
"privacy.trackingprotection.enabled": {
|
|
"value": true,
|
|
"title": "Enable Tracking Protection"
|
|
},
|
|
"privacy.trackingprotection.pbmode.enabled": {
|
|
"value": true,
|
|
"title": "Enable Tracking Protection (Private browsing)"
|
|
},
|
|
"privacy.trackingprotection.socialtracking.enabled": {
|
|
"value": true,
|
|
"title": "Enable Social Tracking Protection",
|
|
"shouldBeDefault": true
|
|
},
|
|
"privacy.trackingprotection.cryptomining.enabled": {
|
|
"value": true,
|
|
"title": "Enable Cryptomining Protection",
|
|
"shouldBeDefault": true
|
|
},
|
|
"privacy.trackingprotection.fingerprinting.enabled": {
|
|
"value": true,
|
|
"title": "Enable Fingerprinting Tracking Protection",
|
|
"shouldBeDefault": true
|
|
},
|
|
"network.cookie.maxageCap": {
|
|
"value": 15552000,
|
|
"title": "Limit maximum cookie lifetime to 180 days"
|
|
}
|
|
}
|
|
},
|
|
"Resist Fingerprinting": {
|
|
"description": "Advanced Fingerprinting protection. This might break websites. For best results make sure to enable \"Privacy\" hardenings.",
|
|
"preferences": {
|
|
"privacy.fingerprintingProtection": {
|
|
"value": true,
|
|
"title": "Enable Suspected Fingerprinters Protection (FPP)",
|
|
"shouldBeDefault": true
|
|
},
|
|
"privacy.fingerprintingProtection.pbmode": {
|
|
"value": true,
|
|
"title": "Enable Suspected Fingerprinters Protection (FPP) (Private browsing)",
|
|
"shouldBeDefault": true
|
|
},
|
|
"privacy.reduceTimerPrecision": {
|
|
"value": true,
|
|
"title": "Reduce timer precision",
|
|
"shouldBeDefault": true
|
|
},
|
|
"privacy.partition.network_state.ocsp_cache": {
|
|
"value": true,
|
|
"title": "Enable OCSP cache",
|
|
"shouldBeDefault": true
|
|
},
|
|
"privacy.partition.network_state.ocsp_cache.pbmode": {
|
|
"value": true,
|
|
"title": "Enable OCSP cache (Private browsing)",
|
|
"shouldBeDefault": true
|
|
},
|
|
"gfx.bundled-fonts.activate": {
|
|
"value": 1,
|
|
"title": "Always load bundled fonts"
|
|
}
|
|
}
|
|
},
|
|
"Attack Surface Reduction": {
|
|
"preferences": {
|
|
"pdfjs.enableScripting": {
|
|
"value": false,
|
|
"title": "Disable PDFJS scripting"
|
|
},
|
|
"pdfjs.enableXfa": {
|
|
"value": false,
|
|
"title": "Disable PDFJS XFA"
|
|
},
|
|
"mathml.disabled": {
|
|
"value": true,
|
|
"title": "Disable MathML (Mathematical Markup Language)"
|
|
},
|
|
"gfx.font_rendering.graphite.enabled": {
|
|
"value": false,
|
|
"title": "Disable graphite"
|
|
},
|
|
"javascript.options.ion": {
|
|
"value": false,
|
|
"title": "Disable Ion"
|
|
},
|
|
"javascript.options.baselinejit": {
|
|
"value": false,
|
|
"title": "Disable baseline JIT"
|
|
},
|
|
"javascript.options.jit_trustedprincipals": {
|
|
"value": false,
|
|
"title": "Disable JIT trustedprincipals"
|
|
},
|
|
"javascript.options.asmjs": {
|
|
"value": false,
|
|
"title": "Disable asm.js"
|
|
},
|
|
"javascript.options.wasm": {
|
|
"value": false,
|
|
"title": "Disable web assembly",
|
|
"requireUserOptIn": true
|
|
},
|
|
"accessibility.force_disabled": {
|
|
"value": 1,
|
|
"title": "Disable Accessibility Services"
|
|
}
|
|
}
|
|
},
|
|
"Disk Avoidance": {
|
|
"description": "Control what data to persist to disk",
|
|
"preferences": {
|
|
"browser.cache.disk.enable": {
|
|
"value": false,
|
|
"title": "Disable disk cache",
|
|
"description": "Don't cache data to disk. Might impact performance negatively",
|
|
"requireUserOptIn": true
|
|
},
|
|
"browser.privatebrowsing.forceMediaMemoryCache": {
|
|
"value": true,
|
|
"title": "Set media cache in Private Browsing to in-memory"
|
|
},
|
|
"media.memory_cache_max_size": {
|
|
"value": 65536,
|
|
"title": "Increase in-memory media cache maximum size"
|
|
},
|
|
"browser.sessionstore.privacy_level": {
|
|
"value": 2,
|
|
"title": "Disable storing extra session data",
|
|
"description": "Extra session data such as form content, cookies and POST data"
|
|
}
|
|
}
|
|
},
|
|
"PDFJS": {
|
|
"preferences": {
|
|
"pdfjs.enableSignatureEditor": {
|
|
"value": true,
|
|
"title": "Enable the ability to add signatures"
|
|
},
|
|
"pdfjs.enablePermissions": {
|
|
"value": false,
|
|
"title": "Never allow documents to prevent copying text",
|
|
"shouldBeDefault": true
|
|
},
|
|
"pdfjs.externalLinkTarget": {
|
|
"value": 2,
|
|
"title": "Open external links in new tabs/windows"
|
|
},
|
|
"pdfjs.sidebarViewOnLoad": {
|
|
"value": 2,
|
|
"title": "Show sidebar by default when viewing PDFs"
|
|
}
|
|
}
|
|
},
|
|
"Miscelaneous": {
|
|
"preferences": {
|
|
"permissions.manager.defaultsUrl": {
|
|
"value": "",
|
|
"title": "Remove special permissions for certain mozilla domains"
|
|
},
|
|
"network.IDN_show_punycode": {
|
|
"value": true,
|
|
"title": "Use Punycode in Internationalized Domain Names to eliminate possible spoofing"
|
|
},
|
|
"extensions.postDownloadThirdPartyPrompt": {
|
|
"value": false,
|
|
"title": "Disable bypassing 3rd party extension install prompts"
|
|
},
|
|
"layout.css.visited_links_enabled": {
|
|
"value": false,
|
|
"title": "Disable coloring of visited links",
|
|
"requireUserOptIn": true
|
|
},
|
|
"media.autoplay.default": {
|
|
"value": 5,
|
|
"title": "Block media autoplay by default"
|
|
},
|
|
"webgl.disabled": {
|
|
"value": true,
|
|
"title": "Disable WebGL (Web Graphics Library)",
|
|
"requireUserOptIn": true
|
|
}
|
|
}
|
|
}
|
|
}
|
|
} |