View Single Post
  #1   (View Single Post)  
Old 4th May 2018
Scripter Scripter is offline
Port Guard
 
Join Date: Apr 2018
Posts: 12
Default firefox quantum leaks buildId

Openbsd 6.3 features Firefox 59.0.2 in lieu of 56 (or 55, can't remember). This new Firefox version ignores the general.buildId.override value in about:config. It leaks the actual buildId: the exact build date and time, down to precise seconds.

I tested this behavior at https://browserleaks.com/javascript

Mozilla will not let me register for an account at this time, so I wanted to let the community know.

I intend to file a bug report with OpenBSD, although I don't think there's much the developers can do.

In the meantime, firefox-esr is available, but many useful applications, including uMatrix, are not available on pre-quantum versions. This is not only annoying, but insecure as well.
Reply With Quote