Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No Resource URI Leak doesn't work #255

Closed
madelynseal opened this issue Oct 28, 2017 · 20 comments
Closed

No Resource URI Leak doesn't work #255

madelynseal opened this issue Oct 28, 2017 · 20 comments

Comments

@madelynseal
Copy link

Hello, I would just like to report that the extension "No Resource URI Leak" doesn't work in waterfox
link: https://addons.mozilla.org/en-US/firefox/addon/no-resource-uri-leak/?src=search

This is an issue if you want to stop fingerprinting as it allows accessing certain files through resource:// URIs https://browserleaks.com/firefox

@dimqua
Copy link

dimqua commented Oct 28, 2017

It seems like this issue was finally fixed in Firefox 57+ and, probably, these fixes can be backported to Waterfox too.

@madelynseal
Copy link
Author

good to know, should this issue be marked as closed then? Or should I wait until the issue is actually fixed?

@dimqua
Copy link

dimqua commented Oct 29, 2017

should I wait until the issue is actually fixed?

Yes, please.

@madelynseal
Copy link
Author

Accidently closed it, I was a little confused for a second sorry

@ghost
Copy link

ghost commented Oct 30, 2017

You may have a look this way
No Resource URI Leak (clone) 1.1.1 runs flawlessly here with Waterfox 55 and should as well with Warefox/Firefox 56

@madelynseal
Copy link
Author

madelynseal commented Oct 30, 2017

If the issue is what he says it is, then this should work. However I usually don't trust some random person posting a patched version just out of principle that it isn't always safe.

The developer's repo isn't on github so I would have to create a new account and isn't very responsive it seems, anyway here is the link

@madelynseal
Copy link
Author

In short, addons that use relative paths for scripts break in FF55+. To fix them you have to convert to absolute paths

@WagnerGMD
Copy link

WagnerGMD commented Nov 1, 2017

Perhaps it's the reason why anothers addons (such as Refresh Blocker, etc) doesn't work anymore ? Nevermind it's just an idea because I will have to replace it in the futur.

Another choice will be to wait the next release (called Waterfox_v56). In fact because it was announced there (n°235) and that's a very good news.
Until this day, you can also replace (or upgrade) it. Bacause the addon (No Resource URI Leak_v1.1.1) seem's to work very fine.

@MrAlex94
Copy link
Collaborator

I'll back port this patch for the final v56 release.

@madelynseal
Copy link
Author

Thanks so much!

@GitCurious
Copy link

Is this patch already in v56 - or will it be in a later revision ?

[I do not see it working at the moment on the first 56 release]

@WagnerGMD
Copy link

I will suppose at the moment no it's missing. Because I had check it and the result is clear : no it doesn't work as expected.

@grahamperrin
Copy link

… No Resource URI Leak (clone) 1.1.1 runs flawlessly …

Tested with Waterfox 56.1.0_2 on FreeBSD-CURRENT. Before and after installation:

2018-04-04 03 17 56

2018-04-04 03 20 15

Would you like to close this issue 255?

If trust of an extension is an issue, it should be raised with the developer. NB earthlng is a member of the ghacksuserjs organisation.

When the patch is backported, the commit can be marked as a fix for an earlier issue, About the leak (resource) · Issue #235 .

@madelynseal
Copy link
Author

Yay I can use this addon again! Yeah I will close it. Thanks

For convenience, here are the links again
ghacks-user.js issue is here: arkenfox/user.js#191

xpi can be downloaded directly here: https://raw.githubusercontent.com/earthlng/testpages/master/no_resource_uri_leak-1.1.1-an%2Bfx%2Bsm%2Btb.xpi

@WagnerGMD
Copy link

WagnerGMD commented Apr 6, 2018

Well I will assume the plan has change ? It won't happen, right ?
Just read (again) the announce. That's why from my point of view, it wasn't about the trust of an addon.

PS : I was thinking today I will take another little time to check it (this time with Waterfox_v56.1.0). But at the end, there is no point.
At least, the next time @MrAlex94 have the decency to apologize (almost 7 months ? No news. Damn right sometimes I'm too kind and very very very patient).

@madelynseal
Copy link
Author

I didn't look into who made the patch until the recent post on this issue. This issue was just for the No Resource URI Leak extension, which a patched version has been made that works (and that I trust).

I agree that @MrAlex94 should have ported the patch by now.

@MrAlex94
Copy link
Collaborator

MrAlex94 commented Apr 7, 2018 via email

@madelynseal
Copy link
Author

Oh ok, hope I didn't come off as rude as well. As long as it gets ported at some point I'm happy.

@MrAlex94
Copy link
Collaborator

Oh ok, hope I didn't come off as rude as well. As long as it gets ported at some point I'm happy.

No, you're okay :-). Just that being respectful costs nothing, seems people seem to forget there's another human being reading these messages sometimes.

@WagnerGMD
Copy link

WagnerGMD commented Apr 15, 2018

  • Did I have the knowledge about this kind of stuff (Mozilla Security Patch) ? No.
  • Did I take the time to update my previous post(s) ? Yes.
  • Did I publish a new post ? Yes (only one because perhaps the notifications didn't work).
  • Did I harass you ? No (not even once).
  • Did I receive any news on this matter ? No.
  • Did I take the time to check it ? Yes. Several Times ? Again yes.
  • Did I give you a very long time to correct it ? Yes.

To be clear, no I don't forget about the human being. Well let's say it's sound rude but to explain, you should at first remember 3 little things :

  • I just discover (all) : it was done for nothing at the end... That's a bad news and no it doesn't help to participate.
  • The fact is somewhere in 7 months, you could take a little moment to publish a new announce (yes even just a little one could be fine (such as "I had to cancelled my previous plan because" etc)) about this matter.
  • When the people try sometimes to participate (even by a little moments), you shoudn't forget (or ignore) them. To resume, that's the not way to follow.

Despite my respect (and no I haven't forgot the real meaning), for me it's seem understandable.

Now (nevermind let's try to move on) I will conclude by thank you I accept your excuse. But don't except from me any patch. Because that's right, (like I said at the beginning) no I don't have the knowledge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants