Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Remove gfx.direct2d.disabled layers.acceleration.disabled
* These preferences were introduced in 61a2cb8 * None of the linked items here or in the commit message suggest that these pref are related to hardening, or avoiding hardware/canvas/fonts/plugins/based fingerprinting * http://www.w2spconf.com/2012/papers/w2sp12-final4.pdf suggests that: "Tying the browser more closely to operating system functionality and system hardware means that websites have more access to [...] resources, not designed to handle adversarial input [...] different behavior can be used to distinguish systems," But does not provide mitigation recommendations related to these prefs * gfx.direct2d.disabled only forces uses of Direct2d on systems where other rendering options such as OpenGL are available * layers.acceleration.disabled: there is no indication that this could serve as an entropy source for fingerprinting, or is otherwise vulnerable https://trac.torproject.org/projects/tor/attachment/ticket/9438/0001-setting-layers.acceleration.disabled-to-true-to-fix-.patch disabled it as a fix for broken display on some machines, not as a hardening measure add flash player CVE list link, update redirected link
- Loading branch information