Opened 4 years ago

Last modified 7 weeks ago

#16339 assigned task

Make sure the ImageCapture API is not leaking information (camera availability)

Reported by: gk Owned by: tbb-team
Priority: High Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-fingerprinting, ff68-esr
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor: Sponsor44-can

Description

Part of the ImageCapture API landed (https://bugzilla.mozilla.org/show_bug.cgi?id=916643). This may leak camera availability in the client side. Marking this for ff45-esr for closer inspection as it is still disabled by pref in ESR 38 (dom.imagecapture.enabled is set to false).

Child Tickets

Change History (10)

comment:1 Changed 4 years ago by gk

Keywords: ff52-esr added; ff45-esr removed
Severity: Normal
Sponsor: None

Still disabled, off to ff52-esr.

comment:2 Changed 2 years ago by gk

Keywords: tbb-7.0-must added

More tickets for 7.0.

comment:3 Changed 2 years ago by gk

Keywords: tbb-7.0-must-alpha added; tbb-7.0-must removed

Getting more tickets on our alpha radar.

comment:4 Changed 2 years ago by gk

Priority: MediumHigh

Moving the investigation tickets to higher priority.

comment:5 Changed 2 years ago by arthuredelstein

Keywords: ff59-esr added; ff52-esr removed
Status: newneeds_review

The pref dom.imagecapture.enabled is still disabled in ESR52, and our TBB/ESR52 alpha. And I confirmed in the JS console that the ImageCapture constructor is correctly unavailable. So I think we can postpone again until ff59-esr.

comment:6 Changed 2 years ago by gk

Keywords: tbb-7.0-must-alpha removed
Status: needs_reviewassigned

comment:7 Changed 20 months ago by gk

Keywords: ff60-esr added; ff59-esr removed

Firefox 60 is the new ESR.

comment:8 Changed 15 months ago by arthuredelstein

Keywords: ff67-esr added; ff60-esr removed

dom.imagecapture.enabled is still disabled in ESR60
https://dxr.mozilla.org/mozilla-esr60/source/modules/libpref/init/all.js#5276

comment:9 Changed 15 months ago by arthuredelstein

Keywords: ff68-esr added; ff67-esr removed

Version 68 of Firefox will be the next ESR.

comment:10 Changed 7 weeks ago by pili

Sponsor: NoneSponsor44-can

Adding Sponsor 44 to ESR68 tickets

Note: See TracTickets for help on using tickets.