Opened 3 years ago

Last modified 2 years ago

#20744 new defect

add 'media.source.enabled' only where JS is enabled in security settings

Reported by: i139 Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-security-slider, tbb-usability-website
Cc: gk Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

media source extensions (MSE)is a "specification allows JavaScript to dynamically construct media streams for <audio> and <video>"

the advances of MSE are:

Allow JavaScript to construct media streams independent of how the media is fetched.
Define a splicing and buffering model that facilitates use cases like adaptive streaming, ad-insertion, time-shifting, and video editing.
Minimize the need for media parsing in JavaScript.
Leverage the browser cache as much as possible.
Provide requirements for byte stream format specifications.
Not require support for any particular media format or codec.

but as user ma1 say in #19200#comment:38

As a side effect the data flow *appears* less transparent, but what we should focus on is that the JavaScript on a certain webpage has now the power to fuzz (and possibly exploit) any available HTML 5 media codec *without even touching the network*.

put from true to false in 'media.source.enabled' when using high in security settings, probably will be a good for hypothetical security

Child Tickets

Change History (3)

comment:1 Changed 3 years ago by mcs

Cc: tbb-team added
Component: - Select a componentApplications/Tor Browser
Owner: set to tbb-team

comment:2 Changed 3 years ago by gk

Cc: gk added; tbb-team removed
Keywords: tbb-security-slider added

comment:3 Changed 2 years ago by cypherpunks

Keywords: tbb-usability-website added
Summary: add 'media.source.enabled' change in security settingadd 'media.source.enabled' only where JS is enabled in security settings

MSE without JS is useless, so repurposing this ticket to allow websites' non-MSE fallback where no JS is allowed.

Note: See TracTickets for help on using tickets.