Opened 10 months ago

Last modified 30 hours ago

#26608 new defect

investigate <link rel="preload">

Reported by: mcs Owned by: tbb-team
Priority: High Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-linkability, ff60-esr, TorBrowserTeam201904
Cc: arthuredelstein Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Support for <link rel="preload"> was added in Firefox 56, but then it was disabled in Firefox 57 "because of various web compatibility issues." We should verify that this feature remains disabled in ESR60 or we should ensure that it is subject to first-party isolation.

Child Tickets

Change History (14)

comment:1 Changed 10 months ago by arthuredelstein

Cc: arthuredelstein added

comment:2 Changed 10 months ago by gk

Priority: MediumImmediate

Bumping prio.

comment:3 Changed 10 months ago by gk

Priority: ImmediateHigh

comment:5 Changed 9 months ago by gk

Keywords: TorBrowserTeam201808 added; TorBrowserTeam201807 removed

Move our tickets to August.

comment:6 Changed 8 months ago by gk

Keywords: TorBrowserTeam201809 added; TorBrowserTeam201808 removed

Moving our tickets to September 2018

comment:7 Changed 7 months ago by gk

Keywords: TorBrowserTeam201810 added; TorBrowserTeam201809 removed

Moving tickets to October

comment:8 Changed 6 months ago by gk

Keywords: TorBrowserTeam201811 added; TorBrowserTeam201810 removed

Moving our tickets to November.

comment:9 Changed 4 months ago by gk

Keywords: TorBrowserTeam201812 added; TorBrowserTeam201811 removed

Moving our tickets to December.

comment:10 Changed 3 months ago by gk

Keywords: TorBrowserTeam201901 added; TorBrowserTeam201812 removed

Moving tickets to Jan 2019.

comment:11 Changed 2 months ago by gk

Keywords: TorBrowserTeam201902 added; TorBrowserTeam201901 removed

Moving tickets to February.

comment:12 Changed 6 weeks ago by gk

Keywords: TorBrowserTeam201903 added; TorBrowserTeam201902 removed

Moving remaining tickets to March.

comment:13 Changed 2 weeks ago by gk

Keywords: TorBrowserTeam201904 added; TorBrowserTeam201903 removed

Moving tickets to April.

comment:14 Changed 30 hours ago by acat

AFAIK this is controlled via network.preload pref and it is still false in current nightly (68). So I would assume that it will be still disabled for next ESR release.

In any case, I enabled the pref in current Tor Browser and tested different kinds of 'link-rel preloads' (audio, video, script, style, fetch...), and could not find a way to make them bypass the FPI.

Note: See TracTickets for help on using tickets.