Opened 2 years ago

Closed 2 years ago

Last modified 18 months ago

#26613 closed defect (fixed)

audit or disable Apple HLS implementation on Android

Reported by: mcs Owned by: tbb-team
Priority: High Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-mobile, ff60-esr, TorBrowserTeam201807
Cc: arthuredelstein, igt0 Actual Points:
Parent ID: Points:
Reviewer: Sponsor: Sponsor8


As of Firefox 59, Apple's HTTPS Live Streaming (HLS) protocol is supported on Android for both audio and video. We should audit this or at least look at how it is implemented, and possible disable it. Mozilla says: "There is not currently any plan to implement it on Firefox Desktop." See:

Child Tickets

Change History (8)

comment:1 Changed 2 years ago by arthuredelstein

Cc: arthuredelstein added

comment:2 Changed 2 years ago by gk

Cc: igt0 added
Status: newneeds_information

It seems there are already proxy bypasses found in this implementation, see: #26028. igt0: do you think we should keep this enabled with your fix or is there more that's an issue?

comment:3 Changed 2 years ago by gk

Priority: MediumImmediate

Bumping prio.

comment:4 Changed 2 years ago by gk

Priority: ImmediateHigh

comment:5 Changed 2 years ago by igt0

When looking the code I looked for:

  • proxy bypasses: the browser implementation uses just the http implementation and it has a proxy bypass, this one is fixed, we just need to backport to FF60.
  • disk avoidance: I wanted to make sure if the player stores any data in the disk and it does, however, it stores the data in the app internal cache using the android context.getCacheDir method. The internal cache can not be accessed by other apps and it has a short life span.
  • fingerprinting: I looked for locale and screen size leaks, and the HLS implementation doesn't leak them. All the text and video selections happen in the app side. The browser doesn't send any data to the server.

So I would say yes we can enable it.

comment:6 Changed 2 years ago by gk

Resolution: fixed
Status: needs_informationclosed

Great, so we are done here.

comment:7 Changed 20 months ago by pili

Sponsor: Sponsor8

comment:8 Changed 18 months ago by gk

Sponsor8 in July 2018.

Note: See TracTickets for help on using tickets.