Opened 2 years ago

Last modified 2 years ago

#27258 new defect

font whitelist means we don't have to set gfx.downloadable_fonts.fallback_delay

Reported by: arthuredelstein Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-fingerprinting-font, ff60-esr
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:


In 8455, "gfx.downloadable_fonts.fallback_delay" was set to -1 to avoid temporarily rendering a local font, which would allow its characters to be measured. But now that we whitelist fonts, it is probably OK to stop setting this pref. We should confirm that the fallback mechanism doesn't provide a whitelist bypass.

Child Tickets

Change History (1)

comment:1 Changed 2 years ago by fixtbb

#8455, tbb-fingerprinting-fonts.
For fingerprinting purposes gfx.downloadable_fonts.fallback_delay_short is available ;)

Note: See TracTickets for help on using tickets.