Disable 0-RTT protocol in the browser
Disable 0-RTT protocol in browser. It is a major tracking vector.
security.tls.enable_0rtt_data in about:config. Also disable in other places.
- Show closed items
Activity
-
Newest first Oldest first
-
Show all activity Show comments only Show history only
Do we actually know if Tor Browser is using 0rtt? or is disabling this pref for defense-in-depth? If we're sending 0rtt then we'll increase the priority.
Trac:
Priority: Very High to Medium
Keywords: N/A deleted, TorBrowserTeam201911 addedWhy is that a major tracking vector and how? See: for instance https://github.com/ghacksuserjs/ghacks-user.js/issues/536#issuecomment-439132784 and we probably had a similar bug report in #28536 (moved) stemming from everyone citing the same badly written article it seems. I am closing this as WORKSFORME as #28536 (moved). Please reopen with more specified concerns if there are any.
Trac:
Status: new to closed
Resolution: N/A to worksforme- Trac closed
closed
- Pili Guerra mentioned in issue #32702 (moved)
mentioned in issue #32702 (moved)