Open Bug 1310626 Opened 8 years ago Updated 1 year ago

Don't make thumbnails of pages where the camera is in use

Categories

(Firefox :: New Tab Page, defect, P5)

52 Branch
defect

Tracking

()

People

(Reporter: marco, Unassigned)

References

Details

(Keywords: privacy, Whiteboard: [snt-scrubbed][newtab-privacy])

For privacy reasons, I think it would be better not to take screenshots of a page where the camera is being used.
Component: New Tab Page → Untriaged
> Component: New Tab Page → Untriaged

Any thinking for more components?
Component: Untriaged → New Tab Page
Flags: needinfo?(mcastelluccio)
Keywords: privacy
Not really, I saw the bug wasn't triaged and thought I used the wrong component.
Flags: needinfo?(mcastelluccio)
Blocks: 755996
How is sharing camera any worse than sharing e.g. ones back account info, or any other page behind a login?

Seems like Firefox screenshots itself needs a privacy and security review. Has it had one?

Privacy:

It looks and acts like a feature one would expect to be pulled off entirely on the local user's machine, being in the browser and all, without any privacy risks at all, yet it is anything but. I pointed my dad at the feature before realizing how it worked, and quickly told him to forget it, when I realized it posts screenshots publicly on the web with an unlisted url. I didn't think my dad would understand that, and I worried he would post private information unknowingly.

Do we think users are aware of the privacy implications?

Security:

I can think of a couple of attack vectors on cross origin protections that I can share on request. Seems like this deserves a security review similar to what we did for screensharing (bug 1280403 etc.) ?
Flags: needinfo?(dveditz)
s/back account/bank account/
This bug is actually about the thumbnails in the new tab page, not in Screenshots.
Ah, my bad. I thought it was about the new Firefox screenshots feature.

Yeah, I've seen my mug on the new tab page after using appear.in, and I found it surprising and a bit disturbing, as it's generally a random shot where I never look very good. :)
Flags: needinfo?(dveditz)
Summary: Don't take screenshots of pages where the camera is in use → Don't make thumbnails of pages where the camera is in use
(In reply to Jan-Ivar Bruaroey [:jib] from comment #6)
> Ah, my bad. I thought it was about the new Firefox screenshots feature.
> 
> Yeah, I've seen my mug on the new tab page after using appear.in, and I
> found it surprising and a bit disturbing, as it's generally a random shot
> where I never look very good. :)

Your concerns seem valid anyway, if you open a new bug please CC me in it :)
Priority: -- → P3
Severity: normal → S3

The new tab page doesn't use screenshots anymore, it uses favicons now.

Though, in the future it's likely some new components, like Firefox View, may decide to use the thumbnail service, and then this bug may be relevant. For FlowState we also implemented a persistent storage in Places (disabled by default behind a pref) for which it would matter.

Lowering priority for now, because it's not being used, but we should keep it into account.

Priority: P3 → P5
Whiteboard: [snt-scrubbed][newtab-privacy]
You need to log in before you can comment on or make changes to this bug.