Closed Bug 1702295 Opened 3 years ago Closed 3 years ago

Collect the about: page that unexpected-security violations occur on

Categories

(Firefox :: Security, enhancement)

enhancement

Tracking

()

RESOLVED FIXED
89 Branch
Tracking Status
firefox89 --- fixed

People

(Reporter: tjr, Assigned: tjr)

References

Details

Attachments

(2 files)

In the Telemetry Events for Javascript Load we are seeing occurrences coming from the about: scheme; but we don't collect the individual about: page. The bug is requesting to add additional telemetry that will collect the full about url.

While I think collecting the full url is safe, just to be double-safe I'm going to exclude any sort of querystring or hash that may be present on the URL. This will at least allow us to narrow it down to the about: page and hopefully we can figure it out from there.

Attached file data-review.txt
Attachment #9212879 - Flags: data-review?(chutten)

Comment on attachment 9212879 [details]
data-review.txt

PRELIMINARY NOTES:
For indefinite collections an individual must be listed as responsible for the collection.
To avoid needing to roundtrip this again, I've assumed that :tjr is that individual.
If that isn't the case, please either identify someone here or mark the attachment as obsolete and clear the data-review+ as the data review is conditional on there being an individual responsible.

DATA COLLECTION REVIEW RESPONSE:

Is there or will there be documentation that describes the schema for the ultimate data set available publicly, complete and accurate?

Yes.

Is there a control mechanism that allows the user to turn the data collection on and off?

Yes. This collection is Telemetry so can be controlled through Firefox's Preferences.

If the request is for permanent data collection, is there someone who will monitor the data over time?

Yes, :tjr is responsible.

Using the category system of data types on the Mozilla wiki, what collection type of data do the requested measurements fall under?

Category 2, Interaction.

Is the data collection request for default-on or default-off?

Default on for all channels.

Does the instrumentation include the addition of any new identifiers?

No.

Is the data collection covered by the existing Firefox privacy notice?

Yes.

Does there need to be a check-in in the future to determine whether to renew the data?

No. This collection is permanent.


Result: datareview+

Attachment #9212879 - Flags: data-review?(chutten) → data-review+
Pushed by tritter@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/4b19c4cb83d0
Collect the about: page that unexpected-security violations occur on r=ckerschb
Status: NEW → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → 89 Branch
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: