privacy.fingerprintingProtection.pbmode has conflicting default value (`false` vs `true`) in StaticPrefList.yaml vs. firefox.js / geckoview-prefs.js
Categories
(Core :: Privacy: Anti-Tracking, defect)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox136 | --- | fixed |
People
(Reporter: dholbert, Assigned: fklc)
References
Details
Attachments
(1 file)
We've got this about:config pref defined, defaulting to false:
https://searchfox.org/mozilla-central/rev/3076c9156ef84aae253ffdc1d391e0bfab2c406b/modules/libpref/init/StaticPrefList.yaml#15278-15281
- name: privacy.fingerprintingProtection.pbmode
type: RelaxedAtomicBool
value: false
mirror: always
However, it really defaults to true everywhere because we give it a different value in various product-specific .js files:
https://searchfox.org/mozilla-central/rev/3076c9156ef84aae253ffdc1d391e0bfab2c406b/browser/app/profile/firefox.js#2471
pref("privacy.fingerprintingProtection.pbmode", true);
(This^ was originally Nightly-only but it became unconditional as of bug 1849903.)
We've also got it defined for Android here:
https://searchfox.org/mozilla-central/rev/3076c9156ef84aae253ffdc1d391e0bfab2c406b/mobile/android/app/geckoview-prefs.js#394
pref("privacy.fingerprintingProtection.pbmode", true);
Maybe we should remove those two pref(...) lines, and just set the default by doing s/false/true/ in StaticPrefList.yaml, to reduce confusion and duplicated mentions of the pref?
(This would of course mean a change in defaults for other Mozilla-based products like Thunderbird, but I'm not sure Thunderbird has a private browsing mode equivalent anyway, so I'm not sure it matters for them, and to the extent that it does matter, it might be an improvement...)
timhuang, do you know if there's any reason we're using these JS files rather than StaticPrefList.yaml to set the default here at this point?
Comment 1•1 year ago
|
||
It's because we only want to enable fingerprinting protection in PBM for desktop-only first and Mobile later. I think we can use StaticPrefList and remove the pref setting on each product-specific pref js file, given that this is enabled on both Desktop and Mobile.
Updated•1 year ago
|
| Assignee | ||
Comment 2•1 year ago
|
||
We had privacy.fingerprintingProtection.pbmode set to false in StaticPrefList.yaml and true in both firefox.js and geckoview-prefs.js. This was because, as :timhuang said, "we only wanted to enable fingerprinting protection in PBM for desktop-only first and Mobile later."
Description
•