Closed Bug 1942947 Opened 1 year ago Closed 1 year ago

privacy.fingerprintingProtection.pbmode has conflicting default value (`false` vs `true`) in StaticPrefList.yaml vs. firefox.js / geckoview-prefs.js

Categories

(Core :: Privacy: Anti-Tracking, defect)

defect

Tracking

()

RESOLVED FIXED
136 Branch
Tracking Status
firefox136 --- fixed

People

(Reporter: dholbert, Assigned: fklc)

References

Details

Attachments

(1 file)

We've got this about:config pref defined, defaulting to false:
https://searchfox.org/mozilla-central/rev/3076c9156ef84aae253ffdc1d391e0bfab2c406b/modules/libpref/init/StaticPrefList.yaml#15278-15281

- name: privacy.fingerprintingProtection.pbmode
  type: RelaxedAtomicBool
  value: false
  mirror: always

However, it really defaults to true everywhere because we give it a different value in various product-specific .js files:
https://searchfox.org/mozilla-central/rev/3076c9156ef84aae253ffdc1d391e0bfab2c406b/browser/app/profile/firefox.js#2471

pref("privacy.fingerprintingProtection.pbmode", true);

(This^ was originally Nightly-only but it became unconditional as of bug 1849903.)

We've also got it defined for Android here:
https://searchfox.org/mozilla-central/rev/3076c9156ef84aae253ffdc1d391e0bfab2c406b/mobile/android/app/geckoview-prefs.js#394

pref("privacy.fingerprintingProtection.pbmode", true);

Maybe we should remove those two pref(...) lines, and just set the default by doing s/false/true/ in StaticPrefList.yaml, to reduce confusion and duplicated mentions of the pref?

(This would of course mean a change in defaults for other Mozilla-based products like Thunderbird, but I'm not sure Thunderbird has a private browsing mode equivalent anyway, so I'm not sure it matters for them, and to the extent that it does matter, it might be an improvement...)

timhuang, do you know if there's any reason we're using these JS files rather than StaticPrefList.yaml to set the default here at this point?

Flags: needinfo?(tihuang)
Depends on: 1849903

It's because we only want to enable fingerprinting protection in PBM for desktop-only first and Mobile later. I think we can use StaticPrefList and remove the pref setting on each product-specific pref js file, given that this is enabled on both Desktop and Mobile.

Flags: needinfo?(tihuang)
Assignee: nobody → fkilic

We had privacy.fingerprintingProtection.pbmode set to false in StaticPrefList.yaml and true in both firefox.js and geckoview-prefs.js. This was because, as :timhuang said, "we only wanted to enable fingerprinting protection in PBM for desktop-only first and Mobile later."

Pushed by fkilic@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/4e1bafb77fbc Remove privacy.fingerprintingProtection.pbmode from product-specific prefs and set it to true on StaticPrefList.yaml. r=tjr,geckoview-reviewers,calu
Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → 136 Branch
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: