Closed Bug 268567 Opened 20 years ago Closed 20 years ago

Insecure default setting of dom.disable_window_open_feature.location

Categories

(Firefox :: Settings UI, defect)

x86
Windows XP
defect
Not set
normal

Tracking

()

VERIFIED DUPLICATE of bug 22183

People

(Reporter: nigel.hawkins, Assigned: bugzilla)

References

Details

User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0

A fresh install seems to have the setting
dom.disable_window_open_feature.location = false

Surely this (and most of the other settings in dom.xxx) should default to true?

With a new window having no location bar, there is no way of telling what site
you are actually looking at. This makes possible phishing attacks easier?

Reproducible: Always
Steps to Reproduce:
Firefox always shows the status bar.  It was decided that this was a better
solution than always showing the location bar.

*** This bug has been marked as a duplicate of 22183 ***
Status: UNCONFIRMED → RESOLVED
Closed: 20 years ago
Resolution: --- → DUPLICATE
Status: RESOLVED → VERIFIED
*** Bug 286981 has been marked as a duplicate of this bug. ***
sorry for bugspam, long-overdue mass reassign of ancient QA contact bugs,
filter on "beltznerLovesGoats" to get rid of this mass change
QA Contact: mconnor → preferences
You need to log in before you can comment on or make changes to this bug.