Re: UK Government's documentation on Firefox security
Gervase Markham <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On 02/11/15 16:10, Gijs Kruitbosch wrote: > I don't really understand what the point of such a pref would be. Surely > then the user would first flip the pref and then bypass the safebrowsing > warning? The document explains how you can lock preferences in an enterprise scenario. I assume we still support that? >> 6) Can't disable Basic/Digest Auth over HTTP >> >> -- UNCO bug about warning: >> https://bugzilla.mozilla.org/show_bug.cgi?id=1185145 > > Note that we already warn about sending the credentials if not done > through the prompt. We warn on every transmission of credentials over HTTP? >> 9) No security event logging > > What is a "security event" ? The document says: "Firefox does not provide any built-in mechanism for logging events for enterprise analysis. It is therefore not possible to determine whether installations adhere to security policies, nor alert on security events such as on-screen security warnings or browser crashes" Gerv