Re: UK Government's documentation on Firefox security

Gervase Markham <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On 02/11/15 16:10, Gijs Kruitbosch wrote:
> I don't really understand what the point of such a pref would be. Surely
> then the user would first flip the pref and then bypass the safebrowsing
> warning?

The document explains how you can lock preferences in an enterprise
scenario. I assume we still support that?

>> 6) Can't disable Basic/Digest Auth over HTTP
>>
>> -- UNCO bug about warning:
>>       https://bugzilla.mozilla.org/show_bug.cgi?id=1185145
> 
> Note that we already warn about sending the credentials if not done
> through the prompt.

We warn on every transmission of credentials over HTTP?

>> 9) No security event logging
> 
> What is a "security event" ?

The document says:

"Firefox does not provide any built-in mechanism for logging events for
enterprise analysis. It is therefore not possible to determine whether
installations adhere to security policies, nor alert on security events
such as on-screen security warnings or browser crashes"

Gerv
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.