Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-223173 | DTBF215 | SV-223173r612236_rule | Medium |
Description |
---|
The Content Blocking/Tracking Protection feature stops Firefox from loading content from malicious sites. The content might be a script or an image, for example. If a site is on one of the tracker lists you set Firefox to use, then the fingerprinting script (or other tracking script/image) will not be loaded from that site. Cryptomining scripts use your computer’s central processing unit (CPU) to invisibly mine cryptocurrency. |
STIG | Date |
---|---|
Mozilla Firefox Security Technical Implementation Guide | 2020-12-10 |
Check Text ( C-24846r531336_chk ) |
---|
Type "about:config" in the address bar, verify that the preference name “privacy.trackingprotection.cryptomining.enabled" is set to “true” and locked. Criteria: If the parameter is set incorrectly, then this is a finding. If the setting is not locked, then this is a finding. |
Fix Text (F-24834r531337_fix) |
---|
Ensure the preference “privacy.trackingprotection.cryptomining.enabled" is set and locked to the value of “true”. |