UCF STIG Viewer Logo

Firefox private browsing must be disabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-251563 FFOX-00-000019 SV-251563r807161_rule Medium
Description
Private browsing allows the user to browse the internet without recording their browsing history/activity. From a forensics perspective, this is unacceptable. Best practice requires that browser history is retained.
STIG Date
Mozilla Firefox Security Technical Implementation Guide 2022-09-09

Details

Check Text ( C-54998r807159_chk )
Type "about:policies" in the browser window.

If "DisablePrivateBrowsing" is not displayed under Policy Name or the Policy Value is not "true", this is a finding.
Fix Text (F-54952r807160_fix)
Windows group policy:
1. Open the group policy editor tool with "gpedit.msc".
2. Navigate to Policy Path: Computer Configuration\Administrative Templates\Mozilla\Firefox
Policy Name: Disable Private Browsing
Policy State: Enabled

macOS "plist" file:
Add the following:
DisablePrivateBrowsing


Linux "policies.json" file:
Add the following in the policies section:
"DisablePrivateBrowsing": true