1b97e4b0e6ad500651709b419d0fd3aa0245206d
Mike Perry Update Torbutton design doc.

Mike Perry authored 13 years ago

torbutton/en/design/FF40_AUDIT  1) - Review of https://developer.mozilla.org/en/Firefox_4_for_developers
torbutton/en/design/FF40_AUDIT  2)   - Potential proxy issues
torbutton/en/design/FF40_AUDIT  3)     - DocShell and plugins inside createHTMLDocument?
torbutton/en/design/FF40_AUDIT  4)       - https://developer.mozilla.org/en/DOM/DOMImplementation.createHTMLDocument
torbutton/en/design/FF40_AUDIT  5)     - WebSockets?
torbutton/en/design/FF40_AUDIT  6)     - Media attributes?
torbutton/en/design/FF40_AUDIT  7)       - "buffered"
torbutton/en/design/FF40_AUDIT  8)       - "preload"
torbutton/en/design/FF40_AUDIT  9)       - new codecs?
torbutton/en/design/FF40_AUDIT 10)     - What the hell is a blob url?
torbutton/en/design/FF40_AUDIT 11)       - https://developer.mozilla.org/en/DOM/window.createBlobURL
torbutton/en/design/FF40_AUDIT 12)       - https://developer.mozilla.org/en/DOM/window.revokeBlobURL
torbutton/en/design/FF40_AUDIT 13)       - Seems only relevent to FS injection..
torbutton/en/design/FF40_AUDIT 14)     - WebThreads are OK:
torbutton/en/design/FF40_AUDIT 15)       - https://developer.mozilla.org/En/Using_web_workers
torbutton/en/design/FF40_AUDIT 16)       - Network activity blocked by content policy
torbutton/en/design/FF40_AUDIT 17)   - Fingerprinting issues:
torbutton/en/design/FF40_AUDIT 18)     - New screen attributes
torbutton/en/design/FF40_AUDIT 19)       - https://developer.mozilla.org/en/DOM/window.mozInnerScreenX, Y
Mike Perry Update design doc to reflec...

Mike Perry authored 13 years ago

torbutton/en/design/FF40_AUDIT 20)     - High Res Animation Timers:
torbutton/en/design/FF40_AUDIT 21)       - https://developer.mozilla.org/en/DOM/window.mozAnimationStartTime
torbutton/en/design/FF40_AUDIT 22)       - https://developer.mozilla.org/en/DOM/Animations_using_MozBeforePaint
torbutton/en/design/FF40_AUDIT 23)         - 50-60hz max.. Can we leverage this?
torbutton/en/design/FF40_AUDIT 24)     - timeStamps on keystroke events
torbutton/en/design/FF40_AUDIT 25)       - https://developer.mozilla.org/en/DOM/event.timeStamp
Mike Perry Update Torbutton design doc.

Mike Perry authored 13 years ago

torbutton/en/design/FF40_AUDIT 26)     - Bounding rectangles -> window sizes?
torbutton/en/design/FF40_AUDIT 27)       - Maybe not display sizes, but seems possible to fingerprint rendered
torbutton/en/design/FF40_AUDIT 28)         content size.. ugh.
torbutton/en/design/FF40_AUDIT 29)         - https://developer.mozilla.org/en/DOM/element.getBoundingClientRect
torbutton/en/design/FF40_AUDIT 30)         - https://developer.mozilla.org/en/dom:range
torbutton/en/design/FF40_AUDIT 31)     - CSS resize, media queries, etc..
torbutton/en/design/FF40_AUDIT 32)     - WebGL may also expose screen properties and video card properties:
torbutton/en/design/FF40_AUDIT 33)       - https://developer.mozilla.org/en/WebGL
torbutton/en/design/FF40_AUDIT 34)       - https://www.khronos.org/registry/webgl/specs/1.0/#5.2
torbutton/en/design/FF40_AUDIT 35)       - https://www.khronos.org/registry/webgl/specs/1.0/#5.11
torbutton/en/design/FF40_AUDIT 36)     - SVG needs auditing. It may also expose absolute coords, but appears OK
torbutton/en/design/FF40_AUDIT 37)       - https://developer.mozilla.org/en/SVG/SVG_animation_with_SMIL
torbutton/en/design/FF40_AUDIT 38)     - Mouse events reveal desktop coordinates
torbutton/en/design/FF40_AUDIT 39)       - https://bugzilla.mozilla.org/show_bug.cgi?id=503943
torbutton/en/design/FF40_AUDIT 40)       - https://developer.mozilla.org/en/DOM/Event/UIEvent/MouseEvent
torbutton/en/design/FF40_AUDIT 41)       - Actual screen dimensions not exposed
torbutton/en/design/FF40_AUDIT 42)   - Identifier Storage
torbutton/en/design/FF40_AUDIT 43)     - Content Secuity Properties may need clearing:
torbutton/en/design/FF40_AUDIT 44)       - https://developer.mozilla.org/en/Security/CSP
torbutton/en/design/FF40_AUDIT 45)     - STS cache needs clearing
torbutton/en/design/FF40_AUDIT 46)     - New window.history functions may allow state smuggling
torbutton/en/design/FF40_AUDIT 47)       - https://developer.mozilla.org/en/DOM/Manipulating_the_browser_history
Mike Perry Update FF bugs in design do...

Mike Perry authored 13 years ago

torbutton/en/design/FF40_AUDIT 48)