Coder Social home page Coder Social logo

Comments (8)

earthlng avatar earthlng commented on July 16, 2024 1

IMO, no. The FBI exploit used workers and I assume other exploits do too.
I wouldn't advise setting it to true for all pages. (ie. in the user.js)
I'd recommend to either temporarily enable it in about:config before loading those pages, or setup a second profile for those pages if you visit them regularly.
Just my 2 cents

from user.js.

earthlng avatar earthlng commented on July 16, 2024 1

There are often alternatives that work without it: http://regexr.com/
No idea if it's as good as the other one, but if something doesn't work for me I'll find something else that does.

from user.js.

 avatar commented on July 16, 2024

What I have experienced is that Google Street View requires it (Street View only, not maps), requires it means set to true (default). How not to agree with earthlng? But at the same time enabling/disabling on a per-site basis is cumbersome given the sites requiring it are numerous and/or frequently called. There are several add-ons which resume to a toolbar button to simply toggle an about:config setting but unfortunately none that I know that handle this dom.workers.enabled.

On another hand I've encountered no issue setting dom.serviceWorkers.enabled and dom.workers.sharedWorkers.enabled to false.

For a quick access to a given about:config setting it is always possible to create a bookmark of the form, i.e. about:config?filter=dom.workers.enabled which at least makes it faster/easier than opening about:config and retyping the query each time.

from user.js.

 avatar commented on July 16, 2024

@crssi indeed.
Well, if it appears that this dom.workers.enabled is really better set to false than I might very well follow the advise which seems argumented (earthlin:

The FBI exploit used workers and I assume other exploits do too

)

I'd use the about:config?filter=dom.workers.enabled to quickly set it to true when required by a site (Google Street View, regex101.com ...). Cumbersome but again, if that important then perhaps better to false. I'll add an internote (provided by the eponymous FF add-on) to remember.

from user.js.

crssi avatar crssi commented on July 16, 2024

That's why I have asked :)
Since the reported CVEs were already fixed by FF if I am correct... I know, I know, there might be (and sure are) some unknown exploits.

from user.js.

earthlng avatar earthlng commented on July 16, 2024

Looks like the Pwn2Own exploit also used workers. If you need more reasons to disable that shit - well, I'm sorry that's all I got ;)
It's also interesting that the exploited experimental feature was pref-ed off in stable but the code ignored it, at least in one place where it really mattered.

from user.js.

Atavic avatar Atavic commented on July 16, 2024

earthlng: Unless there's something more we can help you with here, please consider closing this @crssi

@earthlng Letting this opened will eventually give us more hints. I see there's a quick decision to close issues here. There are a few ones opened now and you can have up to 25 opened issues before the list generates a second pagelist with a bottom link.

I think these opened issues could give more followers, imho.

from user.js.

earthlng avatar earthlng commented on July 16, 2024

I moved the comments regarding the broken addon into a new issue here

from user.js.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.