https://www.qubes-os.org/doc/dispvm-customization/

Docs say that we can customize our firefox default startup settings and homepage. Docs say is safe. There is no any warnings at the doc about that.

But when we starting firefox first time to made ANY customization then firefox profile created and on it firefox store prefs.js (settings) with unique IDS for telemetry and ads purposes. On each request to firefox servers for checking updates, search engines updates etc. firefox will send this id with all requests.

So, saving this changes on the DispVM template for customization will identify our firefox copy as exactly the same on each disp vm instance.

Then, if we will use this firefox on ANY dispVM (inherited from private, public) to open some url. Firefox will run with the same profile and it will send on the network the same ID generated on the first step of the template customization.

As a result global advisory will know that the same "private" person and "public" person use the same firefox. Yes?

It's URGENTLY NOT SECURE! But documentation say simple run firefox and "change startup settings and homepage". Is it normal?

p.s. Or there is some other way to change firefox settings for every new created profile without running firefox? I don't know. And documentation does not show this to user, but send the user by the insecure way with such advice and recommendations.


--
Regards

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/a4800377-94d5-0706-851d-ddb867a6e007%40openmailbox.org.
For more options, visit https://groups.google.com/d/optout.

Reply via email to