Skip to content

Guide to the Secure Configuration of Firefox

Rules, Groups, and Values defined within the XCCDF Benchmark

  • Disable JavaScript's Moving Or Resizing Windows Capability

    JavaScript can configure and make changes to the web browser's appearance by specifically moving and resizing browser windows. This can be disabled...
    Rule Medium Severity
  • Disable Firefox network prediction

    Firefox has a feature where it predicts and caches DNS requests. This can be disabled by setting <code>NetworkPrediction</code> to <code>true</code...
    Rule Medium Severity
  • Firefox

    Firefox is an open-source web browser and developed by Mozilla. Web browsers such as Firefox are used for a number of reasons. This section provide...
    Group
  • The Default Firefox Home Page

    The default home page for Firefox users.
    Value
  • The Default Required Firefox File Types

    The default required file types that need to request usage confirmation in Firefox.
    Value
  • Firefox must be configured to disable the installation of extensions.

    Addon installation may be disabled in an administrative policy by setting the <code>InstallAddonsPermission</code> key under <code>policies</code> ...
    Rule Medium Severity
  • Firefox autoplay must be disabled.

    Audio/Video autoplay may be disabled in an administrative policy by setting the <code>Default</code> key under <code>Permissions</code>, <code>Auto...
    Rule Medium Severity
  • Ensure the Content Blocker uBlock Origin is Installed

    The uBlock Origin will be installed automatically by configuring Firefox policy, and updates will be enabled. It can also be installed through the ...
    Rule Medium Severity
  • Enabled Firefox Cryptomining protection

    Cryptomining protection may be enabled by setting privacy.trackingprotection.cryptomining.enabled to true.
    Rule Medium Severity
  • Disable Firefox Development Tools

    Firefox provides development tools which identify detailed information about the browser and its configuration. These details are often also reco...
    Rule Low Severity
  • Disable Firefox deprecated ciphers

    Pocket may be disabled by setting <code>TLS_RSA_WITH_3DES_EDE_CBC_SHA</code> to <code>true</code> under <code>DisabledCiphers</code> in the policie...
    Rule Medium Severity
  • Firefox must be configured to disable form fill assistance.

    The update check may be disabled in an administrative policy by setting the <code>DisableFormHistory</code> key under <code>policies</code> to <cod...
    Rule Medium Severity
  • Disable Firefox Pocket

    Pocket may be disabled by setting DisablePocket to true in the policies file.
    Rule Medium Severity
  • Disable Firefox Studies

    Pocket may be disabled by setting DisableFirefoxStudies to true in the policies file.
    Rule Medium Severity
  • Firefox must be configured to not delete data upon shutdown.

    The default certificate to present may be configured by setting multiple options under <code>SanitizeOnShutdown</code> key. <ul><li> <code>Cache</c...
    Rule Medium Severity
  • Firefox must be configured so that DNS over HTTPS is disabled.

    DNS over HTTPS feature may be disabled via administrative policy by setting <code>Enabled</code> under <code>DNSOverHTTPS</code> to <code>false</co...
    Rule Medium Severity
  • Firefox encrypted media extensions must be disabled.

    Firefox's Encrypted Media Extensions support playback of media content that is subject to Digital Right Management. These extensions may be disable...
    Rule Medium Severity
  • Enabled Firefox Enhanced Tracking Protection

    Enhanced Tracking Protection may be enabled by setting browser.contentblocking.category to strict.
    Rule Medium Severity
  • Disabled Firefox Extension Recommendations

    Extension recommendations may be disabled by setting <code>extensions.htmlaboutaddons.recommendations.enabled</code> to <code>false</code> in the p...
    Rule Medium Severity
  • Firefox must be configured to not automatically update installed add-ons and plugins.

    Firefox has a feature to permit installed add-ons and plugins to automatically update. The check may be disabled in an administrative policy by set...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules