Guide to the Secure Configuration of Firefox
Rules, Groups, and Values defined within the XCCDF Benchmark
-
Ensure the Content Blocker uBlock Origin is Installed
The uBlock Origin will be installed automatically by configuring Firefox policy, and updates will be enabled. It can also be installed through the Mozilla Add-Ons store at https://addons.mozilla.or...Rule Medium Severity -
Enabled Firefox Cryptomining protection
Cryptomining protection may be enabled by settingprivacy.trackingprotection.cryptomining.enabled
totrue
.Rule Medium Severity -
Disable Firefox Development Tools
Firefox provides development tools which identify detailed information about the browser and its configuration. These details are often also recorded into a log file, giving an attacker the abili...Rule Low Severity -
Disable Firefox deprecated ciphers
Pocket may be disabled by settingTLS_RSA_WITH_3DES_EDE_CBC_SHA
totrue
underDisabledCiphers
in the policies file.Rule Medium Severity -
Firefox must be configured to disable form fill assistance.
The update check may be disabled in an administrative policy by setting theDisableFormHistory
key underpolicies
totrue
.Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Capacity
Modules