[tbb-bugs] #26614 [Applications/Tor Browser]: audit or disable the Web Authentication API

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Jul 2 15:47:52 UTC 2018

#26614: audit or disable the Web Authentication API
     Reporter:  mcs                  |      Owner:  tbb-team
         Type:  defect               |     Status:  new
     Priority:  Medium               |  Milestone:
    Component:  Applications/Tor     |    Version:
  Browser                            |   Keywords:  ff60-esr,
     Severity:  Normal               |  TorBrowserTeam201807
Actual Points:                       |  Parent ID:
       Points:                       |   Reviewer:
      Sponsor:                       |
 As of Firefox 60, Mozilla has enabled support for the Web Authentication
 API by default. We should audit it or at least understand it better, or we
 should disable it by setting `security.webauth.webauthn` to `false`. See:

Ticket URL: <https://trac.torproject.org/projects/tor/ticket/26614>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online

More information about the tbb-bugs mailing list