No warning when server uses not matching rpid for Passkey usage

When i try to login via Passkey on a server that sends a rpid in the challenge-json that does not match the domain there is only a warning in the console. Why is there no… (читать ещё)

When i try to login via Passkey on a server that sends a rpid in the challenge-json that does not match the domain there is only a warning in the console. Why is there no warning where any user can see it e.g. as a Pop-Up? I feel like this might be a way to get users to downgrade from passkey to password in a phishing-attempt.

Thanks for your Answers.

Задан Simon Gräff 1 месяц назад

Последний ответ от markwarner22 1 месяц назад

History not completely deletable

Hello, I'm using Firefox since day 1. Now I just discovered that it's virtually impossible to completely delete the history in Firefox. I do try to delete my browsing hi… (читать ещё)

Hello, I'm using Firefox since day 1. Now I just discovered that it's virtually impossible to completely delete the history in Firefox. I do try to delete my browsing history as suggested in the Firefox documentation. The problem is with "Firefox suggests". Pages that should have been cleared out by deleting the browser history, be it in settings or over the three bar menu still show up there. To me this is unacceptable. I can obfuscate by disabling all address bar search options, but the history data is then still stored somewhere. I do not use any cloud services. Attached you can see an image of what I mean. All browsing history should have been deleted but still show up (also after restarting Firefox).

I would really like to continue to use Firefox but only if I can delete ALL browsing history. Thank you. Best Regards

Задан Crashdog 1 месяц назад

Последний ответ от cor-el 1 месяц назад

Valid S/MIME signature not showing

I have a valid x.509 certificate and am able to send S/MIME signed emails via Thunderbird 128.5.1esr (64-bit) [Windows 10.0.22631.4460). The private key is stored on a Y… (читать ещё)

I have a valid x.509 certificate and am able to send S/MIME signed emails via Thunderbird 128.5.1esr (64-bit) [Windows 10.0.22631.4460).

The private key is stored on a Yubikey. However, the certifying authorities are in the Thunderbird Authorities.

I can send S/MIME signed emails.

Viewing the received email in Gmail (web) correctly shows that email is signed, verified by a known issuer, and provides links to the certificates.

Viewing the same received email in Thunderbird only shows the S/MIME badge/icon when the Yubikey is connected.

Is this intentional behavior? Why doesn't Thunderbird show the S/MIME badge?

Задан mental-tarsus02 1 месяц назад

Did Not Connect: Potential Security Issue

I have been having this issue for a while now. I will get this message on different websites, and then if I try again later it might work. It seems like it's a random cha… (читать ещё)

I have been having this issue for a while now. I will get this message on different websites, and then if I try again later it might work. It seems like it's a random chance of me getting this error. I have tried "about:config" commands as suggested on other posts on this forum and they didn't work. I checked my licenses, proxy settings and still nothing. I got another web browser to see if it's my PC or Firefox, and the other browser worked just fine. I am guessing there is something I need to do within Firefox, but I am not sure what that is.

Задан jurgen24 1 месяц назад

Последний ответ от jonzn4SUSE 1 месяц назад

Sicherheit

Hallo mein Handy und persönliche Daten werden von Häckern oder Cyber Angriffe die klauen mein Daten Können sie mir Helfen damit?

Задан Mohamed Moham 1 месяц назад

Remote content notification bar has disappeared and I can not access content I wish to see. How can I get it back

Remote content notification bar has disappeared and I can not access content I wish to see. How can I get it back without specifying individual email accounts? In other w… (читать ещё)

Remote content notification bar has disappeared and I can not access content I wish to see. How can I get it back without specifying individual email accounts? In other words I liked to be offered the choice each time remote content is blocked.

Задан ianstephencollins 1 месяц назад

Mozilla virus pop ups- legit?

Starting this morning, I am constantly receiving pop ups supposedly from Mozilla regarding viruses. It says "click here to fix the error" Are these legit? I have run my… (читать ещё)

Starting this morning, I am constantly receiving pop ups supposedly from Mozilla regarding viruses. It says "click here to fix the error" Are these legit?

I have run my anti-virus and malware and they show nothing. I also have pop ups blocked.

Задан Peter Lund 1 месяц назад

Последний ответ от James 1 месяц назад

Options for manually editing history are... worse (133.0)

I like to prune my browser history manually to keep things I might need to get back to in the near future, but don't want to clog up my bookmarks with, and get rid of the… (читать ещё)

I like to prune my browser history manually to keep things I might need to get back to in the near future, but don't want to clog up my bookmarks with, and get rid of the rest. As of version 133, this has been made a lot more difficult, unless I'm missing an option somewhere. - In Settings, there's only the "all or nothing" approach for browser history, no way to be selective. (You can be selective when deleting cookies, but not history.) - In the History sidebar, where I used to do this, you can group by date or site. I used both: Group by site to avoid deleting the recent stuff I want to keep, and group by date to delete old things I no longer need (anything over a week old). It's no longer possible to delete e.g. everything from the gmail domain, or everything from October. I have to delete each. and. every. site. individually. For Gmail, for example, this means roughly a gajillion lines per visit. - In the sidebar, the keyboard Delete button no longer works either. I have to manually click the trash can icon, wait for it to vanish, click the next one...

Is the option to edit this efficiently completely gone, or am I missing something?

Задан Lameow 1 месяц назад

Последний ответ от markwarner22 1 месяц назад

'Cookie Mismatch' in Google

It has been working fine - now I get this message: 'We've detected a problem with your cookie settings. Enable cookies Make sure your cookies are enabled. To enable coo… (читать ещё)

It has been working fine - now I get this message:

'We've detected a problem with your cookie settings. Enable cookies

Make sure your cookies are enabled. To enable cookies, follow these browser-specific instructions. Clear cache and cookies

If you have cookies enabled but are still having trouble, clear your browser's cache and cookies. Adjust your privacy settings

If clearing your cache and cookies doesn't resolve the problem, try adjusting your browser's privacy settings. If your settings are on high, manually add www.google.com to your list of allowed sites. Learn more'

I've tried making Google an exception, to no avail.

Задан Christel5 3 месяца назад

Последний ответ от jscher2000 - Support Volunteer 1 месяц назад

Error code: SEC_ERROR_REVOKED_CERTIFICATE - OCSP query fails: how to report?

Today I suddenly started receiving the error code: SEC_ERROR_REVOKED_CERTIFICATE on a secure authentication page that was working until a few hours earlier, belonging to … (читать ещё)

Today I suddenly started receiving the error code: SEC_ERROR_REVOKED_CERTIFICATE on a secure authentication page that was working until a few hours earlier, belonging to a major national bank.

https://www.ssllabs.com/ssltest/ cannot reach that page, other SSL checking sites report variable results (some say one cert in the chain has expired after a CRL, others say all is OK)

The same page/site works flawlessly on Chrome. Firefox incompatibility with popular portals is a growing trend unfortunately.

After a little digging with developer tools, it comes out the OCSP query reports the REVOKED_CERTIFICATE error. Disabling the "Query OCSP [..]" option in Firefox that website starts working fine again.

Now, I would like to still keep using the OCSP queries ON, and I definitely want to keep using Firefox for everything.

My question is: when a portal or website is found to be broken with Firefox (with default settings), with a root cause found like in this case, how can it be reported?

Having a clear report path would be useful to try to make the browser more compatible (in this case : was this a bug? Some wrong information on OCSP responders? Some mess caused by the website mantainers?)

Задан lucrs4096 1 месяц назад

Последний ответ от chris wilson 1 месяц назад

Uncontrolled connections

I start firefox with following policies.json { "policies": { "AppAutoUpdate": false, "BackgroundAppUpdate": false, "DisableAppUpdate": true, … (читать ещё)

I start firefox with following policies.json

{

   "policies": {
       "AppAutoUpdate": false,
       "BackgroundAppUpdate": false,
       "DisableAppUpdate": true,
       "DisableFeedbackCommands": true,
       "DisableFirefoxAccounts": true,
       "DisableFirefoxStudies": true,
       "DisablePocket": true,
       "DisableSystemAddonUpdate": true,
       "DisableTelemetry": true,
       "ExtensionUpdate": false
   }

}

But uncontrolled connections to the following addresses continue anyway:

I may have missed something and you can tell me how I can control these connections inclusive. Because all other connections can be controlled by configs and policies. But not these and it raises big questions. It seems to me that the browser should allow to configure any network requests that aren't related to the user web browsing itself. If some connections cannot be controlled in any way then I can't call it anything other than either a bug or an attempt to monitor users as do in Google Chrome.

Задан anpic 1 месяц назад

iOS viewing cookie value

Is it possible with the iOS app (128.3) to view values of cookies stored for a website? It doesn’t appear as though that is data that can be synced to desktop, either. (W… (читать ещё)

Is it possible with the iOS app (128.3) to view values of cookies stored for a website? It doesn’t appear as though that is data that can be synced to desktop, either. (Would make sense for some browser-specific key:value) If it helps, I know the name of the cookie I’m specifically looking for.

Задан C. Aleph 1 месяц назад

  • Решено

Malwarebytes keeps blocking Mozilla files that seem to originate from it's folder in my laptop as riskware

Malwarebytes keeps blocking Mozilla files that seem to originate from it's folder in my laptop as riskware. Is this something I should make exceptions for? Or is it ris… (читать ещё)

Malwarebytes keeps blocking Mozilla files that seem to originate from it's folder in my laptop as riskware. Is this something I should make exceptions for? Or is it riskware. I'm running Win 11

Задан Fran Turner 1 месяц назад

Дан ответ jscher2000 - Support Volunteer 1 месяц назад

sécurité et vie privée

Bonjour Madame Monsieur, Afin d'utiliser Firefox je désire connaître vos conditions de confidentialités pour ne pas avoir de phishing. Car j'ai déjà été victime d'usurp… (читать ещё)

Bonjour Madame Monsieur, Afin d'utiliser Firefox je désire connaître vos conditions de confidentialités pour ne pas avoir de phishing. Car j'ai déjà été victime d'usurpations de données personnelles. Merci

Задан Davide Alessandro Molina 1 месяц назад