Strict Transport Security store

Bug reports and enhancement requests
Post Reply
al_9x
Master Bug Buster
Posts: 931
Joined: Thu Mar 19, 2009 4:52 pm

Strict Transport Security store

Post by al_9x »

Georgio,

Please correct me if I am wrong, but it seems that that STS introduces an additional site-pref like or cookie like store, that is neither viewable, editable nor clearable from NS ui. Nor, it seems, is it possible to disable STS.

So in light of the above, a couple of requests:
  1. Option to disable STS. It should be possible to disable any feature that allows sites to store any kind of state (cache, cookies, offline storage, history can all be individually disabled)
  2. UI for viewing, editing and clearing the STS store
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20
User avatar
Giorgio Maone
Site Admin
Posts: 9526
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Strict Transport Security store

Post by Giorgio Maone »

al_9x wrote: Option to disable STS. It should be possible to disable any feature that allows sites to store any kind of state (cache, cookies, offline storage, history can all be individually disabled)
You've got noscript.STS.enabled in about:config.
Furthermore, Private Browsing suspends any persistence for STS, while purging session history erases the STS database as well.
al_9x wrote: UI for viewing, editing and clearing the STS store
Maybe in future. In the meanwhile, the store is easily editable by hand, being a simple text file in your profile named NoScript-STS.db.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)
Alan Baxter
Ambassador
Posts: 1586
Joined: Fri Mar 20, 2009 4:47 am
Location: Colorado, USA

Re: Strict Transport Security store

Post by Alan Baxter »

Giorgio Maone wrote:purging session history erases the STS database as well
I'm unsure which setting covers that. In Options > Privacy > Settings for Clearing History, do I need to check Browsing History or Site Preferences or something else? Same question regarding Tools > Clear Recent History > Details.

Could you clarify?
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3
User avatar
Giorgio Maone
Site Admin
Posts: 9526
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Strict Transport Security store

Post by Giorgio Maone »

@Alan Baxter:
Browser History.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)
User avatar
Giorgio Maone
Site Admin
Posts: 9526
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Strict Transport Security store

Post by Giorgio Maone »

BTW, I don't feel that happy with this "erase on browser history erasure" all-or-nothing feature, especially if you erase it automatically after each session, but on the other hand:
  1. If you cleanup for privacy/shame reasons, you'd better use "Private Browsing", which works just fine with STS and has no downsides.
  2. If you do it for some other policy reason but you have no objection to persist data about certain sites you want to protect by forcing HTTPS, you can still use NoScript Options|Advanced|HTTPS|Behavior.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)
al_9x
Master Bug Buster
Posts: 931
Joined: Thu Mar 19, 2009 4:52 pm

Re: Strict Transport Security store

Post by al_9x »

Giorgio Maone wrote:BTW, I don't feel that happy with this "erase on browser history erasure" all-or-nothing feature
If you are going to piggyback on one of built-in Fx clear items, it should probably be "site preferences."

Or you could add your own item, like TMP does (saved sessions)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.20) Gecko/20081217 Firefox/2.0.0.20
Post Reply