UCF STIG Viewer Logo

Cryptomining protection must be enabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-102881 DTBF215 SV-111843r1_rule Medium
Description
The Content Blocking/Tracking Protection feature stops Firefox from loading content from malicious sites. The content might be a script or an image, for example. If a site is on one of the tracker lists you set Firefox to use, then the fingerprinting script (or other tracking script/image) will not be loaded from that site. Cryptomining scripts use your computer’s central processing unit (CPU) to invisibly mine cryptocurrency.
STIG Date
Mozilla FireFox Security Technical Implementation Guide 2020-06-19

Details

Check Text ( C-101627r1_chk )
Type "about:config" in the address bar, verify that the preference name “privacy.trackingprotection.cryptomining.enabled" is set to “true” and locked.

Criteria: If the parameter is set incorrectly, then this is a finding. If the setting is not locked, then this is a finding.
Fix Text (F-108421r1_fix)
Ensure the preference “privacy.trackingprotection.cryptomining.enabled" is set and locked to the value of “true”.