7.9 Enable Warning for External Protocol Handler

Information

This feature configures whether a user is warned before opening an external application for pre-configured protocols were its behavior is undefined.

Rationale:

Enabling a warning to appear before passing data to an external application mitigates the risk that sensitive information will be made vulnerable to outside threats.

Impact:

None - This is the default behavior.

Solution

To establish the recommended configuration, set network.protocol-handler.warn-external-default to true:

Type about:config in the address bar

Type network.protocol-handler.warn-external-default in the filter

Ensure the setting is set as prescribed.

OR

Open the mozilla.cfg file in the installation directory with a text editor

Add the following lines to mozilla.cfg:

lockPref('network.protocol-handler.warn-external-default', true);

Default Value:

True

See Also

https://workbench.cisecurity.org/files/4299

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Unix

Control ID: 667f1f9d2ab5e56aa9badbdd13c6a0074179b08854d480363024c4c07d826de8