7.9 Enable Warning for External Protocol Handler

Information

This feature configures whether a user is warned before opening an external application for pre-configured protocols were its behavior is undefined.

Rationale:

Enabling a warning to appear before passing data to an external application mitigates the risk that sensitive information will be made vulnerable to outside threats.

Impact:

None - This is the default behavior.

Solution

To establish the recommended configuration, set network.protocol-handler.warn-external-default to true:

Type about:config in the address bar

Type network.protocol-handler.warn-external-default in the filter

Ensure the setting is set as prescribed.

OR

Open the mozilla.cfg file in the installation directory with a text editor

Add the following lines to mozilla.cfg:

lockPref('network.protocol-handler.warn-external-default', true);

Default Value:

True

See Also

https://workbench.cisecurity.org/files/4299

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Windows

Control ID: 7dadf2a9bdc50cb694f7be94b1cb690c78bd3d66c889c90e7795ecdd28d2e243