swfdec-mozilla stores privacy sensitive files

Bug #410102 reported by crf
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
swfdec-mozilla (Ubuntu)
Confirmed
Low
Unassigned

Bug Description

Binary package hint: swfdec-mozilla

The swfdec-mozilla flash plugin stores site specific files in ~/.config/swfdec-mozilla.conf
This is a privacy concern, as users may not expect information to be stored in this way, and it isn't obvious how to find, delete or edit it.

This bug is analogous to bug 162045.

Workarounds found in the links in that bug (such as extensions to firefox which delete flash cookies) won't work with swfdec mozilla because it stores site info in a different way.

crf (chrisfahlman)
visibility: private → public
Revision history for this message
Benjamin Otte (Company) (otte) wrote :

Swfdec does not store Flash cookies.

And the configuration file just stores user-set information - the sound and autoplay settings you get in the right-clock menu - and not anything site specific.

Revision history for this message
crf (chrisfahlman) wrote : Re: [Bug 410102] Re: swfdec-mozilla stores privacy sensitive files

It is, in fact, storing site specific settings. Eg, from my file:

[www.nhl.com]
autoplay=true

[global]
autoplay=false

[www.youtube.com]
autoplay=true

[s.ytimg.com]
autoplay=true

Changed in swfdec-mozilla (Ubuntu):
status: New → Confirmed
importance: Undecided → Low
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.