1.1.39 (L1) Ensure 'Network Prediction' is set to 'Disabled'

Information

This setting determines if Firefox is allowed to make URL requests without user consent.

The recommended state for this setting is: Disabled

Prefetching URLs could lead to misinformation on browser history such a a website that was not visited but the user hovered over the URL link. This can be misleading in a forensic investigation.

In addition, there is a chance that information can be leaked about a local network if connected to a public network.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Network Prediction

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

None - This is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(3), 800-53|SC-7(4), CSCv7|7.4

Plugin: Windows

Control ID: ce9cd6ddfb8087c9ee4ebe6a770399899df5fae4884c84c2787cf43c7d353b94