From d82791a93347799898487adcabe827807abda753 Mon Sep 17 00:00:00 2001 From: Thorin-Oakenpants Date: Fri, 5 Jan 2018 09:02:59 +1300 Subject: [PATCH] 1241->active: block mixed passive content #326 --- user.js | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/user.js b/user.js index 442ce73..5411c30 100644 --- a/user.js +++ b/user.js @@ -775,9 +775,8 @@ user_pref("network.stricttransportsecurity.preloadlist", true); /* 1240: disable insecure active content on https pages - mixed content * [1] https://trac.torproject.org/projects/tor/ticket/21323 ***/ user_pref("security.mixed_content.block_active_content", true); -/* 1241: disable insecure passive content (such as images) on https pages - mixed context - * [WARNING] When set to true, this will visually break many sites (March 2017) ***/ - // user_pref("security.mixed_content.block_display_content", true); +/* 1241: disable insecure passive content (such as images) on https pages - mixed context ***/ +user_pref("security.mixed_content.block_display_content", true); /* 1242: enable Mixed-Content-Blocker to use the HSTS cache but disable the HSTS Priming requests (FF51+) * Allow resources from domains with an existing HSTS cache record or in the HSTS preload list * to be upgraded to HTTPS internally but disable sending out HSTS Priming requests, because