diff --git a/Optional-Hardening.md b/Optional-Hardening.md index f1ffe7b..2dfc636 100644 --- a/Optional-Hardening.md +++ b/Optional-Hardening.md @@ -116,6 +116,17 @@ user_pref("default-browser-agent.enabled", false); *** +### Require Safe Negotiation + +Some sites, like `EA.com`, will not let you login due to their weak encryption. + +``` +// PREF: require safe SSL negotiation +user_pref("security.ssl.require_safe_negotiation", true); +``` + +*** + ### Cross-origin referer Do not send a [referer](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referer) when navigating to a different site (e.g., `google.com` → `facebook.com`).