[tor-bugs] #20195 [HTTPS Everywhere/EFF-HTTPS Everywhere]: HTTPS Everywhere's SSL Observatory code doesn't honor domain isolation.

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Oct 7 09:52:06 UTC 2016


#20195: HTTPS Everywhere's SSL Observatory code doesn't honor domain isolation.
-------------------------------------------------+-------------------------
 Reporter:  yawning                              |          Owner:  legind
     Type:  defect                               |         Status:
                                                 |  assigned
 Priority:  High                                 |      Milestone:
Component:  HTTPS Everywhere/EFF-HTTPS           |        Version:
  Everywhere                                     |
 Severity:  Major                                |     Resolution:
 Keywords:  tbb-linkability                      |  Actual Points:
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by bugzilla):

 Replying to [comment:10 gk]:
 > > {{{
 > > [09-22 08:31:02] Torbutton WARN: no SOCKS credentials found for
 current document.
 > > }}}
 TBB has a lot of places with this warning, e.g. while fetching
 `RecommendedTBBVersions`, so what?
 > Alright, so here is what is going on. First, do you see the weird
 floating point number thing appended to the `#` in the
 `check.torproject.org` URL?
 FP with two dots? He-he.
 > Torbutton does not do such things.
 But it looked like yours :)
 > It is visible there that the request does not go over the catch-all
 circuit but rather is put on one without any username/password isolation
 at all.
 If `getinfo circuit-status` doesn't lie, the request does go over the
 catch-all circuit, even though without any username/password isolation at
 all.

 This is another one recent crap from HTTPSE: it look like it was developed
 as a virus or without security audit at all. Is it suitable for TBB?

 (Also it is doing 3 requests in a row to `check.torproject.org`, on
 `NEWNYM` too.)

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/20195#comment:14>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list