Pier Angelo Vendrame pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: a33d5f55 by Pier Angelo Vendrame at 2026-09-22T09:05:26+02:00 fixup! TB 23247: Communicating security expectations for .onion TB 45343: Hide the custom roots warning for onion sites. At the moment, we allow self-signed certificates for onion services. However, tghere are several warnings we need to hide, as they would be misleading of the actual situation. Also, hide any field we get from the certificate, to avoid phishing. In the future, we may re-evaluate accepting self-certificates from onion services. - - - - - 1 changed file: - browser/base/content/browser-siteIdentity.js Changes: ===================================== browser/base/content/browser-siteIdentity.js ===================================== @@ -1192,7 +1192,11 @@ var gIdentityHandler = { this._updateAttribute(element, "ciphers", ciphers); this._updateAttribute(element, "mixedcontent", mixedcontent); this._updateAttribute(element, "isbroken", this._isBrokenConnection); - element.toggleAttribute("customroot", this._hasCustomRoot()); + // tor-browser#45343: hide the custom root warning for Onion sites. + element.toggleAttribute( + "customroot", + this._hasCustomRoot() && !this._uriIsOnionHost + ); this._updateAttribute(element, "httpsonlystatus", httpsOnlyStatus); } @@ -1237,6 +1241,14 @@ var gIdentityHandler = { } } + // tor-browser#45343: hide the custom root warning for Onion sites, but also + // empty the verifier, since it might be a lie. + if (this._uriIsOnionHost && this._hasCustomRoot()) { + owner = ""; + supplemental = ""; + verifier = ""; + } + // Push the appropriate strings out to the UI. document.l10n.setAttributes( this._identityPopupMainViewHeaderLabel, View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/a33d5f55... -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/a33d5f55... You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
participants (1)
-
Pier Angelo Vendrame (@pierov)