[tbb-bugs] #17965 [Tor Browser]: Isolate HPKP pinning to url bar domain

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Jan 1 23:28:47 UTC 2016


#17965: Isolate HPKP pinning to url bar domain
-------------------------------------------------+-------------------------
 Reporter:  mikeperry                            |          Owner:  tbb-
     Type:  defect                               |  team
 Priority:  High                                 |         Status:
Component:  Tor Browser                          |  assigned
 Severity:  Normal                               |      Milestone:
 Keywords:  tbb-linkability,                     |        Version:
  TorBrowserTeam201601                           |     Resolution:
Parent ID:                                       |  Actual Points:
  Sponsor:                                       |         Points:
-------------------------------------------------+-------------------------
Changes (by gk):

 * status:  needs_information => assigned


Comment:

 Replying to [comment:2 gk]:
 > Replying to [comment:1 gk]:
 > > What is the relationship of this ticket to #6458? I thought we should
 deal with both issues in the latter (see my comment:11:ticket:6458) Is
 there a reason you want to split HPKP off?
 >
 > Oh, I am asking here as HSTS seems to creep into your description of
 this ticket. :)

 (Answering my question(s) myself): After thinking a bit more about it it
 seems reasonable to not deal with both features in the same ticket as they
 (and the linkability attacks allowed by them) are different enough and
 unrelated.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/17965#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list