[tbb-bugs] #19200 [Applications/Tor Browser]: HTML5 video not blocked with placeholder, plays automatically

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Nov 17 19:29:04 UTC 2016


#19200: HTML5 video not blocked with placeholder, plays automatically
-------------------------------------------------+-------------------------
 Reporter:  potato                               |          Owner:  tbb-
                                                 |  team
     Type:  defect                               |         Status:
                                                 |  needs_information
 Priority:  High                                 |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Major                                |     Resolution:
 Keywords:  tbb-security-slider,                 |  Actual Points:
  tbb-6.0-issues, noscript, GeorgKoppen201611,   |
  TorBrowserTeam201611                           |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by i139):

 Replying to [comment:38 ma1]:
 >  That's way I believe restricting MSE usage as an additional permission
 for the site (or the webpage, as I said, for convenience rather than
 security, e.g. on Youtube) is the most sensible approach: exactly the same
 NoScript already adopts for WebGL.

 is the best option how we have now.

 however saying about js and codec is proper make a statement about firefox
 codec, in firefox 51 mozilla adding support to flac, noscript or torbutton
 could use a serie of checkbox for codec or for media format, avoiding
 unnecessary and unsafe codec/format adding a extra protection for user

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/19200#comment:40>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list