[tbb-bugs] #19210 [Applications/Tor Browser]: NoScript places WebM videos too late behind click-to-play in higher security levels

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Sep 28 11:38:32 UTC 2016


#19210: NoScript places WebM videos too late behind click-to-play in higher
security levels
-------------------------------------------------+-------------------------
 Reporter:  gk                                   |          Owner:  tbb-
                                                 |  team
     Type:  defect                               |         Status:
                                                 |  needs_information
 Priority:  High                                 |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Major                                |     Resolution:
 Keywords:  tbb-regression, tbb-security-        |  Actual Points:
  slider, tbb-6.0-issues                         |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by test400):

 I confirm behavior for linked video (‚Äčhttp://gensho.acc.umu.se/pub/debian-
 meetings/2016/mini-debconf-vienna/webm/Debian_Installer_for_Novena.webm)

 and all other webm i request directly, also for mp4 files.

 Video plays for 5 seconds, then stops.
 Although sometimes Shorter, only 2 seconds play (even if video is longer)

 Behavior for Embedded video (webm and mp4) is correct though (blocked by
 default, confirm enables).

 With noscript set to "temporarily allow all this page", behavior is same
 for first direct request.
 After requesting video directly a second time, video plays full without
 confirm need.
 This is also not wanted behavior.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/19210#comment:8>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list