[tbb-bugs] #21418 [Applications/Tor Browser]: New Tor Browser http response header, for high security websites

Tor Bug Tracker & Wiki blackhole at torproject.org
Sat Feb 11 06:15:28 UTC 2017


#21418: New Tor Browser http response header, for high security websites
--------------------------------------+--------------------------
 Reporter:  micahlee                  |          Owner:  tbb-team
     Type:  enhancement               |         Status:  new
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------

Comment (by micahlee):

 Tom, that's a very good point about how after the attacker hacks a web
 server they can change the response headers.

 It seems like, to accomplish this for SecureDrop servers, Tor Browser
 would have to bundle some sort of Tor-High-Security preload list of
 domains, similar to the HSTS preload list. And, of course, start
 maintaining that list.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21418#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list