[tbb-bugs] #21323 [Applications/Tor Browser]: Activate mixed content blocking

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Jan 26 23:03:55 UTC 2017


#21323: Activate mixed content blocking
--------------------------------------+-----------------------------------
 Reporter:  arthuredelstein           |          Owner:  tbb-team
     Type:  defect                    |         Status:  needs_information
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:  TorBrowserTeam201701R     |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+-----------------------------------

Comment (by legind):

 We test rulesets with the default settings in browsers which blocks active
 mixed content, but note the comment here: https://www.eff.org/https-
 everywhere/rulesets#mixed-content-blocking-mcb

 > Some rulesets may trigger active mixed content (i.e. scripts loaded over
 HTTP instead of HTTPS). This type of mixed content is blocked in both
 Chrome and Firefox, before HTTPS Everywhere has a chance to rewrite the
 URLs to an HTTPS version. This generally breaks the site. However, the Tor
 Browser doesn't block mixed content, in order to allow HTTPS Everywhere to
 try and rewrite the URLs to an HTTPS version.
 >
 > To enable a rule only on platforms that allow mixed content (currently
 only the Tor Browser), you can add a `platform="mixedcontent"` attribute
 to the ruleset element.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21323#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list