[tbb-bugs] #13747 [Applications/Tor Browser]: Block non .onion content on .onion addresses (was: Block Mixed Content on .onion Addresses)

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Jan 27 20:04:44 UTC 2017


#13747: Block non .onion content on .onion addresses
--------------------------------------+--------------------------
 Reporter:  legind                    |          Owner:  tbb-team
     Type:  enhancement               |         Status:  new
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:  tbb-security              |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------
Changes (by cypherpunks):

 * keywords:   => tbb-security


Comment:

 Previous Summary makes sense too, but is a dupe of #13033.
 > One would hope that an http THS would never include remote resources
 from an http site if they would like to protect their users.
 and from https?
 > It seems like a good security measure to disallow http resources from
 being loaded in TBB.
 at all?

 Anyways, what should be done asap is a warning system for .onion sites
 like that for passive and active mixed content, which allows to
 distinguish altered sites by looking at the address bar.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/13747#comment:8>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list