[tbb-bugs] #13747 [Applications/Tor Browser]: Block non .onion content on .onion addresses

Tor Bug Tracker & Wiki blackhole at torproject.org
Sat Jan 28 00:23:34 UTC 2017


#13747: Block non .onion content on .onion addresses
--------------------------------------+--------------------------
 Reporter:  legind                    |          Owner:  tbb-team
     Type:  enhancement               |         Status:  new
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:  tbb-security              |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------

Comment (by legind):

 Replying to [comment:8 cypherpunks]:
 > Previous Summary makes sense too, but is a dupe of #13033.
 > > One would hope that an http THS would never include remote resources
 from an http site if they would like to protect their users.
 > and from https?

 This is addressed in the next sentence: "In fact, one would hope that a
 THS would never load any resources at all from a source they do not
 control."

 > > It seems like a good security measure to disallow http resources from
 being loaded in TBB.
 > at all?

 No, the specific resources mentioned in this ticket, of course :)

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/13747#comment:10>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list