[tbb-bugs] #22100 [Applications/Tor Browser]: Triggering the external helper dialog leads sometimes to requests going over the catch-all circuit (was: Mozilla's FPI suxx)

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon May 1 18:53:59 UTC 2017


#22100: Triggering the external helper dialog leads sometimes to requests going
over the catch-all circuit
--------------------------------------+--------------------------
 Reporter:  cypherpunks               |          Owner:  tbb-team
     Type:  defect                    |         Status:  new
 Priority:  High                      |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:  tbb-linkability           |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------
Changes (by gk):

 * priority:  Medium => High


Comment:

 Replying to [comment:4 cypherpunks]:
 > Replying to [comment:3 gk]:
 > > Replying to [comment:2 cypherpunks]:
 > > > You have to start testing your product ;), browsing the web with
 opened console and watching torbutton's INFOs in different circumstances.
 > >
 > > I am doing that for weeks now.
 > And? Don't you see FPI violations (except for retrying downloads)?
 > > If you file a bug just dropping that log snippet into the description
 as you did what are we supposed to do with it?
 > Maybe, fix it? No?
 > > And how are we supposed to deal with "and many, many others..." in
 this bug?
 > Make this ticket parent for all regressions in FPI?

 This is no regression, see below. But that said #20685 seems to be the
 parent ticket you are looking for (in case there isn't already a more
 specific fitting your bug). Feel free to open child tickets for issues you
 find with steps to reproduce them. Thanks.

 > > So, again, how can I reproduce the problem you reported?
 > Open http://hpr.dogphilosophy.net/test on Medium settings (notice that
 DevTools suxx too), click "(click to try it)" near ""wave" file(".wav")".
 Isn't it easy?

 Yes, with steps to reproduce it is. FWIW: I see this in 6.5.2 as well, so
 this has nothing to do with Mozilla's First Party Isolation code.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/22100#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list