[tbb-bugs] #27016 [Applications/Tor Browser]: TBA: Audit thirdparty picasso

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Aug 3 00:25:00 UTC 2018


#27016: TBA: Audit thirdparty picasso
------------------------------------------+------------------------------
 Reporter:  sysrqb                        |          Owner:  tbb-team
     Type:  defect                        |         Status:  needs_review
 Priority:  Very High                     |      Milestone:
Component:  Applications/Tor Browser      |        Version:
 Severity:  Normal                        |     Resolution:
 Keywords:  tbb-mobile, tbb-proxy-bypass  |  Actual Points:
Parent ID:  #25851                        |         Points:
 Reviewer:                                |        Sponsor:
------------------------------------------+------------------------------
Changes (by sysrqb):

 * status:  new => needs_review


Comment:

 Replying to [comment:1 sysrqb]:
 > This library using the `NetworkInfo` via the `ConnectivityManager` for
 deciding how many background threads it should create for processing.
 Higher bandwidth connections result in more threads. The default is 3, so
 this shouldn't be a problem. The library also registers for network change
 events. We'll probably need to change it so we don't require these Android
 permissions.
 >

 This doesn't seem like it'll be a problem. Picasso catches missing
 permissions, so that shouldn't be cause a crash.

 > `UrlConnectionDownloader` is the only class that bypasses the proxy, so
 we'll need a patch for that, as well.

 I have a patch for this, branch `27016`, on my repo.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/27016#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list