[tbb-bugs] #23247 [Applications/Tor Browser]: Communicating security expectations for .onion: what to say about different padlock states for .onion services

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu May 24 04:22:30 UTC 2018


#23247: Communicating security expectations for .onion: what to say about different
padlock states for .onion services
-------------------------------------------------+-------------------------
 Reporter:  isabela                              |          Owner:
                                                 |  pospeselr
     Type:  project                              |         Status:
                                                 |  needs_review
 Priority:  High                                 |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  ux-team, tor-hs,                     |  Actual Points:
  TorBrowserTeam201805R                          |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by pospeselr):

 Uploaded new version of patch against the esr60 gecko-dev branch as well
 as an updated esr52 version.  New version has better implemented detection
 of '_hasInsecureLoginForms'.  Relevant logic is piped down from
 nsGlobalWindow::ComputeIsSecureContext which now checks for
 nsContentUtils::HttpsStateIsModern as well as
 nsContentUtils::DocumentHasOnionURI.

 Will be running my ESR60 patch against the TrySerer tonight to see if this
 breaks anything.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/23247#comment:63>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list