[tbb-bugs] #27411 [Applications/Tor Browser]: Security slider is broken in second RC for Tor Browser 8 on Windows

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Sep 4 22:50:26 UTC 2018


#27411: Security slider is broken in second RC for Tor Browser 8 on Windows
--------------------------------------+--------------------------
 Reporter:  gk                        |          Owner:  tbb-team
     Type:  defect                    |         Status:  closed
 Priority:  Immediate                 |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:  fixed
 Keywords:  TorBrowserTam201809       |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------

Comment (by ma1):

 Replying to [comment:13 arthuredelstein]:
 > Replying to [comment:12 rustybird]:
 >
 > > But without a further, Tor Browser specific patch for NoScript (to
 delay page loads until the updateSettings message has arrived), the first
 page load could still happen with the wrong settings.
 >
 > That's an interesting point. But if NoScript is not ready when the first
 page load has happened, then doesn't that mean its settings won't be
 applied to that page anyway?
 >
 First thing NoScript does, before any asynchronous initialization and
 hopefully before any page load (at least it seems to be working reliably
 even with session restore pages) is suspending any web loading activity
 until it's actually ready to enforce policies.

 > '''Edit:''' On further thought, I guess it is possible that when
 NoScript sends its "started" message, then reply will be too slow to catch
 it before NoScript's pre-adjusted settings are applied to the first page.

 That should not be the case, because NoScript waits for the response
 before resuming web loading activity.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/27411#comment:14>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list