[tbb-bugs] #29916 [Applications/Tor Browser]: Group Policies for Firefox can bypass Tor Browser's proxy settings

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Apr 1 08:45:42 UTC 2019

#29916: Group Policies for Firefox can bypass Tor Browser's proxy settings
 Reporter:  gk                                   |          Owner:  tbb-
                                                 |  team
     Type:  defect                               |         Status:
                                                 |  needs_information
 Priority:  High                                 |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  tbb-proxy-bypass,                    |  Actual Points:
  TorBrowserTeam201904, tbb-8.5-must-alpha       |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
Changes (by gk):

 * keywords:  tbb-proxy-bypass, TorBrowserTeam201904 => tbb-proxy-bypass,
     TorBrowserTeam201904, tbb-8.5-must-alpha
 * status:  new => needs_information


 Replying to [comment:6 tom]:
 > I did find another way to control this besides the policy file. I
 believe that we should revert #29445, set
 browser.policies.testing.disallowEnterprise to true, not support enteprise
 policies in any way shape or form, and test a release and alpha build to
 ensure the proxy can't be bypassed.

 Hm, so `browser.policies.testing.disallowEnterprise` set to `true` *alone*
 does not solve our problems here? Or is it just too risky relying just on
 that pref alone? Because *if* folks know what they are doing and want to
 have policy support why not allowing that feature? If the pref alone is
 not enough that sounds like a bug with the pref handling which should get
 fixed independently of this ticket.

Ticket URL: <https://trac.torproject.org/projects/tor/ticket/29916#comment:7>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online

More information about the tbb-bugs mailing list