[tbb-bugs] #20842 [Applications/Tor Browser]: Proposal: Improve Tor Browser font whitelist / bundled fonts

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Feb 27 05:40:23 UTC 2019

#20842: Proposal: Improve Tor Browser font whitelist / bundled fonts
 Reporter:  arthuredelstein           |          Owner:  tbb-team
     Type:  defect                    |         Status:  assigned
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:  tbb-usability, ux-team    |  Actual Points:
Parent ID:  #18097                    |         Points:
 Reviewer:                            |        Sponsor:

Comment (by arthuredelstein):

 Replying to [comment:18 winterflaw]:
 > Okay, so, I have some odd results to report.
 > First, I checked security settings.  They're set to standard.
 > Next, I followed the link you provided to CSS tricks.
 > I'm doing what it says *except* the font-face rule in my code was not
 first, before any style rules.  I moved it, uploaded the CSS file,
 reloaded the site (shift+click on the reload icon) in Tor Browser.  No
 > I then wanted to check the site in Firefox from a HTTP server.  After
 all, HTTP is fairly different to local and I had only checked Firefox from
 local disk.
 > I copied the site to a normal, non-onion site I have (temporarily
 replaced the site there - only two files) and viewed the site in Firefox
 ESR (Debian 9).
 > The Linear B font loaded correctly.
 > I then put the original site back in place, and did a recursive chmod,
 changing all ownerships on all files for all web-sites (including the
 onion site) to "www-data" (files I upload through the Debian UI SFTP end
 up being my username - which should work fine, global "r" permission).
 > (Bear in mind that *prior* to this, the font loaded correctly in Firefox
 ESR over HTTP, which was using a cp -R copy of the onion site.)
 > I then went back to Tor Browser (which was still running - I'd not quit
 it) and reloaded the site - and hey presto, the font is showing.
 > So, I no longer have a problem, but I don't know why.

 Glad to hear it's working! That is indeed mysterious. But it sounds like
 maybe the file was not accessible for some reason? If you could reproduce
 the original problem, it might be interesting to see if you could directly
 download the font files with Tor Browser, or if you are getting some kind
 of HTTP error.

Ticket URL: <https://trac.torproject.org/projects/tor/ticket/20842#comment:19>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online

More information about the tbb-bugs mailing list