[tor-bugs] #3600 [TorBrowserButton]: We should get user confirmation for redirects (was: TBB should display redirects for user confirmation)

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Fri Jul 15 18:56:37 UTC 2011


#3600: We should get user confirmation for redirects
------------------------------+---------------------------------------------
 Reporter:  mikeperry         |          Owner:  mikeperry                    
     Type:  defect            |         Status:  new                          
 Priority:  normal            |      Milestone:  TorBrowserBundle 2.2.x-stable
Component:  TorBrowserButton  |        Version:                               
 Keywords:                    |         Parent:                               
   Points:                    |   Actualpoints:                               
------------------------------+---------------------------------------------
Description changed by mikeperry:

Old description:

> I've been using RequestPolicy for so long I'd not realized that redirects
> have been getting more and more transparent. In Firefox 4/5, the loading
> indications are impossible to differentiate between redirects and
>
> There does not appear to be any obvious about:config options to cause
> this prompting either. We may have to dig into the RequestPolicy source
> to see how they do this.
>
> Redirect notification is important if we're going to try to keep 3rd
> party cookies disabled (or dual-keyed). If redirects are 100%
> transparent, there's little point in disabling 3rd party cookies.

New description:

 I've been using RequestPolicy for so long I'd not realized that redirects
 have been getting more and more transparent. In Firefox 4/5, the loading
 indications are impossible to differentiate between redirects and 3rd
 party loads.

 There does not appear to be any obvious about:config options to enable
 more prompting either. We may have to dig into the RequestPolicy source to
 see how they do this.

 Redirect notification is important if we're going to try to keep 3rd party
 cookies disabled (or dual-keyed). If redirects are 100% transparent,
 there's little point in disabling 3rd party cookies.

 NoScript has some options for notifying in the case of JS redirects. We'll
 probably want to enable those options in TBB, too.

--

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/3600#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list