[tor-bugs] #4192 [Tor Browser]: Serious TBB Launcher bug

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Thu Oct 6 12:47:04 UTC 2011


#4192: Serious TBB Launcher bug
-------------------------+--------------------------------------------------
 Reporter:  ioerror      |          Owner:  mikeperry
     Type:  defect       |         Status:  assigned 
 Priority:  blocker      |      Milestone:           
Component:  Tor Browser  |        Version:           
 Keywords:  security     |         Parent:           
   Points:               |   Actualpoints:           
-------------------------+--------------------------------------------------

Comment(by arma):

 Priority number one, which I hope will get into the next release, is to
 make our Firefox, when run any way other than TBB-launches-Vidalia-
 launches-Firefox, fail closed. So no fetching check.torproject.org, no
 reading the user's system Firefox profile and executing stuff in it, etc.

 Priority number two, which doesn't have to happen immediately but should
 still be high on the priority list, is to either a) tell the user what
 went wrong and tell them what to do instead, or b) have Firefox
 automatically exec to the correct TBB launcher, which in turn would start
 Firefox correctly. 'b' would seem better than 'a', but I look forward to
 Mike's analysis of how messy hacking Firefox in each way would be.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/4192#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list