[tor-bugs] #5686 [EFF-HTTPS Everywhere]: Many rules fail to initiate rewrite to https & some that do produce insecure sessions

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Sun Apr 29 20:38:49 UTC 2012


#5686: Many rules fail to initiate rewrite to https & some that do produce
insecure sessions
-------------------------------------+--------------------------------------
    Reporter:  torcoascor            |       Owner:  pde     
        Type:  defect                |      Status:  reopened
    Priority:  normal                |   Milestone:          
   Component:  EFF-HTTPS Everywhere  |     Version:          
  Resolution:                        |    Keywords:          
      Parent:                        |      Points:          
Actualpoints:                        |  
-------------------------------------+--------------------------------------

Comment(by torcoascor):

 Stranger and stranger. Entered url text below with the following results
 on same workstation after FF cache clear, DNS flush, Java cache clear,
 Norton full disk scan no threats found and FF restart:

 1. www.ibm.com/us/en rewritten to https://www.ibm.com/us/en/ producing
 secure connect with Site ID blue
 2. ibm.com/us/en same outcome as 1 above
 3. ibm.com/us same outcome as 1 above
 4. www.ibm.com same outcome as 1 above (contrast to McAfee same form in 8
 below)
 5. ibm.com resolved to to http://www.ibm.com/us/en/ producing an
 unidentified insecure connect with Site ID grey
 6. www.mcafee.com/us rewritten to https://www.mcafee.com/us/ producing
 secure connect with Site ID blue
 7. mcafee.com/us same outcome as 6 above
 8. mcafee.com or www.mcafee.com resolved to http://www.mcafee.com/us/
 producing an unidentified insecure connect with Site ID grey
 9. mcafee.com/g produces a 404 which after 10 seconds redirects to
 https://www.mcafee.com/us/ producing secure connect with Site ID blue

 Repeated these 3 times each with same outcome. Looks more like a failure
 to rewrite for simple domain-only url forms. Still seeing initial Site ID
 of blue or green replaced within a few seconds with grey unidentified but
 I don't think that has to do with HTTPS Everywhere.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5686#comment:6>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list