[tor-bugs] #7491 [EFF-HTTPS Everywhere]: [FIREFOX] We sometimes flag cookies as "secure" even though they are from HTTP origins

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Nov 26 16:44:26 UTC 2012


#7491: [FIREFOX] We sometimes flag cookies as "secure" even though they are from
HTTP origins
----------------------------------+-----------------------------------------
 Reporter:  pde                   |          Owner:  mikeperry   
     Type:  defect                |         Status:  needs_review
 Priority:  critical              |      Milestone:              
Component:  EFF-HTTPS Everywhere  |        Version:              
 Keywords:                        |         Parent:              
   Points:                        |   Actualpoints:              
----------------------------------+-----------------------------------------
Changes (by pde):

  * status:  new => needs_review


Comment:

 There's an attempt at a fix in the [https://gitweb.torproject.org/pde
 /https-everywhere.git/commitdiff/96396823ad71ad0e8c737d1aebe505055cfc6048
 fixing cookies] branch of my remote.  Mike, it would be awesome if you
 could review this.

 I'm wondering whether a more satisfactory workaround to the limitations of
 the cookie-changed observer might be writing something into the DOM of
 HTTPS pages only, in order to police JS cookie events.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/7491#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list