[tor-bugs] #10424 [Tor Sysadmin Team]: torproject.org doesn't send an HSTS header

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Dec 24 00:19:37 UTC 2013


#10424: torproject.org doesn't send an HSTS header
-----------------------------------+----------------------
     Reporter:  zyan               |      Owner:
         Type:  enhancement        |     Status:  reopened
     Priority:  major              |  Milestone:
    Component:  Tor Sysadmin Team  |    Version:
   Resolution:                     |   Keywords:
Actual Points:                     |  Parent ID:
       Points:                     |
-----------------------------------+----------------------
Changes (by zyan):

 * status:  closed => reopened
 * resolution:  not a bug =>


Comment:

 No, redirecting from http://torproject.org to https://www.torproject.org
 does not prevent the class of attacks that HSTS is supposed to address.
 Ex:

 1. User types in torproject.org. Their browser by default sends them to
 http://torproject.org.
 2. An active MITM intercepts that HTTP request and injects malicious
 content.

 You're in fact vulnerable to sslstrip
 (http://www.thoughtcrime.org/software/sslstrip/) if you don't enforce HSTS
 on torproject.org, simply because a significant percentage of users won't
 make sure that they go to WWW.torproject.org.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10424#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list