[tor-bugs] #7491 [EFF-HTTPS Everywhere]: [FIREFOX] We sometimes flag cookies as "secure" even though they are from HTTP origins

Tor Bug Tracker & Wiki blackhole at torproject.org
Sat Jan 5 00:04:27 UTC 2013


#7491: [FIREFOX] We sometimes flag cookies as "secure" even though they are from
HTTP origins
-------------------------------------+--------------------------------------
    Reporter:  pde                   |       Owner:  mikeperry
        Type:  defect                |      Status:  closed   
    Priority:  critical              |   Milestone:           
   Component:  EFF-HTTPS Everywhere  |     Version:           
  Resolution:  fixed                 |    Keywords:           
      Parent:                        |      Points:           
Actualpoints:                        |  
-------------------------------------+--------------------------------------

Comment(by pde):

 Turns out this "fix" was buggy, and probably caused a regression of #3766,
 as well as the new #7855.  Probably still less bad than this bug, though.

 I've committed some repairs [https://gitweb.torproject.org/https-
 everywhere.git/commitdiff/7781a436230b9ee0a69c897c94a6a4252ad7e946 here],
 but this is actually hard to test correctly for all the cases I can think
 of.

 It's time for us to get a Marionette test suite.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/7491#comment:8>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list