[tor-bugs] #7501 [Tor bundles/installation]: Include PDF.js extension in TBB

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Mar 4 03:31:39 UTC 2013


#7501: Include PDF.js extension in TBB
--------------------------------------+-------------------------------------
 Reporter:  mikeperry                 |          Owner:  mikeperry
     Type:  task                      |         Status:  new      
 Priority:  normal                    |      Milestone:           
Component:  Tor bundles/installation  |        Version:           
 Keywords:  tbb-usability             |         Parent:           
   Points:                            |   Actualpoints:           
--------------------------------------+-------------------------------------
Changes (by mikeperry):

 * cc: isis (added)
  * keywords:  => tbb-usability
  * parent:  #7248 =>


Comment:

 Ok, I spoke with a couple Mozilla folks, and here's the status:

 1. They do not plan to backport security updates for PDF.js to FF17-ESR.
 We have to use the addon.
 2. They plan on providing updates to the addon until FF24-ESR.
 3. PDF.js does try to obey Private Browsing Mode. It tries to avoid
 touching the disk if PBM is on.
 4. They do not evaluate PDF Javascript
 (https://www.adobe.com/content/dam/Adobe/en/devnet/acrobat/pdfs/js_api_reference.pdf)
 5. It *is* possible to evaluate PDFs in third party iframes and object
 tags.

 Point 5 means that we have to test the PDF caching behavior for PDF.js to
 ensure it is similarly isolated per URL bar domain like everything else.
 If not, we may not be able to include it in TBB-stable until we find a way
 to prevent 3rd party tracking via PDFs, or simply find a way to disable
 3rd party PDF loading.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/7501#comment:6>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list