[tor-bugs] #10682 [TorBrowserButton]: Disable update pings for Torbutton and Tor Launcher

Tor Bug Tracker & Wiki blackhole at torproject.org
Sat Feb 8 20:42:15 UTC 2014


#10682: Disable update pings for Torbutton and Tor Launcher
-------------------------+-------------------------------------------------
     Reporter:           |      Owner:  mikeperry
  mikeperry              |     Status:  new
         Type:  defect   |  Milestone:
     Priority:           |    Version:
  critical               |   Keywords:  tbb-security, extdev-interview,
    Component:           |  MikePerry201401R
  TorBrowserButton       |  Parent ID:
   Resolution:           |
Actual Points:           |
       Points:           |
-------------------------+-------------------------------------------------

Comment (by cypherpunks):

 >Can you explain how this fix is a security hole?
 Communicating with localhost over proxy is security hole.
 Torbrowser not Tor. It's ok Tor client prevents localhost connection
 attempts, but this have nothing with browser security. You patches browser
 for dns leaks but why if user could to use tails or netfilter? Because
 design of Torbrowser.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10682#comment:20>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list