[tor-bugs] #9387 [Tor Launcher]: Tor Launcher/Torbutton should provide a "Security Slider"

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Feb 3 15:37:37 UTC 2015


#9387: Tor Launcher/Torbutton should provide a "Security Slider"
-------------------------+-------------------------------------------------
     Reporter:           |      Owner:  gk
  mikeperry              |     Status:  new
         Type:           |  Milestone:
  enhancement            |    Version:
     Priority:  major    |   Keywords:  TorBrowserTeam201502, tbb-security,
    Component:  Tor      |  tbb-usability, tbb-linkability, tbb-3.0,
  Launcher               |  extdev-interview, tbb-isec-report,
   Resolution:           |  tbb-4.5-alpha
Actual Points:           |  Parent ID:
       Points:           |
-------------------------+-------------------------------------------------

Comment (by gk):

 mikeperry: This is the comment to commit
 7975b2023d5dc9bc0437cb5d5fbfe539448900e4: Originally, I had a similar idea
 but just looking at the particular security level and binding the custom
 pref to it is wrong I think. We need to think about the custom setting
 being bound to the *whole* slider instead. And here is why: Level 4 (or
 "high") is not only about setting the preferences in the High section in
 comment:43 but rather all the preferences in Low-Medium/Low-Medium/High
 must be set accordingly as well in order to guarantee the full protection
 AND making sure there are only 4 partitions of users if they stick to the
 slider and don't prefer custom settings. Or take the default mode: if one
 selects the default mode but disables JavaScript then first of all this is
 no default mode anymore even if no particular preference in that mode is
 changed. Doing this is pretty dangerous as we could easily get some users
 that are in default mode but have JavaScript disabled and some that are in
 that mode but have it enabled. And then maybe some that have
 media.audio.enabled and some not, leading to a much larger partition than
 is good for our users.

 Hence just the check if any of the security slider related preferences got
 touched. If so, set the custom checkbox. The only way to set it back
 currently is via the Torbutton menu. We could think about an additional
 option: if the user manages it to manually set all the security slider
 related preferences back to theirs respective values (which is depending
 on the current slider level) then uncheck the custom checkbox as well.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9387#comment:74>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list