[tor-bugs] #10941 [Tor Messenger]: Secure messaging window

Tor Bug Tracker & Wiki blackhole at torproject.org
Sun Jul 5 18:29:50 UTC 2015


#10941: Secure messaging window
-------------------------------+------------------------------------------
     Reporter:  sukhbir        |      Owner:  sukhbir
         Type:  task           |     Status:  assigned
     Priority:  normal         |  Milestone:
    Component:  Tor Messenger  |    Version:
   Resolution:                 |   Keywords:  SponsorO, TorMessengerPublic
Actual Points:                 |  Parent ID:  #14161
       Points:                 |
-------------------------------+------------------------------------------

Comment (by arlolra):

 From gk's audit,

 > I looked at imContentSink.jsm/convbrowser.xml and studied the
 Instantbird audit done by Mozilla. Almost all issues mentioned in the
 audit got fixed; one is left which does not seem to bring a high-risk with
 it especially, as Tor Messenger is configured to use the least permissive
 rendering mode (which is further hardened)
 >
 > ToDo:
 > - look closer at cleanupNode() and change history
 > - look at DOMParser mainly for making sure that no script etc. execution
 is happening prior to sanitization
 > - look closely at usage of TXTToHTML converter (used in convbrowser.xml,
 xmpp.js, xmpp-xml.jsm, ircUtils.jsm and imThemes.jsm)
 > - relevant bugs:
 >  * https://bugzilla.mozilla.org/show_bug.cgi?id=787984
 >  * https://bugzilla.mozilla.org/show_bug.cgi?id=727216

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10941#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list