[tor-bugs] #12820 [Tor bundles/installation]: Test+Recommend Tor Browser with Enhanced Mitigation Experience Toolkit

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri May 29 00:00:17 UTC 2015


#12820: Test+Recommend Tor Browser with Enhanced Mitigation Experience Toolkit
-------------------------------------+-------------------------------------
     Reporter:  mikeperry            |      Owner:  erinn
         Type:  project              |     Status:  accepted
     Priority:  normal               |  Milestone:
    Component:  Tor                  |    Version:
  bundles/installation               |   Keywords:  tbb-security, tbb-isec-
   Resolution:                       |  report
Actual Points:                       |  Parent ID:
       Points:                       |
-------------------------------------+-------------------------------------

Comment (by cypherpunks):

 Currently, ROP Simulate Execution Flow (SimExecFlow) does not work with
 Tor Browser 4.5.1, 4.5, and the last 4.0 release (4.0.8?). The last time
 it worked was in the 3.5 series if I remember correctly (and possibly one
 of the first 4.0 releases). Please note I am talking about releases, I
 have never tested any betas.

 Turning SimExecFlow off for *\Tor Browser\Browser\firefox.exe fixes the
 problem. *\tor.exe and *\Tor Browser\Browser\plugin-container.exe work
 fine with it enabled. I have not tested *\Start Tor Browser.exe or
 *\obfsproxy.exe.

 I run other versions of Firefox (64-bit nightly, 64-bit beta, 32-bit
 release, 32-bit release with DRM removed, portable firefox) and these work
 fine with SimExecFlow on. I have not tested any ESR, however.

 I have also not tested running Tor Browser in safe mode.

 All other mitigations work fine (be sure to add "mozjs.dll;xul.dll"
 without quotes to the EAF+ mitigation).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/12820#comment:6>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list