[tor-bugs] #21877 [Applications/Tor Browser]: HTTP only onion services are marked as insecure in TBB ff52 nightly

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Apr 6 14:30:26 UTC 2017


#21877: HTTP only onion services are marked as insecure in TBB ff52 nightly
--------------------------------------+--------------------------
 Reporter:  blockflare                |          Owner:  tbb-team
     Type:  defect                    |         Status:  new
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------

Comment (by blockflare):

 Replying to [comment:1 cypherpunks]:
 > Yes, HTTP is not HTTPS.

 But onion services are e2e encrypted, even if they don't have an EV Cert,
 they should not be marked as insecure and as "Information you submit could
 be viewed by others  (like passwords, messages, credit cards, etc.)".

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21877#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list