[tor-bugs] #21321 [Applications/Tor Browser]: .onion HTTP is shown as non-secure in Tor Browser

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Aug 4 05:53:51 UTC 2017


#21321: .onion HTTP is shown as non-secure in Tor Browser
-------------------------------------------------+-------------------------
 Reporter:  cypherpunks                          |          Owner:  tbb-
                                                 |  team
     Type:  task                                 |         Status:  closed
 Priority:  High                                 |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Blocker                              |     Resolution:  fixed
 Keywords:  ff52-esr, tbb-7.0-issues, tbb-       |  Actual Points:
  usability, ux-team, tbb-7.0-frequent,          |
  TorBrowserTeam201708R, GeorgKoppen201708       |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------
Changes (by gk):

 * status:  needs_review => closed
 * resolution:   => fixed


Comment:

 Replying to [comment:52 arthuredelstein]:
 > Replying to [comment:49 gk]:
 > > Updated the branch with review feeback and created a new merge
 request: https://oniongit.eu/gk/tor-browser/merge_requests/2. Arthur,
 could you have a look at that one?
 >
 > I reviewed both patches and commented on oniongit.eu. I suggested a
 minor (optional) revision, but otherwise they look good.

 Thanks. I included that and pushed the patches to `tor-
 browser-52.2.0esr-7.0-1` (commits 30b633b92a94bced2537354afe3d228f0eace8da
 and 7a03cca9991cfab93be16e9d5521bc58c35d4d44) and `tor-
 browser-52.2.0esr-7.5-1` (commits df2223e1b1f8a4b782e7e49bbbeb79296ea74dff
 and 490f3cc2d708cf693ebb7c730b7bb2562dc8987c). This will be available in
 Tor Browser 7.0.4 and 7.5a4.

 Just for the record: the patches don't mess with TLS indicators and with
 the concept of a secure context (which is often bound to HTTPS) on
 purpose. I think we should be very wary of blurring the line between TLS
 with a CA-signed certificate and onion services. However, that does not
 mean that only TLS traffic is authenticated and encrypted and everything
 else is untrusted and has to be treated accordingly.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21321#comment:53>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list