[tor-bugs] #22067 [Applications/Tor Browser]: NoScript Click-to-Play bypass with embedded videos and audios

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Jul 10 13:24:49 UTC 2017


#22067: NoScript Click-to-Play bypass with embedded videos and audios
--------------------------------------+-----------------------------------
 Reporter:  samantharis               |          Owner:  tbb-team
     Type:  defect                    |         Status:  needs_information
 Priority:  High                      |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Major                     |     Resolution:
 Keywords:  tbb-security, noscript    |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+-----------------------------------
Changes (by gk):

 * status:  new => needs_information


Comment:

 Replying to [comment:6 ma1]:
 > This does not happen in NoScript's default configuration, only in Tor
 Browser's custom setup.
 >
 > Easiest work-around: turn "Forbid other plugins"
 (noscript.forbidPlugins) to true.
 >
 > Working on a fix for 5.0.6, hopefully by this week.

 This did not make it into 5.0.6, right? At least opening the link in
 comment:4 still results in playing first and blocking shortly later for
 me.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/22067#comment:8>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list