[tor-bugs] #21321 [Applications/Tor Browser]: .onion HTTP is shown as non-secure in Tor Browser

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Jul 24 11:30:05 UTC 2017


#21321: .onion HTTP is shown as non-secure in Tor Browser
-------------------------------------------------+-------------------------
 Reporter:  cypherpunks                          |          Owner:  tbb-
                                                 |  team
     Type:  task                                 |         Status:
                                                 |  needs_review
 Priority:  High                                 |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Blocker                              |     Resolution:
 Keywords:  ff52-esr, tbb-7.0-issues, tbb-       |  Actual Points:
  usability, ux-team, TorBrowserTeam201707R,     |
  GeorgKoppen201707                              |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------
Changes (by gk):

 * cc: arthuredelstein (added)
 * status:  new => needs_review
 * keywords:
     ff52-esr, tbb-7.0-issues, tbb-usability, ux-team,
     TorBrowserTeam201707, GeorgKoppen201707
     =>
     ff52-esr, tbb-7.0-issues, tbb-usability, ux-team,
     TorBrowserTeam201707R, GeorgKoppen201707


Comment:

 Please review: https://oniongit.eu/gk/tor-browser/merge_requests/1. I have
 not looked at a mixed content context. The tests in
 `browser_hasInsecureLoginForms.js` should get adapted once we have those
 bits figured out. But I'd say that should happen in a different bug titled
 "Don't block .onion sites in a mixed content setup" or something like
 that.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21321#comment:46>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list