[tor-bugs] #26456 [Applications/Tor Browser]: HTTP .onion sites inherit previous page's certificate information

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Jun 28 23:23:20 UTC 2018


#26456: HTTP .onion sites inherit previous page's certificate information
--------------------------------------+------------------------------
 Reporter:  pospeselr                 |          Owner:  pospeselr
     Type:  defect                    |         Status:  needs_review
 Priority:  Very High                 |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:  TorBrowserTeam201806R     |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+------------------------------
Changes (by pospeselr):

 * status:  assigned => needs_review
 * keywords:  TorBrowserTeam201806 => TorBrowserTeam201806R


Comment:

 Found the bit of logic that was holding on to the previous page's SSL info
 when transitioning to a non-SSL 'secure' page (ie an onion page) and fixed
 it.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/26456#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list