[tor-bugs] #27719 [Applications/Tor Browser]: Treat unsafe renegotiation as broken

Tor Bug Tracker & Wiki blackhole at torproject.org
Sun Sep 16 00:30:29 UTC 2018


#27719: Treat unsafe renegotiation as broken
--------------------------------------+--------------------------
 Reporter:  cypherpunks2              |          Owner:  tbb-team
     Type:  enhancement               |         Status:  new
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------

Comment (by cypherpunks2):

 Replying to [comment:1 gk]:
 > Relevant Moz bugs:
 >
 > https://bugzilla.mozilla.org/show_bug.cgi?id=535649 (original discussion
 and implementation)
 > https://bugzilla.mozilla.org/show_bug.cgi?id=665859 (flip the pref to
 `true` as this bug report requests)

 The second report is over 7 years old and no progress has been made (it's
 still status NEW). It's very possible that we'll have to toggle this
 ourselves if we want to avoid trivial MITM.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/27719#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list