[tor-bugs] #30730 [- Select a component]: Can't access right click menu for noscript w/o readding icon

Tor Bug Tracker & Wiki blackhole at torproject.org
Sun Jun 2 17:40:19 UTC 2019


#30730: Can't access right click menu for noscript w/o readding icon
-------------------------+--------------------------------------
 Reporter:  cypherpunks  |          Owner:  (none)
     Type:  defect       |         Status:  new
 Priority:  High         |      Component:  - Select a component
  Version:               |       Severity:  Major
 Keywords:               |  Actual Points:
Parent ID:               |         Points:
 Reviewer:               |        Sponsor:
-------------------------+--------------------------------------
 I posted this previously but because a different user of this account
 stirred the pot the ticket got closed. Please be civil in the comments,
 because apparently a slapfight in the comments is grounds to ignore legit
 technical discussions.

 I'd like to point out it's unclear whether re-adding custom icons reduces
 anonymity. (Either through the usual weird fingerprinting exploits - can
 someone programmatically detect url bar length? That's an open question.

 Forcing us to add the NoScript icon back (and some people may put said
 icon in different places) is risky. Especially since people who are
 advanced enough to use safest probably have increased risks if
 fingerprinted or deanonymized.

 Ex: if someone shares a screenshot it's something that makes them unique.
 (Ex: user collects something via Tor, shares with reporter, reporter
 shares screenshot, oppressive government notices both the leaked
 screenshots and the user's TBB setup have the icon placed to the left of
 the onion, whereas the other suspects either have no icon or have it in a
 different spot)

 More importantly, if you right click then click "noscript" that menu only
 comes up if the button is in the toolbar. So you *have* to add the icon to
 use NS functionality.

 Anyone who visits a social website may not want to use the "safer"
 security slider.

 For example I maintain an anonymous social media account on a site with
 many external links - I do *not* trust every random thing linked to on the
 social media site, and strongly prefer to leave my browser on "safest" but
 allow only that site's JS, not everything it links to. I suspect there are
 many similar use cases where 1 site is trusted, but not the sites that may
 be linked to.

 If the developers are deadset on removing the icon, I think at least we
 should be able to access that functionality via the right click menu as a
 compromise.

 I think it's reasonable to ask that either the control be present in the
 toolbar for safest users, or that the right click context menu work for
 advanced users if clutter is the concern.

 (Test for yourself on this page. Right click, then click "noscript". If
 there is no button in your toolbar, nothing appears)

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/30730>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list