[tor-bugs] #32333 [Applications/Tor Browser]: NoScript remembers settings on browser quit

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Jan 15 00:59:08 UTC 2020


#32333: NoScript remembers settings on browser quit
-------------------------------------------------+-------------------------
 Reporter:  kromek                               |          Owner:  tbb-
                                                 |  team
     Type:  defect                               |         Status:
                                                 |  needs_information
 Priority:  High                                 |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  tbb-9.0-issues, noscript,            |  Actual Points:
  TorBrowserTeam202001                           |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by cypherpunks):

 kromec said:
 > even if you enable restrictions again, it will start remembering ruleset
 of websites you set to TRUSTED.

 Tor Browser remembers TRUSTED websites regardless whether disable
 restrictions globally was set before. This behaviour is reproducible on a
 clean Tor Browser install:

 * Launch Tor Browser and visit any website
 * Set the website to TRUSTED
 * Close and restart Tor Browser and visit the website again, the website
 is still set to trusted. The setting persists through reboot.

 The same is true for giving permissions in NoScript's Options.

 * Launch Tor Browser on safest level
 * Click the NoScript icon and in the left menu, go to Options
 * General --> Preset customization, check all items
 * Close and restart Tor Browser, the permissions are preserved. This is
 not reflected in the security settings at all, which still show safest.
 This will also survive reboot.

 Tor Browser will reset itself after changing the security level repeatedly
 though (true for both scenarios).

 Same as kromec,  extensions.torbutton.noscript_persist is set to false,
 Override Tor Browser's Security Level preset is ''not'' checked.

 OS is Debian bullseye/sid

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/32333#comment:12>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list