[tor-talk] Funny, but not amusing browsing

Spam 06 antispam06 at sent.at
Thu Jul 3 20:46:27 UTC 2014


Michael O Holstein:
>> I got worried yesterday when instead of the Wikipedia logo on the 
>> top-left corner there was the picture of a nazi (army) guy with a
> 
> Is this reproducible?

In this instance of TBB, yes. But I haven't tried on a second computer.

> To successfully (without error) insert into an HTTPS connection you
> must be trusted by the client .. would need list of CAcerts from
> firefox/iceweasel, the received HTML, and (ideally) a debug TOR log
> that shows which exit is doing it.

How can I dump them to make a comparison between a new TBB instance,
freshly unziped and mine?

> A rouge cert signed by a vanilla/public CA would be *very*
> problematic, and unlikely to be wasted screwing with Wikipedia ..
> it's far more likely a bogus CA got trusted by your browser, hence
> the interest in verifying all the certs that are in the keystore.

How?

Cheers!


More information about the tor-talk mailing list