[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-bugs] Re: [Tor Bug Tracker & Wiki] #664: Torbutton should not present custom certs if tor is enabled



#664: Torbutton should not present custom certs if tor is enabled
-----------------------+----------------------------------------------------
 Reporter:  mikeperry  |         Type:  enhancement  
   Status:  new        |     Priority:  major        
Milestone:             |    Component:  Tor-Torbutton
  Version:  1.1        |   Resolution:  None         
 Keywords:             |  
-----------------------+----------------------------------------------------

Old description:

> Torbutton should hide random client and server certs the user has if they
> check an option.
> Ideally, we should provide 'certificate jars', but that may not be
> immediately possible with
> the current XPCOM apis.
>
> I'm guessing the option will be optional and likely off by default,
> unless we can do the jar
> thing.
>
> [Automatically added by flyspray2trac: Operating System: All]

New description:

 Torbutton should hide random client and server certs the user has if they
 check an option.
 Ideally, we should provide 'certificate jars', but that may not be
 immediately possible with
 the current XPCOM apis.

 I'm guessing the option will be optional and likely off by default, unless
 we can do the jar
 thing.

 [Automatically added by flyspray2trac: Operating System: All]

--

Comment(by mikeperry):

 See also bug #1505, and the JonDoFox extension's implementation
 (http://www.jondos.org/en/node/1754). JonDos doesn't isolate all certs,
 but they claim that it is important to prevent (silent?) installation of
 new ones (!).

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/664#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online