[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #10682 [TorBrowserButton]: Disable update pings for Torbutton and Tor Launcher



#10682: Disable update pings for Torbutton and Tor Launcher
-------------------------+-------------------------------------------------
     Reporter:           |      Owner:  mikeperry
  mikeperry              |     Status:  new
         Type:  defect   |  Milestone:
     Priority:           |    Version:
  critical               |   Keywords:  tbb-security, extdev-interview,
    Component:           |  MikePerry201401R
  TorBrowserButton       |  Parent ID:
   Resolution:           |
Actual Points:           |
       Points:           |
-------------------------+-------------------------------------------------

Comment (by ben):

 I think cypherpunks is worried that for whatever reason (bug,
 misconfiguration, etc.), Tor might actually answer on that
 https://localhost:9050/ request - and somehow allow an attacker to deliver
 XPI, which will then be installed.
 I think the chance of all that coming together is almost nil, but I agree
 that it's safer to use a port where no server is listening.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10682#comment:21>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs