[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #10682 [TorBrowserButton]: Disable update pings for Torbutton and Tor Launcher



#10682: Disable update pings for Torbutton and Tor Launcher
-------------------------+-------------------------------------------------
     Reporter:           |      Owner:  mikeperry
  mikeperry              |     Status:  new
         Type:  defect   |  Milestone:
     Priority:           |    Version:
  critical               |   Keywords:  tbb-security, extdev-interview,
    Component:           |  MikePerry201401R
  TorBrowserButton       |  Parent ID:
   Resolution:           |
Actual Points:           |
       Points:           |
-------------------------+-------------------------------------------------

Comment (by cypherpunks):

 >Can you explain how this fix is a security hole?
 Communicating with localhost over proxy is security hole.
 Torbrowser not Tor. It's ok Tor client prevents localhost connection
 attempts, but this have nothing with browser security. You patches browser
 for dns leaks but why if user could to use tails or netfilter? Because
 design of Torbrowser.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10682#comment:20>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs