[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #10424 [Tor Sysadmin Team]: torproject.org doesn't send an HSTS header
#10424: torproject.org doesn't send an HSTS header
-----------------------------------+----------------------
Reporter: zyan | Owner:
Type: enhancement | Status: reopened
Priority: major | Milestone:
Component: Tor Sysadmin Team | Version:
Resolution: | Keywords:
Actual Points: | Parent ID:
Points: |
-----------------------------------+----------------------
Changes (by zyan):
* status: closed => reopened
* resolution: not a bug =>
Comment:
No, redirecting from http://torproject.org to https://www.torproject.org
does not prevent the class of attacks that HSTS is supposed to address.
Ex:
1. User types in torproject.org. Their browser by default sends them to
http://torproject.org.
2. An active MITM intercepts that HTTP request and injects malicious
content.
You're in fact vulnerable to sslstrip
(http://www.thoughtcrime.org/software/sslstrip/) if you don't enforce HSTS
on torproject.org, simply because a significant percentage of users won't
make sure that they go to WWW.torproject.org.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10424#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs