[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #523 [Torbutton]: New Identity Button and Timer
#523: New Identity Button and Timer
----------------------------+-----------------------------------------------
Reporter: mikeperry | Owner: koryk
Type: enhancement | Status: assigned
Priority: major | Milestone: 1.4
Component: Torbutton | Version: 1.1
Resolution: None | Keywords:
Parent: | Points:
Actualpoints: |
----------------------------+-----------------------------------------------
Comment(by mikeperry):
Replying to [comment:11 arma]:
> Replying to [comment:10 mikeperry]:
> > For Tor Browser Bundle, doing a New Identity Button is actually much
easier, because Vidalia now launches both Tor and Firefox. It passes a
control port password to Tor via the command line. It can pass this same
password to Torbutton via an environment variable. This way, Torbutton can
connect to Tor's control port to send the SIGNAL NEWNYM itself.
>
> What level of Firefox (or extension) vulnerability would be sufficient
to break into and reconfigure your Tor, in this case?
A vulnerability that enables the full reconfiguration of Tor from Firefox
using this password would also allow arbitrary code execution as the
Firefox user.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/523#comment:12>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs