[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #10941 [Tor Messenger]: Secure messaging window
#10941: Secure messaging window
-------------------------------+------------------------------------------
Reporter: sukhbir | Owner: sukhbir
Type: task | Status: assigned
Priority: normal | Milestone:
Component: Tor Messenger | Version:
Resolution: | Keywords: SponsorO, TorMessengerPublic
Actual Points: | Parent ID: #14161
Points: |
-------------------------------+------------------------------------------
Comment (by arlolra):
From gk's audit,
> I looked at imContentSink.jsm/convbrowser.xml and studied the
Instantbird audit done by Mozilla. Almost all issues mentioned in the
audit got fixed; one is left which does not seem to bring a high-risk with
it especially, as Tor Messenger is configured to use the least permissive
rendering mode (which is further hardened)
>
> ToDo:
> - look closer at cleanupNode() and change history
> - look at DOMParser mainly for making sure that no script etc. execution
is happening prior to sanitization
> - look closely at usage of TXTToHTML converter (used in convbrowser.xml,
xmpp.js, xmpp-xml.jsm, ircUtils.jsm and imThemes.jsm)
> - relevant bugs:
> * https://bugzilla.mozilla.org/show_bug.cgi?id=787984
> * https://bugzilla.mozilla.org/show_bug.cgi?id=727216
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10941#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs