[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-bugs] Re: [Tor Bug Tracker & Wiki] #664: Torbutton should not present custom certs if tor is enabled
#664: Torbutton should not present custom certs if tor is enabled
-----------------------+----------------------------------------------------
Reporter: mikeperry | Type: enhancement
Status: new | Priority: major
Milestone: | Component: Tor-Torbutton
Version: 1.1 | Resolution: None
Keywords: |
-----------------------+----------------------------------------------------
Old description:
> Torbutton should hide random client and server certs the user has if they
> check an option.
> Ideally, we should provide 'certificate jars', but that may not be
> immediately possible with
> the current XPCOM apis.
>
> I'm guessing the option will be optional and likely off by default,
> unless we can do the jar
> thing.
>
> [Automatically added by flyspray2trac: Operating System: All]
New description:
Torbutton should hide random client and server certs the user has if they
check an option.
Ideally, we should provide 'certificate jars', but that may not be
immediately possible with
the current XPCOM apis.
I'm guessing the option will be optional and likely off by default, unless
we can do the jar
thing.
[Automatically added by flyspray2trac: Operating System: All]
--
Comment(by mikeperry):
See also bug #1505, and the JonDoFox extension's implementation
(http://www.jondos.org/en/node/1754). JonDos doesn't isolate all certs,
but they claim that it is important to prevent (silent?) installation of
new ones (!).
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/664#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online