[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #20195 [HTTPS Everywhere/EFF-HTTPS Everywhere]: HTTPS Everywhere's SSL Observatory code doesn't honor domain isolation.
#20195: HTTPS Everywhere's SSL Observatory code doesn't honor domain isolation.
-------------------------------------------------+-------------------------
Reporter: yawning | Owner: legind
Type: defect | Status:
| assigned
Priority: High | Milestone:
Component: HTTPS Everywhere/EFF-HTTPS | Version:
Everywhere |
Severity: Major | Resolution:
Keywords: tbb-linkability | Actual Points:
Parent ID: | Points:
Reviewer: | Sponsor:
-------------------------------------------------+-------------------------
Comment (by bugzilla):
Replying to [comment:10 gk]:
> > {{{
> > [09-22 08:31:02] Torbutton WARN: no SOCKS credentials found for
current document.
> > }}}
TBB has a lot of places with this warning, e.g. while fetching
`RecommendedTBBVersions`, so what?
> Alright, so here is what is going on. First, do you see the weird
floating point number thing appended to the `#` in the
`check.torproject.org` URL?
FP with two dots? He-he.
> Torbutton does not do such things.
But it looked like yours :)
> It is visible there that the request does not go over the catch-all
circuit but rather is put on one without any username/password isolation
at all.
If `getinfo circuit-status` doesn't lie, the request does go over the
catch-all circuit, even though without any username/password isolation at
all.
This is another one recent crap from HTTPSE: it look like it was developed
as a virus or without security audit at all. Is it suitable for TBB?
(Also it is doing 3 requests in a row to `check.torproject.org`, on
`NEWNYM` too.)
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/20195#comment:14>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs