[tbb-bugs] #13747 [Applications/Tor Browser]: Block non .onion content on .onion addresses (was: Block Mixed Content on .onion Addresses)
Tor Bug Tracker & Wiki
blackhole at torproject.org
Fri Jan 27 20:04:44 UTC 2017
#13747: Block non .onion content on .onion addresses
--------------------------------------+--------------------------
Reporter: legind | Owner: tbb-team
Type: enhancement | Status: new
Priority: Medium | Milestone:
Component: Applications/Tor Browser | Version:
Severity: Normal | Resolution:
Keywords: tbb-security | Actual Points:
Parent ID: | Points:
Reviewer: | Sponsor:
--------------------------------------+--------------------------
Changes (by cypherpunks):
* keywords: => tbb-security
Comment:
Previous Summary makes sense too, but is a dupe of #13033.
> One would hope that an http THS would never include remote resources
from an http site if they would like to protect their users.
and from https?
> It seems like a good security measure to disallow http resources from
being loaded in TBB.
at all?
Anyways, what should be done asap is a warning system for .onion sites
like that for passive and active mixed content, which allows to
distinguish altered sites by looking at the address bar.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/13747#comment:8>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tbb-bugs
mailing list