[tor-bugs] #2877 [Tor bundles/installation]: Prevent TLS state from accumulating in TorBrowser
Tor Bug Tracker & Wiki
torproject-admin at torproject.org
Sat Apr 9 02:11:10 UTC 2011
#2877: Prevent TLS state from accumulating in TorBrowser
--------------------------------------+-------------------------------------
Reporter: mikeperry | Owner: mikeperry
Type: defect | Status: new
Priority: normal | Milestone:
Component: Tor bundles/installation | Version:
Keywords: | Parent: #2871
Points: | Actualpoints:
--------------------------------------+-------------------------------------
We've been accumulating a few TLS issues with Torbutton (#2482). In
particular, we need to figure out how to handle user-stored certificates,
the intermediate cert store, and STS. Perhaps we just want to block all of
these by default for TorBrowser? Perhaps we want an extra confirmation
dialog?
STS and the intermediate cert store should definitely be cleared by the
New Identity button, though (#523). We currently lack direct Firefox APIs
for either of these. https://bugzilla.mozilla.org/show_bug.cgi?id=435159
might help with the latter.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/2877>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list