[tor-bugs] #2877 [Tor Browser]: Prevent TLS state from accumulating in TorBrowser
Tor Bug Tracker & Wiki
torproject-admin at torproject.org
Tue Apr 19 03:51:57 UTC 2011
#2877: Prevent TLS state from accumulating in TorBrowser
-------------------------+--------------------------------------------------
Reporter: mikeperry | Owner: mikeperry
Type: defect | Status: new
Priority: normal | Milestone:
Component: Tor Browser | Version:
Keywords: | Parent: #2871
Points: ? | Actualpoints:
-------------------------+--------------------------------------------------
Changes (by mikeperry):
* type: enhancement => defect
Old description:
> We've been accumulating a few TLS issues with Torbutton (#2482). In
> particular, we need to figure out how to handle user-stored certificates,
> the intermediate cert store, and STS. Perhaps we just want to block all
> of these by default for TorBrowser? Perhaps we want an extra confirmation
> dialog?
>
> STS and the intermediate cert store should definitely be cleared by the
> New Identity button, though (#523). We currently lack direct Firefox APIs
> for either of these. https://bugzilla.mozilla.org/show_bug.cgi?id=435159
> might help with the latter.
New description:
We've been accumulating a few TLS issues with Torbutton (#2482). In
particular, we need to figure out how to handle user-stored certificates,
the intermediate cert store, and STS. Perhaps we just want to block all of
these by default for TorBrowser? Perhaps we want an extra confirmation
dialog?
STS and the intermediate cert store should definitely be cleared by the
New Identity button, though (#523). We currently lack direct Firefox APIs
for either of these. https://bugzilla.mozilla.org/show_bug.cgi?id=435159
might help with the latter.
[[TicketQuery(parent=#2877,format=table,col=component|owner|summary|priority|points,order=priority)]]
--
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/2877#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list