[tor-bugs] #10941 [Tor Messenger]: Secure messaging window
Tor Bug Tracker & Wiki
blackhole at torproject.org
Sun Jul 5 18:29:50 UTC 2015
#10941: Secure messaging window
-------------------------------+------------------------------------------
Reporter: sukhbir | Owner: sukhbir
Type: task | Status: assigned
Priority: normal | Milestone:
Component: Tor Messenger | Version:
Resolution: | Keywords: SponsorO, TorMessengerPublic
Actual Points: | Parent ID: #14161
Points: |
-------------------------------+------------------------------------------
Comment (by arlolra):
From gk's audit,
> I looked at imContentSink.jsm/convbrowser.xml and studied the
Instantbird audit done by Mozilla. Almost all issues mentioned in the
audit got fixed; one is left which does not seem to bring a high-risk with
it especially, as Tor Messenger is configured to use the least permissive
rendering mode (which is further hardened)
>
> ToDo:
> - look closer at cleanupNode() and change history
> - look at DOMParser mainly for making sure that no script etc. execution
is happening prior to sanitization
> - look closely at usage of TXTToHTML converter (used in convbrowser.xml,
xmpp.js, xmpp-xml.jsm, ircUtils.jsm and imThemes.jsm)
> - relevant bugs:
> * https://bugzilla.mozilla.org/show_bug.cgi?id=787984
> * https://bugzilla.mozilla.org/show_bug.cgi?id=727216
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10941#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list