[tor-bugs] #22933 [Applications/Tor Browser Sandbox]: Deprecate the extra codecs option.
Tor Bug Tracker & Wiki
blackhole at torproject.org
Sat Jul 15 04:53:38 UTC 2017
#22933: Deprecate the extra codecs option.
--------------------------------------------------+---------------------
Reporter: yawning | Owner: yawning
Type: enhancement | Status: new
Priority: Medium | Milestone:
Component: Applications/Tor Browser Sandbox | Version:
Severity: Normal | Keywords:
Actual Points: | Parent ID:
Points: | Reviewer:
Sponsor: |
--------------------------------------------------+---------------------
Split the codec option off from #22910 since they technically are two
separate things. Relevant details from the original ticket are as
follows:
Having massive "foot + gun" options in general is bad practice.
The extra codecs will expose ffmpeg to the browser container, which is a
concrete increase in attack surface for questionable gain (gstreamer is
never allowed).
It looks like the browser people sort of considered the ffmpeg situation
at #18946, and I initially added the pref in #20806. Really what should
happen is that Tor Browser should bundle their own copy if it's that
critical to functionality instead of pulling in one of 7 different .so
files via dlopen (`dom/media/platforms/ffmpeg/FFmpegRuntimeLinker.cpp`).
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/22933>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list