Ticket #27271: 0001-Bug-27271-Don-t-allow-the-user-to-install-extensions.2.patch

File 0001-Bug-27271-Don-t-allow-the-user-to-install-extensions.2.patch, 1.1 KB (added by igt0, 8 months ago)
  • mobile/android/app/000-tor-browser-android.js

    From 4605e19a5b104ab03c05bfc6fa1ee0eb3418652a Mon Sep 17 00:00:00 2001
    From: Igor Oliveira <igt0@torproject.org>
    Date: Wed, 22 Aug 2018 15:51:32 -0300
    Subject: [PATCH] Bug 27271 -  Don't allow the user to install extensions from
     web
    
    An attacker can send a tampered torbutton extension to the user and
    TBA, currently, is not able to verify if the torbutton extension
    was built by Tor.
    ---
     mobile/android/app/000-tor-browser-android.js | 5 +++++
     1 file changed, 5 insertions(+)
    
    diff --git a/mobile/android/app/000-tor-browser-android.js b/mobile/android/app/000-tor-browser-android.js
    index 399c6f07718b..04a613092e6d 100644
    a b pref("general.useragent.updates.url", ""); 
    5656
    5757// Override this because Orbot uses 9050 as the default
    5858pref("network.proxy.socks_port", 9050);
     59
     60// Do not allow the user to install extensions from web
     61pref("xpinstall.enabled", false);
     62pref("extensions.enabledScopes", 1);
     63pref("extensions.autoDisableScopes", 1);