Custom Query (254 matches)


Show under each result:

Results (1 - 100 of 254)

1 2 3
Ticket Summary Keywords Owner Type Status Priority
#18557 Exempt Graphite preference from Security Slider TorBrowserTeam201603, tbb-security-slider tbb-team enhancement closed Immediate
#2340 protect users against freeze, replay and version-rollback attacks tbb-security tbb-team defect new Very High
#10281 Investigate usage of alternate memory allocators and memory hardening options tbb-security, tbb-hardened, TorBrowserTeam201612R arthuredelstein enhancement closed Very High
#10599 Investigate building TBB with SoftBound or AddressSanitizer gitian, tbb-security, tbb-gitian, tbb-hardening, TorBrowserTeam201511R, GeorgKoppen201511 gk enhancement closed Very High
#10682 Disable update pings for Torbutton and Tor Launcher tbb-security, extdev-interview, MikePerry201401R mikeperry defect closed Very High
#12968 Specify HEASLR (High Entropy Address Space Layout Randomization) in MinGW-w64 tbb-security, tbb-rbm, boklm201811, TorBrowserTeam201908 tbb-team enhancement needs_revision Very High
#15470 cannot edit the certificates in Tor browser, tbb-security, CNNIC tbb-team defect reopened Very High
#16010 Get a working content process sandbox for Tor Browser on Windows ff52-esr, tbb-e10s, tbb-security, GeorgKoppen201709, TorBrowserTeam201709R, tbb-not-backported gk task closed Very High
#16130 Defend against the logjam attack tbb-security tbb-team defect closed Very High
#16352 Play with Intel's MPX for hardened Tor Browser builds tbb-security, TorBrowserTeam201711 tbb-team task new Very High
#16926 Multiple OS: Tor Browser leaks domains to system DNS management. tbb-security tbb-team defect new Very High
#18017 Switch to NSS to mitigate SLOTH attack (CVE-2015-7575) tbb-security, TorBrowserTeam201601R, tbb-5.5 tbb-team task closed Very High
#19907 NoScript could not be verified and gets disabled after restart tbb-security, noscript tbb-team defect closed Very High
#20121 Create Seatbealt profile(s) for Tor Browser tbb-security, TorBrowserTeam201612R tbb-team defect closed Very High
#27276 Update security slider to follow NoScript protocol change tbb-security-slider, ff60-esr, TorBrowserTeam201808R tbb-team defect closed Very High
#27413 Implement better communication between NoScript and Tor Browser noscript, tbb-security-slider, tbb-torbutton, TorBrowserTeam201809 tbb-team enhancement new Very High
#30126 Make Tor Browser on macOS compatible with Apple's notarization tbb-security, TorBrowserTeam201909 tbb-team task closed Very High
#5024 compile time hardening of TBB (RELRO, canary, PIE) tbb-security erinn enhancement closed High
#9387 Tor Launcher/Torbutton should provide a "Security Slider" tbb-security, tbb-usability, tbb-linkability, tbb-3.0, extdev-interview, tbb-isec-report, tbb-4.5-alpha, TorBrowserTeam201503 gk enhancement closed High
#9623 Referers being sent from hidden service websites tbb-torbutton, tbb-security, TorBrowserTeam201510R tbb-team defect closed High
#10065 Improve Hardening for TBB3.0 MikePerry201408R, tbb-3.0, gitian, tbb-security, tbb-gitian, tbb-isec-report erinn defect closed High
#10505 Broken ASLR in windows executable tbb-security tor-client 024-backport 023-backport 025-triaged 025-backport 024-backport erinn defect closed High
#10840 Revert #10682 and block fetches for real tbb-security, extdev-interview, tbb-torbutton tbb-team defect closed High
#12427 Investigate Virtual Table Verification (VTV) hardening for Tor Browser on Linux and Windows tbb-security tbb-team task new High
#12736 DLL hijacking vulnerability in TBB tbb-security, TorBrowserTeam201608 tbb-team defect new High
#12827 Create preference to disable SVG tbb-security, tbb-isec-report, tbb-4.5-alpha, TorBrowserTeam201503R, tbb-testcase mcs enhancement closed High
#13379 Sign our MAR files tbb-security, TorBrowserTeam201412,TorBrowserTeam201412R, tbb-no-uplift-60 mcs defect closed High
#13747 Block non .onion content on .onion addresses (mixed content blocking) tbb-security, TorBrowserTeam201903 tbb-team enhancement new High
#13893 Torbrowser crashes on start when using MS EMET 5.x tbb-security, tbb-crash, tbb-usability-stoppoint-app, fuck-mingw-gcc, GeorgKoppen201609, TorBrowserTeam201610, ff52-esr tbb-team defect assigned High
#14270 Make Tor Browser work with Unix Domain Socket option tbb-security, TorBrowserTeam201610 tbb-team project closed High
#14271 Make Torbutton work with Unix Domain Socket option tbb-torbutton, tbb-security, TorBrowserTeam201609 brade enhancement closed High
#14272 Make Tor Launcher work with Unix Domain Socket option tbb-security, TorBrowserTeam201608R brade enhancement closed High
#14273 Investigate missing Tor Browser patches to make Unix Domain Socket option work tbb-security, TorBrowserTeam201608R mikeperry task closed High
#14676 Implement update verification via Tor consensus in Tor Browser tbb-security, tbb-update tbb-team task new High
#14985 NoScript Clickjacking warning when clicking on embedded content tbb-security, noscript tbb-team defect new High
#16441 8-month-old Tor Browser offers to "Reset Tor Browser", removes extensions tbb-security, tbb-usability, TorBrowserTeam201512R, tbb-no-uplift tbb-team defect closed High
#16534 Failed to remove debugging options in Firefox tbb-security tbb-team defect closed High
#16652 Review vulnerability history from FF31 to FF45 tbb-security, GeorgKoppen201607, TorBrowserTeam201607, tbb-security-slider gk task closed High
#17870 Some Windows 10 users experience authenticode errors if Tor Browser is signed on Linux tbb-security, TorBrowserTeam201601, GeorgKoppen201601 tbb-team defect closed High
#17895 Tor Browser Bundle installer subject to DLL hijacking tbb-gitian, tbb-security, TorBrowserTeam201604R boklm defect closed High
#18042 Make sure certificates signed with SHA-1 are not accepted anymore in ESR 45 tbb-security, ff45-esr, tbb-6.0a5, TorBrowserTeam201604R tbb-team task closed High
#18287 Use SHA-2 signature for Tor Browser setup executables tbb-security, TorBrowserTeam201805, GeorgKoppen201805 tbb-team enhancement closed High
#19200 HTML5 video not blocked with placeholder, plays automatically tbb-security-slider, tbb-6.0-issues, noscript, GeorgKoppen201611, TorBrowserTeam201611 tbb-team defect closed High
#19210 NoScript places WebM videos too late behind click-to-play in higher security levels tbb-regression, tbb-security-slider, tbb-6.0-issues, noscript tbb-team defect closed High
#19850 Disable Plaintext HTTP Clearnet Connections tbb-security, https-everywhere tbb-team enhancement new High
#20149 Test that static public key pins are working tbb-security, tls, ReleaseTrainMigration boklm enhancement assigned High
#21009 sandboxed OSX browser hangs if printing is attempted tbb-security, tbb-sandboxing mcs defect assigned High
#21865 Update security slider to take JIT preference changes into account tbb-torbutton, tbb-security-slider, TorBrowserTeam201704R tbb-team defect closed High
#21885 SVG is not disabled in Tor Browser based on ESR52 ff52-esr, tbb-7.0-must-alpha, tbb-torbutton, tbb-security-slider, TorBrowserTeam201704R tbb-team defect closed High
#22027 TBB sandbox 7.0a3 does not open tbb-e10s, tbb-security tbb-team defect closed High
#22067 NoScript Click-to-Play bypass with embedded videos and audios tbb-security, noscript, TorBrowserTeam201707R tbb-team defect closed High
#22267 Windows build of esr52 Tor Browser has no relocs, SSP and DEP/ASLR flags TorBrowserTeam201705R, tbb-security, ff52-esr, tbb-7.0-must boklm defect closed High
#22699 Use browser pref for javascript at High Security Level tbb-security, tbb-security-slider, TorBrowserTeam201708 tbb-team enhancement new High
#22971 The XPI signing mechanism needs to use different hash functions. tbb-security, ff60-esr tbb-team defect new High
#23409 Review past year's Firefox sec bugs and update security slider settings if necessary (2016/7) tbb-security-slider, tbb-security, TorBrowserTeam201711, GeorgKoppen201711 tbb-team defect closed High
#23661 Set content sandbox for Tor Browser on Windows to level 2 tbb-security tbb-team defect closed High
#23663 ESR52 codebase is incompatible with anything below Universal C Runtime (CRT) in Windows tbb-security tbb-team defect closed High
#23664 Deal with UUID for content sandbox temp folder on Windows and Mac tbb-security, tbb-disk-leak tbb-team defect new High
#25229 Resist Spectre by using retpoline and a new instruction provided by Intel with microcode update tbb-security defect closed High
#26407 Go over security slider governed preferences and update them where needed ff60-esr, tbb-security-slider, TorBrowserTeam201904 tbb-team task new High
#26517 When I have security setting set to "Safest" and I open NoScrip's preferences and click reset, TorBrowser still says Security setting "Safest" even though many sites are now whitelisted ff60-esr, tbb-security-slider, noscript tbb-team defect new High
#26553 Sign our own extensions in Tor Browser ff60-esr, tbb-security, AffectsTails, TorBrowserTeam201904, GeorgKoppen201904 tbb-team defect new High
#26590 SVG isn't blocked in Safest security setting with 8.0a9 ff60-esr, tbb-security-slider, TorBrowserTeam201807R tbb-team defect closed High
#27141 Backport TLS1.3 patches tbb-security tbb-team enhancement closed High
#28873 Cascading of permissions does not seem to work properly in Tor Browser 8 noscript, tbb-security, tbb-torbutton, tbb-8.0-issues, tbb-regression, TorBrowserTeam201812R ma1 defect closed High
#29081 libwinpthread.dll has no ASLR tbb-security, tbb-rbm, TorBrowserTeam201901R, GeorgKoppen201901, tbb-backported tbb-team defect closed High
#30680 NoScript's click-to-play does not work on Twitter videos (on higher security levels) noscript, tbb-security-slider tbb-team defect closed High
#31465 Adapt tor-browser-build projects for macOS notarization tbb-security, tbb-rbm, TorBrowserTeam201908R, GeorgKoppen201908 tbb-team defect closed High
#31961 'Learn more' links on security settings are not working tbb-security-slider, TorBrowserTeam201910, tbb-9.0 tbb-team defect closed High
#3861 begin signing Windows packages the Windows way tbb-3.0, tbb-security, tbb-usability-stoppoint-app, tbb-4.5-alpha gk enhancement closed Medium
#4152 Implement Bottom Up Randomization (Windows platform) tbb-security tbb-team enhancement closed Medium
#4280 build changes for TBB tbb-security, apparmor tbb-team defect closed Medium
#5791 Gather apparmor/selinux/seatbelt profiles for each component of TBB tbb-security, apparmor tbb-team project new Medium
#6948 Shared memory for zygote mind meld tbb-security, tbb-sandboxing tbb-team enhancement new Medium
#7501 Audit PDF.js tbb-security tbb-team task new Medium
#8288 security, relability and repeatability issues in the TBB build process tbb-security, tbb-rbm tbb-team enhancement closed Medium
#9150 Fully hardening the tor binary does not work in TBB 3.0a2 on Linux tbb-3.0, tbb-security erinn defect closed Medium
#10138 Ship 64bit builds for OS X with Gitian gitian, tbb-security, tbb-gitian, tbb-4.5-alpha tbb-team enhancement closed Medium
#10250 Disable RC4 in TBB Firefox tbb-security, ff45-esr-will-have tbb-team defect closed Medium
#10393 Torbrowser updates are verified through the Tor consensus tbb-security, tbb-update tbb-team project new Medium
#10394 Torbrowser's updater updates HTTPS-everywhere tbb-security, TorBrowserTeam201805, https-everywhere tbb-team task new Medium
#10397 Torbrowser's updater integrates additional protections from Thandy's threat model tbb-security, tbb-update tbb-team project new Medium
#10498 Get only the NoScript we want to our users tbb-security, noscript tbb-team defect new Medium
#10512 Firefox.exe doesn't have DEP enabled tbb-security erinn defect closed Medium
#10515 Compile Firefox with buffer overflow protection tbb-security, needs-triage tbb-team enhancement closed Medium
#10571 `import` called in potentially dangerous manner tbb-security, tbb-easy brade defect closed Medium
#11096 Randomize MAC address before start of Tor tbb-security tbb-team enhancement closed Medium
#11511 Investigate why TorLauncher is sometimes not loaded when starting TBB tbb-security tbb-team task closed Medium
#12103 Fully hardening firefox binary is broken since 3.5.3 on Linux tbb-security, tbb-testcase erinn defect closed Medium
#12199 Hardened bundles (with ASan) crash on tbb-security erinn defect closed Medium
#12418 TBBs with UBSan create lots of errors when running tbb-security, TorBrowserTeam201711 tbb-team defect assigned Medium
#12419 TBBs with ASan create alloc_dealloc_mismatch warnings tbb-security, tbb-hardening erinn defect closed Medium
#12420 Investigate deploying STACK to check for optimization-unstable code tbb-security, TorBrowserTeam201711, GeorgKoppen201711 tbb-team task new Medium
#12425 Investigate setjmp/longjmp-based exception handling for Tor Browser on Windows tbb-security tbb-team task new Medium
#12426 Make use of HeapEnableTerminationOnCorruption in Tor Browser on Windows tbb-security, tbb-firefox-patch, tbb-hardened, tbb-easy, TorBrowserTeam201704R tbb-team enhancement closed Medium
#12429 Enable Assertions in Tor Browser release builds tbb-security, tbb-firefox-patch tbb-team enhancement new Medium
#12430 Disable the jar: protocol for external resources via preference tbb-security, tbb-firefox-patch, tbb-isec-report, TorBrowserTeam201502R, MikePerry201502R tbb-team enhancement closed Medium
#12516 Compile Tor Browser with -fwrapv/-fno-strict-overflow tbb-security, tbb-gitian, tbb-hardened, TorBrowserTeam201512R tbb-team enhancement closed Medium
#12523 Backport Firefox patch to mark JIT pages as non-writable tbb-security, tbb-firefox-patch, tbb-hardened, TorBrowserTeam201606R mcs enhancement closed Medium
#12820 Test+Recommend Tor Browser with MS EMET (Enhanced Mitigation Experience Toolkit) tbb-security, tbb-isec-report, GeorgKoppen201610, TorBrowserTeam201610, ff52-esr tbb-team project assigned Medium
1 2 3
Note: See TracQuery for help on using queries.