#7349 Obfsbridges should be able to "disable" their ORPort isis, yawning, cass, mrphs, gk, catalyst, ln5, phoul, dmr, phw new project Very High
#12968 Specify HEASLR (High Entropy Address Space Layout Randomization) in MinGW-w64 tom@…, gk, boklm, sukhbir needs_revision tbb-team enhancement Very High
#26858 TBA: Investigating patching AccountManager igt0, gk needs_revision tbb-team defect Very High
#34374 put trac readonly on june 12th 2020 gk, intrigeri, hiro, gaba, mcs, boklm assigned hiro task Very High
#2940 Adapt browser time based on tor's notion of clock skew... tagnaq@…, gk, adrelanos@…, nicoo new tbb-team enhancement High
#3600 Prevent redirects from transmitting+storing cookies+identifiers joyton, gk, michael, arma, arthuredelstein, tbb-team new tbb-team defect High
#3652 Export clock skew opinion as getinfo command gk, adrelanos@…, arthuredelstein@…, brade, mcs, catalyst, dmr needs_revision enhancement High
#5291 Re-test TBB on dual-stacked IPv6 machine gk, ln5 assigned tbb-team task High
#5292 Build a (manual) TBB test suite gk, Shondoit, tagnaq@…, tichodroma@…, runa, ariyana@…, drwhax@… assigned tbb-team task High
#5798 Improve persistence and WebFont compatibility of font patch gk, arthuredelstein@…, dcf@…, Peter_Baumann_TUD new tbb-team defect High
#7449 TorBrowser creates temp files in Linux /tmp & Windows %temp% and OSX(various places) during the file downloads dialog & when using internal browser video player gk, brade, mcs, g4vin0leary new tbb-team defect High
#8558 Re-verify app-launching defenses on Windows runa, gk assigned tbb-team task High
#8770 Verify that @font-face fallback fonts can't be probed gk new tbb-team task High
#9675 Provide feedback mechanism for clock-skew and other bad problems mcs, Sherief, whonix-devel@…, arthuredelstein, gk, catalyst, dmr assigned brade defect High
#10388 TBB should disable "New Private Window" menu option if disk history is disabled wiretapped, gk new tbb-team defect High
#10493 History not being deleted in TBB after disabling and enabling Private Browsing Mode mcs, brade, gk new tbb-team defect High
#10756 TorBrowser should zero-out cleared partial downloads or not delete them at all mmxbass, gk new tbb-team defect High
#11095 Allow storing passwords in TorBrowser gk, nord-stream@… new tbb-team enhancement High
#11207 Sybil selection should be trickier to game gk new enhancement High
#11222 Inform user if reachable bridges drop below a configurable fraction/number mcs, gk, isabela, phoul, pari needs_information brade defect High
#12683 Permissions in nsIPermissionManager aren't cleared with TorButton's "New Identity" isis, mikeperry, gk new tbb-team defect High
#12736 DLL hijacking vulnerability in TBB gk, tom@… new tbb-team defect High
#12977 Fix Firefox's Full Screen Permissions Prompt gk new tbb-team defect High
#13543 HTML5 media support may lead to fingerprinting gk new tbb-team defect High
#13873 hard lock tails/torbrowser gk, DqZYF new tbb-team enhancement High
#14390 Browser configuration fingerprinting arthuredelstein, gk, brade, mcs, nord-stream@…, adrelanos new tbb-team defect High
#14985 NoScript Clickjacking warning when clicking on embedded content lunar, gk, gacar, brade, mcs, arthuredelstein new tbb-team defect High
#15563 ServiceWorkers violate first party isolation, probably gk, traumschule new tbb-team defect High
#16633 Enable and isolate Firefox connection prediction gk, luke.crouch@… new tbb-team enhancement High
#17159 Deploy the PT reachability tests on some centralised system which reports to BridgeDB/BridgeAuth yawning, isis, gk new defect High
#18367 Windows Tor Browser should not store data in the Browser (application) directory brade, gk, blockflare, db, matt new mcs defect High
#20100 persistent bug crashing TBB Linux/64 (but probably a bug in locally linked shared object) gk needs_information tbb-team defect High
#20214 Ultrasound Cross Device Tracking techniques could be used to launch deanonymization attacks against some users yanick@…, shuanghao@…, federico.maggi@…, gk@…, jackiam2003@…, VasiliosMavroudis, francois@… needs_information tbb-team defect High
#21009 sandboxed OSX browser hangs if printing is attempted gk, brade assigned mcs defect High
#22530 Redirection loop with disabled js on every page of Dbryrtfbcbhgf, gk, qwertyu new hiro defect High
#26209 In Tor Blog comments pages appear even when the limit isn't reached gk reopened hiro defect High
#26419 TBA - Evaluate Android Intent Referrers igt0, gk new tbb-team defect High
#26782 TBA: Translation/Localization Support emmapeel, igt0, gk, hans@… new tbb-team project High
#26844 TBA: Investigate/Setup Fastlane igt0, gk, emmapeel, eighthave, tbb-team needs_revision tbb-team task High
#28679 Bridge connections on startup gk new enhancement High
#29583 HSv3: Faulty cross-certs in introduction point keys (allows naive onionbalance for v3s) s7r, twim, gk new defect High
#31149 Tor is stuck at "Loading Network Status" gk, dcf needs_information defect High
#32534 settle on one canonical jtorctl n8fr8, gk, akwizgran, sisbell needs_review tbb-team defect High
#2739 Clear Memory-Only Intermeditate Cert Store gk, lunar@… new tbb-team defect Medium
#5288 Clickjacking + popups subvert TBB url-bar isolation gk new tbb-team defect Medium
#5464 Decentralized measurement for network load balancing arma, aagbsn, isis@…, robgjansen, gk, starlight@… assigned arma enhancement Medium
#5791 Gather apparmor/selinux/seatbelt profiles for each component of TBB Shondoit, gk, andreas@…, unknown@…, tagnaq@…, tichodroma@…, ioerror, intrigeri, adrelanos@…, arthuredelstein@… new tbb-team project Medium
#5830 Write tool to automate web queries to Tor; and use Stem to track stream/circ allocation and results robgjansen, karsten, gsathya, cwacek, arthuredelstein, gk assigned metrics-team task Medium
#5915 Write patch to make socks handshakes succeed instantly gk, tom, brade, mcs needs_revision enhancement Medium
#6217 Mozilla updates queries happen at regular intervals gk, mcs, brade new tbb-team defect Medium
#6276 Hiding the context menu button breaks the Tools->HTTPS Everywhere menu swrobel, EisahLee@…, brade, mcs, gk accepted pde defect Medium
#7193 Tor's sybil protection doesn't consider IPv6 tyseom, gk needs_revision enhancement Medium
#7501 Audit PDF.js gk, isis, intrigeri new tbb-team task Medium
#7921 Remove/hide fingerprintable UI options gk, arthuredelstein new tbb-team enhancement Medium
#8163 It is no longer deterministic which Sybils we omit gk new defect Medium
#9121 SSL Observatory: tell users when they're being MITMed by a locally-trusted root CA gk, mikeperry new enhancement Medium
#9521 "new identity" leaks memory in eventSuppressor.suppressEventHandling() gk new tbb-team defect Medium
#9541 "Work Offline" button should stop/start tor (as well) gk, overview8 new tbb-team enhancement Medium
#10368 Review and audit Mozilla Sync gk new tbb-team task Medium
#10397 Torbrowser's updater integrates additional protections from Thandy's threat model mcs, brade, gk, adrelanos@… new tbb-team project Medium
#10426 "new identity" button causes in-progress downloads to be aborted gk, Rola, mcs new tbb-team defect Medium
#10607 Tor Browser Bundle 3.5 holds open files (gvfsd-metadata) gk new tbb-team defect Medium
#10839 Block, RFC1918, and others ranges (for Non-Tor SOCKS proxies) gk, o.cornu@… new tbb-team defect Medium
#10874 TorButton won't "blink" for update if using local Tor gk, mikeperry new defect Medium
#10952 Tor Browser leaves developer windows open after New Identity gk, brade, mcs new tbb-team defect Medium
#11038 TBB Test suite: Fingerprint test gk assigned tbb-team task Medium
#11206 Tor Browser will not save Exceptions in the Firefox cookie manager gk new tbb-team defect Medium
#11506 Users are confused by the 2000-01-01 00:00 UTC timestamp gk, boklm, intrigeri new tbb-team defect Medium
#12131 Measure connectivity patterns between relays meejah, phw, atagar, r.a@…, gk, catalyst assigned metrics-team project Medium
#12631 Tor Browser for ARM architecture gk, mcs, arma, boklm, intrigeri, peredor needs_revision project Medium
#12682 Tor Browser's HTML5 canvas fingerprinting dialogue could use a "Revoke" button isis, mikeperry, gk, brade, mcs new tbb-team enhancement Medium
#12820 Test+Recommend Tor Browser with MS EMET (Enhanced Mitigation Experience Toolkit) gk, mcs, arthuredelstein assigned tbb-team project Medium
#12995 default font seems seems to leak system locale information gk new tbb-team defect Medium
#12999 Use one clock skew per URL bar domain gk, adrelanos@… new tbb-team enhancement Medium
#13033 Apply mixed content blocking patch? arthuredelstein, gk new tbb-team task Medium
#13065 counter downgrade / stale mirror attacks on RecommendedTBBVersions - sign / verify tbb versions file gk new tbb-team defect Medium
#13148 Option to prevent history logging in the console gk new zyan enhancement Medium
#13198 clean up torbutton use of Mozilla services mcs, brade, gk new tbb-team defect Medium
#13367 Rate limit gyroscope sampling frequency on FF mobile gk, amoghbl1, fdsfgs@… new tbb-team defect Medium
#13445 Adjust TBB window size gacar, gk new tbb-team enhancement Medium
#13510 Master password can't be changed from default xtrac, gk, patrick@…, he7d3r, etienne new tbb-team defect Medium
#13669 disable "retry DNS on new circuit" for web content gk, mcs, isis new tbb-team defect Medium
#13677 Update Tor Browser 4.x videos mikeperry, gk, phoul, karsten needs_information Sherief task Medium
#13694 Ship with native build instructions for windows gk assigned gk enhancement Medium
#13770 BusyBox-style bundling of Go programs can save space gk new tbb-team enhancement Medium
#13775 Tor Browser won't open with OpenVPN gk new tbb-team defect Medium
#14085 HTTP redirects can leak third-party state (cookies, etc) gk, arthuredelstein, ctang@… new tbb-team enhancement Medium
#14089 Google Drive/Docs do not work in Tor Browser gk, brade, mcs, angelotheram new tbb-team defect Medium
#14205 Closely review all uses of IsCallerChrome() for e10s brade, arthuredelstein, gk assigned mcs task Medium
#14383 finalize RecommendedTBBVersions format sukhbir, micahlee, adrelanos@…, gk new tbb-team enhancement Medium
#14633 Default NoScript settings says "Allow Scripts Globally" is "dangerous" saint, gk, mcs, bastik.public@… new tbb-team defect Medium
#14638 Make it easier to add a bridge in network settings arthuredelstein, gk, brade, mcs new tbb-team enhancement Medium
#14713 Investigate Multiprofile/"Switchy" Support for Tor Browser gk, bastik.public@…, brade, mcs, isis new tbb-team task Medium
#14795 Windows Environmental Variables not usable in Profiles.ini when deploying tor browser across a domain brade, mcs, gk new tbb-team defect Medium
#14836 Can we compile in WebRTC to allow QRCode bridge entry? gk, brade, mcs, mikeperry new task Medium
#14924 Warn users before they install any addons gk, brade, mcs new tbb-team defect Medium
#14936 about:license should show be adapted for Tor Browser gk, brade, mcs new tbb-team defect Medium
#14999 Most/all esc_for_log instances in control.c should change. atagar, brade, mcs, gk new defect Medium
#15000 bring some sanity to quoted strings in the controller api arthuredelstein, atagar, gk needs_revision defect Medium
#15299 Regression tests for #5926 patch gk, boklm new tbb-team task Medium
