Ticket Summary Keywords Status Owner Type Priority
#23840 Google's reCAPTCHA fails 100% cloudflare,google,captcha,noscript reopened hiro defect Immediate
#29607 2019 Q1: Denial of service on v2 and v3 onion service tor-hs, tor-dos, network-team-roadmap-2019-Q1Q2, security, 041-longterm, 041-deferred-20190530, 042-deferred-20190918 needs_information pidgin defect Immediate
#7349 Obfsbridges should be able to "disable" their ORPort tor-bridge, SponsorZ, tor-pt, proposal-needed, censorship, sponsor19, 040-roadmap-proposed, anti-censorship-roadmap new project Very High
#9498 Allow bridge descriptors to contain no address if they are not being published tor-bridge, need-spec, bridgedb, needs-proposal censorship new enhancement Very High
#20742 prop224: Implement stealth client authorization prop224, needs-proposal, prop224-extra, tor-hs, client-authorization, stealth-authorization, term-project, 035-removed, hs-auth assigned asn enhancement Very High
#27413 Implement better communication between NoScript and Tor Browser noscript, tbb-security-slider, tbb-torbutton, TorBrowserTeam201809 new tbb-team enhancement Very High
#31474 NoScript died on autoupdate to 11.0.3. noscript new tbb-team defect Very High
#3652 Export clock skew opinion as getinfo command small-feature, needs-proposal, tor-client, clock-skew, 032-unreached, tbb-needs needs_revision enhancement High
#4580 Some Tor clients go nuts requesting the consensus if there is no recent enough consensus tor-client, tor-dos zombies deprecation new defect High
#4581 Dir auths should defend themselves from too many begindir requests per address prop258, tor-dos, tor-dirauth needs_revision defect High
#5222 Intelligently use capabilities/privileges and drop what we don't need for Mac OS X security tor-client osx needs-insight needs-design assigned enhancement High
#5456 Defend against path bias and tagging attacks SponsorZ-large, needs-proposal, tor-client research-program new project High
#7148 Even better parameter voting protocol needs-proposal, tor-dirauth security new defect High
#7572 Make relay crypto run on multiple CPU cores tor-relay, term-project-ideas, tor-dos multithreading performance cpu assigned yawning defect High
#7829 Support all kinds of DNS over Tor tor-relay, needs-proposal, dnssocks, proposal-219, term-project-ideas new task High
#8387 Unbuilt one-hop circuits sometimes hang around forever tor-client, 2016-bug-retrospective, needs-insight needs-analysis maybe-logs-would-help assigned defect High
#8742 Byte history leaks information about local usage/hidden services byte-history, stats, tor-hs, privacy, tor-relay, 026-triaged-1, 027-triaged-1-in, PostFreeze027 reopened defect High
#9001 Slow Guard Discovery of Hidden Services and Clients tor-hs, path-bias, guard-discovery, needs-proposal, mike-can, prop247, tor-guard, 032-unreached new defect High
#11207 Sybil selection should be trickier to game needs-proposal, needs-design, tor-dirauth new enhancement High
#11327 Dir auths should choose Fast and Guard flags by consensus weight if they don't measure needs-proposal tor-dirauth needs_revision TvdW defect High
#11743 nodelist_add_microdesc: assign md to all appropriate nodes properly prop248, tor-client, crash, tor-relay, needs-design, 2016-bug-retrospective new defect High
#12802 BridgeDB needs Nagios checks for the Email Distributor bridgedb-email, nagios, anti-censorship-roadmap-october assigned enhancement High
#13444 "GhostNode" - support relays that cannot accept incoming connections. anomity, circuit, torrc, security, needs-proposal research-program new project High
#13737 Move circuit building crypto to worker tor-client, tor-hs, multicore, performance, tor-dos, term-project-ideas intro assigned yawning enhancement High
#14985 NoScript Clickjacking warning when clicking on embedded content tbb-security, noscript new tbb-team defect High
#15940 Make a standard transition plan for killing off a client version SponsorS, tor-dos-designs, 034-triage-20180328, 034-removed-20180328 assigned task High
#15941 Form a plan for killing off client versions which assume they'll live forever SponsorS, needs-proposal, tor-dos-designs, 034-triage-20180328, 034-removed-20180328 assigned task High
#16844 Slow clients can't bootstrap because they expire their consensus fetch but then receive all the bytes from it anyway, making them expire their next fetch, putting them in a terrible loop needs-proposal, tor-client, low-bandwidth, sponsor4, bootstrap, 032-unreached new defect High
#17278 Fix malleable relay crypto tor-relay needs-proposal research-program crypto assigned defect High
#18200 TrackHostExits forces circuits to same exit, regardless of SOCKSPort isolation flags needs-analysis needs-diagnosis isolation trackhostexits new defect High
#18346 Separate the various roles that directory authorities play, from a configuration POV prop257, dirauth, tor-dos, security, needs-design assigned enhancement High
#18636 Write sub-proposals for each part of prop257: Refactoring authorities. Implement as appropriate. dirauth, needs-proposal, tor-dos, tor-dos-designs, term-project, research-program, 034-triage-20180328, 034-removed-20180328 assigned project High
#18637 Have OOM handler look at all memory consumption, not just some tor-dos oom memory-handler memory-monitoring assigned enhancement High
#18641 Teach the OOM handler about uploaded descriptors on a dirauth. tor-dos, tor-dirauth, oom assigned enhancement High
#19984 Use a better set of comparison/evaluation functions for deciding which connections to kill when OOS sockets, tor-dos, 034-triage-20180328, 034-removed-20180328 assigned defect High
#20647 Tor and Chutney CI improvements test, chutney, consistency, jenkins, integration-testing, continuous-integration, postfreeze-ok, teor-unreached-2019-03-08, tor-ci, 041-deferred-20190530, 042-can assigned enhancement High
#22331 Tor needs to stop trying to read directories before it changes users 032-unreached, apparmor usability 042-proposed new defect High
#23573 Do we want to close all connections when tor closes? shutdown, privcount, correctness, chutney-wants, review-group-24, 034-triage-20180328, 034-included20180401, 035-roadmap-subtask, 035-triaged-in-20180711, 035-deferred-20190115, 041-proposed needs_revision enhancement High
#23864 Onion browser can be signed with a Enterprise Distribution certificate, to get around China's censorship IOS new defect High
#23882 Investigate implementing a Rust allocator wrapping tor_malloc rust, rust-pilot, 034-triage-20180328, 034-removed-20180328, 041-proposed new enhancement High
#24126 "Temporarily allow all this page" breaks JS on all already opened HTTPS sites (on Medium Security) noscript new tbb-team defect High
#24487 Reverse path selection (choose outer hops first) guard-discovery-prop247-controller, needs-proposal, 034-roadmap-subtask, 034-triage-20180328, 034-included-20180328 assigned defect High
#25088 NoScript failed to load worker script on higher security levels noscript new tbb-team defect High
#25141 enabling CellStatistics results in gigabytes of incremental memory consumption 029-backport, tor-dos, 034-triage-20180328, 034-removed-20180328, 031-unreached-backport new defect High
#25372 relay: Allocation for compression goes very high tor-relay, compression, tor-dos, review-group-34, 034-triage-20180328, performance, oom, 034-removed-must-2018-09-05, regression?, 040-deferred-20190220, 033-unreached-backport new defect High
#26517 When I have security setting set to "Safest" and I open NoScrip's preferences and click reset, TorBrowser still says Security setting "Safest" even though many sites are now whitelisted ff60-esr, tbb-security-slider, noscript new tbb-team defect High
#27146 Mismatched digest in and master mixed chutney network regression, tor-dirauth, macOS, 035-roadmap-proposed, 035-can, teor-unreached-2019-03-08 assigned defect High
#27435 Poland, PLAY operator and OBFS4 pl, needs-proposal new dcf defect High
#27468 CI: add builds with the latest clang and gcc tor-ci, 035-deferred-20190115, 041-proposed, teor-unreached-2019-03-08 assigned enhancement High
#27732 New Identity does not reset NoScript's Temporarily Trusted settings tbb-newnym, tbb-8.0-issues, tbb-regression, tbb-8.0.1-can, noscript new tbb-team defect High
#28244 Followup tasks for Rust asan CI fixes 035-deferred-20190115, 041-proposed new defect High
#28356 DataDirectoryGroupReadable and CacheDirectoryGroupReadable conflicts forcing sandboxed Tor to crash tor-crash, regression, 040-roadmap-proposed, 035-backport, 029-backport-maybe, 035-can, postfreeze-ok, 040-deferred-20190220, 033-unreached-backport-maybe assigned defect High
#28679 Bridge connections on startup tor-bridge, censorship, needs-proposal, 041-proposed, ex-sponsor-19, ex-sponsor19 new enhancement High
#28804 Add circuit padding to padding-spec.txt and write a doc for researchers wtf-pad, tor-relay, tor-cell, padding, tor-spec, 041-proposed, network-team-roadmap-august, scalability-roadmap assigned mikeperry defect High
#28849 Handle dormant mode in process library and for PT's 042-proposed, anti-censorship-roadmap-july, 042-deferred-20190918 needs_information enhancement High
#28970 tor_bug_occurred_(): Bug: ../src/or/hs_client.c:624: setup_intro_circ_auth_key: Non-fatal assertion tor-client, tor-hs, postfreeze-ok, 040-unreached-must, network-team-roadmap-august, regression?, 041-unreached-must, 042-should reopened dgoulet defect High
#29290 Help 2-3 dirauths to deploy sbws 10-proposed, no-changes-version assigned juga task High
#29583 HSv3: Faulty cross-certs in introduction point keys (allows naive onionbalance for v3s) tor-hs, scaling, onionbalance, 040-backport, 035-backport, needs-proposal, network-team-roadmap-september, security, 041-longterm, 041-deferred-20190530 new defect High
#29646 NoScript XSS user choices are persisted tbb-disk-leak xss noscript tbb-newnym ux-team new tbb-team defect High
#29927 Tor protocol errors causing silent dropped cells tor-hs, diagnostic, mystery, security new defect High
#29957 clicking on "click to play" media leaks URLs via NoScript on-disk preferences tbb-disk-leak, tbb-newnym, noscript needs_information tbb-team defect High
#30187 100% cpu usage in winthreads tor_cond_wait windows 035-backport 042-proposed assigned ahf defect High
#30537 WebGL fingerprint is different between Windows versions (and compared to non-Windows OSes) tbb-fingerprinting, tbb-fingerprinting-os new tbb-team defect High
#31896 Bad instructions in Support Portal, "How can I verify Tor Browser's signature?", discourage, deter, and prevent users on macOS from verifying the Signature of downloaded Tor Browser packages Support Portal bad instructions increase chance of users on macOS receiving a Tor Browser package containing corrupted files and/or malware - issue assigned pili defect High
#2282 Publish router descriptors rejected by the authorities or omitted from the consensus tor-dirauth debugging diagnostic easy new enhancement Medium
#2395 Break Wed and Wee weights into two classes each performance loadbalancing tor-client needs-proposal assigned enhancement Medium
#2664 DoS and failure resistence improvements SponsorZ-large, tor-dirauth, tor-dos new enhancement Medium
#2667 Exits should block reentry into the tor network needs-proposal, tor-relay, SponsorU-deferred new defect Medium
#2681 brainstorm ways to let Tor clients use yesterday's consensus more safely prop212, tor-client, small-feature, tor-dos-dirauth, low-bandwidth, sponsor4, sponsor8-maybe, 034-triage-20180328, 034-removed-20180328 035-removed sponsor8-removed new enhancement Medium
#2693 Design and implement improved algorithm for choosing consensus method needs-proposal, tor-dirauth new enhancement Medium
#2998 If your bridge is near your exit, Tor might surprise you by failing your circuit tor-bridge, prop247, needs-proposal new defect Medium
#3029 We should save received documents before parsing them lorax, tor-dirauth, debugging, diagnostic, tor-dos new enhancement Medium
#3037 Internal checks to detect client streams/circuits whose sock request vanished tor-client , debugging, diagnostic new enhancement Medium
#3520 CIRC FAILED REASON=DESTROYED events do not specify which hop sent the RELAY_TRUNCATED cell needs-proposal tor-client tor-control new rransom enhancement Medium
#3572 Disable Orbot transparent redirect for rfc1918 & localhost RFC1918 localhost assigned n8fr8 defect Medium
#4391 `GETINFO ns/all` doesn't return 'p' lines -- make something that does! tor-client, tor-control needs-proposal needs-design intro new defect Medium
#4631 Idea to make consensus voting more resistant needs-proposal, tor-dirauth robustness voting new enhancement Medium
#4794 NoScript Is Not Being Used Properly By The Tor Project NoScript assigned defect Medium
#4826 Write proposal for improved consensus voting schedules needs-proposal, tor-dirauth voting robustness new enhancement Medium
#5048 cbtmintimeout should have a lower maximum maybe-proposal, tor-relay cbt new defect Medium
#5392 Write proposal for n23 patch behavior needs-proposal tor-relay research-program needs_revision task Medium
#5903 Restore ExcludeEntryNodes feature tor-relay, needs-proposal needs-design new enhancement Medium
#5915 Write patch to make socks handshakes succeed instantly needs-proposal, tor-client, intro, performance, application, experiment, tbb-wants?, performance?, ux, 042-deferred-20190918 needs_revision enhancement Medium
#6256 Make circuit isolation isolate exits? (signal NEWNYM exit bucketing) circuit-isolation needs-proposal tor-client need-design maybe-bad-idea new enhancement Medium
#6495 Define ReducedExitPolicy/ExitPolicyGroups in tor/dirauths needs-proposal-maybe tor-relay needs-design exit-policy new enhancement Medium
#6623 --enable-static-tor cannot succeed tor-relay, autotools, build, link, static, 029-backport, 032-unreached-backport, 035-deferred-20190115, 041-proposed, 033-unreached-backport needs_revision defect Medium
#6777 add config option to not rate limit authority dir conns tor-dirauth, rate-limit, easy, tor-dos new defect Medium
#6790 Write proposal draft for directory mirrors to accept, aggregate and hand off descriptors to dirauths needs-proposal, tor-dos-dirauth, tor-dirauth new enhancement Medium
#7126 Multipath consensus integrity verification SponsorZ, key-theft, proposal-needed, tor-dirauth, term-project new enhancement Medium
#7750 Consider packaging inbuf when about to send an end cell tor-relay data-loss tcp-correctness fin-correctness needs-design new enhancement Medium
#8314 HTTPS Everywhere SSL Observatory can't initialize (unfound) libnss3.dylib OS X, Lion, 10.7.5, Firefox 19.0, libnss3.dylib, fail, initialize, NSS component, Observatory new pde defect Medium
#8453 Alter flag-weight balancing equations performance, SponsorZ, needs-proposal, tor-client, 034-triage-20180328, 034-removed-20180328 assigned enhancement Medium
#8787 Check return values for more unix functions tor-client tor-relay posix easy correctness safety new defect Medium
#9024 add supplementary groups when changing uid group, android, tor-client setuid setgid posix new enhancement Medium
#9165 Evaluate datagram-based transports; build and merge as appropriate tor-relay datagram needs-proposal research-program new project Medium
#9208 Allow node operator to avoid Guard flag guard tor-relay needs-proposal needs_information enhancement Medium
#9390 Warn if you're being a public relay but have too-low file descriptor limit tor-relay, easy, dos, resources, logging, 033-triage-20180320, 033-removed-20180320, reviewer-was-teor-20190422 needs_revision enhancement Medium
#9689 Write proposal for RELAY_AUTHENTICATE/multipath AUTHENTICATE delivery key-theft mike-0.2.5 needs-proposal so-crazy-it-just-might-work research-program term-project new project Medium
#9954 Replace broadcast voting protocol with something more robust tor-dirauth robustness voting needs-proposal research-program new defect Medium
#9998 resolve "localhost", "host", "hostname" and "host.localdomain" to tor-client, dns, naming, hosts, easy needs-analysis new enhancement Medium
