#21961 |
should torbrowser enable network.IDN_show_punycode by default?
|
needs_review
|
tbb-team
|
enhancement
|
Immediate
|
|
#16926 |
Multiple OS: Tor Browser leaks domains to system DNS management.
|
new
|
tbb-team
|
defect
|
Very High
|
|
#17175 |
Site is able to detect locale in some way
|
needs_information
|
tbb-team
|
defect
|
Very High
|
|
#18379 |
Mouse Tracking Defenses in Tor Browser
|
new
|
tbb-team
|
enhancement
|
Very High
|
|
#18820 |
Integrate code signing into the release process
|
assigned
|
gk
|
task
|
Very High
|
|
#19907 |
NoScript could not be verified and gets disabled after restart
|
needs_information
|
tbb-team
|
defect
|
Very High
|
|
#20784 |
TBB on OSX: "Something went wrong..."
|
needs_information
|
tbb-team
|
defect
|
Very High
|
|
#25969 |
SOCKS5 proxy hostname parsing problem
|
needs_information
|
tbb-team
|
defect
|
Very High
|
|
#28152 |
Gettor code refactor with Python Twisted
|
new
|
ilv
|
enhancement
|
Very High
|
|
#3600 |
Prevent redirects from transmitting+storing cookies+identifiers
|
assigned
|
pospeselr
|
defect
|
High
|
|
#4580 |
Some Tor clients go nuts requesting the consensus if there is no recent enough consensus
|
new
|
|
defect
|
High
|
Tor: unspecified
|
#10467 |
URLs are leaked to third party if they contain typos
|
new
|
tbb-team
|
defect
|
High
|
|
#11254 |
Tor Browser bundle v3.5 fails to clean up cancelled downloads in Temp folder
|
new
|
tbb-team
|
defect
|
High
|
|
#12427 |
Investigate Virtual Table Verification (VTV) hardening for Tor Browser on Linux and Windows
|
new
|
tbb-team
|
task
|
High
|
|
#13017 |
Determine if AudioBuffers/OfflineAudioContext are a fingerprinting vector
|
new
|
arthuredelstein
|
task
|
High
|
|
#13893 |
Torbrowser crashes on start when using MS EMET 5.x
|
reopened
|
gk
|
defect
|
High
|
|
#17558 |
Sanitize copying to clipboard
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#17879 |
Activating the Flash Player is not working anymore since Tor Browser 5.0.5
|
reopened
|
tbb-team
|
defect
|
High
|
|
#17901 |
Tor would bind ControlPort to public ip address if it has no localhost interface
|
new
|
|
defect
|
High
|
Tor: unspecified
|
#17979 |
CollecTor downloader module
|
new
|
atagar
|
defect
|
High
|
|
#18200 |
TrackHostExits forces circuits to same exit, regardless of SOCKSPort isolation flags
|
new
|
|
defect
|
High
|
Tor: unspecified
|
#18500 |
Investigate impact of fingerprinting via getClientRects()
|
new
|
tbb-team
|
task
|
High
|
|
#18537 |
Resist keyboard and mouse biometrics and tracking
|
assigned
|
nickm
|
enhancement
|
High
|
|
#18589 |
Tor browser writes SiteSecurityServiceState.txt with usage history
|
assigned
|
tbb-team
|
defect
|
High
|
|
#19197 |
New to Tor. Need help please
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#19409 |
Make a deb of snowflake and get into Debian
|
new
|
|
enhancement
|
High
|
|
#19491 |
HTTPS-Everywhere vanished during update
|
needs_information
|
tbb-team
|
task
|
High
|
|
#19517 |
crashing in OS X on 6.0, 6.01, 6.02
|
needs_information
|
|
defect
|
High
|
|
#19850 |
Disable Plaintext HTTP Clearnet Connections
|
new
|
tbb-team
|
enhancement
|
High
|
|
#20100 |
persistent libxul.so bug crashing TBB Linux/64 (but probably a bug in locally linked shared object)
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#20149 |
Test that static public key pins are working
|
assigned
|
boklm
|
enhancement
|
High
|
|
#20214 |
Ultrasound Cross Device Tracking techniques could be used to launch deanonymization attacks against some users
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#20339 |
tor-browser mozilla_user0 directory often appear in /tmp
|
new
|
tbb-team
|
defect
|
High
|
|
#20772 |
src="data:<;base64 images rendered when "Show images"="Blocked"
|
assigned
|
tbb-team
|
defect
|
High
|
|
#20941 |
Tor browser will resize it self after the dock is enabled and the browser is dragged to a new location
|
assigned
|
arthuredelstein
|
defect
|
High
|
|
#21204 |
Mac Sierra Password Protected Directory
|
assigned
|
tbb-team
|
defect
|
High
|
|
#21392 |
"New Identity" takes too long
|
new
|
tbb-team
|
defect
|
High
|
|
#21559 |
Tor browser deanonymization/fingerprinting via cached intermediate CAs
|
new
|
tbb-team
|
defect
|
High
|
|
#22465 |
Tor Broswer Freezing, Crashing
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#22530 |
Redirection loop with disabled js on every page of blog.torproject.org
|
accepted
|
hiro
|
defect
|
High
|
|
#22872 |
SIGSEGV crash in TorBrowser 7.5a2 on OSX 10.11.6
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#22919 |
Form tracking and OS fingerprinting (only Windows, but without Javascript)
|
new
|
tbb-team
|
defect
|
High
|
|
#22960 |
Tor Browser crashes when IPC connection got lost
|
new
|
tbb-team
|
defect
|
High
|
|
#22971 |
The XPI signing mechanism needs to use different hash functions.
|
new
|
tbb-team
|
defect
|
High
|
|
#22977 |
TorBrowser 7.0.2 crash on Mac OS X 10.12.5
|
new
|
tbb-team
|
defect
|
High
|
|
#22978 |
BUG "Could not connect to control port" + Temporary solution
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#23050 |
Tab keeps crashing on Win 8.1 with Tor Browser 7 (in e10s mode)
|
new
|
tbb-team
|
defect
|
High
|
|
#23062 |
Tor browser bundle crashed when clicking on a link
|
new
|
tbb-team
|
defect
|
High
|
|
#23210 |
Favicons are getting reloaded over catch-all-circuit if content process crashes
|
new
|
tbb-team
|
defect
|
High
|
|
#23313 |
The trac "reply/edit/delete" comment buttons now require JavaScript
|
new
|
qbi
|
defect
|
High
|
|
#23424 |
Stop exposing the moz-icon URL scheme to the web
|
new
|
tbb-team
|
defect
|
High
|
|
#23452 |
Tor Browser macOS dmg's are not mountable on some systems
|
new
|
tbb-team
|
defect
|
High
|
|
#23508 |
large clock skews cause numerous bootstrap UX issues
|
new
|
|
defect
|
High
|
Tor: unspecified
|
#23664 |
Deal with UUID for content sandbox temp folder on Windows and Mac
|
new
|
tbb-team
|
defect
|
High
|
|
#23769 |
Tor crashes Mac OS X 12 and 13
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#23864 |
Onion browser can be signed with a Enterprise Distribution certificate, to get around China's censorship
|
new
|
|
defect
|
High
|
|
#23884 |
After Oct 10 MS update my TOR Browser won't open.
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#23893 |
Tor Browser page tabs crash on initial loading of sites including Tor
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#24126 |
"Temporarily allow all this page" breaks JS on all already opened HTTPS sites (on Medium Security)
|
new
|
tbb-team
|
defect
|
High
|
|
#24192 |
When I visit a V3 onion that supplies a invalid certificate, torbrowser will lookup the onion when the get certifice button is clicked
|
new
|
tbb-team
|
defect
|
High
|
|
#24236 |
plugin-container.app crash for TBB for Mac 7.0.9 (based on Mozilla Firefox 52.4.1) (64-bit)
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#24351 |
Block Global Active Adversary Cloudflare
|
reopened
|
tbb-team
|
enhancement
|
High
|
|
#24506 |
Move some bandwidth authority servers to a CDN
|
needs_information
|
tom
|
task
|
High
|
|
#24619 |
Tor 0.3.1.9 exited unexpectedly on Windows
|
new
|
|
defect
|
High
|
Tor: unspecified
|
#24657 |
Firefox crashes everyday
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#25088 |
NoScript failed to load worker script on higher security levels
|
new
|
tbb-team
|
defect
|
High
|
|
#25140 |
Parse only .torrc files in torrc.d directory
|
merge_ready
|
Jigsaw52
|
task
|
High
|
Tor: 0.4.1.x-final
|
#25141 |
enabling CellStatistics results in gigabytes of incremental memory consumption
|
new
|
|
defect
|
High
|
Tor: unspecified
|
#25918 |
Standardize the 'onion service' name
|
new
|
|
defect
|
High
|
Tor: unspecified
|
#26209 |
In Tor Blog comments pages appear even when the limit isn't reached
|
reopened
|
hiro
|
defect
|
High
|
|
#26215 |
Add an option to Proxy tab: "Do nothing"
|
new
|
sukhbir
|
task
|
High
|
|
#26377 |
Fresh Tor Browser 7.5.5 (2018-06-09) for macOS install crashes on start
|
needs_information
|
tbb-team
|
defect
|
High
|
|
#26473 |
Tor Browser high CPU usage while browsing Facebook
|
new
|
tbb-team
|
defect
|
High
|
|
#26517 |
When I have security setting set to "Safest" and I open NoScrip's preferences and click reset, TorBrowser still says Security setting "Safest" even though many sites are now whitelisted
|
new
|
tbb-team
|
defect
|
High
|
|
#27141 |
Backport TLS1.3 patches
|
reopened
|
tbb-team
|
enhancement
|
High
|
|
#27385 |
https://snowflake.torproject.org/embed is confusing
|
new
|
|
defect
|
High
|
|
#27404 |
I cant edit the Wiki after registration
|
reopened
|
qbi
|
defect
|
High
|
|
#27485 |
Onboarding: user not taught *how* to open the security-slider dialog
|
new
|
tbb-team
|
defect
|
High
|
|
#27569 |
Stop bad feature of ThunderBird - Built-in browser
|
new
|
sukhbir
|
defect
|
High
|
|
#27592 |
TBA: 'Clear private data' option does not clear browsing history
|
new
|
tbb-team
|
defect
|
High
|
|
#27596 |
Disable Submitting Crash to Mozilla by Default
|
new
|
sukhbir
|
defect
|
High
|
|
#27732 |
New Identity does not reset NoScript's Temporarily Trusted settings
|
new
|
tbb-team
|
defect
|
High
|
|
#28172 |
Javascript "ON" warnings given on .onion sites!!!
|
new
|
|
defect
|
High
|
|
#28214 |
TOR DOESNT WORK
|
new
|
sukhbir
|
task
|
High
|
|
#28587 |
Android app has stopped finding servers.
|
new
|
n8fr8
|
defect
|
High
|
|
#28605 |
OMG! Guard node only!
|
new
|
tbb-team
|
defect
|
High
|
|
#29152 |
Websites know you IP
|
new
|
hiro
|
defect
|
High
|
|
#6217 |
Mozilla updates queries happen at regular intervals
|
new
|
tbb-team
|
defect
|
Medium
|
|
#9521 |
"new identity" leaks memory in eventSuppressor.suppressEventHandling()
|
assigned
|
tbb-team
|
defect
|
Medium
|
|
#10498 |
Noscript. Path of trust.
|
reopened
|
erinn
|
defect
|
Medium
|
|
#12672 |
Tor log should be accessible while Tor Browser is starting up
|
new
|
brade
|
enhancement
|
Medium
|
|
#12820 |
Test+Recommend Tor Browser with MS EMET (Enhanced Mitigation Experience Toolkit)
|
assigned
|
gk
|
project
|
Medium
|
|
#16978 |
Minority of hostile dirauths can influence consensus in dangerous ways
|
new
|
|
defect
|
Medium
|
Tor: unspecified
|
#17193 |
Don't print bridge IPs/fingerprints in WARN/NOTICE log messages
|
assigned
|
isis
|
defect
|
Medium
|
Tor: unspecified
|
#17367 |
Swap files can contain evidence of browsing history
|
new
|
tbb-team
|
defect
|
Medium
|
|
#17491 |
Orbot crashes when App-mode is enabled
|
new
|
n8fr8
|
defect
|
Medium
|
|
#17600 |
HTTPS Everywhere Breaks web page
|
assigned
|
legind
|
defect
|
Medium
|
|
#17782 |
Relays may publish descriptors with incorrect IP address
|
needs_revision
|
|
defect
|
Medium
|
Tor: unspecified
|
#18080 |
CORS header 'Access-Control-Allow-Origin' missing
|
new
|
tbb-team
|
defect
|
Medium
|
|
#18090 |
Torcrazybutton eats all memory and crashes Tor Browser
|
reopened
|
tbb-team
|
defect
|
Medium
|
|