Opened 6 years ago

Closed 3 years ago

#10084 closed defect (worksforme)

Tech Evangelism - ssl_error_bad_mac_alert -> website is broken

Reported by: cypherpunks Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

On every https: site I have tried so far, with the latest version of the TBB (Linux, 64-bit) I receive the following error message:

Secure Connection Failed

An error occurred during a connection to www.torproject.org.

SSL peer reports incorrect Message Authentication Code.

(Error code: ssl_error_bad_mac_alert)

The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.

Please contact the website owners to inform them of this problem. Alternatively, use the command found in the help menu to report this broken site.

Child Tickets

Change History (3)

comment:1 Changed 6 years ago by nickm

Component: - Select a componentTorBrowserButton
Owner: set to mikeperry

comment:2 Changed 5 years ago by erinn

Component: TorBrowserButtonTor Browser
Keywords: tbb-torbutton added
Owner: changed from mikeperry to tbb-team

comment:3 Changed 3 years ago by bugzilla

Keywords: tbb-torbutton removed
Resolution: worksforme
Severity: Normal
Status: newclosed
Summary: Secure Connection FailureTech Evangelism - ssl_error_bad_mac_alert -> website is broken

essentially disabled RC4, meaning that instead of TLS_RSA_WITH_RC4_128_SHA, the server picks TLS_RSA_WITH_3DES_EDE_CBC_SHA. There appears to be a bug in the server's implementation or use of that cipher suite, because I can reproduce the bad MAC error using curl compiled with openssl

https://bugzilla.mozilla.org/show_bug.cgi?id=1144065

Note: See TracTickets for help on using tickets.