Opened 5 years ago

Closed 5 years ago

#13093 closed enhancement (fixed)

MiTM in the wild: Merge localbitcoins.com rule from master:

Reported by: cypherpunks Owned by: zyan
Priority: High Milestone:
Component: HTTPS Everywhere/EFF-HTTPS Everywhere Version:
Severity: Keywords: httpse-ruleset-bug
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Can you please merge Localbitcoins.com.xml from master into a stable release?

  • It's a straightforward rule from March 2013
  • The site uses Strict-Transport-Security
  • Yesterday, I witnessed a self-signed MiTM attempt against the site. It's likely that exit nodes are running sslstrip too

Child Tickets

Change History (3)

comment:1 Changed 5 years ago by bm

Milestone: HTTPS-E 4 stable
Resolution: fixed
Status: newclosed

Added in c836ca7d.

comment:2 Changed 5 years ago by cypherpunks

Resolution: fixed
Status: closedreopened

Are you sure that commit was pushed all right? Your link gives a 404 - Unknown commit object message, and I can't find the commit in my clone, nor is the rule in the 4.0 or stable branches.

comment:3 in reply to:  2 Changed 5 years ago by bm

Resolution: fixed
Status: reopenedclosed

Replying to cypherpunks:

Are you sure that commit was pushed all right? Your link gives a 404 - Unknown commit object message, and I can't find the commit in my clone, nor is the rule in the 4.0 or stable branches.

Absolutely sure. The canonical repo hasn't been updated. In the mean time you can view the change on the github "mirror".

Note: See TracTickets for help on using tickets.