Opened 9 years ago

Closed 9 years ago

#1672 closed defect (fixed)

Firefox search box typeahead completion leaks plaintext queries

Reported by: schoen Owned by: mikeperry
Priority: High Milestone:
Component: HTTPS Everywhere/EFF-HTTPS Everywhere Version:
Severity: Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Even if an HTTPS Everywhere rule matches the relevant URL, typing text in the Firefox search box will send unencrypted HTTP queries to the host defined for typeahead completion in the search engine definition file.

HTTPS Everywhere thinks it is rewriting these queries (according to the error console), but a packet sniffer verifies that the rewriting never occurs and the queries are actually sent as plaintext! (To be more precise, the protocol scheme and host are never effectively changed; a rewrite rule can still have an effect on the path part of the URL.)

See
https://mail1.eff.org/pipermail/https-everywhere/2010-July/000025.html
for more details.

Child Tickets

Change History (2)

comment:1 Changed 9 years ago by pde

Owner: changed from pde to mikeperry
Status: newassigned

.

comment:2 Changed 9 years ago by pde

Resolution: fixed
Status: assignedclosed

We believe this is fixed in 0.2.2.development.3

Note: See TracTickets for help on using tickets.