Opened 3 years ago

Closed 3 years ago

#21746 closed task (fixed)

Have a closer eye on FlyWeb regarding proxy bypass

Reported by: gk Owned by: gk
Priority: High Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: ff52-esr, TorBrowserTeam201705, tbb-7.0-must, GeorgKoppen201705
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor: Sponsor4

Description (last modified by gk)

As mentioned in #19048 FlyWeb (https://wiki.mozilla.org/FlyWeb and https://hacks.mozilla.org/2016/09/flyweb-pure-web-cross-device-interaction landed but it is behind a pref (dom.flyweb.enabled is set to false). Nevetherless, it is scary enough that we should make sure that it is really disabled.

Child Tickets

Change History (7)

comment:1 Changed 3 years ago by gk

Keywords: TorBrowserTeam201704 tbb-7.0-must-alpha added

comment:2 Changed 3 years ago by gk

Priority: MediumHigh

Moving the investigation tickets to higher priority.

comment:3 Changed 3 years ago by gk

Keywords: TorBrowserTeam201705 added; TorBrowserTeam201704 removed

Moving our tickets to May 2017.

comment:4 Changed 3 years ago by gk

Keywords: tbb-7.0-must added; tbb-7.0-must-alpha removed

We are beyond the alpha testing. Moving tickets for tbb-7.0-must.

comment:5 Changed 3 years ago by gk

Keywords: GeorgKoppen201705 added
Owner: changed from tbb-team to gk
Status: newassigned

comment:6 Changed 3 years ago by gk

Description: modified (diff)

comment:7 Changed 3 years ago by gk

Resolution: fixed
Status: assignedclosed

I think we are good here. As said in the description we have a preference dom.flyweb.enabled which is set to false and looking through the source code all relevant parts adhere to it. Moreover, we already patched parts of FlyWeb related code it in #22165 and #21431. The new mDNS bits will get handled in #21861.

Note: See TracTickets for help on using tickets.