#24239 closed defect (duplicate)

TBB's default values are dangerous

Reported by: cypherpunks Owned by: tbb-team
Priority: High Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

According to this, TBB 7.0.8 have these values.
https://blog.torproject.org/comment/272096#comment-272096

I can also confirmed it by looking at "about:config".

network.IDN_show_punycode = false (expecting TRUE)
security.enable_tls = false (TRUE)
security.ssl3.rsa_des_ede3_sha = true (FALSE)

Why Tor Browser didn't set these values to expected values?

Child Tickets

Change History (1)

comment:1 Changed 19 months ago by gk

Resolution: duplicate
Status: newclosed

For the punycode one we have #21961.

There is no security.enable_tls in Tor Browser. If you look at the source code for ESR 52 (https://dxr.mozilla.org/mozilla-esr52/search?q=security.enable_tls&redirect=false) it isn't even mentioned in it. I don't know where it is coming from in your version of Tor Browser.

For you third issue, see: https://bugzilla.mozilla.org/show_bug.cgi?id=1405511 and previously #18274.

Marking this as duplicate.

Note: See TracTickets for help on using tickets.