Tor browser for Android doesn't verify if the torbutton extension has a signature to install it.
Thus, if someone sends a tampered torbutton extension to the user, they can install it.
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Child items
0
Show closed items
No child items are currently assigned. Use child items to break down this issue into smaller parts.
Linked items
0
Link issues together to show that they're related.
Learn more.
Thanks, this works for me on a fresh build. I am not sure why just adding the prefs does nothing, though. Applied to tor-browser-60.1.0esr-8.0-1 as commit a0620db9e7cd08e3d67a42d0c5b1067d5b3ed355.
igt0, sysrqb: could anyone of you open a follow-up ticket with a plan for fixing the underlying issue better. FWIW: https://bugzilla.mozilla.org/show_bug.cgi?id=1464766 landed in esr60 and might be a thing to consider here.
igt0, sysrqb: could anyone of you open a follow-up ticket with a plan for fixing the underlying issue better. FWIW: https://bugzilla.mozilla.org/show_bug.cgi?id=1464766 landed in esr60 and might be a thing to consider here.