Opened 5 months ago

#28383 new defect

HTTPS Everywhere's exceptions persist

Reported by: janbhez Owned by: legind
Priority: Very High Milestone:
Component: HTTPS Everywhere Version:
Severity: Critical Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Using Tor it is recommended to try secure connections first. Unfortunately HTTPS Everywhere doesn't work this way by default: https://www.eff.org/https-everywhere/faq#why-use-a-whitelist-of-sites-that-support-https-why-cant-you-try-to-use-https-for-every-last-site-and-only-fall-back-to-http-if-it-isnt-available

To try secure connections first, the user has to Disable all unencrypted requests. When HTTPS Everywhere is set to Disable all unencrypted requests, the exceptions (the sites visited via HTTP) persist even after Tor Browser is closed.

When HTTPS Everywhere disabled on a site, Reset to Defaults is not available from the button. To clear the list the user has to open the about:addons page, select HTTPS Everywhere's options and remove sites 1-by-1 from the HTTPS Everywhere Sites Disabled list. There is no "clear all" button.

Child Tickets

Attachments (2)

HTTPS_Everywhere_disabled_on_site_toolbar_button_dropdown.png (11.8 KB) - added by janbhez 5 months ago.
HTTPS_Everywhere_about_addons_options.png (34.2 KB) - added by janbhez 5 months ago.
HTTPS Everywhere about:addons options

Download all attachments as: .zip

Change History (2)

Changed 5 months ago by janbhez

HTTPS Everywhere about:addons options

Note: See TracTickets for help on using tickets.