Despite having "extensions.torbutton.noscript_persist" set to "false", NoScript still remembers trusted sites after quitting the browser. I'm using safest security settings on Debian 10.
This is a big privacy risk because I accidentally created a unique ruleset this way.
Trac: Username: kromek
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Child items 0
Show closed items
No child items are currently assigned. Use child items to break down this issue into smaller parts.
Linked items 0
Link issues together to show that they're related.
Learn more.
UPDATE: It seems to reproduce the issue, you have to allow restrictions globally and restart the browser. It will still have disabled restrictions, and from now on, even if you enable restrictions again, it will start remembering ruleset of websites you set to TRUSTED.
UPDATE: It seems to reproduce the issue, you have to allow restrictions globally and restart the browser. It will still have disabled restrictions, and from now on, even if you enable restrictions again, it will start remembering ruleset of websites you set to TRUSTED.
What do you mean by "allow restrictions globally"? Could you give us complete steps to reproduce this issue?
UPDATE: It seems to reproduce the issue, you have to allow restrictions globally and restart the browser. It will still have disabled restrictions, and from now on, even if you enable restrictions again, it will start remembering ruleset of websites you set to TRUSTED.
What do you mean by "allow restrictions globally"? Could you give us complete steps to reproduce this issue?
Sorry, I meant like this:
Disable restrictions globally (the S! button)
restart the browser
restrictions will still be disabled globally (they shouldn't be), so undo that manually
go to any website and make it TRUSTED (permanently, not temp.)
restart the browser and visit the website again: it will still be trusted and JS enabled for it
Did this only begin in Tor Browser 9? Did you upgrade from Tor Browser 8.5 or is this a new installation?
Trac: Severity: Major to Normal Keywords: N/Adeleted, noscript, tbb-9.0-issues, TorBrowser201911 added Owner: N/Ato tbb-team Status: needs_information to assigned
Did this only begin in Tor Browser 9? Did you upgrade from Tor Browser 8.5 or is this a new installation?
Yes, it began in Tor Browser 9. Previously the issue was non-existent. It remains a bug in 9.0.1.
It happens in new "installation" which in my case is unpacking the TBB on Debian.
even if you enable restrictions again, it will start remembering ruleset of websites you set to TRUSTED.
Tor Browser remembers TRUSTED websites regardless whether disable restrictions globally was set before. This behaviour is reproducible on a clean Tor Browser install:
Launch Tor Browser and visit any website
Set the website to TRUSTED
Close and restart Tor Browser and visit the website again, the website is still set to trusted. The setting persists through reboot.
The same is true for giving permissions in NoScript's Options.
Launch Tor Browser on safest level
Click the NoScript icon and in the left menu, go to Options
General --> Preset customization, check one or more item (scripts, media, whatever)
Close and restart Tor Browser, the permissions are preserved. This is not reflected in the security settings or shield icon at all, both still show "safest". This will also survive reboot.
Tor Browser will reset itself after changing the security level repeatedly though (true for both scenarios).
Same as kromec, extensions.torbutton.noscript_persist is set to false, Override Tor Browser's Security Level preset is not checked.
This is a bug, and it should be fixed, but the NoScript configuration settings are hidden in Tor Browser for a reason. NoScript's settings should only be changes through the security slider.
Of course, some people change the settings manually, and when that leaks information the problem should be fixed.
Trac: Status: needs_information to new Priority: High to Medium Keywords: TorBrowserTeam202002 deleted, TorBrowserTeam202003 added