When a user attempts to download a file with TBB, she will get a Tor-specific dialog box telling her that an external application is needed to handle the file and that such applications are not Tor safe by default. The user is then presented with two choices: to cancel or to launch the application.
The message is somewhat confusing and does not clarify that "launch application" really means "open the save file dialog that I am used to see". We should consider rewording this to something more user-friendly.
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Child items ...
Show closed items
Linked items 0
Link issues together to show that they're related.
Learn more.
The ideal case would be to pop up the warning after the user clicks 'run' (i.e. after the "do you want to save or run it" question), but apparently that's really hard to make Firefox do.
Load external content?An external application is needed to handle:NOTE: External applications are NOT Tor safe by default and can unmask you!If this file is untrusted, you should either save it to view while offline or in a VM, or consider using a transparent Tor proxy like Tails LiveCD or torsocks.Launch application CancelAlways launch applications from now on
How about the following:
Download this file?The Tor Browser Bundle is not able to handle this file. You will need to download it and open it with another application. You should be very careful when downloading files via Tor as these files can contain Internet resources that will be downloaded outside of Tor when you open them. This will reveal your real IP address.If you do want to download this file, it is recommended that you use the Tails liveCD while doing so. See https://tails.boum.org/ for more information.Download fileCancelAlways download files from now on
I think that sounds better. I have two small suggestions (in bold) below since the pure act of downloading is no problem.
Download this file?
The Tor Browser Bundle is not able to handle this file. You will need to download it and open it with another application.
You should be very careful when downloading and opening files outside the Tor Browser Bundle as these files can contain Internet resources that could reveal your real IP address.
If you do want to download this file, it is recommended that you use the Tails liveCD while doing so. See https://tails.boum.org/ for more information.
Download file
Cancel
Always download files from now on
Download this file?The Tor Browser Bundle is not able to handle this file. You will need to download it and open it with another application. You should be very careful when downloading and opening files outsidethe Tor Browser Bundle as these files can contain Internet resourcesthat will be downloaded outside of Tor when you open them. This willreveal your real IP address, thus be non-anonymous.If you do want to download this file, it is recommended that you eitherview it offline in a VM, use a transparent Tor proxy or a Tor Live CD,such as [Tails](https://tails.boum.org/) while doing so.Download file | Cancel | Always download files from now on
We should in any case fix the message to tell the user what's going on -- that should be doable before any new API and would help a lot of the user support requests.
Are people happy with proper's suggested text? It is a bit long, but I think it captures all the issues in terms of the risk for the user. Will people understand it? Will it still cause trouble for people who hit that text when downloading a TBB update?
I'm fine with the proposed text, and I think it should be used. If users are still confused by the new text, I'm sure they will let us know on the help desk, and we can continue improving as needed.
Download this file?The Tor Browser cannot open this file. To view it, you will need todownload it and open it with another application.Opening files may de-anonymize you by connecting to the Internetwithout using Tor, thus revealing your real IP address.To view this file, you should do so offline in a virtual machine.Download file | Cancel | Always download files from now on