When Torbutton's state is toggled in Firefox, it locks down page interaction and
forces the user to reload the page manually. This includes urls that have
been excluded from the proxy in Firefox's advanced network configuration

It would be helpful if Torbutton respected proxy-excluded urls and left their
state alone.

comment:1 Changed 9 years ago by coderman

Relaying IRC commentary into less ephemeral medium:
This is dangerous for at least one reason, probably more. If an exit spoofs DNS or injects identifying links
to a proxy excluded resource they can do "bad things" with a free pass around TorButton. (and bad gets worse
if this white listed site has any CSRF/XSS in it, etc).

For users who are white listing certain resources, transitioning to a tandem regular browser and Tor browser
(with portable Firefox) is much less risky.

To do this right you would almost need a Torbutton per tab type configuration, where a proxy excluded
resource must be loaded in its own distinct tab and non-Tor state. Or maybe there is a more robust and easy
way someone else will come up with :)

Toggle bugs.

