<feed xmlns='http://www.w3.org/2005/Atom'>
<title>user/richard/tor-browser, branch bug_13410_v1</title>
<subtitle>Richard's tor-browser repository</subtitle>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/'/>
<entry>
<title>Bug 13410: Disable self-signed certificate warnings when visiting .onion sites</title>
<updated>2020-02-26T20:35:06+00:00</updated>
<author>
<name>Richard Pospesel</name>
<email>richard@torproject.org</email>
</author>
<published>2020-02-26T20:35:06+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=5c71904dc8e50ded0439050936864361523c0d3b'/>
<id>5c71904dc8e50ded0439050936864361523c0d3b</id>
<content type='text'>
Self-signed certs and certs signed by an unknown certificate authority
are not so much a problem for sites hosted on onion services.

This patch alters the trust level for certs for onion sites, treating
them as trusted by default (for the purposes of cert chain
authentication). Other error conditions (expired certs, mismatched
domain, etc) still raise appropriate messages to the user.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Self-signed certs and certs signed by an unknown certificate authority
are not so much a problem for sites hosted on onion services.

This patch alters the trust level for certs for onion sites, treating
them as trusted by default (for the purposes of cert chain
authentication). Other error conditions (expired certs, mismatched
domain, etc) still raise appropriate messages to the user.
</pre>
</div>
</content>
</entry>
<entry>
<title>squash! Bug 30237: Add v3 onion services client authentication prompt</title>
<updated>2020-02-21T21:26:49+00:00</updated>
<author>
<name>Kathy Brade</name>
<email>brade@pearlcrescent.com</email>
</author>
<published>2020-02-13T20:06:38+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=aed69dc95387429e18b18ad578fb78d4a83d91f2'/>
<id>aed69dc95387429e18b18ad578fb78d4a83d91f2</id>
<content type='text'>
Also fixes bug 19757:
 Add a "Remember this key" checkbox to the client auth prompt.

 Add an "Onion Services Authentication" section within the
 about:preferences "Privacy &amp; Security section" to allow
 viewing and removal of v3 onion client auth keys that have
 been stored on disk.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Also fixes bug 19757:
 Add a "Remember this key" checkbox to the client auth prompt.

 Add an "Onion Services Authentication" section within the
 about:preferences "Privacy &amp; Security section" to allow
 viewing and removal of v3 onion client auth keys that have
 been stored on disk.
</pre>
</div>
</content>
</entry>
<entry>
<title>fixup! Pick up latest Torbutton code</title>
<updated>2020-02-21T21:26:14+00:00</updated>
<author>
<name>Matthew Finkel</name>
<email>sysrqb@torproject.org</email>
</author>
<published>2020-02-21T21:26:14+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=9e9300163c9074f9b12691d42aefc489e27729ef'/>
<id>9e9300163c9074f9b12691d42aefc489e27729ef</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug 32493: Disable MOZ_SERVICES_HEALTHREPORT</title>
<updated>2020-02-19T20:08:38+00:00</updated>
<author>
<name>Nicolas Vigier</name>
<email>boklm@torproject.org</email>
</author>
<published>2020-01-30T13:32:13+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=6046d1d582804594a57d132280376b8027d1ed83'/>
<id>6046d1d582804594a57d132280376b8027d1ed83</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug 32658: Create a new MAR signing key</title>
<updated>2020-02-19T19:50:34+00:00</updated>
<author>
<name>Georg Koppen</name>
<email>gk@torproject.org</email>
</author>
<published>2020-01-17T12:54:31+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=0f42a8ed2229c1ad5da15803eeebd2f849ffdb21'/>
<id>0f42a8ed2229c1ad5da15803eeebd2f849ffdb21</id>
<content type='text'>
It's time for our rotation again: Move the backup key in the front
position and add a new backup key.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
It's time for our rotation again: Move the backup key in the front
position and add a new backup key.
</pre>
</div>
</content>
</entry>
<entry>
<title>Revert "Bug 1603270 - Add telemetry for FirefoxPromoBannerRow user actions. r=VladBaicu, a=RyanVM"</title>
<updated>2020-02-11T20:41:06+00:00</updated>
<author>
<name>Matthew Finkel</name>
<email>Matthew.Finkel@gmail.com</email>
</author>
<published>2020-02-11T20:41:06+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=c2da27fca068dac7658fe53f51124908ee8c723b'/>
<id>c2da27fca068dac7658fe53f51124908ee8c723b</id>
<content type='text'>
This reverts commit 334f572f8b2113c464bd65e1282b7085a1dfb5eb.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This reverts commit 334f572f8b2113c464bd65e1282b7085a1dfb5eb.
</pre>
</div>
</content>
</entry>
<entry>
<title>Revert "Bug 31764: Fix for error when navigating via 'Paste and go'"</title>
<updated>2020-02-11T02:30:11+00:00</updated>
<author>
<name>Nicolas Vigier</name>
<email>boklm@torproject.org</email>
</author>
<published>2020-01-30T10:57:52+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=19fa956d545b6af7f0aa5048bceab7c00ec879cc'/>
<id>19fa956d545b6af7f0aa5048bceab7c00ec879cc</id>
<content type='text'>
This reverts commit 59d89229b68f8fbaa46e910a9bd03a6b26e8403e.

With #32470 we backported Mozilla's fix for this issue.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This reverts commit 59d89229b68f8fbaa46e910a9bd03a6b26e8403e.

With #32470 we backported Mozilla's fix for this issue.
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug 1590538 - Don't pass an empty object to urlbar-user-start-navigation because it doesn't handle it properly. r=Standard8</title>
<updated>2020-02-11T02:30:11+00:00</updated>
<author>
<name>Marco Bonardo</name>
<email>mbonardo@mozilla.com</email>
</author>
<published>2019-10-30T14:25:02+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=a83411dfd84faff2f5a9f40da161339f065504de'/>
<id>a83411dfd84faff2f5a9f40da161339f065504de</id>
<content type='text'>
Differential Revision: https://phabricator.services.mozilla.com/D50634

--HG--
extra : moz-landing-system : lando
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Differential Revision: https://phabricator.services.mozilla.com/D50634

--HG--
extra : moz-landing-system : lando
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug 32414: Make Services.search.addEngine obey FPI</title>
<updated>2020-02-11T02:30:11+00:00</updated>
<author>
<name>Alex Catarineu</name>
<email>acat@torproject.org</email>
</author>
<published>2020-01-10T16:54:18+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=3ad7a3a333643469d0d1e80ebc7670983f9a6a73'/>
<id>3ad7a3a333643469d0d1e80ebc7670983f9a6a73</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug 461204 - Improve the random number generator for the boundaries in multipart/form-data r=smaug</title>
<updated>2020-02-11T02:30:10+00:00</updated>
<author>
<name>Alex Catarineu</name>
<email>acat@torproject.org</email>
</author>
<published>2020-01-13T20:41:14+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=ac96b77c70e682d27b335c483099cbdacbaccb16'/>
<id>ac96b77c70e682d27b335c483099cbdacbaccb16</id>
<content type='text'>
Using a weak RNG for the form boundary allows a website operator to perform several
attacks on users (as outlined in https://trac.torproject.org/projects/tor/ticket/22919)

These include:
 - Identifying Windows users based on the unseeded RNG
 - Identify the number of form submissions that have occurred cross-origin between same-origin submissions

Additionally, a predictable boundary makes it possible to forge a boundary in the middle
of a file upload.

Differential Revision: https://phabricator.services.mozilla.com/D56056

--HG--
extra : moz-landing-system : lando
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Using a weak RNG for the form boundary allows a website operator to perform several
attacks on users (as outlined in https://trac.torproject.org/projects/tor/ticket/22919)

These include:
 - Identifying Windows users based on the unseeded RNG
 - Identify the number of form submissions that have occurred cross-origin between same-origin submissions

Additionally, a predictable boundary makes it possible to forge a boundary in the middle
of a file upload.

Differential Revision: https://phabricator.services.mozilla.com/D56056

--HG--
extra : moz-landing-system : lando
</pre>
</div>
</content>
</entry>
</feed>
