<feed xmlns='http://www.w3.org/2005/Atom'>
<title>user/richard/tor-browser, branch bug_32645_v1</title>
<subtitle>Richard's tor-browser repository</subtitle>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/'/>
<entry>
<title>fixup! Bug 23247: Communicating security expectations for .onion</title>
<updated>2020-01-31T13:02:09+00:00</updated>
<author>
<name>Richard Pospesel</name>
<email>richard@torproject.org</email>
</author>
<published>2020-01-31T12:53:26+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=637dd99341f99dcd21b0de7b3324653cb5af0063'/>
<id>637dd99341f99dcd21b0de7b3324653cb5af0063</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Revert "Bug 31764: Fix for error when navigating via 'Paste and go'"</title>
<updated>2020-01-30T10:57:52+00:00</updated>
<author>
<name>Nicolas Vigier</name>
<email>boklm@torproject.org</email>
</author>
<published>2020-01-30T10:57:52+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=45677fd3bc4fd9b69216bb25efadcbac3026672f'/>
<id>45677fd3bc4fd9b69216bb25efadcbac3026672f</id>
<content type='text'>
This reverts commit 59d89229b68f8fbaa46e910a9bd03a6b26e8403e.

With #32470 we backported Mozilla's fix for this issue.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This reverts commit 59d89229b68f8fbaa46e910a9bd03a6b26e8403e.

With #32470 we backported Mozilla's fix for this issue.
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug 1590538 - Don't pass an empty object to urlbar-user-start-navigation because it doesn't handle it properly. r=Standard8</title>
<updated>2020-01-30T10:56:04+00:00</updated>
<author>
<name>Marco Bonardo</name>
<email>mbonardo@mozilla.com</email>
</author>
<published>2019-10-30T14:25:02+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=d361b0b2c8e51cec5088233006be152c340b6553'/>
<id>d361b0b2c8e51cec5088233006be152c340b6553</id>
<content type='text'>
Differential Revision: https://phabricator.services.mozilla.com/D50634

--HG--
extra : moz-landing-system : lando
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Differential Revision: https://phabricator.services.mozilla.com/D50634

--HG--
extra : moz-landing-system : lando
</pre>
</div>
</content>
</entry>
<entry>
<title>fixup! TB4: Tor Browser's Firefox preference overrides.</title>
<updated>2020-01-28T23:34:48+00:00</updated>
<author>
<name>Nicolas Vigier</name>
<email>boklm@torproject.org</email>
</author>
<published>2020-01-15T12:16:44+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=e8411693ccfa757557eecd97baaa8bb12a5c87dc'/>
<id>e8411693ccfa757557eecd97baaa8bb12a5c87dc</id>
<content type='text'>
Bug 32948: Make referer behavior consistent regardless of private
           browing mode status
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Bug 32948: Make referer behavior consistent regardless of private
           browing mode status
</pre>
</div>
</content>
</entry>
<entry>
<title>fixup! Regression tests for TB4: Tor Browser's Firefox preference overrides.</title>
<updated>2020-01-28T18:22:40+00:00</updated>
<author>
<name>Georg Koppen</name>
<email>gk@torproject.org</email>
</author>
<published>2020-01-08T15:30:20+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=77970cdee3ba6c294a7acfe9d9b5a2ae9511e579'/>
<id>77970cdee3ba6c294a7acfe9d9b5a2ae9511e579</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>fixup! TB4: Tor Browser's Firefox preference overrides.</title>
<updated>2020-01-28T18:22:01+00:00</updated>
<author>
<name>Georg Koppen</name>
<email>gk@torproject.org</email>
</author>
<published>2020-01-09T10:13:29+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=da7e8b35800a41249b5c2a847c4f931c4bf6582a'/>
<id>da7e8b35800a41249b5c2a847c4f931c4bf6582a</id>
<content type='text'>
Remaining clean-up done in #27268.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Remaining clean-up done in #27268.
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug 32414: Make Services.search.addEngine obey FPI</title>
<updated>2020-01-28T17:19:14+00:00</updated>
<author>
<name>Alex Catarineu</name>
<email>acat@torproject.org</email>
</author>
<published>2020-01-10T16:54:18+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=2197dad64e5c3752b1daeab0c676fda07880144c'/>
<id>2197dad64e5c3752b1daeab0c676fda07880144c</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug 461204 - Improve the random number generator for the boundaries in multipart/form-data r=smaug</title>
<updated>2020-01-21T10:08:58+00:00</updated>
<author>
<name>Alex Catarineu</name>
<email>acat@torproject.org</email>
</author>
<published>2020-01-13T20:41:14+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=3b2165b8be4f7fd7889c17cbb39a4348f7666bc8'/>
<id>3b2165b8be4f7fd7889c17cbb39a4348f7666bc8</id>
<content type='text'>
Using a weak RNG for the form boundary allows a website operator to perform several
attacks on users (as outlined in https://trac.torproject.org/projects/tor/ticket/22919)

These include:
 - Identifying Windows users based on the unseeded RNG
 - Identify the number of form submissions that have occurred cross-origin between same-origin submissions

Additionally, a predictable boundary makes it possible to forge a boundary in the middle
of a file upload.

Differential Revision: https://phabricator.services.mozilla.com/D56056

--HG--
extra : moz-landing-system : lando
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Using a weak RNG for the form boundary allows a website operator to perform several
attacks on users (as outlined in https://trac.torproject.org/projects/tor/ticket/22919)

These include:
 - Identifying Windows users based on the unseeded RNG
 - Identify the number of form submissions that have occurred cross-origin between same-origin submissions

Additionally, a predictable boundary makes it possible to forge a boundary in the middle
of a file upload.

Differential Revision: https://phabricator.services.mozilla.com/D56056

--HG--
extra : moz-landing-system : lando
</pre>
</div>
</content>
</entry>
<entry>
<title>fixup! Pick up latest Torbutton code</title>
<updated>2020-01-08T19:15:39+00:00</updated>
<author>
<name>Matthew Finkel</name>
<email>Matthew.Finkel@gmail.com</email>
</author>
<published>2020-01-04T22:05:57+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=78e8d897cd2ec1513f47d7443229b8a45f4a723a'/>
<id>78e8d897cd2ec1513f47d7443229b8a45f4a723a</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug 1590526 - Temporarily allow node adoption across different docGroups for the content/content case r=smaug,zombie a=pascalc</title>
<updated>2020-01-08T19:15:39+00:00</updated>
<author>
<name>Sean Feng</name>
<email>sefeng@mozilla.com</email>
</author>
<published>2019-10-24T20:56:43+00:00</published>
<link rel='alternate' type='text/html' href='https://gitweb.torproject.org/user/richard/tor-browser.git/commit/?id=06b02a14aed59a13bd1634bf4b8171338236c181'/>
<id>06b02a14aed59a13bd1634bf4b8171338236c181</id>
<content type='text'>
As web extensions rely on this node adoption between content to content
documents, we want to continue allowing this capability to work for now.

Differential Revision: https://phabricator.services.mozilla.com/D50348

--HG--
extra : source : 78c33df33145bd63cd303264734d0b7d85151908
extra : histedit_source : 280627c1dba1ad7b8d82f5a315b5c2170bf3167b
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
As web extensions rely on this node adoption between content to content
documents, we want to continue allowing this capability to work for now.

Differential Revision: https://phabricator.services.mozilla.com/D50348

--HG--
extra : source : 78c33df33145bd63cd303264734d0b7d85151908
extra : histedit_source : 280627c1dba1ad7b8d82f5a315b5c2170bf3167b
</pre>
</div>
</content>
</entry>
</feed>
