Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2018-12-17 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
--+--
 Reporter:  asn   |  Owner:  tbb-team
 Type:  enhancement   | Status:  new
 Priority:  Medium|  Milestone:
Component:  Applications/Tor Browser  |Version:
 Severity:  Normal| Resolution:
 Keywords:  new-addon |  Actual Points:
Parent ID:| Points:  6
 Reviewer:|Sponsor:
--+--
Changes (by reportUrl):

 * keywords:  prop224, tbb, network-need, tor-hs => new-addon


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2018-10-15 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need, tor-hs  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--

Comment (by asn):

 Thanks for the feedback intri. Here is also a research paper showing that
 about 52% of Tor users from a survey were also using the bookmark system,
 whereas 9% of people did not use bookmarks because they leaved a trace:
 https://arxiv.org/pdf/1806.11278.pdf

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2018-10-12 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need, tor-hs  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--

Comment (by intrigeri):

 Replying to [ticket:24310 asn]:
 > One technique that people are using to remember their onions are local
 browser bookmarks. That's a pretty secure way to do it actually, with the
 biggest drawback being that the bookmarks are stored long-term on your
 computer which is a problem if your computer gets compromised.

 On
 
https://trac.torproject.org/projects/tor/wiki/org/meetings/2018MexicoCity/Notes/TBBMeetingDays
 I've seen "Secure Bookmarks" mentioned. I'm not sure if this the right
 place to discuss this, feel free to redirect me if it's not :) Here's a
 dump of my thoughts on this topic.

 First, in Tails bookmarks are the most popular persistence feature among
 those we offer (bookmarks, network connections, additional software,
 printers, Thunderbird, GnuPG, Bitcoin client, Pidgin, SSH). This was
 computed from the bug reports we receive so it's a small data set (~100
 reports/month), but at least that's data.

 Second, without bookmarks support at all (be them "secure" or the default
 Firefox feature, which we disable because of the disk avoidance design
 goal), here's what users are likely to do:

 * save the URLs they need in an unencrypted text file: not more secure
 than using the default bookmarks mechanism provided by Firefox (except
 perhaps Firefox stores the last time when a bookmark was visited? in which
 case it would count as browsing history, which is another matter)
 * use a search engine, a wiki, or something like to discover the hard-to-
 remember URL every time they need it, i.e. trust a third-party web service
 to point them to the correct URL; this approach does resist better to
 computer compromise but it also puts user's credentials at risk every time
 they access the hard-to-remember URL. Depending on the threat model,
 either can be safer.

 I have no data to show how aware users are of the risks of either approach
 and I won't try to guess.

 So to me it's not obvious that we're doing our users a service by
 disabling bookmarks and I would even argue that enabling the default
 Firefox bookmarks feature would not be worse than the current state of
 things. Now, if we get something even better, i.e. "Secure Bookmarks",
 that'll be awesome!

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2018-10-12 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need, tor-hs  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--
Changes (by intrigeri):

 * cc: intrigeri (added)


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2018-04-30 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need, tor-hs  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--
Changes (by arthuredelstein):

 * cc: arthuredelstein (added)
 * keywords:  prop224, tbb, network-need, tor-hs, arthuredelstein =>
 prop224, tbb, network-need, tor-hs


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2018-04-30 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
-+-
 Reporter:  asn  |  Owner:  tbb-
 |  team
 Type:  enhancement  | Status:  new
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Normal   | Resolution:
 Keywords:  prop224, tbb, network-need, tor-hs,  |  Actual Points:
  arthuredelstein|
Parent ID:   | Points:  6
 Reviewer:   |Sponsor:
-+-
Changes (by dgoulet):

 * parent:  #25955 =>


Comment:

 This is Tor Browser specific. In rare cases we should link them to Core
 Tor/Tor component but the TBB team should decided that.

 Unparenting. Nothing to do with v2 deprecation.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2018-04-27 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
-+-
 Reporter:  asn  |  Owner:  tbb-
 |  team
 Type:  enhancement  | Status:  new
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Normal   | Resolution:
 Keywords:  prop224, tbb, network-need, tor-hs,  |  Actual Points:
  arthuredelstein|
Parent ID:  #25955   | Points:  6
 Reviewer:   |Sponsor:
-+-
Changes (by cypherpunks):

 * parent:   => #25955


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2018-04-26 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
-+-
 Reporter:  asn  |  Owner:  tbb-
 |  team
 Type:  enhancement  | Status:  new
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Normal   | Resolution:
 Keywords:  prop224, tbb, network-need, tor-hs,  |  Actual Points:
  arthuredelstein|
Parent ID:   | Points:  6
 Reviewer:   |Sponsor:
-+-
Changes (by arthuredelstein):

 * keywords:  prop224, tbb, network-need, tor-hs => prop224, tbb, network-
 need, tor-hs, arthuredelstein


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2018-04-26 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need, tor-hs  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--
Changes (by dmr):

 * cc: dmr (added)
 * keywords:  prop224, tbb, network-need => prop224, tbb, network-need, tor-
   hs


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2018-03-15 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--
Changes (by antonela):

 * cc: antonela (added)


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2017-11-17 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--

Comment (by asn):

 Side-note, [https://lists.torproject.org/pipermail/tor-
 dev/2017-November/012614.html a person from tor-dev] said that they worked
 on a project like this. Perhaps code or ideas or icons might be reusable.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2017-11-17 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--

Comment (by asn):

 Replying to [comment:3 tom]:
 > Does Firefox's Master Password feature encrypt bookmarks?
 >

 Did some digging online and this doesn't seem to be the case. Seems to
 protect usernames and passwords only.

 > Also, could you talk more about client authorization credentials for
 .onions? How are those provided today (For some reason I thought you had
 to edit torrc) via Tor Browser?

 Yep, you need to edit the torrc, there is no way to do it through Tor
 Browser yet. Tickets #14389 and #19757 are related to this.

 HSv2 client auth creds look like this:
 {{{
 HidServAuth tkwk5o5n4eud3vwd.onion rJcrR/ZbCMDdJqTImOBvxB basic1
 }}}
 HSv3 client auth hasn't been implemented yet but it
 [https://gitweb.torproject.org/torspec.git/tree/proposals/224-rend-spec-
 ng.txt#n2283 might look like this].

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2017-11-16 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--
Changes (by phw):

 * cc: phw (added)


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2017-11-16 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--
Changes (by tom):

 * cc: tom (added)


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2017-11-16 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--

Comment (by tom):

 Does Firefox's Master Password feature encrypt bookmarks?

 Also, could you talk more about client authorization credentials for
 .onions? How are those provided today (For some reason I thought you had
 to edit torrc) via Tor Browser?

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2017-11-16 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--
Changes (by mcs):

 * cc: mcs (added)


Comment:

 It looks like AMO includes some add-ons that try to do something similar,
 e.g., https://addons.mozilla.org/en-US/firefox/addon/webext-private-
 bookmarks/

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2017-11-16 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
+--
 Reporter:  asn |  Owner:  tbb-team
 Type:  enhancement | Status:  new
 Priority:  Medium  |  Milestone:
Component:  Applications/Tor Browser|Version:
 Severity:  Normal  | Resolution:
 Keywords:  prop224, tbb, network-need  |  Actual Points:
Parent ID:  | Points:  6
 Reviewer:  |Sponsor:
+--
Description changed by asn:

Old description:

> Onion addresses are hard to remember and with prop224 they are even
> harder, [https://blog.torproject.org/cooking-onions-names-your-onions
> yada yada].
>
> One technique that people are using to remember their onions are local
> browser bookmarks. That's a pretty secure way to do it actually, with the
> biggest drawback being that the bookmarks are stored long-term on your
> computer which is a problem if your computer gets compromised.
>
> One way to improve the situation would be to be able to encrypt your
> bookmarks (a bit like a password manager) so that attackers without your
> password are not able to retrieve your list of onions.
>
> Some extra features that would be cool to have:
> - Some sort of deniability where attackers are not able to see if you
> have any stored bookmarks if they don't know your password.
> - Extra storage for client authorization credential for those onions.
>
> I'm not sure if there is already an addon that does what we want to do
> here, but perhaps we could find something.

New description:

 Onion addresses are hard to remember and with prop224 they are even
 harder, [https://blog.torproject.org/cooking-onions-names-your-onions yada
 yada].

 One technique that people are using to remember their onions are local
 browser bookmarks. That's a pretty secure way to do it actually, with the
 biggest drawback being that the bookmarks are stored long-term on your
 computer which is a problem if your computer gets compromised.

 One way to improve the situation would be to be able to encrypt your
 bookmarks (a bit like a password manager) so that attackers without your
 password are not able to retrieve your list of onions.

 Some extra features that would be cool to have:
 - Some sort of deniability where attackers are not able to see if you have
 any stored bookmarks if they don't know your password.
 - Extra storage for client authorization credential for those onions.
 - Even better this wouldn't be a separate addon, but just an enhancement
 over the current bookmark system of firefox, so that people don't need two
 understand two UXs.

 I'm not sure if there is already an addon that does what we want to do
 here, but perhaps we could find something.

--

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

[tor-bugs] #24310 [Applications/Tor Browser]: Consider encrypted bookmarks addon for storing onions on the browser

2017-11-16 Thread Tor Bug Tracker & Wiki
#24310: Consider encrypted bookmarks addon for storing onions on the browser
-+-
 Reporter:  asn  |  Owner:  tbb-team
 Type:  enhancement  | Status:  new
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor |Version:
  Browser|   Keywords:  prop224, tbb, network-
 Severity:  Normal   |  need
Actual Points:   |  Parent ID:
   Points:  6|   Reviewer:
  Sponsor:   |
-+-
 Onion addresses are hard to remember and with prop224 they are even
 harder, [https://blog.torproject.org/cooking-onions-names-your-onions yada
 yada].

 One technique that people are using to remember their onions are local
 browser bookmarks. That's a pretty secure way to do it actually, with the
 biggest drawback being that the bookmarks are stored long-term on your
 computer which is a problem if your computer gets compromised.

 One way to improve the situation would be to be able to encrypt your
 bookmarks (a bit like a password manager) so that attackers without your
 password are not able to retrieve your list of onions.

 Some extra features that would be cool to have:
 - Some sort of deniability where attackers are not able to see if you have
 any stored bookmarks if they don't know your password.
 - Extra storage for client authorization credential for those onions.

 I'm not sure if there is already an addon that does what we want to do
 here, but perhaps we could find something.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs