Re: [tor-bugs] #19031 [Applications/TorBirdy]: Audit Thunderbird's RSS support

2017-06-11 Thread Tor Bug Tracker & Wiki
#19031: Audit Thunderbird's RSS support
---+-
 Reporter:  sukhbir|  Owner:  sukhbir
 Type:  task   | Status:  new
 Priority:  Medium |  Milestone:
Component:  Applications/TorBirdy  |Version:
 Severity:  Normal | Resolution:
 Keywords: |  Actual Points:
Parent ID: | Points:
 Reviewer: |Sponsor:
---+-

Comment (by cypherpunks):

 If you forget to disable favicon like above, TB will make a connection
 silently. So just disable it.

 > Disable the link so that a user has to manually copy it and doesn't
 inadvertently click on it

 When the user click the link, just "copy" it to clipboard.
 And show "The URL is copied to clipboard" alert.
 Do not open it in Thunderbird because this is not a browser but a mailer.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19031 [Applications/TorBirdy]: Audit Thunderbird's RSS support

2016-12-05 Thread Tor Bug Tracker & Wiki
#19031: Audit Thunderbird's RSS support
---+-
 Reporter:  sukhbir|  Owner:  sukhbir
 Type:  task   | Status:  new
 Priority:  Medium |  Milestone:
Component:  Applications/TorBirdy  |Version:
 Severity:  Normal | Resolution:
 Keywords: |  Actual Points:
Parent ID: | Points:
 Reviewer: |Sponsor:
---+-

Comment (by viktorj):

 I have set "browser.chrome.favicons" to "false" because otherwise it
 seemed to me that Thunderbird fetches the favicons of my feeds directly
 after start because they are not stored on disk. This could be an
 anonymity risk if two different RSS feeds don't use two independent Tor
 circuits because all the icons are fetched at the same time.

 Can you reproduce this or is this a problem which only occurs in my case?

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19031 [Applications/TorBirdy]: Audit Thunderbird's RSS support

2016-06-28 Thread Tor Bug Tracker & Wiki
#19031: Audit Thunderbird's RSS support
---+-
 Reporter:  sukhbir|  Owner:  sukhbir
 Type:  task   | Status:  new
 Priority:  Medium |  Milestone:
Component:  Applications/TorBirdy  |Version:
 Severity:  Normal | Resolution:
 Keywords: |  Actual Points:
Parent ID: | Points:
 Reviewer: |Sponsor:
---+-

Comment (by cypherpunks):

 Does stream isolation work properly, i.e. do 2 different RSS feeds always
 use independent Tor circuits?

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19031 [Applications/TorBirdy]: Audit Thunderbird's RSS support

2016-05-12 Thread Tor Bug Tracker & Wiki
#19031: Audit Thunderbird's RSS support
---+-
 Reporter:  sukhbir|  Owner:  sukhbir
 Type:  task   | Status:  new
 Priority:  Medium |  Milestone:
Component:  Applications/TorBirdy  |Version:
 Severity:  Normal | Resolution:
 Keywords: |  Actual Points:
Parent ID: | Points:
 Reviewer: |Sponsor:
---+-
Changes (by sajolida):

 * cc: sajolida@… (added)


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19031 [Applications/TorBirdy]: Audit Thunderbird's RSS support

2016-05-11 Thread Tor Bug Tracker & Wiki
#19031: Audit Thunderbird's RSS support
---+-
 Reporter:  sukhbir|  Owner:  sukhbir
 Type:  task   | Status:  new
 Priority:  Medium |  Milestone:
Component:  Applications/TorBirdy  |Version:
 Severity:  Normal | Resolution:
 Keywords: |  Actual Points:
Parent ID: | Points:
 Reviewer: |Sponsor:
---+-

Comment (by sukhbir):

 Updates:

 - Automatic fetching was not disabled and the value was hard coded. So we
 needed an overlay which I pushed in 0968621f.
 - HTML has also been disabled. The options are similar to the mailnews
 settings. See 174cd10.
 - JavaScript disabled: already doing it.
 - Proxy settings respected: yes.

 I think the only concern I have now is that clicking the "Website" (in the
 message pane) to get the complete article shows the Launch Application
 window using which a user may choose a browser that is not Tor Browser.
 Now we can do either of the following:

 - Disable the link so that a user has to manually copy it and doesn't
 inadvertently click on it
 - Warn the user but then show the Launch Application and let them decide.
 - Be smart and open in Tor Browser. (I am not sure if this one is easy).

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs


[tor-bugs] #19031 [Applications/TorBirdy]: Audit Thunderbird's RSS support

2016-05-11 Thread Tor Bug Tracker & Wiki
#19031: Audit Thunderbird's RSS support
---+-
 Reporter:  sukhbir|  Owner:  sukhbir
 Type:  task   | Status:  new
 Priority:  Medium |  Milestone:
Component:  Applications/TorBirdy  |Version:
 Severity:  Normal |   Keywords:
Actual Points: |  Parent ID:
   Points: |   Reviewer:
  Sponsor: |
---+-
 Audit Thunderbird's RSS feed reader. Some tasks to start with:

 - Is automatic fetching disabled?
 - Is HTML disabled?
 - Is JavaScript disabled?
 - Are proxy settings respected?

 Are there other anonymity implications?

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs