Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-12-14 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:  closed
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:  fixed
 Keywords:  tbb-linkability, |  Actual Points:  0.5
  GeorgKoppen201610R, ff68-esr,  |
  TorBrowserTeam201910R  |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-
Changes (by gk):

 * status:  reopened => closed
 * resolution:   => fixed


Comment:

 We are done here. The ticket you want is probably #23719.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-12-14 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  reopened
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, |  Actual Points:  0.5
  GeorgKoppen201610R, ff68-esr,  |
  TorBrowserTeam201910R  |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-
Changes (by starlit):

 * status:  closed => reopened
 * resolution:  fixed =>


Comment:

 Possible to enable asmjs for addons only? openpgp.js needs it. Wanting to
 make an in-browser PGP messenger so no binary install is required to
 message over tor.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-10-12 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:  closed
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:  fixed
 Keywords:  tbb-linkability, |  Actual Points:  0.5
  GeorgKoppen201610R, ff68-esr,  |
  TorBrowserTeam201910R  |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-

Comment (by gk):

 FWIW, the fix on the `tor-browser` side landed on `tor-
 browser-68.1.0esr-9.0-2` (5e45bc82579d4d712e0f34cb58ad62f1030127ca).

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-10-09 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:  closed
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:  fixed
 Keywords:  tbb-linkability, |  Actual Points:  0.5
  GeorgKoppen201610R, ff68-esr,  |
  TorBrowserTeam201910R  |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-
Changes (by acat):

 * points:  0.5 =>
 * actualpoints:   => 0.5


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-10-07 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:  closed
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:  fixed
 Keywords:  tbb-linkability, |  Actual Points:
  GeorgKoppen201610R, ff68-esr,  |
  TorBrowserTeam201910R  |
Parent ID:   | Points:  0.5
 Reviewer:   |Sponsor:
-+-
Changes (by gk):

 * keywords:  tbb-linkability, GeorgKoppen201610R, ff68-esr,
 TorBrowserTeam201910 => tbb-linkability, GeorgKoppen201610R, ff68-esr,
 TorBrowserTeam201910R
 * status:  needs_review => closed
 * resolution:   => fixed


Comment:

 Thanks, looks good. cherry-picked to `master` (commit
 dd746af135904c905cbcdf8792fbd6702814fb37).

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-10-07 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  needs_review
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, |  Actual Points:
  GeorgKoppen201610R, ff68-esr,  |
  TorBrowserTeam201910   |
Parent ID:   | Points:  0.5
 Reviewer:   |Sponsor:
-+-
Changes (by acat):

 * status:  needs_revision => needs_review
 * keywords:  tbb-linkability, GeorgKoppen201609, ff68-esr,
 TorBrowserTeam201910 => tbb-linkability, GeorgKoppen201610R, ff68-esr,
 TorBrowserTeam201910


Comment:

 Revised: https://github.com/acatarineu/torbutton/commit/19417+1.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-10-03 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  needs_revision
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, GeorgKoppen201609,  |  Actual Points:
  ff68-esr, TorBrowserTeam201910 |
Parent ID:   | Points:  0.5
 Reviewer:   |Sponsor:
-+-
Changes (by gk):

 * status:  needs_review => needs_revision
 * keywords:  tbb-linkability, GeorgKoppen201609, ff68-esr,
 TorBrowserTeam201910R => tbb-linkability, GeorgKoppen201609, ff68-esr,
 TorBrowserTeam201910


Comment:

 I think the `// XXX: Get rid of the cached asmjs` part in Torbutton can go
 now as well, no? Otherwise this looks good.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-10-03 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  needs_review
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, GeorgKoppen201609,  |  Actual Points:
  ff68-esr, TorBrowserTeam201910R|
Parent ID:   | Points:  0.5
 Reviewer:   |Sponsor:
-+-
Changes (by acat):

 * keywords:  tbb-linkability, GeorgKoppen201609, ff68-esr,
 TorBrowserTeam201910 => tbb-linkability, GeorgKoppen201609, ff68-esr,
 TorBrowserTeam201910R
 * status:  assigned => needs_review


Comment:

 For review: https://github.com/acatarineu/tor-browser/commit/19417 and
 https://github.com/acatarineu/torbutton/commit/19417

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-09-24 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  assigned
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, GeorgKoppen201609,  |  Actual Points:
  ff68-esr, TorBrowserTeam201909 |
Parent ID:   | Points:  0.5
 Reviewer:   |Sponsor:
-+-
Changes (by acat):

 * points:   => 0.5


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-09-12 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  assigned
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, GeorgKoppen201609,  |  Actual Points:
  ff68-esr, TorBrowserTeam201909 |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-

Comment (by cypherpunks):

 How were `typeinference`, `native_regexp`, `baselinejit` & `ion` checked?

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-09-12 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  assigned
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, GeorgKoppen201609,  |  Actual Points:
  ff68-esr, TorBrowserTeam201909 |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-

Comment (by gk):

 Replying to [comment:40 acat]:
 > I do not see any asm.js cache, disk or in-memory.
 >
 > It's not a strong proof, but I did a quick test with
 https://kripken.github.io/Massive/ (there are console logs with asm.js
 compilation time). Testing with Firefox 64, where caching was still
 enabled, shows that for cached asm.js loading time is much faster (like
 50ms vs 1000ms). In 68 there is no difference in times, either in PBM or
 "persisting" mode.
 >
 > Regarding comment:32, if the disk leak was solved (in
 https://bugzilla.mozilla.org/show_bug.cgi?id=1047105), what were the FPI
 concerns back then? Was there an in-memory cache that did not respect FPI?

 Well, it was not really solved as you would get the problem again when not
 being in PBM. If there is no in-memory cache (anymore), good. So asm.js
 files are just loaded on the fly and executed? If there is no storage
 involved and no identifier read-back/extraction over domains, great. Then
 we are done with the FPI concern. If we enable it again we should make
 sure it's disabled on safer and safest levels, though, I think (as it was
 before).

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-09-12 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  assigned
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, GeorgKoppen201609,  |  Actual Points:
  ff68-esr, TorBrowserTeam201909 |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-

Comment (by acat):

 I do not see any asm.js cache, disk or in-memory.

 It's not a strong proof, but I did a quick test with
 https://kripken.github.io/Massive/ (there are console logs with asm.js
 compilation time). Testing with Firefox 64, where caching was still
 enabled, shows that for cached asm.js loading time is much faster (like
 50ms vs 1000ms). In 68 there is no difference in times, either in PBM or
 "persisting" mode.

 Regarding comment:32, if the disk leak was solved (in
 https://bugzilla.mozilla.org/show_bug.cgi?id=1047105), what were the FPI
 concerns back then? Was there an in-memory cache that did not respect FPI?

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-09-12 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  assigned
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, GeorgKoppen201609,  |  Actual Points:
  ff68-esr, TorBrowserTeam201909 |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-
Changes (by gk):

 * keywords:  tbb-linkability, GeorgKoppen201609, ff68-esr,
 TorBrowserTeam201805 => tbb-linkability, GeorgKoppen201609, ff68-esr,
 TorBrowserTeam201909


Comment:

 Replying to [comment:38 acat]:
 > The asm.js caching was removed in
 https://bugzilla.mozilla.org/show_bug.cgi?id=1520931. Should we revisit
 this and try to enable asm.js for esr68? We should be able to remove
 `Services.qms.clear()` in torbutton and revert #31396.

 Sounds good. Please do, if you want. How does it work then, though, if you
 have PBM disabled? Is everything happening on the fly, in memory, or...?
 We should investigate the FPI concerns here, too. See: comment:32

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2019-09-12 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  assigned
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, GeorgKoppen201609,  |  Actual Points:
  ff68-esr, TorBrowserTeam201805 |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-
Changes (by acat):

 * keywords:  tbb-linkability, GeorgKoppen201609, ff52-esr,
 TorBrowserTeam201805 => tbb-linkability, GeorgKoppen201609, ff68-esr,
 TorBrowserTeam201805


Comment:

 The asm.js caching was removed in
 https://bugzilla.mozilla.org/show_bug.cgi?id=1520931. Should we revisit
 this and try to enable asm.js for esr68? We should be able to remove
 `Services.qms.clear()` in torbutton and revert #31396.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2018-06-30 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  assigned
 Priority:  Medium   |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, GeorgKoppen201609,  |  Actual Points:
  ff52-esr, TorBrowserTeam201805 |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-
Changes (by cypherpunks):

 * keywords:
 tbb-linkability, GeorgKoppen201609, TorBrowserTeam201609, ff52-esr,
 TorBrowserTeam201805
 => tbb-linkability, GeorgKoppen201609, ff52-esr, TorBrowserTeam201805


Comment:

 gk forgot to delete an unnecessary keyword.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk

2018-02-08 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  assigned
 Priority:  High |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, GeorgKoppen201609,  |  Actual Points:
  TorBrowserTeam201609, ff52-esr,|
  TorBrowserTeam201802   |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-
Changes (by gk):

 * keywords:  tbb-linkability, GeorgKoppen201609, TorBrowserTeam201609,
 ff52-esr =>
 tbb-linkability, GeorgKoppen201609, TorBrowserTeam201609, ff52-esr,
 TorBrowserTeam201802


Comment:

 Replying to [comment:31 gk]:
 > Replying to [comment:30 legind]:
 > > Here's a friendly ping to revisit this issue, now that the transition
 to 52 is complete.
 >
 > So, the disk leak is gone but there is still the problem of asmjs not
 adhering to our URL bar domain isolation. This part still needs to be
 investigated. I am adjusting the title and description of the ticket.

 Actually, asm.js should be governed by the QuotaManager which in turn
 should take care of FPI. We should double-check that and, if it is indeed
 true, put it again into our security slider-treatment.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19417 [Applications/Tor Browser]: asm.js files should be no linkability risk (was: asm.js files should not be cached to disk in Tor Browser and no linkability risk)

2017-11-02 Thread Tor Bug Tracker & Wiki
#19417: asm.js files should be no linkability risk
-+-
 Reporter:  gk   |  Owner:  tbb-
 |  team
 Type:  defect   | Status:
 |  assigned
 Priority:  High |  Milestone:
Component:  Applications/Tor Browser |Version:
 Severity:  Major| Resolution:
 Keywords:  tbb-linkability, GeorgKoppen201609,  |  Actual Points:
  TorBrowserTeam201609, ff52-esr |
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+-
Changes (by gk):

 * status:  needs_revision => assigned
 * keywords:
 tbb-disk-leak, tbb-linkability, GeorgKoppen201609,
 TorBrowserTeam201609, ff52-esr
 => tbb-linkability, GeorgKoppen201609, TorBrowserTeam201609, ff52-esr


Old description:

> #19400 revealed that asm.js files are cached to disk which violates at
> least our no-disk-leaks requirement. The upstream bug is
> https://bugzilla.mozilla.org/show_bug.cgi?id=1047105.

New description:

 #19400 revealed that asm.js files are cached to disk which violates at
 least our no-disk-leaks requirement. The upstream bug is
 https://bugzilla.mozilla.org/show_bug.cgi?id=1047105 which got fixed in
 Firefox 51. However, there are linkability risks as well we might want to
 address.

--

Comment:

 Replying to [comment:30 legind]:
 > Here's a friendly ping to revisit this issue, now that the transition to
 52 is complete.

 So, the disk leak is gone but there is still the problem of asmjs not
 adhering to our URL bar domain isolation. This part still needs to be
 investigated. I am adjusting the title and description of the ticket.

 > WebAssembly is a related upcoming standard in development at W3C, we
 should also keep an eye on this as well.

 That's true. FWIW wasm got disabled by Mozilla in the ESR 52 series,
 though. We have #21549 for the investigation task.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs