-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security] Remove "Automatic .onion redirect" feature #36933
Labels
feature/tor
OS/Desktop
priority/P2
A bad problem. We might uplift this to the next planned release.
privacy
QA Pass-Linux
QA Pass-macOS
QA Pass-Win64
QA/Test-All-Platforms
QA/Yes
release-notes/include
security
Milestone
Comments
diracdeltas
added
the
priority/P2
A bad problem. We might uplift this to the next planned release.
label
Mar 19, 2024
24 tasks
stephendonner
added
QA/In-Progress
Indicates that QA is currently in progress for that particular issue
QA Pass-Win64
and removed
QA/In-Progress
Indicates that QA is currently in progress for that particular issue
labels
Apr 4, 2024
LaurenWags
changed the title
Remove "Automatic .onion redirect" feature
[Security] Remove "Automatic .onion redirect" feature
Apr 25, 2024
MadhaviSeelam
added
the
QA/In-Progress
Indicates that QA is currently in progress for that particular issue
label
Apr 26, 2024
Verification
Case 1: "Automatic .onion redirect" Preference removed in
|
1.65.123 |
`1.66.90 |
---|---|
Case 2: URL-bar behavior - PASSED
Steps:
- installed
1.66.59
- launched Brave
- loaded
nytimes.com
- clicked on the
Tor
icon/button in the URL bar - confirmed
Private Window with Tor
loadedhttps://www.nytimesn7cgmftshazwhfgzm37qxb44r64ytbb2dj3x62d2lljsciiyd.onion/
example | example |
---|---|
Case 3: Upgrade scenario - PASSED
Steps:
- installed
1.65.123
- launched Brave
- loaded
https://www.theguardian.com/us
- clicked on the
Tor
icon/button in the URL bar - confirmed I landed on
hhttps://www.guardian2zotagl6tmjucg3lrhxdk4dw3lhbqnkvvkywawy3oqfoprid.onion/us
- shut down Brave
- upgraded to
1.66.90
(renamedBrave-Browser
profile folder -->Brave-Browser-Beta
- launched
1.66.90
- opened
brave://settings/privacy
- confirmed no
Automatically redirect .onion sites
preference - loaded
https://www.theguardian.com/us
.com` - clicked on the
Tor
button
Confirmed https://www.guardian2zotagl6tmjucg3lrhxdk4dw3lhbqnkvvkywawy3oqfoprid.onion/us loaded
step 3 | step 5 | step 10 | step 11 | step 12 |
---|---|---|---|---|
Verification
|
example | example |
---|---|
Case 3: Upgrade scenario - PASSED
Steps:
- installed
1.65.123
- launched Brave
- loaded
dw.com
- clicked on the
Tor
icon/button in the URL bar - confirmed I landed on
https://www.dwnewsgngmhlplxy6o2twtfgjnrnjxbegbwqx6wnotdhkzt562tszfid.onion/en/top-stories/s-9097
- shut down Brave
- upgraded to
1.66.91
(renamedBrave-Browser
profile folder -->Brave-Browser-Beta
) - launched
1.66.91
- opened
brave://settings/privacy
- confirmed no
Automatically redirect .onion sites
preference - loaded
dw.com
- clicked on the
Tor
button
Confirmed https://www.dwnewsgngmhlplxy6o2twtfgjnrnjxbegbwqx6wnotdhkzt562tszfid.onion/en/top-stories/s-9097
loaded
ex. | ex. | ex. | ex. | ex. |
---|---|---|---|---|
MadhaviSeelam
added
QA Pass-Linux
and removed
QA/In-Progress
Indicates that QA is currently in progress for that particular issue
labels
Apr 26, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
feature/tor
OS/Desktop
priority/P2
A bad problem. We might uplift this to the next planned release.
privacy
QA Pass-Linux
QA Pass-macOS
QA Pass-Win64
QA/Test-All-Platforms
QA/Yes
release-notes/include
security
The Automatically redirect .onion sites feature has been a common source of complaints from users who turned it on and then forgot about it.
It also creates a potential privacy leak for which there is no easy fix.
Therefore, I think we should remove this potentially dangerous feature entirely like the Tor Browser.
Design
The text was updated successfully, but these errors were encountered: