You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
While this only impacts users who click on the link in a non-Tor browser, in those cases, it does lead to a DNS leak of their attempt to access SecureDrop, so it warrants a "moderate" warning
The text was updated successfully, but these errors were encountered:
eloquence
changed the title
Scan for direct .onion address links on landing page
[scanner integration] Scan for direct .onion address links on landing page
May 31, 2018
This is actually already supported in the current scanner code (see validate_onion_address_not_in_href in scanner.py), it's just not used for the grades. Closing.
Part of epic #488. We recommend not to directly link .onion addresses (https://docs.securedrop.org/en/stable/deployment/landing_page.html#do-not-hyperlink-onion-addresses), so we should verify whether such links are present and record it in the scan results.
While this only impacts users who click on the link in a non-Tor browser, in those cases, it does lead to a DNS leak of their attempt to access SecureDrop, so it warrants a "moderate" warning
The text was updated successfully, but these errors were encountered: