[Whonix-devel] #31798 [Applications/Tor Browser]: wipe all mentions of netflix, paypal, youtube, ... from noscript in Tor Browser

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Sep 20 15:25:20 CEST 2019


#31798: wipe all mentions of netflix, paypal, youtube, ... from noscript in Tor
Browser
--------------------------------------+--------------------------
 Reporter:  adrelanos                 |          Owner:  tbb-team
     Type:  defect                    |         Status:  new
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------

Comment (by adrelanos):

 Replying to [comment:3 adrelanos]:
 > noscript [feature request] environment variable to clear default
 whitelist
 >
 > https://forums.informaction.com/viewtopic.php?f=10&t=25743

 Got answer:

 > Sorry but there is currently no way for a WebExtension to read
 environment variables.

 ----

 Replying to [comment:2 gk]:
 > Meanwhile it would be helpful to understand why those issues only happen
 in Whonix so far and get some steps to reproduce.

 It's not 100% reproducible yet.

 I've been using Tor Browser 8.5.5. I've enabled git version control for
 the Tor Browser folder so I can easily simulate a first start of Tor
 Browser using {{{git clean -dff ; git reset --hard ; git status}}}.

 On Debian buster.

 Create folder {{{/usr/share/homepage/whonix-welcome-page}}}.

 {{{
 sudo mkdir -p /usr/share/homepage/whonix-welcome-page
 }}}

 Open file {{{/usr/share/homepage/whonix-welcome-page/whonix.html}}} with
 root rights.

 {{{
 sudoedit /usr/share/homepage/whonix-welcome-page/whonix.html
 }}}

 Paste.

 {{{
 <!DOCTYPE html>
 }}}

 Save.

 Start Tor Browser.

 {{{
 TOR_NO_DISPLAY_NETWORK_SETTINGS=1 TOR_SKIP_LAUNCH=1 ./start-tor-
 browser.desktop /usr/share/homepage/whonix-welcome-page/whonix.html
 }}}

 Tor Browser menu -> addons -> noscript -> preferences -> per site
 permissions

 You'll see noscript's default permissive websites enabled.

 ----

 What I can say with more certainty what helps to avoid triggering this bug
 is:

 * not using a local browser start page
 * not passing a local browser start page as command line parameter
 * not setting environment variable {{{TOR_DEFAULT_HOMEPAGE}}}

 ----

 Previously in Whonix I managed to nail down setting
 {{{TOR_SKIP_CONTROLPORTTEST=1}}} to trigger the bug vs {{{unset
 TOR_SKIP_CONTROLPORTTEST}}} to avoid the bug.

 ----

 Too many environment variables causing this?

 Could be a race condition in noscript?

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/31798#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the Whonix-devel mailing list