#783579 epiphany-browser: leaks DNS queries when used with Tor

Package:
epiphany-browser
Source:
epiphany-browser
Description:
Intuitive GNOME web browser
Submitter:
Christoph Anton Mitterer
Date:
2015-06-08 19:24:21 UTC
Severity:
important
#783579#5
Date:
2015-04-28 04:26:53 UTC
From:
To:
Hi.

Apparently it seems that even when configured to use Tor as proxy,
epiphany is so "smart" to send DNS queries directly to the wire,
thus making any effort of Tor useless.

Just check with wireshark and one can see it.


Marking this as grave so that people get notified about this
inadequacy... actually people in many contries who need to rely
on Tor, can get into severe troubles when their anonymity is compromised.


Chris.

#783579#10
Date:
2015-06-01 03:30:19 UTC
From:
To:
control: severity -1 important
control: tags -1 upstream

Am 28.04.2015 um 06:26 schrieb Christoph Anton Mitterer:

Please file this issue upstream and report back with the bug number.

#783579#19
Date:
2015-06-01 16:49:40 UTC
From:
To:
I kindly ask someone else to report this upstream.

My past experience has shown that upstream has no interest in security,
e.g. when I reported the extremely critical bug that each of epiphany's
TLS connections can be immediately hacked by simply redirecting.
That was denied at first and IIRC is still not solved.

I've just noted this further security issue by accident and reported it
for the benefit of other Debian users, e.g. the package description
could warn about the great security deficiencies in epiphany (at least
if the TLS bug is still open) or the product could be removed from
Debian altogether.
That being said, I consider contributing upstream a waste of time since
there seem to be no interest in security, which is why I'd ask someone
else to take these struggles.
Oh and I don't think that this is appropriate.
It basically means that this bug is hidden away unless people manually
search the BTS (apt-listbugs won't show it with just important).
And since a non working Tor can mean much more critical things to some
people than anything our severities covers, from torture to death, we
should rather employ the loudest bells and whistles to inform anyone
that epiphany cannot be securely used with Tor.


Cheers,
Chris.

#783579#24
Date:
2015-06-01 18:55:45 UTC
From:
To:
Am 01.06.2015 um 18:49 schrieb Christoph Anton Mitterer:

Too bad you see it that way.

hyperbole, eh? I'm sure it kills kittens, too.

 we

Feel free to talk to the debian security team. If they confirm your
assessment of the severity, I have no objections to raise the severity
again.

#783579#29
Date:
2015-06-01 22:34:50 UTC
From:
To:
Control: forwarded -1 https://bugzilla.gnome.org/show_bug.cgi?id=750249
Well,... since you've asked so kindly, I've forwarded it upstream,
though I don't expect anything to happen and don't make me responsible
to keep that tracked ;-)
Well,... ask people like Bradley/Chelsea Manning or others like from
totalitarian countries (CN, AF, CU, SA,... and so on).
I guess if any of those would have relied on anonymity just to find out
that the respective regime was laughing at it when they saw&caught him
by using epiphany... they wouldn't consider it hyperbole.
Nah,... I'm really tired of these severity-wars and as e.g. #702976
(which is open for some years now and describes any TLS in epiphany
being effectively useless - but as said I haven't checked whether it's
fixed already) shows, the security team doesn't necessarily handle
things better.

IMHO, having bugs open with higher severities shouldn't be considered a
personal offence / shame / whatever by the maintainers... but rather as
a simple means of reaching people through the proper means (e.g.
apt-listbugs) which may be heavily affected by an issue.


Cheers,
Chris.