- Package:
- epiphany-browser
- Source:
- epiphany-browser
- Description:
- Intuitive GNOME web browser
- Submitter:
- Christoph Anton Mitterer
- Date:
- 2015-06-08 19:24:21 UTC
- Severity:
- important
Hi. Apparently it seems that even when configured to use Tor as proxy, epiphany is so "smart" to send DNS queries directly to the wire, thus making any effort of Tor useless. Just check with wireshark and one can see it. Marking this as grave so that people get notified about this inadequacy... actually people in many contries who need to rely on Tor, can get into severe troubles when their anonymity is compromised. Chris.
control: severity -1 important control: tags -1 upstream Am 28.04.2015 um 06:26 schrieb Christoph Anton Mitterer: Please file this issue upstream and report back with the bug number.
I kindly ask someone else to report this upstream. My past experience has shown that upstream has no interest in security, e.g. when I reported the extremely critical bug that each of epiphany's TLS connections can be immediately hacked by simply redirecting. That was denied at first and IIRC is still not solved. I've just noted this further security issue by accident and reported it for the benefit of other Debian users, e.g. the package description could warn about the great security deficiencies in epiphany (at least if the TLS bug is still open) or the product could be removed from Debian altogether. That being said, I consider contributing upstream a waste of time since there seem to be no interest in security, which is why I'd ask someone else to take these struggles. Oh and I don't think that this is appropriate. It basically means that this bug is hidden away unless people manually search the BTS (apt-listbugs won't show it with just important). And since a non working Tor can mean much more critical things to some people than anything our severities covers, from torture to death, we should rather employ the loudest bells and whistles to inform anyone that epiphany cannot be securely used with Tor. Cheers, Chris.
Am 01.06.2015 um 18:49 schrieb Christoph Anton Mitterer: Too bad you see it that way. hyperbole, eh? I'm sure it kills kittens, too. we Feel free to talk to the debian security team. If they confirm your assessment of the severity, I have no objections to raise the severity again.
Control: forwarded -1 https://bugzilla.gnome.org/show_bug.cgi?id=750249 Well,... since you've asked so kindly, I've forwarded it upstream, though I don't expect anything to happen and don't make me responsible to keep that tracked ;-) Well,... ask people like Bradley/Chelsea Manning or others like from totalitarian countries (CN, AF, CU, SA,... and so on). I guess if any of those would have relied on anonymity just to find out that the respective regime was laughing at it when they saw&caught him by using epiphany... they wouldn't consider it hyperbole. Nah,... I'm really tired of these severity-wars and as e.g. #702976 (which is open for some years now and describes any TLS in epiphany being effectively useless - but as said I haven't checked whether it's fixed already) shows, the security team doesn't necessarily handle things better. IMHO, having bugs open with higher severities shouldn't be considered a personal offence / shame / whatever by the maintainers... but rather as a simple means of reaching people through the proper means (e.g. apt-listbugs) which may be heavily affected by an issue. Cheers, Chris.