Security/Fusion/Esr140: Difference between revisions

(→‎P2: need help from upstream!: not waiting on needinfo, need to figure out something else)
Line 35: Line 35:
** E.g., [https://bugzilla.mozilla.org/show_bug.cgi?id=1940296 Bug 1940296] for vsync, but we currently force Wayland off because we don't know how fingerprintable it is  
** E.g., [https://bugzilla.mozilla.org/show_bug.cgi?id=1940296 Bug 1940296] for vsync, but we currently force Wayland off because we don't know how fingerprintable it is  
** See also [https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/42645 #42645]  
** See also [https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/42645 #42645]  
* ''TB 23247: Communicating security expectations for .onion'' ([https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/646be9d321f1d24a4e81e60bf24fd445b6c09a10 646be9d3]): over the years, some patches have been uplifted for optionally treating .onion http as HTTPS. Can we resume the work also on that? Do we have a meta?  
* ''[https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/23247 TB 23247]: Communicating security expectations for .onion'' ([https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/646be9d321f1d24a4e81e60bf24fd445b6c09a10 646be9d3]): over the years, some patches have been uplifted for optionally treating .onion http as HTTPS. Can we resume the work also on that? Do we have a meta?  


==== Build and vendoring ====
==== Build and vendoring ====
Confirmed users
425

edits