Security/Fennec+Tor Project

< Security
Revision as of 08:03, 7 June 2017 by Ethantseng (talk | contribs) (Create this page.)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Requirements

In order to empower Fennec the same capability as Orfox, the Tor Browser on Android, we have to meet the following minimal requirements.

  • All network connections (Gecko and Java code) must be proxied.
  • Only allow incognito mode (e.g. turn off JavaScript, WebRTC, etc.)
  • Run NoScript and HTTPS Everywhere
  • Apply all the Tor Browser patches


Value Proposition of Tor on Fennec

It would be awesome if Fennec could prompt the user with something like "you have Orbot installed, which is a secure network proxy which allows to:"

  • Bypass censorship
  • Improve network security on unsecure network
  • Access .onion sites

Caveat!!
Before we are certain that Fennec has the same level of anonymity features as Orfox does, don't use the word anonymous because it provides a false sense of security to users.

Bug Tracking

All Fennec+Tor bugs are being tracked by the meta bug: bug 1357994 - [META] Tor on Fennec

Priority Definition

  • P1: Must Have for MVP
  • P2: Nice to Have
  • P3: Backlog


Work Items

Fennec Product Engineering

  • [P1] Proxy all Fennec code
  • [P1] Integrate the library NetCipher into Fennec
  • [P1] Choose preferences to be active during Tor Mode on Fennec
  • [P1] Confirm that WebTRC prefs actually disable WebRTC
  • [P2] Refactor Fennec code to provide a unified proxy interface
  • [?] Add HTTPS Everywhere
  • [?] FLAG_SECURE
  • [?] Add NoScript

Fennec Backend Engineering

  • [P1] Enable/Review First Party Isolation on Fennec
  • [P1] Fennec Proxy Bypass Test Harness
  • [P1] Enable all tests to be run on Fennec

Fennec UI/Marketing

  • [?] If Orbot detected, prompt in Fennec to use it
  • [?] If Orbot not detected, prompt in Fennec to install it
  • [?] Develop messaging about capabilities. “Bypass Censorship”, “Access .onion sites”, “Improve network security” but not “Anonymity”


Dashboard

P1 Bugs

Bugzilla query error

Array ( [type] => error [message] => http-bad-status [params] => Array ( [0] => 429 [1] => Unknown Error ) ) 1


P2 Bugs

Bugzilla query error

Array ( [type] => error [message] => http-bad-status [params] => Array ( [0] => 429 [1] => Unknown Error ) ) 1


P3-P5 Bugs

Bugzilla query error

Array ( [type] => error [message] => http-bad-status [params] => Array ( [0] => 429 [1] => Unknown Error ) ) 1


To Be Triaged

Bugzilla query error

Array ( [type] => error [message] => http-bad-status [params] => Array ( [0] => 429 [1] => Unknown Error ) ) 1