dslreports logo
 
    All Forums Hot Topics Gallery
spc
uniqs
7

chachazz
Premium Member
join:2003-12-14

chachazz

Premium Member

Re: [Extension] HTTPS Everywhere - Beta development builds

4.0development.3 - (2012-12-3)

• Hacky solution to a very nasty bug in which directives would cause cookies
to be flagged as secure even if they were set from
• HTTP origins!
»trac.torproject.org/proj ··· ket/7491
»mail1.eff.org/pipermail/ ··· 397.html
• Ship 245 new rulesets
• Fixes include: Internet Archive, Rackspace
• Disable broken: American Public Media, Verizon, Nieuwsblad.be, MyOpenID
• (Plus fixes and rulesets disabled between 4.0dev2 and 3.0.4
• Observatory-only translations: Croation, Hebrew

Note: we could really use help testing the securecookie functionality!
If you use a site that you know has a securecookie rule, it would be
great if you could try it out and make sure that it still seems to work
properly and that HTTPS Everywhere still secures the cookie.
chachazz

chachazz

Premium Member

HTTPS-Everywhere 4.0 development.4
chachazz

chachazz

Premium Member

4.0development.5 (2013-1-18)
Internet Freedom Day development release

•Fix the implementation of safeToSecureCookie
- Get »trac.torproject.org/proj ··· ket/7491 right(er)
- Fix »trac.torproject.org/proj ··· ket/7855
• Fix a ruleset processing bug, which would prevent
from matching x.y.z.com
• Ship all ruleset fixes from 3.1.2 and 3.1.3
- Except Etsy, where we're trying to fix rather than disable the ruleset
»trac.torproject.org/proj ··· ket/7774
• Ship 354 new rulesets
• Update cert whitelist
• Update translations: Korean, Polish, French

»www.eff.org/https-everywhere
chachazz

chachazz

Premium Member

https-everywhere-4.0development.6
(No changelog at the moment)
»www.eff.org/https-everywhere
chachazz

chachazz

Premium Member

4.0development.8 (2013-06-04)
* Fix broken ruleset dialog in Firefox 22+
»trac.torproject.org/proj ··· ket/8997
* The toolbar button chnages to indicate active rulesets:
»trac.torproject.org/proj ··· ket/4886
* Ship 31 new rulesets
* New translations: Japanese and Sinhala
* Updated translations: Hungarian, Lithuanian, Slovenian
* Ruleset fixes from 3.2.2:
»eff.org/r.5bSj
* Observatory cert whitelist update

4.0development.7 (2013-05-17)

* Implement XHR outstanding request limits to work around TCP connection
exhaustion if the SSL Observatory server is slow or down:
»trac.torproject.org/proj ··· ket/8670
»bugzilla.mozilla.org/sho ··· d=856748
* Add a note hinting users how to toggle rulesets (thanks to Pavel Kazakov)
»trac.torproject.org/proj ··· ket/4967
* Ship all fixes from 3.2:
»eff.org/r.b9Qc
* Other known ruleset fixes: EA, Yandex
»trac.torproject.org/proj ··· ket/8571
* Ship 1308 new rulesets!
* Numerous new and updated translations

»www.eff.org/https-everywhere
chachazz

chachazz

Premium Member

chachazz

chachazz

Premium Member

4.0development.10
• Numerous rules added, modified, and deleted
• Added utils/find_rules.py, python script by Osama Khalid to apply HTTPS Everywhere rules to URLs
• Updated readme to include more dependencies

»www.eff.org/https-everywhere
chachazz

chachazz

Premium Member

4.0development.12 - (2013-09-12)
Fix clients1.google.com OSCP meltdown
»trac.torproject.org/proj ··· ket/9713
Updated rules: ConnMan, Viddler.com, ISC, GNOME, Dozuki, Thingiverse, Box,
ComputerWorld, Makerbot, McClatchy Interactive.com, Mozilla, Ohio State
University, printrbot, Thingiverse, Tradedoubler, XiTi.com, Flameeyes, Open
Clipart Library, Musopen, CERN, FilZilla, Google Services, Linux Foundation,
Debian, Python.org, Ardour, Netmarble, Drexel University, Guifi.net,
net-security.org, University of California, WordPress blogs, Perl.org
New rules: Akira.org, AntiPolygraph.org, Banu.com, break.com, Click and
Pledge.com, DataCoup.com, linux-sunxi.org, Lockbox.com, PSC.edu, University
of Greifswald, University of Rostock, WIMM.com, ZeusClicks.com,
gayorrents.net, Addison.com.hk, Auto Ad Manager.com, Blutmagie.de,
Brixwork.com, HDtracks.com, hostname.sk, iPXE.org, Linn Records.com,
Navigant Research.com, OpenLDAP.org, Quotes and Sayings.com, Solid-Run.com,
TU-Dresden.de, Tux.Org, Ultrasurf.us, Zamzar.com, chaox.net, digilinux.ru,
iNaturalist.org, IUCNredlist.org, jensge.org, Libre Graphics World.org,
NAB.org, PengPod.com, pythonhosted.org, randombit.net, factorable.net,
JoeyH.name, Acunetix.com, Alex Cabal.com, Altera.com, Commotionwireless.net,
CounterMail.com, dotplex.de, Dyne.org, finalrewind.net, Keelog.com,
Mailinator.com, My Shadow.com, OpenMailBox.org, PwdHash.com, Silent
Sender.com, Standard Ebooks.com, Tarasic.com.tw, Barracuda.com

4.0development.11 - (2013-08-30)

• Notify users who have been accidentally updated from stable to dev
»trac.torproject.org/proj ··· ket/9600
• Added and updated numerous rules, including Craigslist
• Fixes toolbar button size
»trac.torproject.org/proj ··· ket/9511
• Declare loop variables with var to avoid global memory leaks
• Updated localizations

»www.eff.org/https-everywhere
chachazz

chachazz

Premium Member

4.0development.14 - (2013-12-02)
• Deprecate the ContentPolicy API, fixing a crash bug lurking since Firefox 20:
»bugzilla.mozilla.org/sho ··· d=939180
• Fix really silly Observatory UI bug that would leave the Observatory off for non-Tor users after they turned it on
• Ship 438 new rulesets
• Update Observatory blacklist

»www.eff.org/https-everywhere
chachazz

chachazz

Premium Member

Https Everywhere 4.0development.16 (2014-04-14)
• Restore code that loads custom rule files:
»github.com/EFForg/https- ··· pull/156
• Use loadContext interface to get windows associated with requests
• Reduce annoying logging messages
• Report cert warning pages to SSL Observatory
• Remove SSL Observatory observers when disabled
• Don't set LOAD_REPLACE flag:
»github.com/EFForg/https- ··· pull/134
• Add script to merge rulesets in Alexa Top 1M, thanks to Claudio MOretti:
»github.com/EFForg/https- ··· pull/149
• 8 new rules
• 59 modified rules

»www.eff.org/https-everywhere