[HTTPS-Everywhere] Wikiblame subverts HTTPS Everywhere

Peter Eckersley pde at eff.org
Wed Aug 25 16:01:51 PDT 2010


Bug report here:

https://trac.torproject.org/projects/tor/ticket/1866

We will release an update to fix this shortly.

On Sun, Aug 22, 2010 at 02:35:18PM -0430, Jamil Navarro wrote:
> Hi everybody,
> It seems that URLs starting with "http://en.wikipedia.org/w/index.php"
> are not matched by the current wikipedia rules. The new rule would
> have to rewrite those URLs into
> "https://secure.wikimedia.org/wikipedia/en/w/index.php".
> In a short while I may have a rule ready.
> 
> Jamil Navarro
> 
> 
> On Sun, Aug 22, 2010 at 1:52 PM, Chris Palmer <chris at noncombatant.org> wrote:
> > Andrew A. Gill writes:
> >
> >> Go to <http://wikipedia.ramselehof.de/wikiblame.php>.  Search for
> >> something in the page history.  When you click on a link, you'll be taken
> >> to the insecure Wikipedia site.  I'm not sure how that happens, but this
> >> should probably be corrected.
> >
> > I can reproduce the problem. I put "pumpkin" in the Page field, and "gourds"
> > in the Search for field. Then I clicked the "11:54, 17 July 2010" diff link.
> >
> > Perhaps the problem is that the diff links use the en.wikipedia.org hostname
> > and not www.wikipedia.org. I just tried again after installing the latest
> > version of HTTPS Everywhere, but it seems to still be happening. I don't
> > know why this should be, since the rule for Wikipedia would seem to handle
> > this.
> >
> > I'll add a feature request: It would be nice if the Preferences window for
> > HTTPS Everywhere showed a list of text boxes containing the rewrite rules
> > (both the built-in ones and any user-added ones) instead of just text boxes.
> >
> > _______________________________________________
> > HTTPS-everywhere mailing list
> > HTTPS-everywhere at mail1.eff.org
> > https://mail1.eff.org/mailman/listinfo/https-everywhere
> >
> _______________________________________________
> HTTPS-everywhere mailing list
> HTTPS-everywhere at mail1.eff.org
> https://mail1.eff.org/mailman/listinfo/https-everywhere

-- 
Peter Eckersley                            pde at eff.org
Senior Staff Technologist         Tel  +1 415 436 9333 x131
Electronic Frontier Foundation    Fax  +1 415 436 9993



More information about the HTTPS-everywhere mailing list