diff --git a/doc/spec/proposals/131-verify-tor-usage.txt b/doc/spec/proposals/131-verify-tor-usage.txt index 0620928c06..bbc0b3634a 100644 --- a/doc/spec/proposals/131-verify-tor-usage.txt +++ b/doc/spec/proposals/131-verify-tor-usage.txt @@ -68,7 +68,7 @@ Extensions: configuration could include the following HTML:

Connection chain

@@ -78,8 +78,8 @@ Extensions: browser:

Connection chain @@ -92,6 +92,35 @@ Extensions: loaded then the user will know that external connectivity through Tor works. + Automatic Firefox Notification: + + All forms of the website should return valid XHTML and have a + hidden link with an id attribute "TorCheckResult" and a target + property that can be queried to determine the result. For example, + a hidden link would convey success like this: + + + + failure like this: + + + + and DNS leaks like this: + + + + Firefox extensions such as Torbutton would then be able to + issue an XMLHttpRequest for the page and query the result + with resultXML.getElementById("TorCheckResult").target + to automatically report the Tor status to the user when + they first attempt to enable Tor activity, or whenever + they request a check from the extension preferences window. + + If the check website is to be themed with heavy graphics and/or + extensive documentation, the check result itself should be + contained in a seperate lightweight iframe that extensions can + request via an alternate url. + Security and resiliency implications: What attacks are possible?