PageRenderTime 64ms CodeModel.GetById 33ms RepoModel.GetById 0ms app.codeStats 0ms

/mozilla-https-everywhere-2.1/Changelog

#
#! | 471 lines | 419 code | 52 blank | 0 comment | 0 complexity | e7ff8841d5e2749eb353f8e1ec57143c MD5 | raw file
Possible License(s): GPL-2.0
  1. 2.1 (2012-06-18)
  2. * Fix context menu breakage when URIs lack a host
  3. * Fixes: CiteULike, MozillaMessaging, Yandex, Demonoid, Pirate Party,
  4. Gentoo, NYTimes, Microsoft, Wikipedia, Lenovo
  5. https://mail1.eff.org/pipermail/https-everywhere-rules/2012-June/001189.html
  6. https://trac.torproject.org/projects/tor/ticket/6091
  7. https://mail1.eff.org/pipermail/https-everywhere-rules/2012-June/001190.html
  8. https://mail1.eff.org/pipermail/https-everywhere-rules/2012-May/001186.html
  9. https://mail1.eff.org/pipermail/https-everywhere/2012-May/001433.html
  10. * Disable broken: MarketWatch, Disqus, Magento, Lavasoft, Project Syndicate,
  11. Typepad/Say Media
  12. https://trac.torproject.org/projects/tor/ticket/5899
  13. https://trac.torproject.org/projects/tor/ticket/5496
  14. 2.0.5 (2012-05-16)
  15. * Rebuild 2.0.4 without a bug in the release scripts that prevented all the
  16. rulesets from being absent
  17. 2.0.4 (2012-05-16)
  18. * Fix for compatibility with some other Firefox extensions:
  19. https://trac.torproject.org/projects/tor/ticket/5682
  20. * Fixes: Wordpress stylesheets, USENIX, Mozilla, Opera, Indymedia
  21. https://trac.torproject.org/projects/tor/ticket/5905
  22. https://mail1.eff.org/pipermail/https-everywhere-rules/2012-April/001105.html
  23. * Disable broken: Pandora, Miranda IM, Pastebin.ca, PaidContent
  24. https://trac.torproject.org/projects/tor/ticket/5804
  25. https://trac.torproject.org/projects/tor/ticket/5776
  26. 2.0.3 (2012-04-26)
  27. * Fix a downgrade attack that might allow attackers to deny HTTPS
  28. Everywhere protection for cookies on some domains.
  29. https://trac.torproject.org/projects/tor/ticket/5676
  30. * Minor redirection mechanism fixes
  31. * Fixes: WordPress, Yandex, OpenDNS, Via.me/AWS
  32. * Improvements: Mozilla
  33. * Disable broken: ReadWriteWeb
  34. 2.0.2 (2012-04-19)
  35. * Fix a weird wrong DOM-origin bug that occurred while redirects were in
  36. progress (this might have security implications, although we are unsure
  37. if it was exploitable).
  38. https://trac.torproject.org/projects/tor/ticket/5477
  39. * By default, use https://google.co.cctld instead of
  40. encrypted.google.com
  41. * Add an optional ruleset to use https://www.google.com
  42. instead of encrypted.google.com, too
  43. * Ruleset fixes: Debian, Kohls, Malwarebytes, Yandex, Wikipedia, Mises.org,
  44. OpenDNS, Wizards of the Coast, Lenovo, Barnes and Noble
  45. https://trac.torproject.org/projects/tor/ticket/5509
  46. https://trac.torproject.org/projects/tor/ticket/5491
  47. https://trac.torproject.org/projects/tor/ticket/5303
  48. * Stumble across more horrible security holes in the Verizon website:
  49. https://mail1.eff.org/pipermail/https-everywhere-rules/2012-February/001003.html
  50. * Disable the Gentoo ruleset on non-CAcert platforms
  51. * Disable buggy rulesets: IBM, Scribd, Wunderground :( :( :(
  52. https://trac.torproject.org/projects/tor/ticket/5344
  53. https://trac.torproject.org/projects/tor/ticket/5435
  54. https://trac.torproject.org/projects/tor/ticket/5630
  55. 2.0.1 (2012-02-27)
  56. * 2.0 is now Stable!
  57. * Fix tiny settings window on some versions of Windows:
  58. https://trac.torproject.org/projects/tor/ticket/5197
  59. * Fix drop down menu bug for the non-English versions of the UI
  60. * Added Farsi and Arabic translations
  61. * Disable Netflix, which was demonstrating a lot of breakage
  62. * Improvements: Wikipedia
  63. * Fixes: Google, Samba
  64. * Ship 4 new rulesets since 2.0development.6
  65. (404 new rulesets since 1.2.2!)
  66. * Check ruleset grammaticity with xmllint/RelaxNG
  67. chrome-2012.02.09
  68. * make <exclusion pattern> rulesets elements work in the Chrome version
  69. https://trac.torproject.org/projects/tor/ticket/5042
  70. (also disable the LinkedIn ruleset)
  71. * Support for Google Sorry
  72. * 6 new rulesets
  73. 2.0.0development.6 (2012-02-08)
  74. * Fix a nasty UI crash bug on Windows
  75. https://trac.torproject.org/projects/tor/ticket/5020
  76. * Ruleset fixes: Google Video, Yandex, LDS
  77. https://trac.torproject.org/projects/tor/ticket/5026
  78. https://trac.torproject.org/projects/tor/ticket/5042
  79. * Disable problematic LinkedIn ruleset
  80. * An experimental ruleset for the Google "Sorry" page
  81. * Improved Nederlands translation
  82. * Ship 6 new rulesets
  83. chrome-2012.02.06{,.01}
  84. * First "Official" EFF alpha Chrome release
  85. * Installable on Chrome|Chromium 18+
  86. * Two point versions, to test the autoupdating mechanism
  87. 2.0.0development.5 (2012-02-02)
  88. * Fix some data structure inefficiencies that should reduce RAM consumption
  89. by 25-75MB (!)
  90. https://trac.torproject.org/projects/tor/ticket/4804
  91. * Global enable / disable option
  92. https://trac.torproject.org/projects/tor/ticket/4060
  93. * Google Cache is back! :)
  94. * Ship 126 new rulesets
  95. * Fixes: Wikipedia, Identi.ca, Verizon, CCC.de, UserScripts, Yandex,
  96. Hidemyass, Mozilla, Pogo, Google, Google Images, Google Video,
  97. The Pirate Bay, AK Vorrat, JBoss
  98. * Improvements: EFF, Flickr, RedHat, Diaspora, PrivatePaste, KDE,
  99. Portugese Govt
  100. * Disable broken: NSF.gov, WHO.int, Economist
  101. * New experimental Yahoo! ruleset (off by default)
  102. * New translations: Spanish, Nederlands
  103. 2.0.0development.4 (2011-11-15)
  104. * The translations actually work
  105. * Add new translations: Chinese, Russian
  106. * Ship 37 new rulesets
  107. * Exclude Userscript paths as an insecure workaround for the Greasemonkey
  108. and Scriptish instances of this bug:
  109. https://trac.torproject.org/projects/tor/ticket/3190
  110. * Fixes: Java.com, Yandex, Wordpress, Wikipedia, Bahn.de, UNSW, Apache,
  111. DuckDuckGo, Google Images
  112. * Improvements: Debian, Tumblr, Apple, Facebook, VeriSign, Google Services,
  113. Flickr, Youtu.be
  114. * Disable broken: Target, OpenUniversity, TV.com, Radio Shack,
  115. Yahoo Mail :( :(,
  116. Google Cache coverage in Google Services :( :( :(
  117. 2.0.0development.3 (2011-10-19)
  118. * Selectively reenable nsIContentPolicy::shouldLoad()
  119. Fixes: https://trac.torproject.org/projects/tor/ticket/4194
  120. Fixes: https://trac.torproject.org/projects/tor/ticket/4149
  121. * Crazy experimental IOUtils hacks from NoScript
  122. https://bugzilla.mozilla.org/show_bug.cgi?id=677643#c75
  123. (Appears to fix
  124. https://mail1.eff.org/pipermail/https-everywhere/2011-October/001208.html,
  125. which is probably a general redirection bug)
  126. * Secure cookies set by JavaScript as well as those set by HTTP
  127. Fixes: https://trac.torproject.org/projects/tor/ticket/3766
  128. * Perform initialisation synchronously, reducing races during startup
  129. Fixes: https://trac.torproject.org/projects/tor/ticket/3533
  130. * Ship 9 new rulesets
  131. * Disable: MikeWest
  132. * Improvements: YouTube, Google Images
  133. 2.0.0development.2 (2011-10-05)
  134. * Enable YouTube by default
  135. (also closes https://trac.torproject.org/projects/tor/ticket/4032)
  136. * Merge nsIContentPolicy disablement from stable
  137. (closes https://trac.torproject.org/projects/tor/ticket/3882)
  138. * Context menu should work on error pages
  139. (https://trac.torproject.org/projects/tor/ticket/3815)
  140. * Fix the ASN setting button in the observatory prefs
  141. (https://trac.torproject.org/projects/tor/ticket/4170)
  142. * Make the Observatory much more efficient
  143. * Ship 46 new rulesets
  144. * Update for new Wikipedia HTTPS deployment
  145. * Ruleset Fixes and Enhancements: Yandex, Identica, SBB, Polldaddy, XKCD,
  146. Statcounter, Caltech, UCSD, FlickR, Android
  147. * Disable broken: LastPass, Avast, EPEAT, Bloglines
  148. * Improve the state of our translations-in progress
  149. * Fancy new Python build scripts
  150. 2.0.0development.1 (2011-09-15)
  151. * Begin alpha testing for the Decentralized SSL Observatory!
  152. (currently opt-in, with a popup prompt if you have Tor Button installed)
  153. * Ship 164 new rulesets
  154. * Enable Google Maps by default
  155. * Pending translations: Arabic, Dutch, German, Portugese, Latvian, Russian,
  156. Swedish
  157. * Fixes: OpenDNS, WordPress, Flickr
  158. * Expansions & Improvements: Google Services, Twitter, Gowalla, Apple, Bit.ly
  159. AdBlock Plus, KLM, Adobe, UCSD, Heroku, Wikipedia
  160. * Disable broken rulesets: Deviantart, Bandcamp, Securityfocus
  161. * Improved build scripts
  162. 1.2.2 (2012-01-09)
  163. * Google Cache is back!
  164. * Fixes: Wikipedia, Identi.ca, Verizon, CCC.de, UserScripts,
  165. Yandex
  166. * Improvements: EFF
  167. * Disable broken: NSF.gov, WHO.int
  168. 1.2.1 (2011-10-15)
  169. * Google Cache is broken, remove it from GoogleServices :( :( :(
  170. * Fix for the Google Image Search homepage
  171. * Exclude help.duckduckgo.com:
  172. https://trac.torproject.org/projects/tor/ticket/4399
  173. * Disable Yahoo! Mail:
  174. https://trac.torproject.org/projects/tor/ticket/4441
  175. * Installable on Firefox 10
  176. 1.2 (2011-10-14)
  177. * Fixes: WordPress, Statcounter, Java, Bahn.de, SICS.se
  178. * Improvements: use fancy new HTTPS Wikipedia
  179. * Disable broken: OpenUniversity, TV.com, Random.org, kb.CERT
  180. 1.1 (2011-10-19)
  181. * Further tweaks to internals, will hopefully fix a number of weird issues:
  182. https://trac.torproject.org/projects/tor/ticket/4194
  183. https://trac.torproject.org/projects/tor/ticket/4149
  184. https://mail1.eff.org/pipermail/https-everywhere/2011-October/001208.html
  185. * YouTube is enabled by default!
  186. * Fixes: Yandex, Statcounter, Polldaddy, SBB.ch
  187. * Improvements: Facebook+
  188. * Disable broken: Bloglines, EPEAT
  189. 1.0.3 (2011-09-26)
  190. * Mozilla is about to release Firefox 7, the stable branch needs to be
  191. installable there!
  192. * Disabling nsIContentPolicy callbacks should fix this crash bug:
  193. https://trac.torproject.org/projects/tor/ticket/3882
  194. https://bugzilla.mozilla.org/show_bug.cgi?id=677643
  195. It /might/ cause us to fail to rewrite requests in obscure corner cases.
  196. We haven't found any in testing, but vigilance will be required.
  197. * Support for Google Maps
  198. * Fixes: WordPress, Lenovo, OpenDNS, Avast, Ripe.net, TV.com, 38.de
  199. * Disable broken: Seagate
  200. 1.0.2 (2011-09-20)
  201. * Major improvements to the Wikipedia ruleset
  202. * Disable broken/buggy rulesets: DeviantArt, eHow, About.me, Bandcamp,
  203. StudiVZ, Securityfocus, BankofAmerica :( :( :(
  204. * Small fixes: OpenDNS, WordPress, links in the "About" page
  205. * Declare incompatibility with Firefox 7 & 8 until Mozilla fixes this:
  206. https://bugzilla.mozilla.org/show_bug.cgi?id=677643
  207. 1.0.1 (2011-08-10)
  208. * Disable some rulesets with partial compatibility issues: Reddit,
  209. StumbleUpon, Heroku
  210. * Small Yandex fix
  211. * Fix/improvement for Google Instant outside the US
  212. 1.0.0 (2011-08-04)
  213. * Release 1.0 into the stable branch!
  214. * Improve toolbar UI for error pages somewhat (it still isn't perfect)
  215. * Bugfixes: Microsoft, Dropbox, Netflix, MySQL
  216. * Disable a couple of broken rules
  217. 1.0.0development.5: (2011-07-13)
  218. * Ship rulesets as a single "default.rulesets" file, shrinking the .xpi from
  219. ~370 kB to ~120kB and speeding Firefox startup:
  220. https://trac.torproject.org/projects/tor/ticket/3404
  221. * Fix an ephemeral bug where disabled-by-default rules would be briefly
  222. enabled when first installed
  223. * Wikipedia shows up in the toolbar/context menu
  224. * Fixes to netflix & netzpolitik
  225. * Toolbar/context menu can be opened with left or right click
  226. 1.0.0development.4: (2011-07-06)
  227. * Fix a bug with Google Translate
  228. * Unbreak the Netflix blog
  229. * Toolbar button now looks OK in Seamonkey
  230. * Declare compatibility with the next round of Firefox alphas
  231. 1.0.0development.3: (2011-07-04)
  232. * Do not show a bizarre popup when people click the HTTPS toolbar button on
  233. error pages
  234. * Fix a GoogleServices bug that broke logout from non-US google accounts :(
  235. 1.0.0development.2: (2011-07-01)
  236. * Fix bugs that arose when trying to move the toolbar menu icon:
  237. https://trac.torproject.org/projects/tor/ticket/3497
  238. * Handle usernames and passwords in URIs more explicitly
  239. https://trac.torproject.org/projects/tor/ticket/2199
  240. * By default, move context menu from toolbar to addons bar
  241. * Ship 22 new rulesets
  242. * Add support for Google Plus, Accounts and AdWdords
  243. * Improvements to Microsoft, Twitter and Gitorious
  244. 1.0.0development.1: (2011-06-27)
  245. * Add a context menu to let users toggle rulesets that are/might be
  246. applicable to the current page (we can now stabilise the dev branch!)
  247. * Ship 42 new rulesets
  248. * Support for Google Image Search (except the very first landing page :/)
  249. * Fixes: Netflix, Plone
  250. * Improvements: Google APIs, Google Services, Mediawiki
  251. * Disable broken rules: OKCupid, Surveymonkey
  252. * Declare compatibility with recent Seamonkey releases
  253. 0.9.9.development.6:
  254. * Optimistically declare compatibility with Firefoxes up to v 7.*
  255. * Ship 193 new rulesets
  256. * Fixes & Improvements: Wikipedia, AmazonAWS, Google Images, Microsoft,
  257. Mozilla, Netflix, Google User Content, Twitter, Gitorious, AdBlock Plus,
  258. Youtube, he.net, Bitcoin
  259. * Remove broken rules: Match.com
  260. 0.9.9.development.5:
  261. * Compatible with Firefox 4.0.1+
  262. * New ruleset management UI (thanks to katmagic and Stefan Tomanek)
  263. * Ship 136 new rulesets
  264. * Fixes: reCAPTCHA, Google Images, Gentoo, Gitorious
  265. * Improvements: Bit.ly, Yahoo, Nokia
  266. * Disable: WashingtonPost :(, Doubleclick, OpenSSL.org (!)
  267. 0.9.9.development.4:
  268. * Ship 117 new rulesets
  269. * Fixes: MySQL, GroupOn, country-specific Google news sites,
  270. * Improvements: mail.com, WordPress
  271. * Leave WashingtonPost ruleset on in the hope that it gets fixed soon :/
  272. * Disable broken rules: HTC, I2P ...
  273. 0.9.9.development.3:
  274. * In the settings dialogue, offer "Reset defaults" instead of "Enable all"
  275. * Merge fixes from NoScript that avoid some torbutton bugs
  276. * Ship 56 new rulesets
  277. * Numerous tweaks + fixes, including NYTimes and AddThis
  278. 0.9.9.development.2:
  279. * Prevent the preferences window from swallowing the screen on OS X / Windows
  280. * Stop the StartCom rule from breaking StartCom OCSP/CRLs (which can't be HTTPS)
  281. * Attempt to do the same for for CAcert
  282. * Fixes to: Reddit, Drupal.org
  283. * Disable some problematic rulesets: Cisco, Opera
  284. * Enable: Reddit
  285. * Ship another 62 rulesets
  286. 0.9.9.development.1:
  287. * The efficient ruleset checking implementation should now hopefully be...
  288. efficient
  289. * Ship all the rulesets (!!!)
  290. * Except the ones that cause cert warnings, which are there but off by default
  291. * Build scripts attempt to validate rulesets before making a .xpi
  292. 0.9.7:
  293. * Support firefox 5 and 6 betas
  294. * Numerous improvements and fixes to Google and GoogleServices support
  295. * Fixes to AmazonAWS
  296. * Secure j.mp via bit.ly
  297. * Fix gentoo bugs
  298. 0.9.6:
  299. * Support firefox 4.0.1
  300. * Unbreak recaptcha
  301. * Disable google.com/jsapi (which was breaking some embedded maps, though
  302. that bug *might* have been fixed)
  303. 0.9.5:
  304. * WashingtonPost is broken and seems to be staying that way; disable it :(
  305. * Replace "Enable All" with "Reset Defaults"
  306. * Fixes & Improvements to WordPress + Mozilla
  307. 0.9.4:
  308. * Significant performance improvements
  309. * Disable Cisco by default
  310. * Fixes & improvements to: NYTimes, WashingtonPost, Cisco, WordPress
  311. * Support Google Code
  312. * Disable Google Custom Search Engines (they don't work)
  313. * Support global installation for OS distributions (thanks dm0)
  314. 0.9.3:
  315. * Significant performance improvements
  316. * Disable Cisco by default
  317. * Fixes & improvements to: NYTimes, WashingtonPost, Cisco, WordPress
  318. * Support Google Code
  319. * Disable Google Custom Search Engines (they don't work)
  320. * Support global installation for OS distributions (thanks dm0)
  321. 0.9.2:
  322. * Fix a bug in our redirection loop detection that was causing touble with
  323. some parts of NYTimes, Facebook, and other sites
  324. (closes: https://trac.torproject.org/projects/tor/ticket/2217)
  325. 0.9.1:
  326. * Unbreak the "all x news articles" links in Google News
  327. * Exclude nytimes.com/roomfordebate, since it's broken in https.
  328. 0.9.0:
  329. * This is our "Firesheep" release. It has numerous anti-firesheep
  330. improvements!
  331. * Split the stricter parts of the Facebook rule into a "Facebook+" rule.
  332. It's what's required to protect Facebook from Firesheep and similar cookie
  333. theft attacks, but it may break apps, because apps.facebook.com currently
  334. has the wrong cert.
  335. * Allow rulesets to specify that the secure flag should be set on some
  336. cookies even if the site operator failed to do so
  337. * Ship rules for:
  338. - Amazon S3 (AWS)
  339. - Github
  340. - Bit.ly
  341. - Dropbox
  342. - Evernote
  343. - Cisco
  344. * Extensive improvements (including secure cookies) in the Twitter and
  345. Facebook rules
  346. * Support for full Live / Hotmail encryption
  347. * Significant performance optimisation decreases CPU load
  348. Fixes:
  349. https://trac.torproject.org/projects/tor/ticket/1656
  350. https://trac.torproject.org/projects/tor/ticket/2194
  351. * Rearrange our Channel Replacement code!
  352. Fixes https://trac.torproject.org/projects/tor/ticket/1684
  353. https://bugzilla.mozilla.org/show_bug.cgi?id=548102
  354. Thanks to Giorgio Maone and Boris Zbarsky!
  355. * Add scrollbars if there are a lot of rules present in the Preferences
  356. dialog (may still be somewhat buggy...)
  357. * Optimise GoogleServices.xml and support Google code search
  358. * Patch for future compatiability with Request Policy:
  359. https://trac.torproject.org/projects/tor/ticket/1574
  360. * Support for the Firefox 4 API
  361. * The Amazon rule was causing a lot of glitches; it is now off by default
  362. * Control log verbosity with an about:config variable
  363. * Numerous minor rule improvements
  364. 0.2.2:
  365. * Fix a glitch in the Content Policy path that may or may not have been
  366. responsible for these bugs:
  367. https://trac.torproject.org/projects/tor/ticket/1700
  368. https://trac.torproject.org/projects/tor/ticket/1672
  369. https://trac.torproject.org/projects/tor/ticket/1673
  370. The patch breaks toolbar search suggestions. And who knows what else?
  371. * Don't send some country homepages to https://www.google.com/webhp?hl= ;
  372. use https://encrypted.google.com instead
  373. * Cleanup and refactor the URI replacement and rewriting code. Should
  374. hopefully fix https://trac.torproject.org/projects/tor/ticket/1649
  375. * Add a Google APIs rule
  376. * Remove some Extremely Nasty code that would delete malformed rulesets (!)
  377. (it was pasted from Torbutton's cookie handling logic...)
  378. * Add code.google.com to Google Services
  379. * The client=firefox* workaround is no longer necessary once we're sending
  380. non-US users to encrypted.google.com rather than www.google.com
  381. * Better coverage for GMX, Google services, Twitter
  382. * Scroogle homepage in HTTPS
  383. * Add rules for
  384. - Mail.com logins
  385. - Microsoft (limited coverage)
  386. * Fix a nasty Google/Wikipedia bug within 0.2.2.development.{1,2}
  387. 0.2.1:
  388. * Although google said https://www.google.com would continue to work, that
  389. wasn't absolutely true.
  390. * The new encyrpted.google.com seems to require queries to be #q=thing
  391. rather than search?q=thing, at least some of the time. So let's do that.
  392. 0.2.0:
  393. * Work around the fact that Google does not allow client=firefox* HTTPS
  394. searches from outside the US, by rewriting those URIs
  395. * Add rules for:
  396. - Amazon
  397. - GMX
  398. - Live.com (Hotmail logins)
  399. - Meebo
  400. - the Netherlands Government
  401. - Wordpress.com
  402. - Zoho
  403. * Remove the assumption that non-US searches would always start with an hl=
  404. language parameter
  405. * Handle searches to the google.com/firefox script better
  406. * Remove accidental duplicates of a couple of rules!
  407. * Bump maxVersion into the future so we're compatible with Firefox alphas
  408. * Fix more legacy eff.org bugs
  409. 0.1.2:
  410. * Apparently, we are not actually compatible with Firefox 2.0.0.x, so don't
  411. install with it!
  412. * Further generalisation of Wikimedia rules
  413. * Fix bugs in the handling of obscure parts of eff.org and torproject.org
  414. * A bug in a user rules file should produce an error, rather than causing all
  415. rules to fail to load
  416. 0.1.1:
  417. * Generalise the Wikipedia rules to other Wikimedia services
  418. * In preferences window, add a link to instructions for writing one's own
  419. rules