Skip to content

SecureDrop banner with steps to change the Tor Browser security level are outdated #7818

@henry-torproject

Description

@henry-torproject

Description

Since Tor Browser 15.0 (and some of 14.5), Tor Browser requires a restart to change the security level. See the issue tracker on gitlab. The current SecureDrop banner that instructs visitors to change their security level is now outdated.

Steps to Reproduce

Set Tor Browser to the "Standard" or "Safer" security level and restart.

Visit https://securedrop.org/directory/washington-post/.

Expected Behavior

If you want any instructions, they should let the user know that they can change the security level in their browser security settings, and they may need to restart the browser and revisit the website.

Actual Behavior

The banner says

Your Tor security settings are too low!

Set your Tor security level to "Safest" for maximum protection

  1. Click the shield icon in the browser toolbar
  2. Click Advanced Security Settings
  3. Select Safest and close the Preferences tab
  4. Refresh the page

Note, there are a few problems with this:

  1. "Advanced Security Settings" does not existing in the UI.
  2. Changing security level will require a restart, which means the SecureDrop web page will be lost between sessions.

Comments

Note that we (tor browser developers and UX) are currently responding to changes in Firefox's settings design for the 16.0 release, so I wouldn't write your instructions in a way that depends too heavily on the current settings layout. However, it is generally expected for this to remain under "Security level".

Here's are some example instructions that currently work:

  1. Open your browser settings and navigate to the "security level" settings.
  2. Change your "security level" to "Safest" and restart Tor Browser.
  3. Reconnect to Tor and revisit this page.

Or

  1. Open your browser settings and search for "security level".
  2. Change your "security level" to "Safest" and restart Tor Browser.
  3. Reconnect to Tor and revisit this page.

Or

  1. Click the shield icon in the browser toolbar.
  2. Click "Settings…".
  3. Change your "security level" to "Safest" and restart Tor Browser.
  4. Reconnect to Tor and revisit this page.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status

    Ready to go

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions