[tbb-bugs] #15599 [Tor Browser]: Range requests are not isolated to URL -bar domain

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Apr 6 12:53:55 UTC 2015


#15599: Range requests are not isolated to URL -bar domain
-----------------------------+--------------------------------------------
     Reporter:  gk           |      Owner:  tbb-team
         Type:  defect       |     Status:  new
     Priority:  major        |  Milestone:
    Component:  Tor Browser  |    Version:
   Resolution:               |   Keywords:  tbb-linkability, tbb-4.5-alpha
Actual Points:               |  Parent ID:
       Points:               |
-----------------------------+--------------------------------------------

Old description:

> If a server sends the Accept-Range header + a proper content size Tor
> Browser is starting range requests that are not isolated to the URL bar
> domain. You can test this e.g. with
> https://kpdyer.com/publications/usenix2014-fte.pdf. Works even in a third
> party context with https://people.torproject.org/~gk/misc/range-request-
> test.html (your security slider level needs to be below medium-high in
> this case).

New description:

 If a server sends the Accept-Ranges header + a (proper) Content-Length Tor
 Browser is starting range requests that are not isolated to the URL bar
 domain. You can test this e.g. with
 https://kpdyer.com/publications/usenix2014-fte.pdf. Works even in a third
 party context with https://people.torproject.org/~gk/misc/range-request-
 test.html (your security slider level needs to be below medium-high in
 this case).

--

Comment (by gk):

 I think this is due to
 {{{
 getFirstPartyURI failed for
 https://kpdyer.com/publications/usenix2014-fte.pdf
 }}}
 I wonder if we could get that fixed last-minute for 4.5.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/15599#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list