[tbb-bugs] #23216 [Applications/Tor Browser]: The `languagechange` event is noticeable on all open tabs
Tor Bug Tracker & Wiki
blackhole at torproject.org
Fri Aug 11 12:50:45 UTC 2017
#23216: The `languagechange` event is noticeable on all open tabs
------------------------------------------+-----------------------------
Reporter: gk | Owner: tbb-team
Type: defect | Status: new
Priority: Medium | Milestone:
Component: Applications/Tor Browser | Version:
Severity: Normal | Keywords: tbb-linkability
Actual Points: | Parent ID:
Points: | Reviewer:
Sponsor: |
------------------------------------------+-----------------------------
It turns out that there is the `languagechange` event which is noticeable
on all open tabs allowing to correlate activity of a user cross-domain and
bypassing our unlinkability requirement.
Now, triggering that one can't be done remotely and is probably not done
very often. But still we should find a way to make it much less obvious to
third party scripts that a particular user made language related changes
and has been on website A, B, and C.
Reported on HackerOne by tomvg.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/23216>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tbb-bugs
mailing list