[tbb-bugs] #21657 [Applications/Tor Browser]: Test to make sure we isolate or disable all speculative connects

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Mar 6 20:38:24 UTC 2017


#21657: Test to make sure we isolate or disable all speculative connects
--------------------------------------+--------------------------
 Reporter:  arthuredelstein           |          Owner:  tbb-team
     Type:  defect                    |         Status:  new
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------
Description changed by arthuredelstein:

Old description:

> There are a variety of "resource hint" features in Tor Browser that we
> want to make sure are isolated by first-party or disabled. These include
> {{{
>   link rel=preconnect
>   link rel=prefetch
>   link rel=prerender
> }}}
> and possibly more.
> We should test this for the ESR45 and ESR52 versions of Tor Browser,
> because isolation will have different mechanisms.
>
> See https://w3c.github.io/resource-hints/

New description:

 There are a variety of "resource hint" features in Tor Browser that we
 want to make sure are isolated by first-party or disabled. These include
 {{{
   link rel=preconnect
   link rel=prefetch
   link rel=prerender
 }}}
 and possibly more.
 We should test this for the ESR45 and ESR52 versions of Tor Browser,
 because isolation will have different mechanisms.

 See https://w3c.github.io/resource-hints/

 We should also look into "SpeculativeConnect" code in Firefox to make sure
 there aren't any other cases of non-first-party isolated connections.

--

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21657#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list