[tbb-bugs] #22320 [Applications/Tor Browser]: Referrer not hidden when comming from a .onion address

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon May 22 07:36:59 UTC 2017


#22320: Referrer not hidden when comming from a .onion address
-------------------------------------------------+-------------------------
 Reporter:  pege                                 |          Owner:  tbb-
                                                 |  team
     Type:  defect                               |         Status:
                                                 |  needs_review
 Priority:  Medium                               |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  ff52-esr, tbb-7.0-must,              |  Actual Points:
  TorBrowserTeam201705R                          |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------
Changes (by gk):

 * status:  new => needs_review
 * cc: arthuredelstein (added)
 * keywords:   => ff52-esr, tbb-7.0-must, TorBrowserTeam201705R


Comment:

 It seems to me the Firefox patch is wrong. What we want to have is
 `network.http.referer.spoofOnionSource` and not
 `network.http.referer.hideOnionSource`. `bug_22320`
 (https://gitweb.torproject.org/user/gk/tor-
 browser.git/commit/?h=bug_22320&id=c3a849a2b5f57a4860c16975be9c12fed22ed910)
 in my public repo fixes that.

 pege: Does adding that preference fix the problem for you as well?
 Arthur: Assuming I am right could you open a Mozilla bug correcting the
 patch ("(use target URI as referer)" in `all.js` is wrong as well)?

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/22320#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list