[tbb-bugs] #30683 [Applications/Tor Browser]: Properties in dom/locales/$lang/chrome/ allow detecting user locale

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Jun 13 07:09:22 UTC 2019


#30683: Properties in dom/locales/$lang/chrome/ allow detecting user locale
---------------------------------------+--------------------------
 Reporter:  gk                         |          Owner:  tbb-team
     Type:  defect                     |         Status:  new
 Priority:  High                       |      Milestone:
Component:  Applications/Tor Browser   |        Version:
 Severity:  Normal                     |     Resolution:
 Keywords:  tbb-fingerprinting-locale  |  Actual Points:
Parent ID:                             |         Points:
 Reviewer:                             |        Sponsor:
---------------------------------------+--------------------------

Comment (by gk):

 Replying to [ticket:30683 gk]:
 > z3t reported a bunch of issues on HackerOne regarding detection of user
 locale with the help of `dom/locales/$lang/chrome/` properties. PoCs done
 by z3t:
 >
 > `dom/dom.properties`:
 https://people.torproject.org/~gk/tests/tor_form_locale_leak.html

 `<input type="email">` is relevant here as well (thanks to mik317 on
 HackerOne for pointing this out).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/30683#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list