[tbb-bugs] #29646 [Applications/Tor Browser]: NoScript XSS user choices are persisted

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Jun 17 10:12:06 UTC 2019


#29646: NoScript XSS user choices are persisted
-------------------------------------------------+-------------------------
 Reporter:  atac                                 |          Owner:  tbb-
                                                 |  team
     Type:  defect                               |         Status:  new
 Priority:  High                                 |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  tbb-disk-leak xss noscriptm tbb-     |  Actual Points:
  newnym                                         |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by cypherpunks):

 > That persists over New Identity, which is definitely a bug.
 Another bug for another ticket.
 > But I am not sure what the best solution for the disk persistence would
 be.
 Disk Avoidance from the design guide. Settings should be in-memory only.

 `Keywords:      noscriptm`?
 Does `ma1` know about it?

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/29646#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list