[tor-bugs] #1816 [Torbutton]: Create a prototype Content Script for Google Chrome

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Wed Sep 1 07:25:17 UTC 2010


#1816: Create a prototype Content Script for Google Chrome
------------------------+---------------------------------------------------
  Reporter:  mikeperry  |       Owner:  mikeperry
      Type:  task       |      Status:  closed   
  Priority:  normal     |   Milestone:           
 Component:  Torbutton  |     Version:           
Resolution:  fixed      |    Keywords:           
    Parent:  #1770      |  
------------------------+---------------------------------------------------

Comment(by mikeperry):

 Eek, it turns out that it is possible to fingerprint that certain addons
 are installed by sourcing their chrome-extensions urls from page script.
 If the addon is installed, the page will source. If it is not installed,
 the page won't source and you can detect this by either catching an
 exception or registering a listener for onerror.

 This is bad for Torbutton's undiscoverability requirement:
 https://www.torproject.org/torbutton/design/#undiscoverability

 However, I'm guessing a lot of addons inject tags that source things from
 their own addons dir into pages they have permissions over.. Bleh. Maybe
 this is something we can use Web Request to handle.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/1816#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list