[tor-bugs] #3600 [TorBrowserButton]: We should get user confirmation for automated redirect cycles (was: We should get user confirmation for redirects)

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Fri Oct 7 00:16:25 UTC 2011


#3600: We should get user confirmation for automated redirect cycles
------------------------------+---------------------------------------------
 Reporter:  mikeperry         |          Owner:  mikeperry                    
     Type:  defect            |         Status:  new                          
 Priority:  major             |      Milestone:  TorBrowserBundle 2.3.x-stable
Component:  TorBrowserButton  |        Version:                               
 Keywords:                    |         Parent:                               
   Points:                    |   Actualpoints:                               
------------------------------+---------------------------------------------

Comment(by mikeperry):

 pde pointed out that without exceptions, prompting for all redirects is
 going to cause warning fatigue, especially now that both google and
 twitter use them by default for click tracking.

 So instead, let's try to address the linkability issue. We should prompt
 for automated redirect cycles that bounce off an intermediate site without
 prompting the user before returning to a previous site in the redirect
 chain. Such automated cycles would be evidence of parternerships
 attempting to elevate ad servers to first-party status.

 We can track these cycles with a navigation observer, but it will be a fun
 challenge to differentiate automated redirects from those that stop for
 user input from XPCOM. We may need to alter some APIs. :/

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/3600#comment:10>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list