[tor-bugs] #5715 [TorBrowserButton]: TorBrowser not defending against evercookies despite of TorBrowserButton "New Identity"

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Tue May 1 16:40:53 UTC 2012


#5715: TorBrowser not defending against evercookies despite of TorBrowserButton
"New Identity"
------------------------------+---------------------------------------------
 Reporter:  guiseppe          |          Owner:  mikeperry
     Type:  defect            |         Status:  new      
 Priority:  critical          |      Milestone:           
Component:  TorBrowserButton  |        Version:           
 Keywords:  MikePerry201205   |         Parent:           
   Points:                    |   Actualpoints:           
------------------------------+---------------------------------------------
Changes (by mikeperry):

  * keywords:  evercookie, linkability => MikePerry201205


Comment:

 Wow. This is just an awesomely bad regression. Thanks for testing. I'm
 still not sure how this data is persisting. According to about:cache, "New
 Identity" is properly clearing all cache entries..

 In fact, if I wait a minute or two, or do something else between samy.pl
 visits, it is in fact unable to regenerate my evercookies.. Sounds like
 the cache picked up some fun race conditions while we weren't looking...

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5715#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list