[tor-bugs] #5715 [TorBrowserButton]: "New Identity" has cache race conditions that temporarily allow evercookies

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Mon May 14 21:16:43 UTC 2012


#5715: "New Identity" has cache race conditions that temporarily allow evercookies
---------------------------------+------------------------------------------
    Reporter:  guiseppe          |       Owner:  mikeperry      
        Type:  defect            |      Status:  reopened       
    Priority:  critical          |   Milestone:                 
   Component:  TorBrowserButton  |     Version:                 
  Resolution:                    |    Keywords:  MikePerry201205
      Parent:                    |      Points:  3              
Actualpoints:  3                 |  
---------------------------------+------------------------------------------
Changes (by cypherpunks):

  * status:  closed => reopened
  * resolution:  fixed =>


Comment:

 Bad news from the evercookie frontierline.

 I have tested the new TBB (2.2.35-12).
 'samy.pl/evercookie' is still able to recover evercookies.

 Procedure to reproduce this:
 Go on the testing page, create an evercookie, click "New Identity", then
 return on the site and reactivate the evercookie.
 You will see: linkability is back!

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/5715#comment:10>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list