[tor-bugs] #9623 [TorBrowserButton]: Referers being sent from hidden service websites

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Aug 29 17:57:49 UTC 2013


#9623: Referers being sent from hidden service websites
----------------------------------+-----------------------
     Reporter:  cypherpunks       |      Owner:  mikeperry
         Type:  defect            |     Status:  new
     Priority:  major             |  Milestone:
    Component:  TorBrowserButton  |    Version:
   Resolution:                    |   Keywords:
Actual Points:                    |  Parent ID:
       Points:                    |
----------------------------------+-----------------------

Comment (by cypherpunks):

 This is not only an issue about users being tracked.

 It's also bad for owners of hidden services as the addresses are getting
 discovered. Maybe the user was on a private website which nobody should
 learn, or at least on a private webpage on a public website.

 Or maybe the referer could include login credentials, or other dangerous
 information.

 The current behavior doesn't really fit well with the "hidden service"
 idea.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9623#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list