[tor-bugs] #3600 [TorBrowserButton]: Prevent redirects from transmitting+storing cookies+identifiers

Tor Bug Tracker & Wiki blackhole at torproject.org
Sat Mar 9 00:17:38 UTC 2013


#3600: Prevent redirects from transmitting+storing cookies+identifiers
------------------------------+---------------------------------------------
 Reporter:  mikeperry         |          Owner:  mikeperry                    
     Type:  defect            |         Status:  new                          
 Priority:  major             |      Milestone:  TorBrowserBundle 2.3.x-stable
Component:  TorBrowserButton  |        Version:                               
 Keywords:  tbb-linkability   |         Parent:                               
   Points:                    |   Actualpoints:                               
------------------------------+---------------------------------------------

Comment(by mikeperry):

 Somewhere, somehow we should enumerate the various ways automated
 redirects can happen. Here's a few off the top of my head:
 1. HTTP 3xx headers
 2. meta-refresh
 3. window/document.location updates
 4. JS-driven form submits
 5. Synthetic click events (https://developer.mozilla.org/en-
 US/docs/DOM/element.dispatchEvent)
 6. window.history manipulation (can't really target specific domains
 though)
 7. Clickjacking (out of scope, as Mozilla hopefully considers these to be
 a security issue?)

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/3600#comment:21>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list