[tor-bugs] #10703 [TorBrowserButton]: Fallback charset enables fingerprinting of bundle localization

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Feb 14 04:15:39 UTC 2014


#10703: Fallback charset enables fingerprinting of bundle localization
-------------------------+-------------------------------------------------
     Reporter:  dcf      |      Owner:  mikeperry
         Type:  defect   |     Status:  needs_review
     Priority:  normal   |  Milestone:
    Component:           |    Version:
  TorBrowserButton       |   Keywords:  tbb-fingerprinting, tbb-pref,
   Resolution:           |  MikePerry201402R
Actual Points:           |  Parent ID:
       Points:           |
-------------------------+-------------------------------------------------

Comment (by dcf):

 Replying to [comment:13 mikeperry]:
 > We can also remove the code that blacklists UTF-8, if you still think
 that is a better choice?

 Let's do windows-1252 for all locales. I enhanced my detector script to
 distinguish iso-8859-1 and windows-1252, and it turns out that the en-US
 default in 24ESR and 28 beta is windows-1252. windows-1252 is a superset
 of iso-8859-1, it's what Mozilla recommends for a fallback, and it's what
 their `FallbackEncoding::Get` falls back to if it can't understand the
 locale.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10703#comment:14>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list