[tor-bugs] #8706 [Firefox Patch Issues]: .recently-used.xbel contains filenames if browser stored them to disk (was: .recently-used.xbel contains TBB filename (Debian Linux))

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Jul 8 09:23:12 UTC 2014


#8706: .recently-used.xbel contains filenames if browser stored them to disk
-------------------------------------+-------------------------------------
     Reporter:  runa                 |      Owner:  mikeperry
         Type:  defect               |     Status:  new
     Priority:  normal               |  Milestone:
    Component:  Firefox Patch        |    Version:
  Issues                             |   Keywords:  backport-to-mozilla,
   Resolution:                       |  tbb-disk-leak
Actual Points:                       |  Parent ID:
       Points:                       |
-------------------------------------+-------------------------------------
Changes (by cypherpunks):

 * owner:  erinn => mikeperry
 * keywords:   => backport-to-mozilla, tbb-disk-leak
 * component:  Tor bundles/installation => Firefox Patch Issues


Comment:

 > A forensic analysis of the Tor Browser Bundle on Debian Linux (#8166)
 showed that the file ~/.recently-used.xbel contains the filename of the
 Tor Browser Bundle tarball: tor-browser-gnu-linux-x86_64-2.3.25-5-dev-en-
 US.tar.gz, as well as the time and date it was added, modified, and
 visited.
 This item was saved not by Tor Browser process but download manager or
 whatever that used to save bundle to disk. You can't prevent this item to
 appear by Tor Browser intervention if it doesn't exist yet.

 But this file contains Tor Browser's stuff too, when user saves any files
 to disk, includes html pages.
 Look at [https://www.mail-archive.com/xfce4-commits@xfce.org/msg39495.html
 Midori], it prevents unwanted stuff. Firefox in private mode should to
 prevent that stuff too. If not then Tor Browser need to be patched
 separately.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/8706#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list