[tor-bugs] #15580 [Tor Browser]: Update design doc for TBB 4.5

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Apr 30 19:20:43 UTC 2015


#15580: Update design doc for TBB 4.5
-------------------------+-------------------------------------------------
     Reporter:           |      Owner:  mikeperry
  mikeperry              |     Status:  new
         Type:  task     |  Milestone:
     Priority:  normal   |    Version:
    Component:  Tor      |   Keywords:  TorBrowserTeam201504, tbb-4.5-alpha
  Browser                |  Parent ID:
   Resolution:           |
Actual Points:           |
       Points:           |
-------------------------+-------------------------------------------------

Comment (by gk):

 I have feedback up to the fingerprinting part. The two bigger things in
 the attached patch are that tracking with HTTP works perfectly fine
 without having JavaScript enabled and that we did not fully isolate
 `URL.createObjectURL` to the URL bar domain but rather just disable it in
 worker contexts for now.
 One thing that confused me and is not reflected in the patch is the "IP
 address, Tor Circuit, and HTTP Keep-Alive linkability" part. I did not
 really get what the IP address isolation adds/means in this context. And
 mixing somehow IP address unlinkability and Tor circuit unlinkability in
 {{{
 The Tor client has
 logic to prevent connections with different SOCKS usernames and passwords
 from
 using the same Tor circuit, which provides us with IP address
 unlinkability.
 }}}
 makes it a bit confusing. I think we should just omit the IP address
 references and talk about Tor circuit unlinkability in these cases. This
 makes the point in a straightforward way without distinguishing between
 both.

 I like the fingerprinting introduction really well. It occurred to me that
 we can make our position even clearer but then I got distracted by the
 HTTP submission. I'll provide a second patch for that and review the rest
 of it as soon as I can. Might not be tomorrow or over the weekend but I am
 optimistic that we can send the mail to Nick on Monday.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/15580#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list