[tor-bugs] #16856 [Tor Browser]: 'network.http.speculative-parallel-limit' default setting provides tracking-risk

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Aug 20 15:01:21 UTC 2015


#16856: 'network.http.speculative-parallel-limit' default setting provides
tracking-risk
-----------------------------+-------------------------------
     Reporter:  RickGeex_    |      Owner:  tbb-team
         Type:  defect       |     Status:  needs_information
     Priority:  major        |  Milestone:
    Component:  Tor Browser  |    Version:
   Resolution:               |   Keywords:
Actual Points:               |  Parent ID:
       Points:               |
-----------------------------+-------------------------------

Comment (by hap-penis):

 Duplicate of #16840 https://trac.torproject.org/projects/tor/ticket/16840


 Replying to [comment:1 gk]:
 > What makes you sure we are susceptible to this risk given that
 >
 > a) We set `network.predictor.enabled` to `false`
 > b) We are in Private Browsing Mode and "The seer does not record any
 data, nor does it take any action, when in private browsing mode."
 (https://wiki.mozilla.org/Privacy/Reviews/Necko)
 > c) The seer should not be active at all given that we are using a proxy,
 see: https://gitweb.torproject.org/tor-
 browser.git/tree/netwerk/base/nsIOService.cpp?h=tor-
 browser-38.2.0esr-5.5-1#n1540)
 >
 > ?

 That's good news! So... are we sure there's no new connections on link
 hover?

 Aside / off topic: What about some of the other automatic connections
 listed in: https://support.mozilla.org/en-US/kb/how-stop-firefox-making-
 automatic-connections#w_prefetching
 Like link prefetching?:
 {{{<link rel="prefetch" href="/images/big.jpeg">}}}
 {{{network.prefetch-next}}} is set to true in TBB.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/16856#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list