[tor-bugs] #6458 [Tor Browser]: Disable HSTS for third party content on non-HSTS domains
Tor Bug Tracker & Wiki
blackhole at torproject.org
Mon Jan 5 13:36:47 UTC 2015
#6458: Disable HSTS for third party content on non-HSTS domains
-------------------------+-------------------------------------------------
Reporter: | Owner: tbb-team
mikeperry | Status: new
Type: defect | Milestone:
Priority: major | Version:
Component: Tor | Keywords: tbb-linkability, tbb-bounty, tbb-
Browser | firefox-patch
Resolution: | Parent ID:
Actual Points: |
Points: |
-------------------------+-------------------------------------------------
Comment (by mikeperry):
Here's a PoC I came across:
http://www.radicalresearch.co.uk/lab/hstssupercookies/
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/6458#comment:8>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list