[tor-bugs] #3600 [Tor Browser]: Prevent redirects from transmitting+storing cookies+identifiers

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Jan 5 20:57:02 UTC 2015


#3600: Prevent redirects from transmitting+storing cookies+identifiers
-------------------------+-------------------------------------------------
     Reporter:           |      Owner:  tbb-team
  mikeperry              |     Status:  new
         Type:  defect   |  Milestone:  TorBrowserBundle 2.3.x-stable
     Priority:  major    |    Version:
    Component:  Tor      |   Keywords:  tbb-linkability, tbb-testcase, tbb-
  Browser                |  torbutton
   Resolution:           |  Parent ID:
Actual Points:           |
       Points:           |
-------------------------+-------------------------------------------------

Comment (by mikeperry):

 With double-keyed cookies, we could make redirect destinations behave like
 third parties of the redirecting site for purposes of cookie storage,
 cache storage, DOM storage, etc. This may require complicated state
 keeping for chained redirects, unless we simply ignore redirect chains..

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/3600#comment:26>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list