[tor-bugs] #12999 [Tor Browser]: Use one clock skew per URL bar domain

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Jan 29 02:52:02 UTC 2015


#12999: Use one clock skew per URL bar domain
--------------------------------+------------------------------------------
     Reporter:                  |      Owner:  tbb-team
  arthuredelstein               |     Status:  new
         Type:  enhancement     |  Milestone:
     Priority:  normal          |    Version:
    Component:  Tor Browser     |   Keywords:  tbb-fingerprinting-time-skew
   Resolution:                  |  Parent ID:
Actual Points:                  |
       Points:                  |
--------------------------------+------------------------------------------
Changes (by mikeperry):

 * parent:  #3059 =>


Comment:

 One thing that Arthur and I discussed today was adding some kind of RELAY
 cell command to obtain the current time from the exit. In retrospect, this
 also seems bad, because the exit could use this to lie to you about the
 current time to get you to accept an expired or invalid SSL cert, or to
 generally cause havock on your notion of time for a webapp.

 Another option is to periodically run tlsdate-style time lookups using a
 helper app independent from Tor, and use that for time. I think this may
 actually be the sanest approach.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/12999#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list