[tor-bugs] #16617 [Tor Browser]: Potential security hole du to cache policy

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Jul 20 19:50:48 UTC 2015


#16617: Potential security hole du to cache policy
-------------------------+----------------------------------
 Reporter:  gojul        |          Owner:  tbb-team
     Type:  defect       |         Status:  new
 Priority:  normal       |      Milestone:  Tor: unspecified
Component:  Tor Browser  |        Version:  Tor: unspecified
 Keywords:               |  Actual Points:
Parent ID:               |         Points:
-------------------------+----------------------------------
 Hi,

 I've remarked that Tor browser on-disk cache is actually set to the
 default, i.e. 1024 MB of storage on hard drive. Such an information could
 be actually used to leak information about which web pages were actually
 opened by the user. Setting this hard disk cache by default to zero would
 actually solve the issue, and displaying a warning if this setting is
 altered would also be fine.

 Rgds,

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/16617>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list