[tor-bugs] #17208 [Tor Browser]: New reported disk leaks in Tor Browser

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Oct 2 14:05:31 UTC 2015


#17208: New reported disk leaks in Tor Browser
---------------------------------+---------------------------
     Reporter:  arthuredelstein  |      Owner:  tbb-team
         Type:  defect           |     Status:  new
     Priority:  normal           |  Milestone:
    Component:  Tor Browser      |    Version:
   Resolution:                   |   Keywords:  tbb-disk-leak
Actual Points:                   |  Parent ID:
       Points:                   |    Sponsor:
---------------------------------+---------------------------

Comment (by arthuredelstein):

 Replying to [comment:1 teor]:
 > We could randomise LastWritten in the state file, but unfortunately, on
 many OSs, the file metadata on disk would record access dates & times
 anyway.

 Good point. So we would need to modify the file metadata as well. `touch`
 is an example of a program that can do this.

 > Also see #17188, if we do randomise this, we should randomly *subtract*
 some time from the times written in the file.

 Unfortunately, in the case given in the presentation above, we would
 perhaps need to subtract hours or days to sufficiently protect the user.
 How much time could be subtracted before we lose the benefits of
 LastWritten?

 Is there any alternative way for tor to detect clock changes without
 storing the last usage on disk?

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/17208#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list