[tor-bugs] #10703 [TorBrowserButton]: Fallback charset enables fingerprinting of bundle localization

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Aug 30 05:54:10 UTC 2016


#10703: Fallback charset enables fingerprinting of bundle localization
-------------------------------------------------+-------------------------
 Reporter:  dcf                                  |          Owner:
                                                 |  mikeperry
     Type:  defect                               |         Status:  closed
 Priority:  Medium                               |      Milestone:
Component:  TorBrowserButton                     |        Version:
 Severity:  Normal                               |     Resolution:  fixed
 Keywords:  tbb-fingerprinting, tbb-pref,        |  Actual Points:
  MikePerry201402R                               |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------
Changes (by dcf):

 * status:  reopened => closed
 * resolution:   => fixed


Comment:

 Replying to [comment:18 xfix]:
 > The bug appears to still exist, and can be checked on
 https://hsivonen.com/test/moz/check-charset.htm

 Thanks for this. I've checked it out, and it appears to be a separate
 issue from this ticket. So I've re-closed this ticket and opened a new
 one: #20025.

 Strangely, I can only reproduce #20025 on an HTTPS server with HSTS. I
 tested several variations, including Content-Encoding, and HSTS is the
 only factor that seemed to make it work. The hsivonen.com server has HSTS.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10703#comment:19>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list