[tor-bugs] #17367 [Tor Browser]: Swap files can contain evidence of browsing history

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Jan 25 22:49:23 UTC 2016


#17367: Swap files can contain evidence of browsing history
--------------------------------------------+--------------------------
 Reporter:  arthuredelstein                 |          Owner:  tbb-team
     Type:  defect                          |         Status:  new
 Priority:  Medium                          |      Milestone:
Component:  Tor Browser                     |        Version:
 Severity:  Major                           |     Resolution:
 Keywords:  tbb-disk-leak, tbb-disk-traces  |  Actual Points:
Parent ID:  #17208                          |         Points:
  Sponsor:                                  |
--------------------------------------------+--------------------------
Changes (by bugzilla):

 * keywords:  tbb-disk-leak => tbb-disk-leak, tbb-disk-traces
 * severity:  Normal => Major


Comment:

 hiberfil.sys is not your problem, but it is good to warn users that opened
 TBB is copied to disk with all sensitive data (current session) when they
 hibernate (but they must know it from OS manual).
 > Is there any way we can programmatically clean up the pagefile on New
 Identity and/or browser exit? What about OS X and Linux?
 Direct disk access instead of OS ;)

 Now seriously:
 You MUST clean up memory after usage like memwipe in Tor does!

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/17367#comment:6>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list