[tor-bugs] #18589 [Applications/Tor Browser]: Tor browser writes SiteSecurityServiceState.txt with usage history

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Apr 3 16:58:37 UTC 2017


#18589: Tor browser writes SiteSecurityServiceState.txt with usage history
--------------------------------------+--------------------------
 Reporter:  cypherpunks               |          Owner:  tbb-team
     Type:  defect                    |         Status:  assigned
 Priority:  High                      |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Major                     |     Resolution:
 Keywords:  tbb-disk-leak             |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+--------------------------

Comment (by gacar):

 Replying to [comment:13 gk]:

 > Interesting. Does the same happen with a vanilla Firefox 45.8.0esr? How
 did you test that?

 No, Firefox 45.8.0esr stores the HSTS and HPKP pins from all sites.

 I start with a fresh profile, visit HSTS/HPKP enables sites such as
 github.com, ssllabs.com and metrics.torproject.org. Then I close the
 browser and check the SiteSecurityServiceState.txt contents.

 Vanilla ESR stores GitHub, ssllabs and metrics.torproject.org HSTS (and
 HPKP where available) pins, whereas TB only stores entries related to
 torproject.org.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/18589#comment:14>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list