[tor-bugs] #26147 [- Select a component]: Information leaks with automatic searching via URL bar.

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon May 21 16:28:13 UTC 2018


#26147: Information leaks with automatic searching via URL bar.
--------------------------------------+--------------------
     Reporter:  cypherpunks           |      Owner:  (none)
         Type:  defect                |     Status:  new
     Priority:  Medium                |  Milestone:
    Component:  - Select a component  |    Version:
     Severity:  Normal                |   Keywords:
Actual Points:                        |  Parent ID:
       Points:                        |   Reviewer:
      Sponsor:                        |
--------------------------------------+--------------------
 In the Tor browser, if you enter a malformed URL, it immediately thinks
 it's a search query and pushes that malformed URL over to the assigned
 default search (DDG, Startpage, etc)

 This is a type of information leak.

 It would be better if a malformed URL is entered and you press Enter,
 you're asked if you are sure you want to search for this or not.

 It could be in a strip appears under the URL bar, like the strip that
 appears when you first run the Tor browser for the first time asking about
 the default configuration, or a popup from the URL bar, like the enable
 canvas or enable notification popups.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/26147>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list