[tor-bugs] #31324 [Applications/Tor Browser]: Spoof the Tor Browser time displayed to websites

Tor Bug Tracker & Wiki blackhole at torproject.org
Sat Aug 3 05:52:22 UTC 2019


#31324: Spoof the Tor Browser time displayed to websites
--------------------------------------+----------------------------------
 Reporter:  cypherpunks               |          Owner:  tbb-team
     Type:  enhancement               |         Status:  closed
 Priority:  Medium                    |      Milestone:
Component:  Applications/Tor Browser  |        Version:  Tor: unspecified
 Severity:  Normal                    |     Resolution:  not a bug
 Keywords:                            |  Actual Points:
Parent ID:                            |         Points:
 Reviewer:                            |        Sponsor:
--------------------------------------+----------------------------------

Comment (by tom):

 I actually tend to agree with cypherpunks here.  I don't think it's
 something we should work on in the short - or even medium term - BUT...

 Mozilla had vaguely discussed the idea of building in roughtime in the
 browser, but then we were stymied on what we would actually *use* it for.
 We thought we could use it for showing an accurate "Your clock is set
 wrong and that may be why you're getting cert errors" error page. But we
 were afraid of using it for anything else - like cert validation or
 Javascript - because people do actually rely on setting their system clock
 back or forward to test cert things or (more commonly) to cheat at online
 Javascript games.

 But I don't think those things would preclude Tor Browser from doing the
 safer thing and a) getting an accurate clock from <something> and b) using
 it for everything. Under the guise of a) preventing NTP attacks and b)
 preventing fingerprinting based on clock skew.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/31324#comment:5>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list