[tor-bugs] #32002 [Applications/Tor Browser]: Double-check Storage Access API for disk leaks and 3rd party cookie blocking adherence

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Oct 8 13:48:03 UTC 2019


#32002: Double-check Storage Access API for disk leaks and 3rd party cookie
blocking adherence
-------------------------------------+-------------------------------------
     Reporter:  gk                   |      Owner:  tbb-team
         Type:  task                 |     Status:  new
     Priority:  Medium               |  Milestone:
    Component:  Applications/Tor     |    Version:
  Browser                            |   Keywords:  tbb-disk-leak,
     Severity:  Normal               |  TorBrowserTeam201910
Actual Points:                       |  Parent ID:
       Points:  0.2                  |   Reviewer:
      Sponsor:                       |
-------------------------------------+-------------------------------------
 The [https://developer.mozilla.org/en-US/docs/Web/API/Storage_Access_API
 Storage Access API] is a means to prevent trackers across origins yet to
 not break authentication flows and other benign 3rd party identifier
 usage.

 We should make sure it's not using the disk in our default Tor Browser
 mode.

 Moreover, we disable third-party cookies outright, mainly because we have
 not looked at the first-party isolation yet (#21905), and we should make
 sure this is not bypassed in non-private-browsing-mode contexts.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/32002>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list