[tor-bugs] #30599 [Applications/Tor Browser]: Cloudflare alt-svc onions cause a different exit to be used at each request

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Jan 17 01:34:26 UTC 2020


#30599: Cloudflare alt-svc onions cause a different exit to be used at each request
--------------------------------------+-----------------------------------
 Reporter:  cypherpunks2              |          Owner:  tbb-team
     Type:  defect                    |         Status:  needs_information
 Priority:  High                      |      Milestone:
Component:  Applications/Tor Browser  |        Version:
 Severity:  Normal                    |     Resolution:
 Keywords:  ux-team                   |  Actual Points:
Parent ID:  #30024                    |         Points:
 Reviewer:                            |        Sponsor:  Sponsor27-must
--------------------------------------+-----------------------------------
Changes (by sysrqb):

 * status:  new => needs_information


Comment:

 After some more investigation, I can't reproduce this. The failure I
 mentioned in #27502 was most likely because I triggered a full page reload
 which bypassed the cache (shift-reload). I didn't realize at that time
 reloading a page like that ignores validated alt svc addresses, as well.
 There is some delay between receiving a response advertising an alt-svc
 and when the browser actually uses it, but I haven't witnessed switching
 between alt-svc and original. I tested zerobin.net as well, and saved a
 paste. I then loaded that paste in another tab and I found it was loaded
 over the alt svc.

 Maybe this was a bug that existed in 60esr or it was a bug caused by
 Cloudflare (or both). I'd like to know if anyone is still experiencing
 this in a reproducible way.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/30599#comment:11>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list